You have commented 339 times on Rantburg.

Your Name
Your e-mail (optional)
Website (optional)
My Original Nic        Pic-a-Nic        Sorry. Comments have been closed on this article.
Bold Italic Underline Strike Bullet Blockquote Small Big Link Squish Foto Photo
Home Front: WoT
"Data storm" blamed for nuclear-plant shutdown
2007-05-20
Could have bene provoked by an outside data spike: that's not comforting.
The U.S. House of Representative's Committee on Homeland Security called this week for the Nuclear Regulatory Commission (NRC) to further investigate the cause of excessive network traffic that shut down an Alabama nuclear plant.

During the incident, which happened last August at Unit 3 of the Browns Ferry nuclear power plant, operators manually shut down the reactor after two water recirculation pumps failed. The recirculation pumps control the flow of water through the reactor, and thus the power output of boiling-water reactors (BWRs) like Browns Ferry Unit 3. An investigation into the failure found that the controllers for the pumps locked up following a spike in data traffic -- referred to as a "data storm" in the NRC notice -- on the power plant's internal control system network. The deluge of data was apparently caused by a separate malfunctioning control device, known as a programmable logic controller (PLC).

In a letter dated May 14 but released to the public on Friday, the Committee on Homeland Security and the Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology asked the chairman of the U.S. Nuclear Regulatory Commission to continue to investigate the incident.

"Conversations between the Homeland Security Committee staff and the NRC representatives suggest that it is possible that this incident could have come from outside the plant," Committee Chairman Bennie G. Thompson (D-Miss.) and Subcommittee Chairman James R. Langevin (D-RI) stated in the letter. "Unless and until the cause of the excessive network load can be explained, there is no way for either the licensee (power company) or the NRC to know that this was not an external distributed denial-of-service attack."

The PLC was connected to the plant's Ethernet network, according to an NRC information notice on the incident. The PLC controlled Unit 3's condensate demineralizer -- essentially a water softener for nuclear plants. The flood of data spewed out by the malfunctioning controller caused the variable frequency drive (VFD) controllers for the recirculation pumps to hang.

Such failures are common among PLC and supervisory control and data acquisition (SCADA) systems, because the manufacturers do not test the devices' handling of bad data, said Dale Peterson, CEO of industrial system security firm DigitalBond. "What is happening in this marketplace is that vendors will build their own (network) stacks to make it cheaper," Peterson said. "And it works, but when (the device) gets anything that it didn't expect, it will gag."
Posted by:Steve White

#7  Am I the only one who finds it supremely ironic and hysterically funny that DOS has finally come to mean denial-of-service?

DOS = Disk Operating System
DoS = Denial of Service

It helps if you grasp the subtle differences between the acronym's.
Posted by: Natural Law   2007-05-20 22:53  

#6  there is no way for either the licensee (power company) or the NRC to know that this was not an external distributed denial-of-service attack.

Am I the only one who finds it supremely ironic and hysterically funny that DOS has finally come to mean denial-of-service?
Posted by: Zenster   2007-05-20 17:04  

#5  How about a plain old pressure switch? (several times redundant of course)do away with computer controls except as backup.
Posted by: Redneck Jim   2007-05-20 13:10  

#4  Why would a nuclear plant's Local area network (LAN) be connected to the Internet? (Another article mentioned the LAN was 10 Mbps - very OLD tech. I've seen old network interface cards go bad and saturate a network).
Posted by: DMFD   2007-05-20 09:29  

#3  Take it from me (worked on design and construction of 4 nukes) the PLC and SCADA systems are strictly internal. Could be a dopey loop in the logic sequence under certain conditions that just now became apparent - low flow at certain temps or PSI for example.
Posted by: Jack is Back!   2007-05-20 06:49  

#2  DRUDGE > DICAPRIO says HUMANS FACE EXTINCTION FROM GLOBAL WARMING. Wouldn't had happened iff we all wore togas and lived green like Leonardo.
Posted by: JosephMendiola   2007-05-20 03:46  

#1  Doesn't know what to do with bad data? Sounds suspiciously like Macrosoft's sloppy work.
Posted by: gorb   2007-05-20 01:27  

00:00