Beautiful Virgin Islands

Saturday, Feb 22, 2025

How the US military used a creepy island to test cyberattacks on the grid — in the middle of a pandemic - CyberScoop

How the US military used a creepy island to test cyberattacks on the grid — in the middle of a pandemic - CyberScoop

The U.S. government officials trying to test the country’s ability to respond to a major cyberattack thought they had pulled out all the stops. Engineers had planned to simulate the kind of security incident that would cause an electrical blackout, after all, and had even planned to hold the event on an isolated island off the coast of New York.

Even with all that preparation, a once-in-a-century pandemic still wasn’t in the script.

Until this year, National Guard personnel, Pentagon contractors and engineers at big U.S. utilities would typically gather in person to run through exercises involving dire scenarios, from a weeks-long power outage to a mock attack on utility computers that appeared to delete data.

In October, though, COVID-19 forced planners from the departments of Defense and Energy to figure out how to run the event virtually, with participants plugged in from around the country. And they used the pandemic as another opportunity to prepare for the unpredictable.

The goal of the recurring effort, which is backed by a $118-million Pentagon program, is to try anticipate how state-sponsored hacking groups could sabotage key utilities. The exercise provides important defensive insights for some of America’s largest electricity providers, and comes as an increasing number of hacking groups have taken an interest in the industrial control systems that those utilities use to deliver power.

This year’s unusual setup ended up being “useful for modeling how people would respond remotely to a widespread cyberattack,” said Walter Weiss, a cerebral program manager at the Pentagon’s R&D arm — the Defense Advanced Research Projects Agency — who helped plan the exercise. “That just added additional realism.”

Organizers allowed utility engineers and researchers to participate, despite the coronavirus, by accessing software tools used to defend against the simulated attacks. While most participants joined remotely, a diehard crew made the trek to the austere, windswept spit of land called Plum Island, off Long Island, that has hosted past exercises.

The exercise in October tasked mock electric utilities, staffed by real utility workers, with restoring power after a debilitating set of simulated cyberattacks. Participants had to use a generator to gradually restart a power system, substation by substation, and test DARPA-funded forensic tools in the process.

Weiss pointed to a 2019 threat assessment from U.S. intelligence agencies that said that China and Russia had the ability to use cyberattacks to, respectively, temporarily disrupt natural gas pipelines and electric distribution networks.

The exercise planners drew on real-world incidents, too. The 2015 suspected Russian cyberattack on Ukrainian electric infrastructure, which cut power for some 225,000 people, blinded utility operators to what was going on in power distribution networks. Plum Island combatants were trying to avoid a similar type of loss of visibility.

“That’s a great wake-up call and resonates with utilities we’re trying to work with,” Weiss said.

An eerie setting


The latest exercise was the seventh, and final drill, on Plum Island under a DARPA program called Rapid Attack Detection, Isolation and Characterization Systems (RADICS).

The number of electric utility employees and government contractors allowed on the island this year was kept under 30. Participants were regularly tested for the coronavirus before and after they stepped off the ferry and onto the island, which has a spooky effect on visitors that’s hard to overstate. (Plum Island has also been the government’s home for studying animal-borne diseases.)

“We had our own dedicated ferry schedule and didn’t interact with anyone other than the RADICS team, so it felt a bit more isolated,” said Tim Yardley, a senior researcher at the University of Illinois, who spent six weeks on Plum Island setting up infrastructure for the exercise. “The eerie part for me was the drive across the country [during a pandemic].”

Engineers installed high-speed fiber optic links on the island to allow people to take part digitally. They also helped configure a virtual private network so that members could log into the exercise from their laptops.

Yardley said participants were initially concerned that the remote environment would sap the exercise of its hands-on value. But the takeaway instead, he said, was that “you could actually do an incident response and make this work.”

“The tools were successful in that way,” said Yardley, a veteran of multiple Plum Island drills. “They automated many of the things that would take a person a lot longer to do in person.”

“Was it ideal? No,” he continued. “But technology could serve to aide in this way. I think it was eye-opening for many of the participants.”

Weiss and Yardley said the exercise participants were able to use the DARPA tools to help stabilize the grid on Plum Island, and eventually restore power.

Spotting the lie


The RADICS program funds technology including data-ingesting software that sorts normal from suspicious activity on a power network, and a system for conducting emergency communications between a substation and a control center.

Particularly handy during the latest Plum Island exercise was a dashboard that allowed users to accurately monitor network activity “even if your own systems are lying to you,” as Weiss put it. That means if a control panel is telling a utility operator that a substation is running normally, when it really isn’t, the dashboard would have been able to spot the lie.


Substation equipment is pictured on Plum Island, New York. Exercise participants had to restore power in the face of simulated cyberattacks.


The 2015 attack on Ukrainian power companies remains a stark example of what might go wrong when detection fails. No cyberattack anywhere near that magnitude has happened on U.S. electric infrastructure, but utility operators still prepare to defend against such threats.

“Two things a cyberattack can do to the grid are make it not tell you the truth, or make it not work how you expect it to work,” Weiss said. “So in general, the whole scenario is about finding what parts of the grid are doing that to you.”

With the Plum Island project coming to a close, DARPA has handed off the software tools to the Department of Energy, which works closely with utilities, to introduce more of that technology out into the field, Weiss said. Some of that is already happening. New Jersey-based company Perspecta Labs, for example, is looking to market its malware-hunting system to utilities.

Valuable data in the vault


Six weeks after the Plum Island experiment in October, the U.S. government held another elaborate cybersecurity drill for the power sector.

The “tabletop exercise” hosted by the Department of Energy on Dec. 9 included executives from some of the biggest power companies in the U.S. Officials from multiple national security agencies were also on hand, according to exercise planners.

Like Plum Island, the exercise envisioned aggressive cyberattacks on the electric sector by a foreign adversary. Participants had to talk through how they would respond to the incident, trade intelligence and revert to backup power solutions. It’s part of a long-running DOE exercise series known as Liberty Eclipse, which has historically included the Plum Island program.

“Shaping these conversations under blue-sky conditions can help mitigate redundancy, bureaucracy, and frustration down the road,” said Brian Harrell, a former senior Department of Homeland Security official who is now chief security officer at renewable power company Avangrid, and who participated in the Liberty Eclipse tabletop exercise.

The Department of Energy did not respond to interview requests for this article, though the department said in a statement that the goal of Liberty Eclipse was “to validate tools that enhance information sharing capabilities and identify threats to the energy sector.”

Grid-focused cybersecurity officials in the government will be studying lessons learned from both sets of exercises for some time. It’s an example of the institutional knowledge on the resiliency of the grid that the Biden administration will inherit, and need to use, as foreign adversaries continue to probe such infrastructure.

For his part, Yardley is now preparing to send several hard drives of exercise data to U.S. government officials, including network traffic from the simulated attacks. He said he hopes the government will eventually make the data public so that researchers and the broader power industry can study it.

That kind of data is valuable, Yardley said, because “obviously, you can’t go download off the internet data of a utility being attacked by what looks like a nation-state.”

Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
Good News: Senate Confirms Kash Patel as FBI Director
Officials from the U.S. and Hungary Engage in Talks on Economic Collaboration and Sanctions Strategy
James Bond Franchise Transitions to Amazon MGM Studios
Technology Giants Ramp Up Lobbying Initiatives Against Strict EU Regulations
Alibaba Exceeds Quarterly Projections Fueled by Growth in Cloud and AI
Tequila Sector Faces Surplus Crisis as Agave Prices Dive Sharply
Residents of Flintshire Mobile Home Park Grapple with Maintenance Issues and Uncertain Future
Ronan Keating Criticizes Irish Justice System Following Fatal Crash Involving His Brother
Gordon Ramsay's Lucky Cat Restaurant Faces Unprecedented Theft
Israeli Family Mourns Loss of Peace Advocate Oded Lifschitz as Body Returned from Gaza
Former UK Defense Chief Calls for Enhanced European Support for Ukraine
Pope Francis Admitted to Hospital in Rome Amid Rising Succession Speculation
Senate Republican Leader Mitch McConnell, at the age of 83, Declares His Retirement.
Whistleblower Reveals Whitehall’s Focus on Kabul Animal Airlift Amid Crisis
Politicians Who Deliberately Lie Could Face Removal from Office in Wales
Scottish Labour Faces Challenges Ahead of 2026 Holyrood Elections
Leftwing Activists Less Likely to Work with Political Rivals, Study Finds
Boris Johnson to Host 'An Evening with Boris Johnson' at Edinburgh's Usher Hall
Planned Change in British Citizenship Rules Faces First Legal Challenge
Northumberland Postal Worker Sentenced for Sexual Assaults During Deliveries
British Journalist Missing in Brazil for 11 Days
Tesco Fixes Website Glitch That Disrupted Online Grocery Orders
Amnesty International Critiques UK's Predictive Policing Practices
Burglar Jailed After Falling into Home-Made Trap in Blyth
Sellafield Nuclear Site Exits Special Measures for Physical Security Amid Ongoing Cybersecurity Concerns
Avian Influenza Impact on Seals in Norfolk: Four Deaths Confirmed
First Arrest Under Scotland's Abortion Clinic Buffer Zone Law Amidst International Controversy
Meghan Markle Rebrands Lifestyle Venture as 'As Ever' Ahead of Netflix Series Launch
Inter-Island Ferry Services Between Guernsey and Jersey Set to Expand
Significant Proportion of Cancer Patients in England and Wales Not Receiving Recommended Treatments
Final Consultation Launched for Vyrnwy Frankton Power Line Project
Drug Misuse Deaths in Scotland Rise by 12% in 2023
Failed £100 Million Cocaine Smuggling Operation in the Scottish Highlands
Central Cee Equals MOBO Awards Record; Bashy and Ayra Starr Among Top Honorees
EastEnders: Four Decades of Challenging Social Norms
Jonathan Bailey Channels 'Succession' in Bold Richard II Performance
Northern Ireland's First Astronaut Engages in Rigorous Spacewalk Training
Former Postman Sentenced for Series of Sexual Offences in Northumberland
Record Surge in Anti-Muslim Hate Crimes Across the UK in 2024
Omagh Bombing Inquiry Concludes Commemorative Hearings with Survivor Testimonies
UK Government Introduces 'Ronan's Law' to Combat Online Knife Sales to Minors
Metal Detectorists Unearth 15th-Century Coin Hoard in Scottish Borders
Woman Charged in 1978 Death of Five-Year-Old Girl in South London
Expanding Sinkhole in Godstone, Surrey, Forces Evacuations and Road Closures
Bangor University Announces Plans to Cut 200 Jobs Amid £15 Million Savings Target
British Journalist Charlotte Peet Reported Missing in Brazil
UK Inflation Rises to 3% in January Amid Higher Food Prices and School Fees
Starmer Defends Zelensky Amidst Trump's 'Dictator' Allegation
Zelensky Calls on World Leaders to Back Peace Efforts in Light of Strains with Trump
UK Prime minister, Mr. Keir Starmer, has stated that any peace agreement aimed at ending the conflict in Ukraine "MUST" include a US security guarantee to deter Russian aggression
×