The Register® — Biting the hand that feeds IT

Feeds

US killer spy drone controls switch to Linux

Flying assassins upgraded after Windows virus outbreak

Ensure Ease of Recovery with Asigra’s Agentless Software

The control of US military spy drones appears to have shifted from Windows to Linux following an embarrassing malware infection.

Ground control systems at Creech Air Force Base in Nevada, which commands the killer unmanned aircraft, became infected with a virus last September. In a statement at the time the Air Force dismissed the electronic nasty as a nuisance and said it posed no threat to the operation of Reaper drones, but the intrusion was nonetheless treated seriously.

"The ground system is separate from the flight control system Air Force pilots use to fly the aircraft remotely; the ability of the pilots to safely fly these aircraft remained secure throughout the incident," it said.

The discovery of the virus was nonetheless hugely embarrassing for the Air Force. The credential-stealing malware, first reported by Wired, made its way from a portable hard drive onto ground systems, which control the drones' weapons and surveillance functions. Portable disks are used to load map updates and transfer mission videos from one computer to another, Defense News added.

"The malware was detected on a standalone mission support network using a Windows-based operating system," a US Air Force statement at the time explained. "The malware in question is a credential stealer, not a keylogger, found routinely on computer networks and is considered more of a nuisance than an operational threat. It is not designed to transmit data or video, nor is it designed to corrupt data, files or programs on the infected computer. Our tools and processes detect this type of malware as soon as it appears on the system, preventing further reach."

Drone units were advised to stop using the removable drives to prevent another outbreak. Behind the scenes other changes appear to have been made: screenshots of drone control computers uploaded by security researcher Mikko Hypponen suggest that at least some of the consoles have been migrated from Microsoft Windows to open source Linux.

Photos of US drone control systems taken in 2009 (here) and 2011 (here) provide evidence of the change - in the earlier picture the Windows desktop GUI can be easily discerned whereas the latter slide indicates the new systems are Linux-based and have "improved displays".

The 2009 photo originally came from the air force base's website but the image has since been removed. A cropped copy can be found here. The 2010 slide came from an unclassified presentation on the US's unmanned drone operations.

Hypponen told The Reg: "If I would need to select between Windows XP and a Linux based system while building a military system, I wouldn't doubt a second which one I would take." ®

What you need to know about cloud backup

Everybody relax...

It's OK, the infected systems reportedly only control the weapons.

28
0

Security issues

ATM systems have frequently had security problems, you can find several cases where ATM devices have been infected with various worms...

While it's true that there's no substitute for competent administration, and that competent admins can configure windows systems to be far more secure than it is by default... The same is true of linux, competent configuration of linux will also result in a system that is more secure than it is by default.

Also a lot of those admins' time will be wasted trying to work around windows many shortcomings or disabling/removing poorly designed functionality. Also if you harden a windows box, various things no longer work and users may be used to or even require these features.

Assuming equally competent admins on both sides, the linux system will still be more secure.

19
0

@Err...

Both the low level design of Windows, and its closed source nature, make it fundementally more vulernable than Linux. Later Windows versions have copied some unix security features, like sudo. But the world is still populated by old versions of Windows, and systems lacking proper AV. Thus the vector. It is Windows' legacy, as much as anything, that puts people at risk.

19
0

More from The Register

Microsoft to open Windows Stores inside 600 Best Buy locations
Product showcases 'must be seen to be believed'
Author Iain (M) Banks falls to cancer at 59
Misses the release of his final work
 breaking news
What did the Lehman Brothers implosion look like to a techie?
Insider tells all about the Gnab Gib at Lehmans
It's official: 'tweet' an English word – not just in the avian sense
If the Oxford English Dictionary says it is so, then it is so
 breaking news
The only Waze is Google: Ad giant tipped to gobble map app 'for $1.3bn'
Pac-Man-satnav-ish upstart in bidding war with Apple, Facebook
 breaking news
1-in-10 e-tomes 'are self-published'... most are 'rubbish' says book ed
Publishing man scoffs at go-it-alone writers, ursines still fouling in forests
 breaking news
Facebook RSS reader said to uncloak June 20
Secret event scooped by Scottish developer?