Digital apocalypse: the road to destruction

Without warning, a power station shuts down. Moments later, others. Cities are blacked out, but in the grid control room the screens show nothing wrong. Simultaneously, air traffic control fails, as do traffic lights. The stock market collapses under a barrage of fake transactions, erasing billions of dollars in minutes. Security of the domain name system collapses too, and news sites are hijacked to spread false information. Enemy hackers have taken control. It's the Digital Apocalypse.

Apocalypse

(Apocalypse film image by Kevin Dooley, CC2.0)

Could it actually happen?

The US Department of Defense takes the threat seriously and now considers the cyber realm to be the fifth battle-space, along with land, sea, air and space.

Speaking at the RSA Conference in San Francisco yesterday, US Deputy Secretary of Defense William Lynn said that the attacks his team has seen so far have only caused disruption — relatively unsophisticated, short in duration and narrow in scope. But the most dangerous networked threats could cause actual physical damage — as Stuxnet did to Iran's nuclear program.

"It is possible to imagine attacks on military networks or critical infrastructure like our transportation system and energy sector that could cause severe economic damage, physical destruction or even loss of life," he said. "A couple dozen programmers wearing flip-flops and drinking Red Bull can do a lot of damage."

But elsewhere in the conference, a panel of information security specialists hosed down some of the more elaborate scenarios.

"Electric companies are in the business of safety and reliability, so from a contingency plan perspective they've pretty much got it down cold," said Mike Echols, critical infrastructure protection program manager for the Salt River Project, one of Arizona's largest power and water utilities, adding that disrupting multiple power stations "would take a pretty sophisticated hacker".

The energy sector is more prepared than many people imagine, Echols said. A sector-wide computer emergency response team (CERT) is being formed with assistance from the Department of Energy. The industry already liaises with the military.

The telecommunications system is similarly robust, according to Bob Dix, who works on critical infrastructure protection for Juniper Networks.

"Last year the IT sector and the telecommunications sector conducted a pretty extensive risk assessment against a set of functions that we deliver," Dix said. "We are, by and large, resilient in these systems."

There's similar confidence in the finance sector.

"A lot of it comes down to resiliency," said Justin Peavey, chief information security officer for financial services solutions provider Omgeo. That resiliency comes from conscious design and testing, and sometimes just through the diversity of systems developed over years: mainframes running COBOL alongside modern servers.

There's also no single place to attack. "The financial industry has no heart," Peavey said, to audience laughter. "Nothing to drive that stake through," added Echols.

"It's kind of like trying to attack transportation," Peavey said. "Maybe you can cause traffic jams some place. Maybe you could take out a car or two, or bus... What we're talking about here is the differentiation between an attack that might bring down a component, a company, maybe even a major data feed, versus the topic of this session here, which is cyber apocalypse."

According to Peavey, an attacker probably wouldn't even have a suitable test environment consisting of disparate mainframes and market interfaces to develop a complex attack that would work the first time without being detected. And while millions of fraudulent transactions would undermine trust, trust can be restored by rolling back to the last-known good system state.

Yet not all share the optimism. "I have to disagree with my colleagues here a little bit," said Dmitri Alperovitch, vice president of threat research with McAfee. "There is a lot of resiliency in all these industries. Unfortunately, a lot of that resiliency was designed with a mindset of safety as opposed to security."

The lesson from Stuxnet, for example, was that operators looking at control room screens are useless if those screens are being fed false data.

Alperovitch's definition of a digital apocalypse is "anything that dramatically changes our way of life", including events that cause mass casualties.

"The stock market shutting down for a couple hours, not a big deal. If it's down for a month, that has huge implications for the rest of the economy," he said. "When we had the 48-hour blackout, we survived. Not a big deal. Birth rates went up. If that had lasted for weeks and months, our entire world could change."

For Dix, the key concern is control systems. "People used to ask me what kept me up at night. It would be a simultaneous physical attack and an attack on the control system that controlled the ability to get water out of fire hydrants, to control traffic systems. That kind of simultaneous event worries me even today," he said.

"We need to understand the capabilities in this cyber realm can kill people, and folks need to understand that capability is here today."

Stilgherrian is attending the RSA Conference in San Francisco as a guest of Microsoft.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

A short commentary on major Social Media stuff ups and mistakes. Remember some of these? http://t.co/iYaRwew0 #in

Westpac board goes paperless with iPads http://t.co/dBaSipFk Opportunity for an alternate revenue stream? Secure apps for business.

JobWatch: where the #jobs are http://t.co/GmTv3FbC via @zdnetaustralia

Are specific gaming development degrees bollocks? http://t.co/z2zbaWvT ^ST

Google kicks Oracle in its patent teeth | ZDNet http://t.co/0K1NGnVM

Way to go Successfactors! #SAP #SAPRocks #sydney
http://t.co/AIq71RCn

Westpac board goes paperless with iPads http://t.co/JpLtmTgW via @zdnetaustralia

Apple's next iPhone: 4-inch display; 12.5% more productivity http://t.co/1DnHrEHX

by http://t.co/vmlLt4bh: Google didn't infringe on Oracle patents: jury: A jury has unanimously decided that Goog... http://t.co/M5ftCLct

NSW Govt appoints Silicon Valley champion http://t.co/5pIEloDg

HP is planning to cut 27,000 jobs by 2014 as part of a massive company restructure. http://t.co/tQzU1wcA ^ML

Google didn't infringe on Oracle patents: jury: A jury has unanimously decided that Google did not infringe on t... http://t.co/HqEqNSvp

HP to slash 27,000 jobs http://t.co/5yB4UmPK

Google didn't infringe on Oracle patents: jury: A jury has unanimously decided that Google did not infringe on t... http://t.co/u4J2Y3Vg

The jury has ruled: Google didn't infringe on Oracle's patents http://t.co/2oGS0os5 ^ST

RT @zdnetaustralia: Telstra to launch its first 4G Windows phone, the HTC Titan: http://t.co/9QyDsgrT ^LH

Take a look at the most recent App Wrap by @zdnetaustralia. What app could you not live without? http://t.co/402W5eo6

The new @MDSNZ courses come up for some lively discussion on @ZDNetAustralia http://t.co/L4TOpTtL

SA Health's journey to e-health http://t.co/wbCN7eRk

Targeted Malware still the popular choice of entry... http://t.co/HhIMyzKN

The IT Industry is in a state of transition never more evident than with HP
http://t.co/cycwD1vH

Targeted Malware still the vehicle of choice
http://t.co/Q1yAFe67

Lets throw Windows RT in the mix of Android and iOS mobile devices. Some of the management features of Windows RT means easier LOB (Line...

2 hours ago by fhemani on Windows 8 set for BYOD: Microsoft

The pros and cons of social media classrooms | ZDNet http://t.co/IecM2sd2

If getting a degree was only about getting *any* job, then I would agree that a more specialised program might limit opportunities. Howe...

2 hours ago by Mario Wynands on Surely IT is more than just a game?

Looks interesting: Your ownClloud RT @hdiblasi: Build your own open-source cloud with ownCloud 4 http://t.co/mJVyNGsC

Happy ending to absurd patent abuse story. Jury clears Google of infringing on Oracle patents http://t.co/ftUc4VDV

Jury clears Google of infringing on Oracle patents http://t.co/wckh6e8Z

Iceland taps Facebook to rewrite its constitution http://t.co/YqeTxhCz

RT @DellEnterprise: Dell Secureworks talks with ZDNet about Android's biggest #security flaws - http://t.co/LSFLQVFq #infosec

RT @oztechguy: Telstra to launch first 4G Windows phone http://t.co/ODcr16E3 but to business only! How disappointing

Live Webcast: Turning Data into Business Insight with Analytics http://t.co/HrCcLbpe

National Botnet Network coming: Earthwave - ZDNet Australia http://t.co/VDkypo8J [will make application level DOS more apparent]

#Cybercrime golden age over in two years? - #Security - #News - http://t.co/4VOZ5Jah

I'm the Chair of the NZ Game Developers Association, and have also consulted or worked for the Universities of Auckland, Otago and Waikat...

3 hours ago by sknightly on Surely IT is more than just a game?

