Results 1 to 20 of 120

Thread: Cyber attacks on the USA (catch all)

Threaded View

Previous Post Previous Post   Next Post Next Post
  1. #9
    Council Member
    Join Date
    Oct 2007
    Posts
    717

    Default

    "CIA Confirms Cyber Attack Caused Multi-City Power Outage" 18 January, 2008, The SANS Institute at Merit Network Email Archives:

    SANS FLASH
    CIA Confirms Cyber Attack Caused Multi-City Power Outage

    On Wednesday, in New Orleans, US Central Intelligence Agency senior analyst Tom Donohue told a gathering of 300 US, UK, Swedish, and Dutch government officials and engineers and security managers from electric, water, oil & gas and other critical industry asset owners from all across North America, that "We have information, from multiple regions outside the United States, of cyber intrusions into utilities, followed by extortion demands. We suspect, but cannot confirm, that some of these attackers had the benefit of inside knowledge. We have information that cyber attacks have been used to disrupt power equipment in several regions outside the United States. In at least one case, the disruption caused a power outage affecting multiple cities. We do not know who executed these attacks or why, but all involved intrusions through the Internet."

    According to Mr. Donohue, the CIA actively and thoroughly considered the
    benefits and risks of making this information public, and came down on
    the side of disclosure.
    CIA: Hackers Shook Up Power Grids by Noah Shachtman at Danger Room; Noah's got some more on this, including a Washington Poat article and Michael Tanji's take on this.

    More Cyber War Gouge at Defense Tech:

    The CIA went on to say they suspect, but cannot confirm, that some of these attackers had the benefit of inside knowledge. The very next day the Federal Energy Regulatory Commission (FERC) approved eight mandatory cyber security standards that extend to all entities connected to the nation's power grid. The following are the eight areas addressed by these standards:

    1. Critical cyber asset identification
    2. Security management controls
    3. Personnel and training
    4. Electronic security perimeters
    5. Physical security of critical cyber assets
    6. System security management
    7. Incident reporting and response planning
    8. Recovery plans for critical cyber assets

    These eight standards were created to increase the security of our CIP and reduce the risk of a successful attack. Disruption of a county’s critical infrastructure would have significant direct and indirect damages. Most of these damages would be psychological, economic and financial. Analysis of a cyber attack on critical infrastructure targets resulted in the following data:

    Target value: High
    Impact analysis: Elevated
    Required skills: Moderate
    Attack costs: Low
    Current defenses: Moderate (elevated for nuclear sites)
    More, including a references link, at the link.

    What are these attackers doing this for, simply money? Or something else?
    Last edited by Norfolk; 01-19-2008 at 08:44 PM. Reason: Added even more stuff.

Similar Threads

  1. Russo-Ukraine War 2016 (April-June)
    By davidbfpo in forum Europe
    Replies: 1088
    Last Post: 07-01-2016, 08:44 PM
  2. The Threat from Swarm Attacks (catch all)
    By davidbfpo in forum Doctrine & TTPs
    Replies: 4
    Last Post: 08-07-2012, 11:42 AM
  3. USAF Cyber Command (catch all)
    By selil in forum Media, Information & Cyber Warriors
    Replies: 150
    Last Post: 03-15-2011, 09:50 PM
  4. Attacks in Iraq Down Considerably
    By SWJED in forum Blog Watch
    Replies: 1
    Last Post: 01-23-2006, 10:33 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •