Feeds

Stuxnet 'a game changer for malware defence'

EU agency warning

5 things you didn’t know about cloud backup

The Stuxnet malware is a game changer for critical information infrastructure protection, an EU security agency has warned.

ENISA (European Network and Information Security Agency) warns that a similar attack of malware capable of sabotaging industrial control systems as Stuxnet may occur in future.

The worm, whose primary method of entry into systems is infected USBs, essentially ignores vulnerable Windows boxes but aggressively attacks industrial control (SCADA) systems from Siemens, establishing a rootkit as well as a backdoor connection to two (now disconnected) command and control servers in Malaysia and Denmark.

PLC controllers of SCADA systems infected with the worm might be programmed to establish destructive over/under pressure conditions by running pumps at different frequencies, for example. There's no evidence either way as to whether this has actually happened, but what is clear is that the malware has caused a great deal of concern and inconvenience. India, Indonesia and Iran have recorded the most incidents of the worm, according to analysis of infected IP addresses by security firms.

Incidents of infection were first recorded in Malaysia, but the appearance of the malware in Iran has been the focus of comment and attention. Plant officials at the controversial Bushehr nuclear plant in Iran have admitted that the malware has infected laptops. However government ministers, while blaming the attack on nuclear spies, had downplayed the impact of the attack and denied it has anything to do with a recently announced two-month delay in bringing the reactor online.

Dr Udo Helmbrecht, executive director of ENISA, commented: "Stuxnet is a new class and dimension of malware. Not only for its complexity and sophistication (eg by the combination of exploiting four different vulnerabilities in Windows, and by using two stolen certificates) and from there attacking complex Siemens SCADA systems. The attackers have invested a substantial amount of time and money to build such a complex attack tool."

"The fact that perpetrators activated such an attack tool, can be considered as the 'first strike' against major industrial resources. This has tremendous effect on how to protect national (CIIP) in the future," he added.

Ilias Chantzos, director of government relations at Symantec, told a meeting at the Symantec Vision conference in Barcelona this week that millions had been spent developing the malware.

"Stuxnet would have involved a team of between 5-10 people, six months research and access to SCADA systems. The motive behind the malware was to spy and re-program industrial control systems.

Chantzos declined to enter into speculation about who created the malware or its intended target beyond saying "only a well-funded criminal organisation or nation state would have the resources to develop the malware".

Steve Purser of ENISA told journalists that Stuxnet has taught security experts nothing they didn't already know. "What is significant is its target and impact. We have to prepare for a future Stuxnet."

Critical protection methodologies and best practices will have to be reassessed in the wake of Stuxnet, according to ENISA.

Large scale attacks on critical infrastructure require a coordinated international response. No Member State, hardware/software vendor, CERT or law enforcement agency can successfully mitigate sophisticated attacks like Stuxnet on their own. ENISA plans to support these efforts by helping to devise revised best practices for securing SCADA systems.

In addition, ENISA, in co-operation with all EU Member States and three EFTA countries, plan to mount the first pan-Europe cyber-security exercise in early November. Cyber Europe 2010 will set out to test member states' plans, policies and procedures for responding to potential critical information infrastructure crises or incidents, such as those posed by Stuxnet. The scheme is similar and smaller than the Cyber-Storm program in the US.

ENISA, which was established in 2004, was granted a five-year extenuation to its responsibilities last month. The agency's analysis of Stuxnet and links to other resources can be found here. ®

Next gen security for virtualised datacentres

More from The Register

next story
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Hear ye, young cyber warriors of the realm: GCHQ wants you
Get involved, get a job and then never discuss work ever again
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.