Secure systems to power the future of smart grids


  • English
  • Arabic

A new threat to personal information is emerging from an unlikely source: the humble domestic light switch.

As the digital age continues to grow, hackers are finding new ways to secure sensitive information that could have serious repercussions. And that information can now be gathered through power networks.

The introduction of smart grids, or the digitalisation of electrical power grids, has created new vulnerabilities as homes and utilities are beginning to rely on network connectivity.

Fadi Aloul, a cyber security advisor and professor at the American University in Sharjah, says smart grids are the future and offer several advantages over current systems such as being able to monitor electricity usage remotely via an electronic device.

Have you ever been on your way to work and suddenly wondered: “Did I turn off the coffee pot?” With a smart power system a user can check what devices are switched on in their home via a mobile phone. A user can turn off the breaker that powers kitchen appliances with just a screen swipe while they are not actually at home.

The Dubai Electricity and Water Authority (Dewa) began a smart metering pilot project in 2005 that led to the utility upgrading its automation network including communications systems and remote operations. Dewa's smart networks and metering project, estimated to cost Dh7 billion, will replace 250,000 meters spanning over residential, industrial and commercial properties.

While this technology will elevate services, Mr Aloul cautions that there was no such existence of a completely secure system. Just like a user being able to access and cut power remotely, so can criminals.

“With every new gadget, there comes a lot of risk and security issues, especially at the beginning,” he says. “Security could come last on priorities – that gives hackers the freedom to take advantage.”

Mr Aloul says criminals could monitor a consumer’s home network to access data. This could include electricity usage, which may indicate when a homeowner is out of town, giving useful information to a potential burglar. A more serious risk could be the compromising of sensitive information on a home computer. “Everything is physically accessible with a smart grid,” Mr Aloul says.

Home networks are especially vulnerable because the public is not well educated about the risks, he says. By contrast, companies such as utilities funnel money into making servers stronger. “The human security [aspect] is the weakest link in any organisation and that’s what most hackers are after.”

Mr Aloul says there are three main entry points, or gateways for cyber criminals, in smart grid networks. These include: home devices such as meters; utility companies; and the network in between such as transmission and distribution lines.

Utility and commercial operations have already seen attacks from large, organised hacker groups, which ultimately hurt companies and sometimes governments. In addition, Mr Aloul points out that cyber activists or even state-funded groups could target power operations that may even threaten national security by executing attacks to take out entire power grids.

The American technology firm, F5 Networks, says it is looking to focus more on power-sector security as more systems depend on these types of connections.

The senior systems engineering manager Gary Newe says security is a “hot” division for the company right now.

The information technology research firm Gartner expects the cyber security industry to grow 8.2 per cent this year to US$76.9 billion. And the increasing adoption of mobile, cloud, social and information that is often interconnected will drive new security measures through 2016.

“Once you start to look at user information and move it to real time metering, the possibilities of what that data could be used for are pretty much endless,” Mr Newe says.

He says with critical infrastructure such as power stations, sensitive information in the wrong hands can cause serious damage.

"If [companies] are connected to the internet or internal networks, hackers can find a way to exploit [operations]," says Mr Newe. "There is the potential for scary things to happen."

He points to a recent attack by hackers on a German steel mill. The German federal office for Information Security (BSI) released its annual report in December that said hackers used emails to release malware, a software bug, that penetrated the mill’s automation system. The attack made parts of the plant fail, resulting in a potentially fatal furnace blast. The BSI said the infiltration caused “massive damage”, but did not specify how much the attack cost the company.

This particular crime used a method known as spear phishing; sending emails that target particular company individuals. These messages appear to come from an official source, such as the head of the company, and ask for login information including passwords.

Mr Newe says there has been a noticeable shift in the cyber criminals’ approach over the past 12 to 18 months. There has been a rise in “blended attacks” where a large attack is perpetrated to act as a diversion from a smaller, more targeted attack.

He also points to “denial of service” attacks, whereby a server is so overwhelmed with requests it goes offline. In addition is what is termed the domain name system reflection approach, where an attack is amplified by using a critical piece of internet infrastructure such as the network interface bandwidth, or data processing capacity.

This method can debilitate very large networks such as real-time trading platforms or financial institutions.

Mr Newe says F5 has seen cyber attacks rocket by 200 to 300 per cent in the past 12 months.

This has led to the European Union, among others, looking to aggressively address the issue before it is too late.

According to a July report by the Organisation for Security and Cooperation in Europe (OSCE), the EU allocated €3.5 million (Dh14.5m) to develop a decision support system (DSS) for power grid operators.

This computer system helps organisations to determine security responses based on various simulations.

The EU DSS will help grid operators mimic cyber invasions to analyse which areas could be brought down while also calculating the amount of time it would be likely to take to restore the compromised infrastructure.

The system will also assess the economic costs of an incident and provide recommendations on how to address weaknesses in Europe’s power supply. Although the system is still under construction, the potential financial losses as a result of electricity disruptions can be seen in examples such as Egypt’s chronic power shortages that reached heights last summer.

While Mr Newe says it is extremely difficult to assess how much cyber attacks are costing networks, large-scale power outages caused by other reasons can give an idea.

In September, the Suez Canal Authority was forced to declare a state of emergency as blackouts crippled vessel movement on the waterway that provides some $5bn in annual revenue. Ships were forced to remain stationary because communication networks, which depend on electricity, were unable to function. Disruptions to industries such as iron, steel and oil refineries and pumping stations cost the Egyptian government an estimated $140m in revenue.

Power grids are also susceptible to natural disasters. In the United States, Mississippi suffered a major blow to the its economy in 2005 when Hurricane Katrina destroyed the power supply for one of its main revenue earning industries, gaming.

Prior to the storm, casinos on the Mississippi Gulf Coast generated about $2.8bn in annual revenue and made up about $330m of state and local governments’ tax revenues, according to the American Gaming Association.

To get an idea of what the cost of a similar outage caused by online criminals might be, substitute “cyber attack” for Hurricane Katrina”.

Based on the revenue losses recorded for 2005, each day the casinos were unable to operate cost the industry some $7.6m, or $320,000 an hour. A power failure taking out the grid for three hours would result in a loss of almost $1m.

“Gaming, finance, power – hackers don’t discriminate. It’s across the board,” Mr Newe says.

But he is optimistic about the power sector doing everything it can to increase protection with the rise in the deployment of of smart grids because “they’re charged to protect consumer data”.

He adds that solutions usually only come after a situation has occurred. “We don’t know what the possibilities are and we don’t know the vulnerabilities,” Mr Newe says.

“It will take someone to identify the problem before we can combat it.”

lgraves@thenational.ae

Follow The National's Business section on Twitter

THE CLOWN OF GAZA

Director: Abdulrahman Sabbah 

Starring: Alaa Meqdad

Rating: 4/5

The specs: 2018 Jeep Grand Cherokee Trackhawk


Price, base: Dh399,999
Engine: Supercharged 6.2-litre V8
Gearbox: Eight-speed automatic
Power: 707hp @ 6,000rpm
Torque: 875Nm @ 4,800rpm
Fuel economy, combined: 16.8L / 100km (estimate)

Conflict, drought, famine

Estimates of the number of deaths caused by the famine range from 400,000 to 1 million, according to a document prepared for the UK House of Lords in 2024.
It has been claimed that the policies of the Ethiopian government, which took control after deposing Emperor Haile Selassie in a military-led revolution in 1974, contributed to the scale of the famine.
Dr Miriam Bradley, senior lecturer in humanitarian studies at the University of Manchester, has argued that, by the early 1980s, “several government policies combined to cause, rather than prevent, a famine which lasted from 1983 to 1985. Mengistu’s government imposed Stalinist-model agricultural policies involving forced collectivisation and villagisation [relocation of communities into planned villages].
The West became aware of the catastrophe through a series of BBC News reports by journalist Michael Buerk in October 1984 describing a “biblical famine” and containing graphic images of thousands of people, including children, facing starvation.

Band Aid

Bob Geldof, singer with the Irish rock group The Boomtown Rats, formed Band Aid in response to the horrific images shown in the news broadcasts.
With Midge Ure of the band Ultravox, he wrote the hit charity single Do They Know it’s Christmas in December 1984, featuring a string of high-profile musicians.
Following the single’s success, the idea to stage a rock concert evolved.
Live Aid was a series of simultaneous concerts that took place at Wembley Stadium in London, John F Kennedy Stadium in Philadelphia, the US, and at various other venues across the world.
The combined event was broadcast to an estimated worldwide audience of 1.5 billion.

The specs: Fenyr SuperSport

Price, base: Dh5.1 million

Engine: 3.8-litre twin-turbo flat-six

Transmission: Seven-speed automatic

Power: 800hp @ 7,100pm

Torque: 980Nm @ 4,000rpm

Fuel economy, combined: 13.5L / 100km

UAE currency: the story behind the money in your pockets
COMPANY PROFILE
Name: Almnssa
Started: August 2020
Founder: Areej Selmi
Based: Gaza
Sectors: Internet, e-commerce
Investments: Grants/private funding
While you're here
COMPANY PROFILE
Name: Kumulus Water
 
Started: 2021
 
Founders: Iheb Triki and Mohamed Ali Abid
 
Based: Tunisia 
 
Sector: Water technology 
 
Number of staff: 22 
 
Investment raised: $4 million 
THE SPECS

Engine: 6.75-litre twin-turbocharged V12 petrol engine 

Power: 420kW

Torque: 780Nm

Transmission: 8-speed automatic

Price: From Dh1,350,000

On sale: Available for preorder now

PROVISIONAL FIXTURE LIST

Premier League

Wednesday, June 17 (Kick-offs uae times) Aston Villa v Sheffield United 9pm; Manchester City v Arsenal 11pm 

Friday, June 19 Norwich v Southampton 9pm; Tottenham v Manchester United 11pm  

Saturday, June 20 Watford v Leicester 3.30pm; Brighton v Arsenal 6pm; West Ham v Wolves 8.30pm; Bournemouth v Crystal Palace 10.45pm 

Sunday, June 21 Newcastle v Sheffield United 2pm; Aston Villa v Chelsea 7.30pm; Everton v Liverpool 10pm 

Monday, June 22 Manchester City v Burnley 11pm (Sky)

Tuesday, June 23 Southampton v Arsenal 9pm; Tottenham v West Ham 11.15pm 

Wednesday, June 24 Manchester United v Sheffield United 9pm; Newcastle v Aston Villa 9pm; Norwich v Everton 9pm; Liverpool v Crystal Palace 11.15pm

Thursday, June 25 Burnley v Watford 9pm; Leicester v Brighton 9pm; Chelsea v Manchester City 11.15pm; Wolves v Bournemouth 11.15pm

Sunday June 28 Aston Villa vs Wolves 3pm; Watford vs Southampton 7.30pm 

Monday June 29 Crystal Palace vs Burnley 11pm

Tuesday June 30 Brighton vs Manchester United 9pm; Sheffield United vs Tottenham 11.15pm 

Wednesday July 1 Bournemouth vs Newcastle 9pm; Everton vs Leicester 9pm; West Ham vs Chelsea 11.15pm

Thursday July 2 Arsenal vs Norwich 9pm; Manchester City vs Liverpool 11.15pm

 

Veere di Wedding
Dir: Shashanka Ghosh
Starring: Kareena Kapoo-Khan, Sonam Kapoor, Swara Bhaskar and Shikha Talsania ​​​​​​​
Verdict: 4 Stars

match info

Southampton 0

Arsenal 2 (Nketiah 20', Willock 87')

Red card: Jack Stephens (Southampton)

Man of the match: Rob Holding (Arsenal)

What is the definition of an SME?

SMEs in the UAE are defined by the number of employees, annual turnover and sector. For example, a “small company” in the services industry has six to 50 employees with a turnover of more than Dh2 million up to Dh20m, while in the manufacturing industry the requirements are 10 to 100 employees with a turnover of more than Dh3m up to Dh50m, according to Dubai SME, an agency of the Department of Economic Development.

A “medium-sized company” can either have staff of 51 to 200 employees or 101 to 250 employees, and a turnover less than or equal to Dh200m or Dh250m, again depending on whether the business is in the trading, manufacturing or services sectors. 

Benefits of first-time home buyers' scheme
  • Priority access to new homes from participating developers
  • Discounts on sales price of off-plan units
  • Flexible payment plans from developers
  • Mortgages with better interest rates, faster approval times and reduced fees
  • DLD registration fee can be paid through banks or credit cards at zero interest rates
Profile of Bitex UAE

Date of launch: November 2018

Founder: Monark Modi

Based: Business Bay, Dubai

Sector: Financial services

Size: Eight employees

Investors: Self-funded to date with $1m of personal savings

Profile of RentSher

Started: October 2015 in India, November 2016 in UAE

Founders: Harsh Dhand; Vaibhav and Purvashi Doshi

Based: Bangalore, India and Dubai, UAE

Sector: Online rental marketplace

Size: 40 employees

Investment: $2 million

Specs
Engine: Electric motor generating 54.2kWh (Cooper SE and Aceman SE), 64.6kW (Countryman All4 SE)
Power: 218hp (Cooper and Aceman), 313hp (Countryman)
Torque: 330Nm (Cooper and Aceman), 494Nm (Countryman)
On sale: Now
Price: From Dh158,000 (Cooper), Dh168,000 (Aceman), Dh190,000 (Countryman)
Gothia Cup 2025

4,872 matches 

1,942 teams

116 pitches

76 nations

26 UAE teams

15 Lebanese teams

2 Kuwaiti teams

MATCH INFO

Leeds United 0

Brighton 1 (Maupay 17')

Man of the match: Ben White (Brighton)

The alternatives

• Founded in 2014, Telr is a payment aggregator and gateway with an office in Silicon Oasis. It’s e-commerce entry plan costs Dh349 monthly (plus VAT). QR codes direct customers to an online payment page and merchants can generate payments through messaging apps.

• Business Bay’s Pallapay claims 40,000-plus active merchants who can invoice customers and receive payment by card. Fees range from 1.99 per cent plus Dh1 per transaction depending on payment method and location, such as online or via UAE mobile.

• Tap started in May 2013 in Kuwait, allowing Middle East businesses to bill, accept, receive and make payments online “easier, faster and smoother” via goSell and goCollect. It supports more than 10,000 merchants. Monthly fees range from US$65-100, plus card charges of 2.75-3.75 per cent and Dh1.2 per sale.

2checkout’s “all-in-one payment gateway and merchant account” accepts payments in 200-plus markets for 2.4-3.9 per cent, plus a Dh1.2-Dh1.8 currency conversion charge. The US provider processes online shop and mobile transactions and has 17,000-plus active digital commerce users.

• PayPal is probably the best-known online goods payment method - usually used for eBay purchases -  but can be used to receive funds, providing everyone’s signed up. Costs from 2.9 per cent plus Dh1.2 per transaction.

WWE TLC results

Asuka won the SmackDown Women's title in a TLC triple threat with Becky Lynch and Charlotte Flair

Dean Ambrose won the Intercontinental title against Seth Rollins

Daniel Bryan retained the WWE World Heavyweight Championship against AJ Styles

Ronda Rousey retained the Raw Women's Championship against Nia Jax

Rey Mysterio beat Randy Orton in a chairs match

Finn Balor defeated Drew McIntyre

Natalya beat Ruby Riott in a tables match

Braun Strowman beat Baron Corbin in a TLC match

Sheamus and Cesaro retained the SmackDown Tag Titles against The Usos and New Day

R-Truth and Carmella won the Mixed Match Challenge by beating Jinder Mahal and Alicia Fox