20
Hacking the Smart Grid OWASP Tampa 1

Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

  • Upload
    others

  • View
    15

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

Hacking the Smart GridOWASP Tampa

1

Page 2: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

Presenter

Tony Flick

Principal, FYRM Associates

Over 6 Years in Information Assurance

2

Page 3: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

AgendaWhat is the smart grid?

Known problems

Security initiatives

Timeline

History repeating

Web Application Interfaces

Recommendations

3

Page 4: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

What is the Smart Grid?

Current infrastructure

Future infrastructure

4

Page 5: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

What Makes up the Smart Grid?

Devices

Network infrastructure

Bi-directional communication

5

Page 6: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

Problems

Physical security

Bi-directional communication introduces attack vectors

Same problems as every other type of network/application

6

Page 7: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

Implications

Privacy Concerns

Denial-of-Service

Electricity theft

7

Page 8: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

Security Initiatives

The Energy Independence and Security Act of 2007

NIST Interoperability Framework

Advanced Metering Infrastructure System Security Requirements (AMI-SEC)

NERC CIP 002-009

8

Page 9: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

Timeline - Part 1Examples of Integrating Security from the beginning (2006 - 2009):

Energy Independence and Security Act of 2007

NIST Smart Grid Interoperability Framework

Initial list of standards for inclusion in version 1.0 released on May 8, 2009.

Advanced Metering Infrastructure (AMI) System Security Requirements v1.01

2007 - 2008

NERC CIP

2006, 2009

Critical Electric Infrastructure Protection Act (CEIPA) - (HR 2195)

2009

9

Page 10: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

Timeline - Part 1IDesign and implementation of the smart grid

2002 actually occurred before 2006

Anyone have a flux-capacitor?

Austin - 2002

Salt River Project - 2006

10

Page 11: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

Timeline Repercussions Example• Oncor Energy Timeline

• Purchase 900,000 smart meters

• State issues operating standards

• Replace non-compliant smart meters

• Who do you think is paying for the old and new smart meters?

• Early Adopter fee?

11

Page 12: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

Low Hanging Fruit

Eight Utility Company Web Sites

Sensitive information over clear-text protocols

What amount of security is in a name?

Cross Site Scripting

Information Leakage

12

Page 13: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

The Major Players

iGoogle (PowerMeter)

Microsoft Live (Hohm)

13

Page 14: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

We Have an App For That

Monitor Usage - Current Majority

Control Appliances

iTunes App Store

Energy UFO

14

Page 15: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

Social Networking

Do you want everyone to know how much electricity you are using?

The power of groups

Twitter now

Facebook in the works

15

Page 16: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

Social Networking

16

Page 17: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

Social Networking

17

Page 18: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

Consumer Perspective

You don’t have to sign up for these services

...but then what’s the point?

18

Page 19: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

Duck and Cover?

Fix the low hanging fruit

Opportunity missed at the beginning, but we can still do some good

Allow security to mature

Innovation vs. Security/Regulation

19

Page 20: Hacking the Smart Grid - OWASP · 2020. 1. 17. · NIST Smart Grid Interoperability Framework Initial list of standards for inclusion in version 1.0 released on May 8, 2009. Advanced

General Discussion

If you have any followup questions:

Email me: tony.flick at fyrmassociates.com

20