1.7 Cybersecurity of Power Facilities: Past, Present, and Future
75
and in 2016 Saudi Aramko again was the victim of the same malware. Two years
later, 7 oil piping companies from Energy transfer partners LP to Tras Canada Corp,
made announcements about attempts to damage one-third part of their electronic
and communication networks. The attacks of tremendous scale at power facilities
are constantly happening all over the worlds and their top managers should be well
prepared for them. In fact to safeguard multi-level security of power networks they
should implement the entire complex of measures.
Here it should be noted that creation of malicious software has been getting more
and more trivial task: a “skeleton” of any bug may be purchased at Internet sites
and filled then with any content. The number of tampering attempts and attacks
perpetrated even by unskilled users is building up because criminal services and
malicious software development tools are readily available.
However, far from every cyberaccident in the scope of power facilities go public: as
a rule, big companies tend to refrain from disclosing the facts of their vulnerability
and insecurity. But some of such accidents still enter the public domain. Thus in
Germany in 2014 at thermal power plant 15 years old teenager from his computer
tapped into microcontrollers which were accessible through service center network.
When in control of the thermal power plant he caused emergency shutdown.
The most notorious cyberattack at nuclear power facility took place in 2010 [1].
As it was shown in current chapter software virus Stuxnet penetrated into spinners
control systems at the uranium enrichment plant in Iran and destroyed one-third part
of them. At the result, the plant’s activity was shut down. In this joint covert operation
by special forces of the USA and Israel there were used bug triggered hardware
Trojans in Siemens’s microcontrollers the spinners were controlled by. The worms
were built-in microcontroller design without the privity of company-producer.
In 2015 in Ukraine an “unidentified violator” using malicious software Black
Energy intercepted control over power supply networks and simultaneously blackedout a few provinces. Meanwhile, the systems of electric power networks operators
were blocked out: they could watch how shutdown was going on, but could not
interfere and prevent it.
The experts believed that in the course of this attack there supposedly had been
altered the RTU Configurations (hardware and software devices of medium level of
Automated Control System for Technological Process) which actually joins bottom
and top levels of Automated Control System for Technological Process. As a consequence there was destroyed the data at Computerized Workbenches of dispatch operators; call-centers of electric network companies were subjected to DD0S-strikes
(the attacks targeted at service\maintenance failure). As it frequently happens, the
results of investigating cyberattacks which were followed by de-energization at 7 pcs.
110 kV and 23 pcs 35 kV transforming substations and black-outs in five regions
of the country for 6 h called in questions and invoked lot of guesses and assumptions. However, if geopolitical considerations and version about violators are set
aside, let us heed our attention to the following events: the attacks of Black Energy at
Ukrainian power network were detected and recorded even in 2014 and in September
of the same year at least experts of Eset company warned about possibility of striking
Précédent

- 97/839

Suivant