New Threats to Utility SCADA Systems

Mission Critical Systems for the Energy Industryfor communication between the master station
Supervisory Control and Data Acquisitionand communications equipment.
(SCADA) systems that collect and manage data- SCADA systems are becoming ubiquitous. Thin
across a large facility from a central computer,clients, web portals, and web-based products are
play a major role in the utility industry, helping togaining popularity with most major vendors. The
manage large and diverse information loads fromincreased convenience of end users viewing their
power plants of all types. Interconnectivity hasprocesses remotely introduces security
made these systems increasingly vulnerable toconsiderations resulting in SCADA-based systems
cyber attacks.being vulnerable to cyber-attacks.
The Growing Vulnerability of SCADA Control- The mission-critical nature of a large number of
SystemsSCADA systems makes them targets of
The control systems for the electric grid used tocyber-terrorist. In a worst case scenario, failure of
operate in a stand-alone environment withouta SCADA system could cause massive financial
computer or communication links to an externallosses through loss of data or actual physical
Information Technology (IT) infrastructure. Overdestruction, misuse or theft, even loss of life,
the past fifteen years such stand-alone enclaveseither directly or indirectly.
have been increasingly connected to both the- SCADA systems no longer have the benefit of
corporate environment and the external world,security-through obscurity that may have existed
and the utility SCADA systems are no exception.in the past from the use of specialized protocols
Computer and communication networkand proprietary interfaces. Increasingly, SCADA
interconnection brings with it thepotential fornetworks are being connected to the Internet.
cyber attacks on these systems by adversaries.- Similar to other networked technologies, SCADA
This is a critical problem since such an attack cannetworks must have physical, administrative, and
affect several entities across the countrytechnical security safeguards.
simultaneously. Such attacks have the enhanced- Security and authentication in designing,
potential to cause a cascading negative effect todeploying, and operating SCADA networks is
the Bulk Power System.paramount. For example, security devices such as
SCADA Control System Threats Are MoreIPS/IDS, firewalls, and other technological security
Vulnerable Than Evermeasures must be deployed to help protect
- SCADA systems are coming in line withSCADA systems. Automated security information
standard networking technologies. The currentmanagement solutions are also needed to help
generation of SCADA systems is increasinglyconsolidate the security logs across the SCADA
using open system architecture to distributesystem wide-area network.
functionality across a wide-area network (WAN)