About the SA Blog Network  

Observations

Observations


Opinion, arguments & analyses from the editors of Scientific American
Observations HomeAboutContact

Thousands of Industrial Systems Unwittingly Hooked Up to Internet


ShareShare  ShareEmail  PrintPrint



The computers that control large industrial control systems—the sewage plants, power stations, and assembly lines that keep civilization running—aren’t supposed to be online. Computers online tend to get hacked, of course, and you wouldn’t want your local power plant under rogue control. But a graduate student was able to locate and map more than 10,000 industrial control systems that are directly connected to the Internet, as reported by Kim Zetter at Wired’s Threat Level Blog. What’s more, only 17 percent of those devices bothered to ask for authorization to connect, suggesting that network managers simply didn’t realize that their control systems were online.

The finding adds a discouraging twist to worries that hackers might take over critical infrastructure. Indeed, individuals have regularly managed to electronically penetrate industrial systems, with destructive real-world consequences. Last year, David Nicol of the University of Illinois described how hackers could conceivably take down a good portion of the U.S. power grid. His analysis relied on simple techniques commonly used by hackers to steal credit cards and the like; never did he assume that the important control systems would be sitting out in the open without any protections in place.

It’s unclear how many of the 10,000 control systems were set up to control critical infrastructure like power stations, says Éireann P. Leverett, the researcher who published the study. He notified the U.S. Department of Homeland Security of his findings last September. But one thing is clear: If, as it appears, this many systems have been online without the knowledge of the people in charge, we can’t let the assumption that something isn’t connected to the Internet take the place of a real security protocol.

Image: Grizzly Peak Sub-Station, California; courtesy of Lawrence Berkeley National Lab

About the Author: Michael Moyer is the editor in charge of technology coverage at Scientific American Follow on Twitter @mmoyr.

The views expressed are those of the author and are not necessarily those of Scientific American.





Post a comment | Read Comments (4)

Comments 4 Comments

Add Comment
  1. 1. MargaretMcFarland 4:37 pm 01/24/2012

    Check out this online job offer, earn up to $90/h working from home -
    C A S H S H A R P . C O M

    Link to this
  2. 2. jtdwyer 5:20 pm 01/24/2012

    (Naive) systems integraters may purposely provide internet connections to facilitate systems support and maintenance…

    Link to this
  3. 3. Nag nostic 2:01 am 01/27/2012

    Hey jtdwyer, do you do anything other than reply to Scientific American articles as they’re posted, each and every day?

    Link to this
  4. 4. bucketofsquid 11:43 am 01/31/2012

    @Nag nostic – JT is retired so he is free to do whatever he wants. Commenting on forums beats the hell out of watching TV and letting his brain jell.

    I want to know what jackass thought that a forum without a report abuse option for posts like post #1 (at the time I’m posting this) which is for a scam site and has nothing to do with the article, would be a good idea. One would think that a science magazine would discourage organized crime instead of encouraging it.

    Link to this

Add a Comment
You must log in or register as a ScientificAmerican.com member to submit a comment.