前美国国家安全局局长称:水系统控制器不应联网。
Water system controllers don't belong on the internet, says ex-NSA chief

原始链接: https://www.theregister.com/security/2026/08/07/water-system-controllers-dont-belong-on-the-internet-says-ex-nsa-chief-after-suspected-iran-attacks/5285070

前美国国家安全局局长保罗·中曾根(Paul Nakasone)在黑客大会(DEF CON)上发出警告称,美国供水系统极易遭受网络攻击,并指出近期已有 12 个州发生相关入侵事件。尽管联邦调查局尚未正式指明肇事者,但许多专家认为,伊朗在幕后针对可编程逻辑控制器(PLC)发动了攻击,这些控制器负责管理水泵等核心基础设施。 中曾根强调,由于这些系统连接互联网,再加上分布在 5 万个分散的市政设施中缺乏专门的网络安全资源,导致系统处于危险的暴露状态。他认为现状难以为继,并呼吁提高标准,特别是将 PLC 与互联网进行物理隔离。 为了应对这一问题,中曾根主张采取协作防御策略。他重点介绍了诸如“DEF CON Franklin”(志愿者黑客协助公用事业部门)以及他个人发起的旨在增强基础设施韧性的开源平台“奇美拉计划”(Project Chimera)等举措。最后,他敦促改变国家保护这些重要系统的方式,强调政府、学术界和网络安全社区之间的合作对于保护国家庞大且资金不足的攻击面至关重要。

最近 Hacker News 上的一场讨论引起了对关键水利基础设施安全性的担忧,起因是前美国国家安全局(NSA)局长发表声明,建议水利系统控制器应保持离线状态。 评论者普遍认为,互联网连接带来了不必要的漏洞。一位用户强调,即使是没有连接互联网的系统,也常因不安全的射频或蓝牙链路而被攻破,并指出任何联网的系统本质上都存在风险。另一位参与者提到,尽管系统现代化可能带来益处,但老旧硬件(如已有 30 年历史的 PLC)特别容易遭受攻击,因此建议在部署更安全的架构之前,人工监控是更稳妥的选择。 总体而言,舆论反映了一种“通过隔离实现安全”的思维方式,参与者警告称,远程连接的便利性远不及被攻击所带来的严重后果。
相关文章

原文

Security

Calling all defenders

With at least 12 US states’ water systems having been hacked - most likely by Iran - we have to get better at cyber defense, according to retired General and Ex-NSA chief Paul Nakasone, who was speaking to reporters at DEF CON.

“We have to have higher standards,” Nakasone said. “These PLCs should not be connected to the internet.”

In late July, the FBI said it was investigating attacks conducted by “malicious cyber actors” targeting operational technology devices, including programmable logic controllers (PLCs). Iran-linked crews have targeted these devices, which monitor sensor data like tank levels, and can turn pumps on and off, for years

Some private-sector security researchers say that they suspect Iranian intruders are behind the recent cyberattacks disrupting water and wastewater facilities. “I'd be shocked if it's not Iran,” Halcyon Ransomware Research Center SVP Cynthia Kaiser told The Register at DEF CON on Friday. “It's almost certain it's Iran.”

Neither the FBI nor anyone in the Trump administration, however, has officially blamed Iran.

Nakasone said he believes that the feds are “taking a measured approach” to attribution. “But I see an actor here that has certainly shown a history of being able to do this,” he added, referring to earlier Iranian cyberattacks targeting water facilities’ PLCs. 

“They certainly have the capability,” Nakasone said. “There's an intent … we're in conflict with Iran.”

US water systems present a massive attack surface across disparate facilities that are historically underfunded and have limited IT staff, and sometimes no dedicated cybersecurity employees.

“We have to think differently about how we defend it,” Nakasone said. “Let's talk about the attack surface that we're looking at right now. We’ve got 50,000 different water municipalities in the United States, 90 percent of our water comes from these 50,000.”

Defending these water systems requires partnerships, he added, pointing to DEF CON Franklin, a project launched two years ago at the annual event with hackers volunteering their time and talent to help secure water facilities.

Nakasone also serves as founding director of Vanderbilt University’s Institute of National Security, and its Wicked Problems Lab. He's also working on Project Chimera, a cybersecurity platform being developed by academics and cybersecurity practitioners, and built on open-source technologies to boost critical infrastructure resilience.

“How do you defend better? You defend with a series of partners, in a much more involved approach than we have right now,” Nakasone said.®

联系我们 contact @ memedata.com