Pakistanis angry over detentions in Times Sq. case Monday, May 24, 2010
ISLAMABAD – Relatives of three men detained by Pakistan for alleged links to the suspect in the attempted Times Square bombing say the men are innocent.
They
AFP - Thursday, August 6TAIPEI (AFP) - - Taiwan's Beijing-friendly government on Wednesday denied boycotting an Australian film festival amid a row over the e
BERLIN (Reuters) - Chancellor Angela Merkel suffered a double blow on Thursday as a senior party ally in east German
Minister seeks closure of anti-Berlusconi websites Wednesday, December 16, 2009
ROME (AFP) - – The Italian government moved Tuesday to close down Internet sites encouraging further violence against Prime Minister Silvio Berlusconi, who
By ELAINE KURTENBACH,AP Business Writer AP - Wednesday, March 18SHANGHAI - Asia's stock market rally seemed to be running out of steam Wednesday, despite an
Edition:
U.S.
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
Home
Business
Business Home
Economy
Technology
Media
Small Business
Legal
Deals
Earnings
Social Pulse
Business Video
The Freeland File
Aerospace & Defense
Markets
Markets Home
U.S. Markets
European Markets
Asian Markets
Global Market Data
Indices
M&A
Stocks
Bonds
Currencies
Commodities
Futures
Funds
peHUB
World
World Home
U.S.
Brazil
China
Euro Zone
Japan
Mexico
Russia
India Insight
World Video
Reuters Investigates
Decoder
Politics
Politics Home
Election 2012
Campaign Polling
Political Punchlines
Supreme Court
Politics Video
Tech
Technology Home
MediaFile
Science
Tech Video
Tech Tonic
Social Pulse
Opinion
Money
Money Home
Tax Break
Lipper Awards 2012
Global Investing
MuniLand
Unstructured Finance
Linda Stern
Mark Miller
John Wasik
James Saft
Analyst Research
Alerts
Watchlist
Portfolio
Stock Screener
Fund Screener
Personal Finance Video
Money Clip
Investing 201
Life
Health
Sports
Arts
Faithworld
Business Traveler
Entertainment
Oddly Enough
Lifestyle Video
Pictures
Pictures Home
Reuters Photographers
Video
Reuters TV
Reuters News
Article
Comments (0)
Follow Reuters
Facebook
Twitter
RSS
YouTube
Read
Russia warns West over Syria after Obama threats
|
21 Aug 2012
Ecuador's leader says open to talks with Britain on Assange
|
21 Aug 2012
Akin rebuffs Romney, Republican, calls to quit Senate race
|
2:57am EDT
Ethiopians mourn strongman ruler Meles, dead at 57
|
21 Aug 2012
Accused Colorado gunman saw three mental health experts: report
21 Aug 2012
Discussed
138
Obama’s lead over Romney grows despite voters’ pessimism
122
Romney to announce vice presidential choice Saturday
94
Analysis: Are Israelis tough enough for a long war with Iran?
Sponsored Links
Pictures
Reuters Photojournalism
Our day's top images, in-depth photo essays and offbeat slices of life. See the best of Reuters photography. See more | Photo caption
Art of Damien Hirst
A look at the unusual and controversial art of Damien Hirst. Slideshow
Longest lived women: Hong Kong
Hong Kong women are now the longest-lived women in the world, overtaking a record formerly held by Japan. Slideshow
U.S. looks into claims of security flaw in Siemens gear
Tweet
Share this
Email
Print
Related News
Insight: Experts hope to shield cars from computer viruses
Mon, Aug 20 2012
Virus found in Mideast can spy on bank transactions
Thu, Aug 9 2012
White House may use executive order to protect key computer networks
Wed, Aug 8 2012
Hopes fade for new U.S. cybersecurity law in 2012
Thu, Aug 2 2012
London ready to fight off Olympic hack attacks
Tue, Jul 24 2012
Analysis & Opinion
Knight Capital’s filings reveal scant oversight focus on tech risks for board
Related Topics
Tech »
Cyber Crime »
By Jim Finkle
BOSTON |
Tue Aug 21, 2012 11:48pm EDT
BOSTON (Reuters) - The U.S. government is looking into claims by a cyber security researcher that flaws in software for specialized networking equipment from Siemens could enable hackers to attack power plants and other critical systems.
Justin W. Clarke, an expert in securing industrial control systems, disclosed at a conference in Los Angeles on Friday that he had figured out a way to spy on traffic moving through networking equipment manufactured by Siemens' RuggedCom division.
The Department of Homeland Security said in an alert released on Tuesday that it had asked RuggedCom to confirm the vulnerability that Clarke, a 30-year-old security expert who has long worked in the electric utility field, had identified and identify steps to mitigate its impact.
