research stories | fall 2022

hacking the hackers—q & a with dr. amir ameli

power transmission lines superimposed over a screen of computer code

istock

dr. amir ameli is an electrical engineering professor with the lakehead-georgian partnership researching how to stop cyberattacks against power systems. he describes his work as part of the last line of defence against cyberattacks that have already infiltrated power systems.

dr. amir ameli

how did you become interested in researching cybersecurity for power systems?

i was actively looking for a good research topic for my phd at the university of waterloo when, on december 23, 2015, the first real-world cyberattack against a power system happened in ukraine. fifty substations were targeted by hackers and the supply of energy was disrupted to approximately 225,000 customers for about six hours.

i realized that cybersecurity would become a serious issue for these critical pieces of infrastructure in the near future. my main goal is to devise strategies, tools, and general principles to securely evolve and modernize power networks and to develop more reliable protection schemes.

why is cybersecurity important for power grids?

it is hard to overstate the importance of electricity to canada. any significant disruption of electricity directly impacts our national security, public safety, and economy.

for instance, a power outage in august 2003 in northeastern north america caused a loss of an estimated $2.3 billion cad to ontario's economy and very likely led to the loss of life. our reliance on electricity has grown significantly since then and is projected to continue to grow—most notably with the electrification of the transportation sector.

how much could electrical companies save by preventing hackers from getting in?

it depends on the type of attack and its objectives, but to give you a worst-case scenario, a cyberattack that shuts down parts of the united states' power grid could cost the u.s. economy as much as $1 trillion, according to a report published by reuters.

what are the goals of hackers attacking power systems?

some attackers are looking for financial gain, such as cheating power markets or securing ransom payments. the average ransom demand in canada was $148,700 cad in the first quarter of 2020 (canadian centre for cyber security), up 33% from 2019. some cyberattacks happen for political or terroristic reasons. for instance, in 2015, the department of homeland security confirmed reports of isis attempting to penetrate the u.s. energy system. attacking a country's power and energy system can paralyze all other infrastructure as well. in these cases, cyberattacks aim to create country-wide blackouts or cascading failures.

how much do cyberattacks cost businesses and governments annually in north america?

the statistics below provide a sense of the importance, frequency, and detection difficulties of cyberattacks:

• the average cost of a data breach in 2020 was $3.86 million usd (ibm)
• global losses from cybercrime are predicted to be nearly $10.5 trillion usd by 2025 (cybersecurity ventures)
• personal data was involved in 58% of data breaches in 2020 (verizon)
• 91% of attacks start through phishing (cybersecurity ventures)

in basic language, how do you prevent these systems from being hacked?

to prevent cyberattacks, we must identify potential entry points and open ports through which attackers can access the system. then, through a vulnerability analysis, we can figure out potential cyberattack targets and analyze the impact of attacks against them. once this has been done, we develop techniques to monitor the behaviour of critical components and schemes in real-time. if an attack bypasses the preventive measures and performs a malicious activity or succeeds in deviating the normal behaviour of a component or scheme, we can detect it. and, in some cases, we can mitigate cyberattacks.

how does the software you designed respond when a hacker attempts to access a power system?

we have different strategies for discovering and mitigating cyberattacks, for example, learning and detecting the signature of cyberattacks. the important point is that we don't have a one-size-fits-all solution— we must tailor solutions to the specifications, features, and needs of each individual application.

 

 

 

back to fall 2022