• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • The Power System Malware Problem, and a ‘Perfect’ Solution

    August 17, 2010 Alex Woodie

    Security products vendor BrickHouse Security issued a warning last week over the malware that foreign computer hackers have placed in critical American industrial components using the Internet. The good news is that the security infiltration has to do with electrical power systems, not the IBM Power Systems servers that run a good chunk of midsize American businesses. The bad news is that bad guys may now have the ability to take everything off line, including your Power Systems servers and the Internet connections that feed them.

    The Wall Street Journal sparked concern across the country with an April report about how Russians and Chinese spies hacked into the American electrical grid in an attempt to map it (apparently, they couldn’t wait for the July 2010 National Geographic map of the three interconnected national grids). The WSJ reports that American intelligence officials detected Trojan Horses left behind by the spies that could be used to damage the grid and, by connection, network communications.

    BrickHouse blogger Stan Shyshkin warns that new “smart grid” technology could make the problem worse. IBM is a big proponent of smart grids, in which sensors are implemented at end points to create a demand feedback loop, thereby lowering power consumption and boosting grid efficiency. “Transforming a largely one-way distribution network like the power grid into a two-way system that sends and receives information from consumers gives the hackers additional entrances into the grid,” Shyshkin writes.

    The National Security Agency (NSA) has stepped up to the plate and is promising to crack down on the security vulnerability with a new program called Perfect Citizen. Unveiled last month, the new program involves installing sensors at companies and organizations that are involved with running the power grid and other critical infrastructure components.

    Perfect Citizen also involves patching the weak links in the grid, such as the end-point sensors in the new smart grids, or “smart meters,” which are based on common off-the-shelf components that hackers could easily deconstruct. Defense contractor Raytheon reportedly has the first Perfect Citizen contract. It’s hard to imagine how IBM, whose experts and technology are involved with counter-terrorism, is not somehow involved with Perfect Citizen.

    The takeaway for Power Systems shops is to realize that threats to security and business continuity today come in many shapes and sizes. Not only must Power Systems shops worry about tornadoes, earthquakes, disgruntled employees, and computer hackers, but now they must consider the ramifications of a greater likelihood of disruptions in access to electricity and network bandwidth. (Malware, ironically, is one of the least of Power Systems shops’ concerns.)

    Granted, if the Western electrical grid is taken offline by hackers, there will be much greater problems for society than companies being unable to access their IBM i applications. Nuclear power plants would be damaged, financial networks would be taken offline, dams would be opened up, and sewage would back up. Even Facebook and Twitter would be effected.

    But as the old saying goes, forewarned is forearmed. Perhaps now is a good time to review your disaster recovery plan, make sure the UPS is functioning properly, and check that there’s plenty of diesel for the generator.



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    Midrange Dynamics North America

    With MDRapid, you can drastically reduce application downtime from hours to minutes. Deploying database changes quickly, even for multi-million and multi-billion record files, MDRapid is easy to integrate into day-to-day operations, allowing change and innovation to be continuous while reducing major business risks.

    Learn more.

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    SEQUEL Software:  FREE Webinar. Aug 25. Learn how SEQUEL simplifies EnterpriseOne data access.
    PowerTech:  FREE Webinar! Top 10 IBM i Security Risks. August 25, 10 a.m. CT
    COMMON:  Join us at the Fall 2010 Conference & Expo, Oct. 4 - 6, in San Antonio, Texas

    IT Jungle Store Top Book Picks

    Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
    The iSeries Express Web Implementer's Guide: List Price, $49.95
    The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
    The System i Pocket RPG & RPG IV Guide: List Price, $69.95
    The iSeries Pocket Database Guide: List Price, $59.00
    The iSeries Pocket SQL Guide: List Price, $59.00
    The iSeries Pocket Query Guide: List Price, $49.00
    The iSeries Pocket WebFacing Primer: List Price, $39.00
    Migrating to WebSphere Express for iSeries: List Price, $49.00
    Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
    Getting Started with WebSphere Express for iSeries: List Price, $49.00
    Can the AS/400 Survive IBM?: List Price, $49.00
    Chip Wars: List Price, $29.95

    Unica Snapped Up By Big Blue for $480 Million IBM Ducks i Pricing on Most Entry Power7 Servers

    Leave a Reply Cancel reply

Volume 10, Number 29 -- August 17, 2010
THIS ISSUE SPONSORED BY:

PowerTech
New Generation Software
RevSoft
Linoma Software
Twin Data Corporation

Table of Contents

  • IBM Rounds Out Entry Power7 Server Lineup
  • IBM Quintuples Performance with the Power 795
  • Experia Touts SilverDev Tool for IBM i
  • Raz-Lee Unveils GUI for IBM i Journal Security Tool
  • RevSoft Delivers Smart Phone Interface for IBM i Monitoring Tool
  • mrc Unveils Software Exchange for m-Power Users
  • IBM i ERP Developer Achieves QA Gains with Original
  • Jack Henry Taps INETCO for Electronic Payment Monitoring
  • SugarCRM Has a Sweet Quarter
  • The Power System Malware Problem, and a ‘Perfect’ Solution

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Meet The Next Gen Of IBMers Helping To Build IBM i
  • Looks Like IBM Is Building A Linux-Like PASE For IBM i After All
  • Will Independent IBM i Clouds Survive PowerVS?
  • Now, IBM Is Jacking Up Hardware Maintenance Prices
  • IBM i PTF Guide, Volume 27, Number 24
  • Big Blue Raises IBM i License Transfer Fees, Other Prices
  • Keep The IBM i Youth Movement Going With More Training, Better Tools
  • Remain Begins Migrating DevOps Tools To VS Code
  • IBM Readies LTO-10 Tape Drives And Libraries
  • IBM i PTF Guide, Volume 27, Number 23

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle