Tuesday, March 15, 2011

The Smart Grid Brass Ring For Consumers

Since I live and breathe Smart Grid these days (even though I am focused solely on Smart Grid security), I am constantly dumbfounded at the lack of awareness of the Smart Grid by most people I speak to "on the street".  I go to parties, social engagements, or wherever I may travel,  and am asked what I do for a living, and when I tell whoever is inquiring that I work in Smart Grid Cyber Security, the inevitable question is nearly always "What is a smart grid?"

It is particularly interesting when one of my neighbors asks me and I take him (or her) to the meter on the side of their house and point to the recently installed Smart Meter and explain what it is and how it works.  Sometimes I hear comments like "Oh yeah, I heard some people have had their bills go up." or "I hear these cause cancer."

So we are essentially with either no perception of the Smart Grid, or a collection of sound bites that fail to tell the story.

...but what is the story?

What I mean by this is "What is the story from a consumer perspective?"  Why do I want a Smart Meter, or a Smart Grid anyway?

Years ago, before I had a computer, I heard of this "Internet".  It was all over the place, this Internet discussion.  Internet this, Internet that, email, surfing, World Wide Web, @this, .com that, blah, blah, blah.  It was a big joke to those of us who did not partake in the festivities...at least for a little while.

Then the internet became cool.  No, I don't mean cool in a hipster with gel in his hair sense.  I mean that the Internet became an environment where everyone could get something out of it beyond the interesting technology that makes it all work.  It became a fixture.  It started to take off.

The Internet did not really take off until it became something that delivered value to those who partook in it.  Once we realized that we could save money shopping online, save stamps with online banking, save fuel with online shopping, download music, movies, news, entertainment, etc. we all took to it like ants to picnics.  We are hooked.

Then came the whole smart phone revolution.  We discovered that we could not only carry this cool Internet with us, but we could also download interesting "apps" that we could do interesting things with, and suddenly discovered that these apps were something we could no longer live without.

Okay...maybe that is a stretch, but those of us who live happily in the app using world will probably agree that apps are a great thing, and they endear us to our devices.

So that brings me around to the Smart Grid, and consumer adoption.  This morning I saw an article about a new iPhone application called JouleBug, which makes a game out of saving energy.  The application is rather low tech, but it is sort of interesting with good graphics.  It illustrates a conversation I have had with some people in the Smart Grid space, where I insist that what it will take for consumers to "buy into" the Smart Grid is a combination of some sort of savings on power consumption AND an interesting way to interact with the ecosystem.  Sound bites on news programs and lower bills alone will not win us over.  An cool iPhone application (as an example) with cool graphics, push notifications, easy to use, and a general fun feeling may indeed be a winner.  If it gets us to change our energy usage in a positive way...even better.  After all, changing consumer behavior is really what the Smart Grid is about.

We, as humans, are not far removed from the creatures that flock towards bright and shiny things.  Perhaps we are a bit shallow in that regard, but if it gets us to save energy, then so be it.

Just my opinion.

Thursday, March 10, 2011

Knowing What To Ask For

One of my favorite conference speakers has to be Robert Former of Itron.  Robert is the in-house penetration tester at Itron.  He is paid to break things, and it is a job he thoroughly enjoys.  Like many vulnerability testers, he is essentially a no nonsense guy that shoots from the hip.  If you ask Robert a question about security, you are likely to get a very practical (and honest) answer.

One of the comments Robert has made (on more than one occasion) is that AMI vendors deliver what their customers ask for.  Early deployments of Smart Meters lacked many of the security features of today's Smart Meters for two reasons.  One reason was that many of the security concerns we face today simply did not exist in our conscience back then.  Sure, some will argue that we should have known better, and we should have learned our lesson from blah blah blah, but the reality of how we deal with security is only partially pro-active.  Think about this for a moment.  You are not going to walk about town in a bulletproof vest until you realize that there are bullets flying.  You may take a few precautions if you hear news of some people getting shot, but barricading yourself in body armor is not likely unless you are living in a war zone.

So with AMI, despite all the glorious hype we sometimes see, rest assured we are nowhere near a war zone.  Yes, there have been a few shots fired over the bow, but I have yet to hear of any casualties (or, for that matter, any injuries whatsoever).

The other reason why early meters lacked security found in today's meters is because utilities simply did not demand it.  Utilities wanted (and still want) inexpensive, reliable, and easy to manage meters.  Adding security to a meter can directly impact all three of these criteria.  Early deployments were focused on just getting everything to work, and many still are.

Yet we live and we learn...or so we hope.  The fact is that utilities are now keenly aware of the need for security, and they are now beginning to demand it from vendors.

However, this is not necessarily working out as well as it should.

I have had conversations with several vendors who have told me that some potential customers have essentially copied and pasted the entire NIST IR 7628 final report (which is 3 volumes) and said something akin to "do this" to their vendors.  As someone who is currently working on developing testing and certification guidelines for Smart Grid security as part of the NIST Testing and Certification CSWG working sub-group, I can assure you that this is not a good idea.  This is like handing a copy of "Larousse Gastronomique" to a caterer and saying "cook this".

Knowing what to ask for is crucially important for a utility.  Without some type of guidance, utilities are not going to be very effective at making demands.  In fact, without knowledge of what they ask for, utilities are likely to accept anything they are given as a response to their demands.  I mean, how are they going to verify anything anyway?

The work being done in OpenSG is seeking to rectify this.  There are a number of prominent utilities working in OpenSG, but the majority of utilities in the USA are not active members of OpenSG.  There is a wealth of information available to anyone who wants it, and anyone (utility or not) can participate in the work.  By educating themselves about security, utilities can create RFP's in an informed manner, and they can also take advantage of the tools and people available to help them verify that they are getting what they demand.  Getting involved is easy.  Send an email to darren@utilisec.org (who is the current chair), or Bobby@enernex.com (the current co-chair) and you will be on your way.

The answers are out there.

Sunday, March 6, 2011

Travis Goodspeed Outside The Box

You are not likely to forget your first encounter with the very neighborly Travis Goodspeed.  He is a rather lanky young man (age 24 as of this posting) hailing from the Knoxville, TN area, who speaks with the slightest Southern drawl, and sports a rather impressive crop of dreadlocks.  Travis is an extraordinarily polite, easygoing, and friendly person who is very sociable and is quite fond of West Coast Style IPA beer, which he longs for when he visits Germany (where malty lager is the brew of choice).

Travis likes to challenge security assertions.  He likes to shave, etch, probe, and otherwise infiltrate computer chips in his quest to discover what secrets lie within.  He insists he does this for fun, and after sitting with him for a bit and listening to his exploits, I am convinced he must be having the time of his life. I am also glad he is not one of "the bad guys".

I had the pleasure of having Travis join us at my Smart Grid Security East conference, as a panelist and as a fixture in my expo area, where he set up shop with some of his tools and toys (some homegrown, some off the shelf) and proceeded to show the crowd how he managed to hack the "security" of a Microsoft Wireless Keyboard.  Mind you, this was not an old keyboard, but one he had recently purchased.  Apparently Microsoft decided to use the MAC address as the key for this keyboard communication scheme.  Travis showed how, using a rather interesting badge he had created, he was able to monitor every keystroke typed into the keyboard, and display it on a monitor.

I find this particularly intriguing, because for the last year or so I have been working on security guidelines for the State of California Office of Health Information Integrity as part of the Security Steering Committee for the Privacy and Security Advisory Board.  We have been creating guidelines addressing security for health information exchanges in order to help ensure that health care organizations in California align themselves with requirement under the HIPAA HITECH privacy and security regulations.  While we have done all we can to deal with issues such as how people should interface with systems, and how data should be handled in the system (mind you, it is not perfect, but we are working hard on the issues), something like a wireless keyboard communication protocol is so far out of scope it may as well be a discussion on the topic of corn pads.

We still live in a world where, from a security perspective, device manufacturers are essentially exempt from any liability for making silly choices.  Microsoft has enough money and brain trust to address this issue properly.  They could easily implement a design that transcends this level of silliness, but they choose not to do so.  Yet a health care organization that decides to replace their keyboards with the cool wireless ones available from their hardware supplier is one Travis Goodspeed Hope Badge away from having everything they type into the electronic health record becoming publicly available information.

People like Travis (and there are a lot of people like him, both good and not so good) think way outside of the box.  Organizations that spend millions (and even billions) of dollars trying to secure their systems who fail to understand this should prepare for lots of sleepless nights, and many sour looks as they face their boards of directors.

Friday, March 4, 2011

The Greatest Outcome

Well, 6 months of hard work, planning, endless phone calls, emails, accolades, assaults, cancellations, headaches, strong cups of coffee, sponsorship groveling, blogging, writing, and finally making it all happen are over.

My Smart Grid Security East conference was a success.  With the help of all the wonderful speakers, sponsors, and my own team, we made it happen.   We have a bunch of videos to edit and post on the site, and some papers, presentations, and slide shows to upload, but the lion's share of the work is done.

It is quite overwhelming when so many brilliant people tell you how wonderful something you built is.  These are all people I respect TREMENDOUSLY, and I cannot help feeling elated by their approval.  It is both exhilarating and humbling.  I would love to list them all in this blog posting, but you would probably stop reading halfway through the list, and I want to bring up a far more important point...so hang on.

As my conference drew to a close, I reflected on all the moments I felt defined my sense of accomplishment for this event.  There was the opportunity to sit down to lunch with Bill Hunteman, Senior Advisor for Cyber Security for the US Department of Energy, who chatted openly about the DOE's roll and challenges.  Then there was the opportunity to enjoy breakfast with Matt Carpenter and Michael Assante.  I had an opportunity to converse extensively with the young, brilliant, and very "neighborly" Travis Goodspeed, who exposes security flaws in between pints of his favorite IPA's.  I enjoyed countless meals and moments with Daniel Thanos of GE Energy, and Bobby Brown of EnerNex, and Erich Gunther (who wears so many hats...well, lets just say he is everywhere).

Then there were all the wonderful AMI security minds.  There was Ed Beroset of Elster, and Stephen Chasko of Landis+Gyr, and Ido Dubrawsky and Robert Former of Itron.  All brilliant people working hard to build the products that we will rely on to securely manage our energy infrastructure going forward.

I literally could go on for several pages, but suffice it to say I had many "moments" with some great people.

Yet, life has a way of showing you what really matters right at the moment when you think you have it all figured out.  As I was leaving the conference hall at the final moments of the event, I was approached by a lovely young lady, who goes by the name of Summer.  She had won a free pass to my conference through a contest Andy Bochman of the Smart Grid Security Blog held.

She had contacted me by email after she won, and was thrilled because she is focusing her studies on Smart Grid cyber security, and she was attending school at the nearby Tennessee Tech University.  I welcomed her and told her she could bring along someone else from the school as a guest of the conference.

As Summer approached me, her young face broke out into a huge smile, and she profusely thanked me for the event and the opportunity to hear from the brightest minds in the world of Smart Grid security.  She then told me that the person she had brought with her had decided to change his thesis topic to Smart Grid security.

It was at that moment that I felt truly humbled.  As I get older (and hopefully wiser), and raise my children to be the best that they can be, the things that matter the most to me are maturing.  There was a time when I felt it would be great to be remarkably wealthy (okay, I still think that would be great), or achieve great fame (granted, that wouldn't be so bad either), but what matters the most is when you find a way to be the change you want to see.  I look at so much of what our youth has to deal with today, and often wonder how they can possibly cope with the mess they have been given.  I wonder where they can look for any guidance that will in any way affect them in a positive manner, and at that moment realized that something I had created served to positively influence at least 2 young minds.

Wouldn't we all like to do that?

Be the change you want to see...

Friday, February 11, 2011

Keeping Out Of The Trough

I am absolutely thrilled and truly blessed beyond all words to be hosting the Smart Grid Security East conference (co-hosted by EnerNex) in Knoxville, TN from February 28th to March 2nd.  I have had the great pleasure of working with some of the finest security minds in the Smart Energy industry for the last year, and most of them are speaking at my event.  If you are not aware of this by now, you should take a closer look.  I think you will be duly impressed.

What struck me as an absolutely fantastic illustration of what the Smart Grid security landscape looks like today was a slide that Ido Dubrawsky of Itron sent me (and gave Bobby Brown of EnerNex credit for):


This one slide really says it all for me, and completely illustrates my goal for creating this conference.  The people I have been working with in the NIST, OpenSG, and DHS groups for the last year are indeed (by and large) luminaries in the world of Smart Grid security.  Everyone acknowledges that there are issues to deal with, and we are well above "The Trough" and are rapidly moving along the path of true productivity in addressing security. Have we "solved" the security problems of the Smart Grid...no.

Will we ever "solve" the problem?

Well, this is like asking the question "Will we ever solve the problem of obesity?".

There is an easy way to solve the obesity problem.  Simply stop eating.  Of course the problem with that solution is that it tends to lead to bigger problems.  However, we have discovered that putting a little thought into what we eat, and combining it with some other good practices, tends to lead to a pretty darn good quality of life and avoids obesity (I am not a good example of this, but I am working on it).  If you find yourself not quite understanding how to tackle this problem, there are plenty of people out there to help you.

The same holds true for Smart Grid security.  It is an ongoing issue that comes about as the result of an idea to implement a system which will ultimately serve to address some major energy issues throughout the world, and ultimately improve our quality of life.  It is not being ignored, and if want to know more about what is being done to address the issues, the answers are out there.

I hope some of you can make it to my conference.


Wednesday, December 15, 2010

The Smart Grid Security Misinformation Network

It seems that a lot of the news we hear about Smart Grid security seems to focus on how we are all potentially doomed due to the lack of attention being given to Smart Grid security.  Bad news does seem to get a lot of attention, so I can certainly see how this may be a great way to attract readers.  I have a Google Alert set to "Smart Grid Security", and every evening I get an email with the latest headlines.  It seems to come in waves, but I get a lot of links to random postings where the author proclaims that not enough attention is being given to Smart Grid security.

I am not sure what "enough" really means in the eyes of many of these authors, but I will say that there are a lot of people paying very close attention to Smart Grid security.  I personally belong to 2 of 12 NIST Smart Grid Cyber Security Working Groups (http://collaborate.nist.gov/twiki-sggrid/bin/view/SmartGrid/WorkingGroupInfo) and these groups generally meet for 1 hour per week.  Members from every corner of the energy and security industries regularly attend these meetings, and the discussions and associated tasks are certainly focused on securing our Smart Grid.  The NIST CSWG is also where the NISTIR 7628 Security Guidelines came from, which was a collaborative effort of over 400 people from the energy, security, legal, regulatory, government, educational, and general technology industries.  Many of these same people are still quite active in the efforts of the NIST Smart Grid Interoperability Panel (SGIP) and NIST CSWG.  Besides the NIST effort, several standards development organizations have become involved in working towards developing standards for securing the smart grid.  

The US Department of Homeland Security has put together a comprehensive Industrial Control Systems Joint Working Group (ICSJWG), which is open to anyone who wants to help (http://www.us-cert.gov/control_systems/icsjwg/index.html).  I am also a member of this group, and recently attended a conference (also open to anyone who wishes to attend) in Seattle Washington.  The speakers were all excellent (okay, I was one of them), and the presentations are all freely available at http://www.us-cert.gov/control_systems/icsjwg/presentations.html .

Under the UCA International Users Group (UCAIUG) there exists the vaunted and very active Open Smart Grid (OpenSG) users group, with several active Smart Grid security groups operating under their umbrella.  Literally hundreds of people (many of the same working with the NIST groups) meet regularly to discuss security, take on tasks, and publish documentation which has been utilized by NIST to help develop their special publications (including NISTIR 7628), and by both utilities and public utility commissions to guide their security efforts and regulatory efforts.

The Federal Energy Regulatory Commission (FERC) has worked with the North American Electric Reliability Corporation (NERC), who have developed critical infrastructure protection requirements (NERC CIPS), which are used by utilities for auditing the security in bulk generation and transmission.  The US Department of Energy (DOE) has granted millions of dollars to organizations who are charged with researching and developing security methods to protect our energy infrastructure.

There are several active Smart Grid and Industrial Control Systems active mailing lists, and several LinkedIN groups focused on Smart Grid security discussions and collaboration.  Several research organizations (most notably Pike Research) have invested enormous efforts on researching and reporting on the topic of Smart Grid security, and the security product and vendor community has come out in force to address the challenges that are constantly being discovered and discussed among Smart Grid security professionals.

Of course, I must take the opportunity to also give myself a shameless plug, since I created the Smart Grid Security Summit (www.smartgridsecuritysummit.com), which took place this past Summer, and this has led to the upcoming Smart Grid Security East conference (www.smartgridsecurityeast.com), where representatives from all the above mentioned organizations (and a lot more) will be presenting on nearly every Smart Grid security topic there is to talk about.  I certainly hope some of you can make it to the event.  It will be worth your time if Smart Grid security information is what you seek.  You can also freely join and attend meetings of the NIST, DHS, and OpenSG groups.  Anyone interested in helping is welcome.

Otherwise, please continue to peruse the fear, uncertainty, and doubt (FUD) driven news headlines.  If nothing else, they are quite entertaining.

Sunday, December 5, 2010

WikiLeaks and Why "Plan B" is now more important than "Plan A"

We all understand the idea of "Plan A" and "Plan B".  Plan A is the plan we put in place that is meant to work as planned.  In security, it is the plan we hope will ensure the CIA (Confidentiality, Integrity, and Availability) triad is in place.  We put a lot of effort into Plan A, and then the more intelligent among us will put some effort into a Plan B.  This is the plan we switch over to in the event Plan A fails.

This is generally the "damage control" mode plan.  This is the plan we all hope we never have to go to, since by this point something very bad has happened.  This could be something like...say perhaps...all of our national secret and top secret information getting leaked on a website.

That can be a really bad thing...

By now we are all probably keenly aware that the masterminds behind the WikiLeaks website have decided that information must all be publicly shared no matter what.  Someone asked me my opinion about this several days ago....if I thought it was a good thing of bad thing...and my response was simple.  I do not have an opinion about it being a good thing or bad thing.  What I do know is that it is something that exists,  and we must now figure out a way to deal with it, because it is NOT going to go away...EVER!  It is like winter in Cleveland...deal with it.

I know this may sound harsh, but that is what we are facing.  We live in an age where information ebbs and flows (and overflows) like water in an ocean.  It comes to us as a gentle and calm breeze, or as a hurricane.  It drifts down like snowflakes, or comes crashing down like an avalanche.

Okay...enough analogies...you get the picture.  The truth is, we simply no longer have the control of information we once thought we had.  The very nature in which we communicate today has created an environment were massively scalable information storms can occur.  In the "good old days" we communicated by sending letters and talking.  Today we communicate by generating data that gets pumped into "The Cloud", and then BLINDLY trust that it will only get to the intended recipients and nobody else.

Isn't that cute...

The Plan A way of dealing with information has been to protect the confidentiality, integrity, and availability of the information for as long as information has been important to us (essentially forever, but perhaps more so today in the information age).  While we have created some absolutely fantastic systems for insuring both the integrity and availability of information over the last several decades, it seems that the very systems we have built have made it increasingly more difficult to insure confidentiality.  Through the application of Moore's Law we have created systems with insane amounts of processing power, and have driven down the cost of these systems to almost nothing (I say almost nothing because you can find computers for free these days...at least in the San Francisco Bay Area), meaning that anyone can get their hands on the tools needed to both obtain and distribute information.  There was a time when getting confidential information meant breaking encryption or applying brute force or dictionary attacks on systems.  While this is still true today, we now live in a world where there are so many people accessing systems throughout the world, we no longer need to break into systems to get a hold of sensitive information.  Today somebody who has authorized access to information either copies it or sends it into the cloud for all to consume.  What makes this so difficult to control is that there are so many who have access to information, and either through direct access or aggregation the information can be assembled into nice little information bombs.

In other words, confidentiality has become nearly impossible to both achieve and manage.

This makes Plan A an incredibly difficult plan to manage, and certainly makes our reliance on Plan A more and more difficult to justify from a due diligence/due care perspective.  We simply live in an age where we MUST assume compromise.  We must accept the fact that, at some point, confidentiality goes out the window.  Time to look at Plan B.

I am not sure what the US Government is doing with respect to Plan B.  I saw an article where the US Government is warning college students to not talk about WikiLeaks...or else.  I see some efforts to shut down the WikiLeaks site, and cut off funding sources.  I imagine these are all some valid steps to take...in an act of desperation.  Okay, maybe it is not desperation, but it certainly seems desperate.  I mean...c'mon...do we really believe this is going to do anything more that irritate a bunch of college students who already do not like our government to begin with, and who are perhaps infinitely more savvy about the information age?

I am fairly certain that Plan B has not been given the level of attention it should have been given.  It is very difficult for people who are intelligent AND arrogant (a bad but common combination) to consider the possibility that their best laid plans may have a fatal flaw.  Consequently, anything more than a cursory level of attention to Plan B is considered an admission that maybe they are not as smart as they think they are.  Perish the thought!

The truth is, Plan B has ALWAYS been more important than Plan A.  By the time you get to point where you need to use Plan B, things have generally gotten very bad.  This is now the time were you must not only figure out how to keep things operational, but also undo the damage that caused Plan A to fail.  This is the "do or die" moment.

We certainly need to continually focus on protecting information.  We do indeed have systems and methods available to us today that can buy us some time in the race between those who need to protect information and those who want to uncover it.  We simply need to understand that at some point the information we so dearly protected is likely to be become publicly available, and use that mentality to weather the information age.  It may take some time, but I am sure we will eventually get to a point where we can deal with this...much like I dealt with 21 years of Cleveland winters.