Learning only matters if it helps you cross the bridge between where you are & where you want to be. In this respect, if where you want ...

3 hours ago by mitch.olson on Surely IT is more than just a game?

Targeted attacks using malware still the preference http://t.co/08BTpDTO

15 Oct 2007 It's a good thing that Kim Kardashian has a new show on E! titled "Keeping Up With the Kardashians" because it appears that i...

3 hours ago by Amampnema on IT Business Forum overcomes political uncertainty

As one of the founders of an 18 person game developer in NZ, I can tell you that your fears are not justified. We hire graduates from th...

3 hours ago by JonathanRogers on Surely IT is more than just a game?

@butterflyeffecs - really? Seriously?! You actually expected more of zdnet??? This article really does take the cake though - its gone we...

12 hours ago by lex on Android fragmentation steers Vic Health

Goods Shopping Location Discount Of Japan's Largest Abroad Train Brands. Coach Escape Shelter 89% Off.We Entertain Jammed Items Such As A...

14 hours ago by befeffofs on Reservoir blogs: Fan fakes Tarantino diary

1963年ナイキの創業者フィル・ナイトが訪日、オニツカ(現アシックス)の経営陣を訪問。 最新の機能性や斬新なデザインによって、常に新しいもの求める若者たちの心を掴んできたナイキスニーカー。今回はエアジョーダンやエアマックスなど、ナイキスニーカーの歴史に欠かせない名品から今...

14 hours ago by Speerbprayexy on Reservoir blogs: Fan fakes Tarantino diary

14 hours ago by Ideoforie on Reservoir blogs: Fan fakes Tarantino diary

Ferragamo Shoes Is Distinguished Brand.Ferragamo Is So Baby Valuation Broaden, It Is Secure To Shopping Outlet Online Stores.Ferragamo Ba...

14 hours ago by axollaCrake on Reservoir blogs: Fan fakes Tarantino diary

We Are Specialty Fit out Miu Miu Handbags, Miu Miu Purse, Miu Miu Sunglasses And So On. Miu Miu Sale Online Big Reduction With No Trade O...

14 hours ago by MoxboowsVix on Reservoir blogs: Fan fakes Tarantino diary

Pay off Trainer Wallet&Coach Pocket In Our Coach Store With Sad Sacrifice And Finish Quality, Save 80% Off. Cheap Carriage Overnight bag ...

14 hours ago by Fefinfani on Reservoir blogs: Fan fakes Tarantino diary

クリスチャン ルブタンは靴職人としてのスピリットが強いことで有名で、インタヴューでは下記のように語っています。Christian Louboutin「私は女性に、私の作る靴をファッションとは別の領域のにある、美の対象としてみてほしい。靴というものはアクセサリーではなく、その...

15 hours ago by ganitaickexia on Reservoir blogs: Fan fakes Tarantino diary

Celine luggage,Celine carrier bag,pocketbook Celine,CELINE Celine is synonymous with trait and fastidiousness prevalent since founding in...

15 hours ago by unulseDralola on Reservoir blogs: Fan fakes Tarantino diary

15 hours ago by Elundaninulge on Reservoir blogs: Fan fakes Tarantino diary

Normally would expect better from zdnet. I call BS. It appears that if you look at their decision it is about using HTML5 to develop thei...

16 hours ago by butterflyeffecs on Android fragmentation steers Vic Health

oBoDwZrOrsjUq //www.2012chanelbagsforsale.com]chanel handbags gWbyPIERM niLqoOE //www.2012chanelbagsforsale.com]chanel outlet hBaJhfpEu...

16 hours ago by khngmspwbzm on Deakin Uni opts for Cisco Unified Computing

Akku Asus A32-K72 Original,Kompatibler Ersatz akku für Li-ion Asus A32-K72 Original Laptop Akkus Asus A32-K72 Original,A32-K72 Original...

17 hours ago by akkuakku on HP Compaq 6730b

It is great to see the NSW government taking this step, however there's plenty of home-grown talent loeaving or being rediverted due to l...

18 hours ago by Aceyducey on NSW Govt appoints Silicon Valley champion

This story has been voted 10 times in the last 24 hours!

1 day ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

1 day ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar