Showing posts with label control systems. Show all posts
Showing posts with label control systems. Show all posts

Monday, October 20, 2014

Active Control Theory Applied to Quantum Based Technologies?

What does a 1980s experimental aircraft have to do with state-of-the art quantum technology? Lots, as shown by new research from the Quantum Control Laboratory at the University of Sydney, and published in Nature Physics today.

Over several years a team of scientists has taken inspiration from aerospace research and development programs to make unusually shaped experimental aircraft fly.

"It always amazed me that the X-29, an American airplane that was designed like a dart being thrown backwards, was able to fly. Achieving this, in 1984, came through major advances in a discipline called control engineering that were able to stabilise the airplane," said Associate Professor Michael Biercuk, from the School of Physics and director of the Quantum Control Laboratory.

"We became interested in how similar concepts could play a role in bringing quantum technologies to reality. If control engineering can turn an unstable dart into a high-performance fighter jet, it's pretty amazing to think what it can do for next-generation quantum technologies."

The result is that the researchers have been able to turn fragile quantum systems into useful pieces of advanced tech useful for everything from computation and communications to building specialised sensors for industry. The trick was figuring out how to protect them from their environments using control theory.

Monday, August 05, 2013

We Are Already at War, Cyberwar

Despite what is said at first in the article, its not just the Chinese. 

The largest source of attacks?   

Russia.
A Chinese hacking group accused this February of being tied to the Chinese army was caught last December infiltrating a decoy water control system for a U.S. municipality, a researcher revealed on Wednesday.

The group, known as APT1, was caught by a research project that provides the most significant proof yet that people are actively trying to exploit the vulnerabilities in industrial control systems. Many of these systems are connected to the Internet to allow remote access (see “Hacking Industrial Systems Turns Out to Be Easy”). APT1, also known as Comment Crew, was lured by a dummy control system set up by Kyle Wilhoit, a researcher with security company Trend Micro, who gave a talk on his findings at the Black Hat conference in Las Vegas.

The attack began in December 2012, says Wilhoit, when a Word document hiding malicious software was used to gain full access to his U.S.-based decoy system, or “honeypot.” The malware used, and other characteristics, were unique to APT1, which security company Mandiant has claimed operates as part of China’s army (see “Exposé of Chinese Data Thieves Reveals Sloppy Tactics”).

“You would think that Comment Crew wouldn’t come after a local water authority,” Wilhoit told MIT Technology Review, but the group clearly didn’t attack the honeypot by accident while seeking another target. “I actually watched the attacker interface with the machine,” says Wilhoit. “It was 100 percent clear they knew what they were doing.”

Wilhoit went on to show evidence that other hacking groups besides APT1 intentionally seek out and compromise water plant systems. Between March and June this year, 12 honeypots deployed across eight different countries attracted 74 intentional attacks, 10 of which were sophisticated enough to wrest complete control of the dummy control system.

Cloud software was used to create realistic Web-based login and configuration screens for local water plants seemingly based in Ireland, Russia, Singapore, China, Japan, Australia, Brazil, and the U.S. If a person got beyond the initial access screens, they found control panels and systems for controlling the hardware of water plant systems.

None of the attacks displayed a particularly high level of sophistication, says Wilhoit, but the attackers were clearly well versed in the all-too easily compromised workings of industrial control systems. Four of the attacks displayed a high level of knowledge about industrial systems, using techniques to meddle with a specific communication protocol used to control industrial hardware.

Wilhoit used a tool called the Browser Exploitation Framework, or BeEF, to gain access to his attackers’ systems and get precise data on their location. He was able to access data from their Wi-Fi cards to triangulate their location.

The 74 attacks on the honeypots came from 16 different countries. Most of the noncritical attacks, 67 percent, originated in Russia, and a handful came from the U.S. About half the critical attacks originated in China, and the rest came from Germany, U.K., France, Palestine, and Japan.

The results lead Wilhoit to conclude that water plants, and likely other facilities, around the world are being successfully compromised and taken control of by outside attackers, even if no major attack has been staged. “These attacks are happening and the engineers likely don’t know,” he told MIT Technology Review.

Noel.  You wanted the grand scenario of the great cluster f*ck?  Here it is.  Imagine someone pulling the trigger and the utilities of the developed world, even China and India, going splat all at once.  The mjaority of the attackers above are rank amateurs.  Imagine if something like STUXNET was written...you drop a new controller in to replace the old stuff and...blamo  Infected again.

More and more I think stuff like this should NOT be online or connected to computers that are online.  The convenience be damned.