Cyberwar defenders train at UNO - Omaha.com
Published Sunday, April 22, 2012 at 1:00 am / Updated at 3:40 am
Cyberwar defenders train at UNO

A few taps on his tablet computer and Justin Roberts sends a pair of trains loaded with hazardous materials on a collision course.

Or forces a nuclear plant into meltdown. Or shuts down the power grid for the entire Eastern Seaboard.

OK, the University of Nebraska at Omaha senior is really just sending malicious signals to a series of computerized controllers along the wall of a university lab, turning their winking lights from green to red.

But it's through such exercises that students at the Nebraska University Center for Information Assurance examine how terrorists, hostile countries or simply bored hackers could inflict massive damage by infiltrating the nation's critical infrastructure systems.

"In here, it's just lights, but when you think about how many things that could be connected to ... rail systems, water treatment centers, traffic control stations ...," said grad student Casey Glatter. "(It's) the idea of him sending a single message to a single one of these devices, but causing a catastrophic failure."

The school is creating defenders to join the cyberwar's front lines, with careers at major private-sector companies, government security agencies or military operations such as the U.S. Strategic Command.

The center is looking to expand its activities with a new master's degree program specific to information assurance. It's also seeking additional federal scholarship funding for students who agree to take government positions after they graduate. The program already has graduated 35 such scholars.

Glatter is off to Sandia National Laboratories in Albuquerque, N.M., after he finishes his studies next month. Another student, Tory Cullen, is joining Facebook.

Roberts is sticking around to continue his work in graduate school.

He recalled how he figured out —as a 12-year-old — how to get free access to HBO programming through his computer.

"Then I figured out UNO has a degree program that lets me do that," Roberts said.

He added that he now pays for his premium cable programming.

The students are working on how to simulate critical infrastructure systems, then launch cyberattacks to see how the systems react.

They want to know what happens if a particular part of the system gets hijacked. How does that affect the rest of the system? How does that affect the public?

It's like staging a virtual Armageddon.

They would like to connect their software models of power grids into actual computerized controllers and eventually hook up the whole thing to the Internet. Then they will watch the hackers tear into it and find weaknesses in the defenses.

They've already taken an early stab at that by putting online a system that appeared to the outside world to be a simple power controller.

This was not the kind of site someone would stumble upon while searching for the latest Kardashian news. You would find it only if you were looking for something to hack. And people were looking.

The students were able to track cyberattacks against the site from across the globe, many from China. Those attacks were particularly concentrated in an area around a university closely tied to the Chinese government.

That revelation underscored the importance of training U.S. students in ways to defend from cyberattacks. While the United States is believed to have been engaged in some offensive cyber-operations, such as the one that damaged Iranian nuclear facilities, these students are focused for now on the defensive side.

The UNO cyberscholars do compete sometimes against students at other universities in "capture the flag" contests, which can involve trying to hack into each others' computers, but they said that's more about understanding the way attacks work to design better defenses.

One defensive mechanism they're working on is a "gumstick" encryption device — so named because it's the size of a stick of gum — that could easily be popped into existing systems.

Ken Dick, research fellow of IT innovation, said that would be helpful, because the typical controllers that hackers could target don't have enough computing power to include encryption. By popping the gumstick into the system, companies could block intruders.

In many cases, it's simply not clear how vulnerable U.S. systems might be, because utilities and businesses generally don't volunteer information about their security designs or their experience with cyberattacks.

And things are ever-changing. Robin Gandhi, UNO assistant professor of information assurance, quoted one expert who says the country gets smarter on Tuesdays because that's when Microsoft regularly releases security patches to its software.

There's enough concern about the situation that Congress is examining different ways to tighten the country's cyberdefense.

Nebraska lawmakers such as U.S. Rep. Lee Terry have visited with the UNO center about the situation. Terry is among those leading House Republican efforts on cybersecurity.

Bill Mahoney, UNO assistant professor of information assurance, said it's not clear how effectively utilities and companies are protecting their new systems.

He noted that it's not unusual to simply open your laptop and find an unsecured wireless network, often just labeled "linksys." That means someone bought a router, plugged it in and never bothered to set up a password.

"You have the same possibility of that happening in equipment that controls things that have a very profound impact on people's lives," Mahoney said.

You might imagine a terrorist with a bomb that is set to take out the power grid, but Mahoney said all someone has to do is figure out the correct substations to hack into, and they could cause the system to go down like a line of dominoes.

"You hack into New York, and it trickles all the way west from there," he said. "You don't even have to leave your cave. ... It's cost-effective terrorism."

Contact the writer:

202-630-4823, joe.morton@owh.com

Contact the writer: Joseph Morton

joe.morton@owh.com    |  

Joe is The World-Herald's Washington, D.C., bureau, covering national political developments that matter most to Midlanders.

Explosive device blows hole in windshield, damages another car
Financial picture improving for city-owned Mid-America Center
19-year-old arrested in connection with March shooting
No injuries after fire at midtown's old Mercer Mansion
17 senators in Nebraska Legislature hit their (term) limits
Keystone XL pipeline backers blast 'political expediency' as foes hail ruling to delay decision
29-year-old Omahan arrested for 22nd time in Lincoln
Nebraska senators to study tax issues over break
Portion of Saddle Creek Road closed after water main break
Teenager arrested after woman's purse is snatched outside Omaha store
Police identify 21-year-old shot in ankle near 30th, W Streets
Cult murderer's death row appeal denied, but execution in limbo
Beau McCoy strikes Obama doll in TV ad; Democrats are not happy
Police: Slaying of woman in Ralston apartment likely over drugs
Interstate construction to cause lane shifts, closings in Omaha area
Kelly: A California university president returns to her Nebraska roots on Ivy Day
Omahan charged in fatal shooting in Benson neighborhood
Friday's attendance dips at Millard West after bathroom threat
High school slam poets don't just recite verses, 'they leave their hearts beating on the stage'
Crack ring's leaders join others in prison as a result of Operation Purple Haze
Haze in area comes from Kansas, Oklahoma
Man taken into custody in domestic dispute
Omaha judge reprimanded for intervening in peer attorney's DUI case
Intoxicated man with pellet gun climbs billboard's scaffold; is arrested
Police seek public's help in finding an armed man
< >
COLUMNISTS »
Kelly: A California university president returns to her Nebraska roots on Ivy Day
The main speaker at today's Ivy Day celebration at the University of Nebraska-Lincoln is a college president who grew up roping calves and earned her Ph.D. at the prestigious Oxford University in England.
Breaking Brad: Stuck in a claw machine? You get no Easter candy
I know of one kid in Lincoln who will be receiving a lump of coal from the Easter Bunny, just as soon as he's extricated from that bowling alley claw machine.
Breaking Brad: Mountain lion season's over, but the bunny's fair game!
Thursday was the last day of a Nebraska Legislature session. Before leaving town, legislators passed a bill to hold a lottery to hunt the Easter Bunny.
Breaking Brad: At least my kid never got stuck inside a claw machine
We need a new rule in Lincoln. If your kid is discovered inside the claw machine at a bowling alley, you are forever barred from being nominated for "Mother of the Year."
Breaking Brad: How many MECA board members can we put in a luxury suite?
As a stunt at the Blue Man Group show, MECA board members are going to see how many people they can stuff into one luxury suite.
Deadline Deal thumbnail
The Jaipur in Rockbrook Village
Half Off Fine Indian Cuisine & Drinks! $15 for Dinner, or $7 for Lunch
Buy Now
PHOTO GALLERIES »
< >
SPOTLIGHT »
Omaha World-Herald Contests
Enter for a chance to win great prizes.
OWH Store: Buy photos, books and articles
Buy photos, books and articles
Travel Snaps Photo
Going on Vacation? Take the Omaha World-Herald with you and you could the next Travel Snaps winner.
Click here to donate to Goodfellows
The 2011 Goodfellows fund drive provided holiday meals to nearly 5,000 families and their children, and raised more than $500,000 to help families in crisis year round.
WORLD-HERALD ALERTS »
Want to get World-Herald stories sent directly to your home or work computer? Sign up for Omaha.com's News Alerts and you will receive e-mails with the day's top stories.
Can't find what you need? Click here for site map »