Stuxnet Targeting Specific SCADA Configurations
Stuxnet Targeting Specific SCADA Configurations.
The debate on whether or not the Israelis wrote the Stuxnet malware rages on – but it seems pretty clear from the research from ESET and Siemens own findings – here that the virus is apparently only activated in plants with a specific configuration.
To be exact – the target is not the SCADA system itself but rather the Siemens WinCC visualization and process monitoring software – WinCC which runs on standard Windows platforms as I pointed out in a previous post, and not on a hardened version of Windows as Shai Blitzblau seems to think.
Note also – that standard anti-virus programs with updated signatures as of August 2010 remove Stuxnet, so the continued propagation of the malware is either via a mutation or on Windows systems not running an anti-virus, which would not be too surprising, since apparently most Siemens WinCC installations are still using default admin passwords.
Analysis of virus and status of investigations
- The virus has been isolated on a test system in order to carry out more extensive investigations. Previously analyzed properties and the behavior of the virus in the software environment of the test system suggest that we are not dealing with the random development of one hacker, but with the product of a team of experts who must have IT expertise as well as specific know-how about industrial controls, their deployment in industrial production processes and corresponding engineering knowledge.
- As far as we know at the moment, industrial controls from Siemens are affected. The Trojan is activated whenever WinCC or PCS7 software from Siemens is installed.
- Further investigations have shown that the virus can theoretically influence specific processes and operations in a very specific automation environment or plant configuration in addition to passing on data. This means that the malware is able, under certain boundary conditions, to influence the processing of operations in the control system. However, this behavior has not yet been verified in tests or in practice.
- The behavioral pattern of Stuxnet suggests that the virus is apparently only activated in plants with a specific configuration. It deliberately searches for a certain technical constellation with certain modules and certain program patterns which apply to a specific production process. This pattern can, for example, be localized by one specific data block and two code blocks.
- This means that Stuxnet is obviously targeting a specific process or a plant and not a particular brand or process technology and not the majority of industrial applications.
This conclusion also coincides with the number of cases known to Siemens where the virus was detected but had not been activated, and could be removed without any damage being done up to now.
This kind of specific plant was not among the cases that we know about.
Explore posts in the same categories: Uncategorized
November 6, 2010 at 6:38 AM
BEFORE THE LIKES OF STUXNET COME TO A vulnerable Pain for the Terrorists, we shouldn`t Help the terrorist support we should Go to the End of that INsolvancy would Prepare All of the things that
November 6, 2010 at 6:31 PM
THERE IS ALSO ONE THING THAT YOU MISSED AND THAT THIS TROJAN RAN ON PREVIOUSLY UNKNOWN VULNERABILITIES AND THAT GAVE THE STUXNET VIRUS TIME TO RUN ON A GLOBAL BASIS UNDETECTED FOR ABOUT A YEAR BEFORE IT WAS EVENTUALLY DEACTIVATED [WE] THINK. AND NOW ALL OF THE SUDDEN THE VIRUS IS SUPPOSEDLY BEING CONTROLLED. THAT IS NOTHING MORE THAN AN OPENSOURCE PUBLICALLY AVAILABLE REPORT COMING FROM THE GLOBAL SECURITY PROGRAMS THAT BATTLE AGAINST THIS STUFFF ON A DAILY BASIS AND SECURES THE FACT THAT THIS ENTERPRIZE HAS THE POWER TO DO THIS ANYTIME IT LIKES. ESPECIALLLY AS IRAN`s DELIMA TOOK CENTER STAGE WHILE THE WORLDS DATABASES WERE EXPLOITED UNLESS THEY HAD PROTECTION FROM THIS VIRUS AHEAD OF ITS REALEASE. THAT IS A WELLL LAYEDOUT PLAN TO PREPARE FOR AND SECURE THE GLOBAL NETWORKS OF A STRONG GLOBAL ALLIANCE AGAINST ANY TERRORIST THREAT. THE ENEMIES OF THAT CONTROL SYSTEM SHOULD PROBABLY NOT GET TOO FIESTY OVER TRIVIAL WARS THAT COULD DDELIVER THEIR SAME DELIMA TOO. GO STUXNET. TERRORIST JIHADS BE DAMNED.