The summer’s blackouts weren’t caused by a worm or virus, but the failures highlight infrastructure weak spots, a report concluded this week. The Internet was far more seriously affected than previously thought by the blackouts that swept Europe and North America this summer, and without more investment in backup power it is in no shape to supersede the telephone network for primary communications, according to the report, by data analysis company Renesys.

“While the very largest provider networks — the Internet backbones — were apparently unaffected by the blackout (in North America), many thousands of significant networks and millions of individual Internet users were offline for hours or days,” the report stated. “Banks, investment funds, business services, manufacturers, hospitals, educational institutions, Internet service providers, and federal and state government units were among the affected organizations.”

On Aug. 14, the North American blackout hit more than 9,700 customer networks, belonging to over 3,500 organizations, in the affected area, the report said. A third of these networks suffered from “abnormal connectivity outages” during the blackout. Of those, more than 2,000 networks suffered severe connectivity outages for longer than four hours, and over 1,400 networks for longer than 12 hours—some even more than 48 hours.

The networks suffering from abnormal connectivity outages belonged to over 1,700 organizations, and more than 1,000 groups had outages of all of their networks that lasted longer than four hours. Nearly half of those organizations involved in global Internet routing lost connectivity to some or all of their networks in the blackout area.

The failures were not caused by malicious attackers nor any of the major Internet threats spreading at the time, according to a report released last week by a joint task force appointed by the U.S. and Canadian governments.

“Analysis to date provides no evidence that malicious actors are responsible for, or contributed to, the outage,” said the report by the Security Working Group, a team that focused on the security of the U.S. and Canadian power and distribution systems. “There is also no evidence, nor is there any information suggesting, that viruses and worms prevalent across the Internet at the time of the outage had any significant impact on power generation and delivery systems.”

That report — titled “Interim Report: Causes of the August 14th Blackout in the United States and Canada”—doesn’t dismiss the threat of a cyberattack affecting critical infrastructure. It cites a previous incident at an offline nuclear power plant as an example of the potential effects of a cyberattack. The Davis-Besse plant, run by FirstEnergy Nuclear, had control systems infected by the Microsoft SQL Slammer worm, which proceeded to cause havoc on the plant’s internal network. The power plant’s safety system and process computer were inaccessible for several hours. The nuclear facility had been offline so workers could fix a problem with the reactor.

The task force continues to work with law enforcement in both countries to examine the possibility that malicious attackers had a hand in the Aug. 14 power outage.

However, the report from Renesys stressed that specific effects of the blackout on Internet availability were geographically well-localized, and no evidence was found of cascading failures affecting global Internet stability.

This is backed up by the London Internet Exchange (LINX), which is the largest Internet exchange point in Europe. More than half of all Internet traffic in Europe passes through it. A spokeswoman for LINX said that in mid-August there was a slight dip in traffic flowing through the LINX routers, but that this dip was too small to be significant.

“We route a lot of traffic from ISPs in the U.S., so if the traffic had affected them we would see it,” she said. “We saw no problems for August—the network traffic continued to flow.”

Besides, she said, none of the serious operators have their equipment running without backup generators. “The backup generators at Telehouse on Broadway in New York can provide enough power to run a small city.”
More here.