Electromagnetic pulse and geomagnetic disturbance events "pose a serious threat to the electric grid and its supporting infrastructures that serve our Nation," according to testimony delivered by a federal official to the U.S. Senate Committee on Homeland Security and Governmental Affairs.
Electromagnetic pulse (EMP) and geomagnetic disturbance (GMD) events are two types of events that could affect the nation's electric grid. Generally speaking, GMD events are naturally occurring solar magnetic disturbances which periodically disrupt the earth’s magnetic field. These disruptions can induce currents on the electric grid that may simultaneously damage or destroy key transformers over a large geographic area.
On February 27, 2019, Joseph
McClellan, director of the Federal Energy Regulatory Commission's
Office of Energy Infrastructure Security, testified before the Senate
committee. As described in his testimony, EMP events can be generated by "devices that range from small, portable, easily concealed battery-powered units all the way through missiles equipped with nuclear warheads." High-altitude nuclear detonations can generate three distinct EMP effects: "a short high energy radio-frequency-type burst called E1 that can destroy electronics; a slightly longer burst that is similar to lightning termed E2; and a final effect termed E3 that is similar in character and effect to GMD, with the potential to damage transformers and other electrical equipment."
According to Director McClellan's testimony, any of these effects could lead to "wide-area blackouts." In his testimony, he cited reports by the federal EMP Commission as finding that "a single EMP attack could seriously degrade or shut down a large part of the electric power grid," with the potential that significant parts of electric infrastructure could be “out of service for periods measured in months to a year or more."
He also cited a 2010 study by Oak Ridge National Laboratory as finding that "EMP and GMD events pose substantial risk to equipment and operation of the Nation’s electric grid and under extreme conditions could result in major long-term electrical outages," that "GMD disturbances are inevitable with only the timing and magnitude subject to variability," and that a solar storm such as occurred in 1921 "could damage or destroy over 300 bulk power system transformers interrupting service to 130 million people with some outages lasting for a period of years." Director McClellan clarified that subsequent analysis suggested that in case of such an event, "the power grid may collapse before significant damage was done to transformers; resulting in a potentially wide-spread, but relatively short, power outage."
Director McClellan also spoke to the Federal Energy Regulatory Commission's "dual-fold approach" to address these threats: employing mandatory standards to establish foundational practices while also working collaboratively with industry, the states and federal agencies to identify and promote best practices to mitigate advanced threats. According to a report released in 2018 by the U.S. Government Accountability Office, U.S. and Canadian electricity suppliers have taken steps to prepare for potential electromagnetic disruptions, but more research is needed on both geomagnetic
disturbances and high-altitude electromagnetic pulses.
Showing posts with label critical infrastructure protection. Show all posts
Showing posts with label critical infrastructure protection. Show all posts
FERC official testifies on electromagnetic pulses and geomagnetic disturbances
Friday, March 8, 2019
Labels:
blackout,
critical infrastructure protection,
electromagnetic,
EMP,
FERC,
geomagnetic,
GMD,
nuclear,
reliability,
risk,
security,
Senate,
standard,
threat
Cybersecurity, solar energy and the electric grid
Monday, May 12, 2014
A group of Russian hackers claims to have identified security gaps in widely-used solar panel monitoring software. The monitoring platform's developer is said to be fixing the gaps -- but can hackers damage the electric grid?
German company Solare Datensysteme GmbH makes a series of devices to track and monitor solar panel performance. Its "Solar-Log" product line monitors the performance of solar photovoltaic systems and uses an internet connection and software to offer users additional management tools. According to the company's website, Solar-Log systems manage roughly 229,300 solar plants that producing an aggregate average of 5.66 terawatt-hours (TWh) per day.
According to an article on tech website The Register, a Russian hacking firm known as Positive Security has warned that the previous Solar-Log software was vulnerable to malicious cyberattacks that could cause power grid reconfiguration and cascading blackouts. The article claims that attackers could download and modify Solar-Log configuration files without needing propert authentication. Files could be compromised to change user passwords and run code provided by the attacker. The article suggests that malicious hackers could manipulate "specific power-generation related values", letting users could overstate the amount of power pumped back into grids by their solar installations.
The exact details of the weaknesses identified by Positive Security is being kept secret until the Solar-Log maker can distribute a patch shoring up system security. As with past bugs, it is likely that Solare Datensysteme and other product makers will continue to plug holes in their cybersecurity, as new flaws are exposed and as systems evolve. But solar panel monitoring systems are not the only energy-related infrastructure vulnerable to hacking; items ranging from utility smart meters to utility-scale power generator controls may be at risk of compromise from outside forces.
A series of regulations are designed to protect the grid against these threats. The Federal Energy Regulatory Commission has approved mandatory cybersecurity reliability standards for the U.S. bulk power system. Acting under its authority pursuant to the Energy Policy Act of 2005, through Order No. 706 the Commission has approved a series of Critical Infrastructure Protection (CIP) cyber security reliability standards proposed by electric reliability organization North American Electric Reliability Corporation (NERC). Both NERC and the Commission continue to evaluate further changes to those standards, along with other standards bolstering the physical security of the electric grid.
New cybersecurity threats crop up regularly, prompting product developers, service providers, and regulators to engage in a continual effort to identify, block, and protect against threats to the electric power system. For developers of energy technologies or projects, compliance with key regulations is a critical element of this protection, as is taking a proactive view to ensure safe and reliable operations. While it is hard to predict the next front in this war, count on it to be ever shifting.
| Solar panels supporting Goblin Valley State Park, Utah. |
According to an article on tech website The Register, a Russian hacking firm known as Positive Security has warned that the previous Solar-Log software was vulnerable to malicious cyberattacks that could cause power grid reconfiguration and cascading blackouts. The article claims that attackers could download and modify Solar-Log configuration files without needing propert authentication. Files could be compromised to change user passwords and run code provided by the attacker. The article suggests that malicious hackers could manipulate "specific power-generation related values", letting users could overstate the amount of power pumped back into grids by their solar installations.
The exact details of the weaknesses identified by Positive Security is being kept secret until the Solar-Log maker can distribute a patch shoring up system security. As with past bugs, it is likely that Solare Datensysteme and other product makers will continue to plug holes in their cybersecurity, as new flaws are exposed and as systems evolve. But solar panel monitoring systems are not the only energy-related infrastructure vulnerable to hacking; items ranging from utility smart meters to utility-scale power generator controls may be at risk of compromise from outside forces.
A series of regulations are designed to protect the grid against these threats. The Federal Energy Regulatory Commission has approved mandatory cybersecurity reliability standards for the U.S. bulk power system. Acting under its authority pursuant to the Energy Policy Act of 2005, through Order No. 706 the Commission has approved a series of Critical Infrastructure Protection (CIP) cyber security reliability standards proposed by electric reliability organization North American Electric Reliability Corporation (NERC). Both NERC and the Commission continue to evaluate further changes to those standards, along with other standards bolstering the physical security of the electric grid.
New cybersecurity threats crop up regularly, prompting product developers, service providers, and regulators to engage in a continual effort to identify, block, and protect against threats to the electric power system. For developers of energy technologies or projects, compliance with key regulations is a critical element of this protection, as is taking a proactive view to ensure safe and reliable operations. While it is hard to predict the next front in this war, count on it to be ever shifting.
Subscribe to:
Posts (Atom)