RuggedCom, a Canadian subsidiary of Siemens that sells networking equipment for use in harsh environments such as areas with extreme weather, said it was investigating Clarke's findings, but declined to elaborate.
Clarke said that the discovery of the flaw is disturbing because hackers who can spy on communications of infrastructure operators could gain credentials to access computer systems that control power plants and other critical systems.
"If you can get to the inside, there is almost no authentication, there are almost no checks and balances to stop you," Clarke said.
This is the second bug that Clarke, a high school graduate who never attended college, has discovered in products from RuggedCom, which are widely used by power companies that rely on its equipment to support communications to remote power stations.
In May, RuggedCom released an update to its Rugged Operating System software after Clarke discovered that it had a previously undisclosed "back door" account that could give hackers remote access to the equipment with an easily obtained password.
The Department of Homeland Security's Industrial Control Systems Cyber Emergency Response Team, which is known as ICS-CERT, said in its advisory on Tuesday that government analysts were working with RuggedCom and Clarke to figure out how to best mitigate any risks from the newly identified vulnerability.
EASILY AVAILABLE KEY
Clarke said that problem will be tough to fix because all Rugged Operating System software uses a single software "key" to decode traffic that is encrypted as it travels across the network.
He told Reuters that it is possible to extract that "key" from any piece of RuggedCom's Rugged Operating System software.
Clarke obtained RuggedCom's products by purchasing them through eBay.
He conducted the original research in his spare time with equipment spread out on the bed of his downtown San Francisco apartment. Earlier this year, he was hired by Cylance, a firm that specializes on securing critical infrastructure and was founded by Stuart McClure, the former chief technology officer of Intel Corp's McAfee security division.
Marcus Carey, a researcher with Boston-based security firm Rapid7, said potential attackers might exploit the bug discovered by Clarke to disable communications networks as one element of a broader attack.
"It's a big deal," said Carey, who previously helped defend military networks as a member of the U.S. Navy Cryptologic Security Group. "Since communications between these devices is critical, you can totally incapacitate an organization that requires the network."
So far there have been no publicly reported cases of cyber attacks that have caused damage on U.S. critical infrastructure.
The Stuxnet virus was used to cripple Iran's nuclear program in 2010, causing physical damage to a uranium enrichment facility in that nation. Researchers recently found pieces of another virus known as Flame that they believe been used to destroy data in facilities in Iran.
The report on the RuggedCom vulnerability is among 90 released so far this year by ICS-CERT about possible risks to critical infrastructure operators. That is up from about 60 in the same period a year earlier, according to data published on the agency's website.
"DHS works closely with public and private sector partners to develop trusted relationships and help asset owners and operators establish policies and controls that prevent incidents," said DHS spokesman Peter Boogaard. "The number of incidents reported to DHS's ICS-CERT has increased, partly due to this increased communication."
(Editing by Bill Trott)
Tech
Cyber Crime
Related Quotes and News
Company
Price
Related News
Tweet this
Link this
Share this
Digg this
Email
Reprints
We welcome comments that advance the story through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of Reuters. For more information on our comment policy, see http://blogs.reuters.com/fulldisclosure/2010/09/27/toward-a-more-thoughtful-conversation-on-stories/
Comments (0)
Be the first to comment on reuters.com.
Add yours using the box above.
Edition:
U.S.
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
Back to top
Reuters.com
Business
Markets
World
Politics
Technology
Opinion
Money
Pictures
Videos
Site Index
Legal
Bankruptcy Law
California Legal
New York Legal
Securities Law
Support & Contact
Support
Corrections
Connect with Reuters
Twitter
Facebook
LinkedIn
RSS
Podcast
Newsletters
Mobile
About
Privacy Policy
Terms of Use
AdChoices
Copyright
Our Flagship financial information platform incorporating Reuters Insider
An ultra-low latency infrastructure for electronic trading and data distribution
A connected approach to governance, risk and compliance
Our next generation legal research platform
Our global tax workstation
Thomsonreuters.com
About Thomson Reuters
Investor Relations
Careers
Contact Us
Thomson Reuters is the world's largest international multimedia news agency, providing investing news, world news, business news, technology news, headline news, small business news, news alerts, personal finance, stock market, and mutual funds information available on Reuters.com, video, mobile, and interactive television platforms. Thomson Reuters journalists are subject to an Editorial Handbook which requires fair presentation and disclosure of relevant interests.
NYSE and AMEX quotes delayed by at least 20 minutes. Nasdaq delayed by at least 15 minutes. For a complete list of exchanges and delays, please click here.