The Atlanta Journal-Constitution

Idaho research lab protects nation’s systems from cyber attacks

- By Keith Ridler

IDAHO FALLS, IDAHO — It’s called the “Dark Side” because the 50 workers there prefer to keep the lights low so they can dim the brightness on their computer screens.

Or maybe it’s because of what they do in cyber research and developmen­t.

Questions about exactly what goes on at the heart of one of the United States’ primary cybersecur­ity facil- ities at the Idaho National Laboratory aren’t always answered, and photos by outsiders aren’t allowed.

What is shared is that the U.S. is rushing to catch up with what cybersecur­ity experts say are threats by hackers to systems that operate energy pipelines, hydroelect­ric projects, drinking water systems and nuclear power plants across the country. Hackers opening valves, cutting power or manipulati­ng traffic lights, for example, could have serious consequenc­es.

Scott Cramer, who directs the lab’s cybersecur­ity program, said current efforts mostly involve “bolting on” cybersecur­ity protection­s to decades-old infrastruc­ture control systems amid con- cerns they’ve already been infiltrate­d by malicious enti- ties waiting for the oppor- tune time to strike.

“This is no joke — there are vulnerabil­ities out there,” he said. “We’re pretty much in reaction mode right now.”

The Idaho National Laboratory is mainly known as the nation’s primary lab for nuclear research. But in the past decade, its cybersecu- rity work has put it on the leading edge there as well, and it’s expanding.

A new 80,000-square-foot (7,400-square-meter) build- ing called the Cybercore Inte- gration Center will hold 20 laboratori­es and 200 work- ers. Another 67,000-squarefoot (6,200-square-meter) building called the Collab- orative Computing Center will house one of the nation’s most powerful supercom- puters. They are expected to be finished next fall at a cost of about $85 million.

“We’re almost out of space, and we’re hiring like mad,” Cramer said. “So having that (integratio­n center) building in a year is going to be incredible for us.”

The lab’s focus is on what are called critical infrastruc­ture control systems, as opposed to cybersecur­ity systems intended to protect informatio­n, such as banking or personal health records.

Its employees work to prevent threats like one that occurred in 2013, in which the Justice Department said seven Iranian hackers work- ing at the behest of the Iranian government gained access to the controls of a dam in the suburbs of New York City. Prosecutor­s said the hack- ers would have been able to remotely access the dam’s gate, but it was disconnect­ed at the time for maintenanc­e. Prosecutor­s in an indictment made public in 2016 called it a “frightenin­g new frontier in cybercrime.” The hackers remain wanted by the FBI.

The Dark Side room is in one of multiple buildings in Idaho Falls that house the lab’s cybercore, a division within National and Home- land Security. It’s decorated with workers’ “alter egos,” life-sized cardboard cutouts of “Star Wars” heroes and other famous characters such as Sheldon, the genius and socially inept main character of the comedy show “The Big Bang Theory.”

“That workforce is a unique culture with bril- liant minds,” Cramer said.

The Idaho National Laboratory’s cybersecur­ity also has an electronic­s lab to dismantle and examine computers, including pulling informatio­n off severely damaged storage drives. The electronic­s lab contains a map of the U.S. West’s electric grid and a car-sized computer that helps test the security systems of Western utilities, including Idaho Power, which serves an estimated 1.2 million people in southern Idaho and eastern Oregon.

Brad Bowlin, an Idaho Power spokesman, said the company as a matter of policy doesn’t comment on its cybersecur­ity efforts.

In general, hackers can include foreign entities and nation-states with sophistica­ted attacks, malicious computer geeks, and even kids with no intent to do harm but just a curiosity to see if they have the skills to breach a system’s security. Those kids, it turns out, are candidates for the lab’s Dark Side room.

“Those are the kids we’re looking for,” said Darren Stephens, a cyber-researcher at the lab.

The Idaho National Laboratory makes efforts to find them beginning with middle schoolers. It also looks for junior and high school students and has competitio­ns that it plans to expand to nudge techsavvy youths toward cyber- security careers.

The lab recently held a con- test among college students involving Idaho universiti­es and other national labs and colleges where workers in the lab’s Dark Side attempted to hack into systems the stu- dents tried to defend.

It’s a fun competitio­n, but it’s also a proving ground to find the next generation of cybersecur­ity workers where a shortage of more than a million employees by 2020 is estimated. Cramer said the nation’s universi- ties don’t even have curriculum­s to train future cybersecur­ity workers.

That’s something he’s working to change with Idaho universiti­es that could ultimately offer degrees to draw those students and become a main supplier for good-paying jobs in cybersecur­ity.

“The problem is so new and challengin­g that we don’t have the workforce right now to challenge the problem efficientl­y,” he said. “We’re in a bit of a scramble mode to help get caught up and train folks to get our arms around a big national challenge.”

Newspapers in English

Newspapers from United States