The threat of a home automation botnet and its impact on the power grid
Koivu, Aleksi (2023)
Diplomityö
Koivu, Aleksi
2023
School of Energy Systems, Sähkötekniikka
Kaikki oikeudet pidätetään.
Julkaisun pysyvä osoite on
https://urn.fi/URN:NBN:fi-fe2023061956332
https://urn.fi/URN:NBN:fi-fe2023061956332
Tiivistelmä
Home automation is rising in popularity. This brings many benefits to both the users and the wider society. However, this also brings many risks as well. Each intelligent device increases the attack surface that an attacker could exploit. If appropriate security measures are applied these risks are largely mitigated. The majority of successful hacking attempts are made through well-known weaknesses in security devices and could be prevented if commonly recommended security measures were applied.
There is already some previous research on the cybersecurity of home automation devices, often focusing on what security measures device manufacturers should apply, and there have been successful mass hackings made on home automation devices, such as the Mirai botnet. This thesis provides further insight into the current state of security with home automation devices by analysing currently commercially available devices for some common vulnerabilities. In light of these findings, and through analysing the spread of malware in recent history, the likely impacts of an IoT botnet on the Finnish power grid are explored.
Vulnerabilities were found in most of the tested devices. Most of the vulnerabilities are not critical to the system’s security, though some exceptions were found. Three possible impact scenarios were identified. Either targeting the frequency or the voltage balance of the power grid to cause a partial or complete blackout on the grid or targeting the electricity prices with the aim of financial gain. Based on the found vulnerabilities and the historical spread of malware, targeting the voltage balance or electricity prices were found to be more likely scenarios, as the overall amount of controllable load needed to achieve either is significantly lesser when compared to causing a sufficient frequency shift. Kotiautomaation suosio on kasvamassa. Tämä tuo monia etuja sekä laitteiden käyttäjille sekä yhteiskunnalle laajemmin. Tämä tuo myös riskejä. Jokainen älykäs laite kasvattaa mahdollista hyökkäysrajapintaa, jota hyökkääjät voisivat hyödyntää. Riskeiltä suuresti vältyttäisiin, jos sopivat turvallisuus ratkaisut otettaisiin käyttöön. Suurin osa hakkerointiyrityksistä tapahtuu käyttäen hyvin tunnettuja heikkouksia laitteiden turvallisuudessa, ja näiltä voitaisiin suojautua noudattamalla hyvin tunnettuja kyberturvallisuusohjeita.
Kotiautomaatiolaitteiden turvallisuudesta on jo aiempia tutkimuksia, usein liittyen siihen mitä käytäntöjä laitevalmistajien tulisi laitteissa noudattaa. Onnistuneita laajoja hakkerointiyrityksiä on tehty kotiautomaatio laitteisiin kuten Mirai bottinetti. Tämä työ lisää tietoa tällä hetkellä kaupallisesti saatavilla olevien kotiautomaatiolaitteiden turvallisuudesta tarkastelemalla näistä yleisiä haavoittuvuuksia. Löydösten perusteella, ja tarkastelemalla viimeaikaisten haittaohjelmien leviämistä, kotiautomaatio bottinettien vaikutuksia Suomen sähköverkkoon pohditaan.
Haavoittuvuuksia löydettiin monista testatuista laitteista. Suurin osa haavoittuvuuksista ei ole systeemin turvallisuudelle kriittisiä, mutta muutama poikkeus löydettiin. Kolme mahdollista vaikutusskenaariota tarkasteltiin. Joko verkon taajuuteen tai jännitteeseen vaikuttaminen tarkoituksena aiheuttaa osittainen tai täydellinen sähkökatkos tai sähkön hintaan kohdistuva vaikuttaminen tavoitteena rahallinen hyötyminen. Löydettyjen haavoittuvuuksien ja historiallisen haittaohjelmien leviämisen perusteella jännitteeseen tai sähkön hintaan tähtääminen todettiin todennäköisemmäksi skenaarioksi, koska tällöin vaaditun kontrolloitavan kuorman määrä on huomattavasti vähäisempi.
There is already some previous research on the cybersecurity of home automation devices, often focusing on what security measures device manufacturers should apply, and there have been successful mass hackings made on home automation devices, such as the Mirai botnet. This thesis provides further insight into the current state of security with home automation devices by analysing currently commercially available devices for some common vulnerabilities. In light of these findings, and through analysing the spread of malware in recent history, the likely impacts of an IoT botnet on the Finnish power grid are explored.
Vulnerabilities were found in most of the tested devices. Most of the vulnerabilities are not critical to the system’s security, though some exceptions were found. Three possible impact scenarios were identified. Either targeting the frequency or the voltage balance of the power grid to cause a partial or complete blackout on the grid or targeting the electricity prices with the aim of financial gain. Based on the found vulnerabilities and the historical spread of malware, targeting the voltage balance or electricity prices were found to be more likely scenarios, as the overall amount of controllable load needed to achieve either is significantly lesser when compared to causing a sufficient frequency shift.
Kotiautomaatiolaitteiden turvallisuudesta on jo aiempia tutkimuksia, usein liittyen siihen mitä käytäntöjä laitevalmistajien tulisi laitteissa noudattaa. Onnistuneita laajoja hakkerointiyrityksiä on tehty kotiautomaatio laitteisiin kuten Mirai bottinetti. Tämä työ lisää tietoa tällä hetkellä kaupallisesti saatavilla olevien kotiautomaatiolaitteiden turvallisuudesta tarkastelemalla näistä yleisiä haavoittuvuuksia. Löydösten perusteella, ja tarkastelemalla viimeaikaisten haittaohjelmien leviämistä, kotiautomaatio bottinettien vaikutuksia Suomen sähköverkkoon pohditaan.
Haavoittuvuuksia löydettiin monista testatuista laitteista. Suurin osa haavoittuvuuksista ei ole systeemin turvallisuudelle kriittisiä, mutta muutama poikkeus löydettiin. Kolme mahdollista vaikutusskenaariota tarkasteltiin. Joko verkon taajuuteen tai jännitteeseen vaikuttaminen tarkoituksena aiheuttaa osittainen tai täydellinen sähkökatkos tai sähkön hintaan kohdistuva vaikuttaminen tavoitteena rahallinen hyötyminen. Löydettyjen haavoittuvuuksien ja historiallisen haittaohjelmien leviämisen perusteella jännitteeseen tai sähkön hintaan tähtääminen todettiin todennäköisemmäksi skenaarioksi, koska tällöin vaaditun kontrolloitavan kuorman määrä on huomattavasti vähäisempi.
