Michele Kearney's Nuclear Wire

Major Energy and Environmental News and Commentary affecting the Nuclear Industry.
Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Wednesday, September 29, 2010

A Way to Attack Nuclear Plants Industrial computer systems are typically far less secure than they should be, experts say. By Robert Lemos

For the last few months, a sophisticated computer worm has wriggled its way between some of the most critical control systems in the world.
Going nuclear: The Stuxnet computer worm may have designed to infiltrate an Iranian nuclear facility in Natanz, 180 miles south of Tehran.
Credit: Getty Images
The timing of the worm's release, combined with several clues buried in its code, has led some experts to speculate that the worm, dubbed Stuxnet, was originally designed to sabotage an Iranian nuclear facility, possible the enrichment plant in Natanz, roughly 180 miles south of Tehran. This week, officials in Iran confirmed that Stuxnet had been found on systems inside the plant, although they denied that it had caused any harm.
But Stuxnet has since spread to hundreds more industrial systems within Iran and around the world. Experts say this highlights a worrisome weak spot in critical infrastructure that could become a new focus for saboteurs and malicious hackers.
Stuxnet infects computers by using previously unseen flaws in Microsoft's Windows operating system. It has most likely spread via hand-carried USB flash drives. From an infected Windows computer, it targets a specialized type of computer known as a programmable logic controller, or PLC. These computers are widely used in critical infrastructure, including manufacturing, water processing, power generation, and transportation. PLCs connect to, and control, devices used to perform many tasks, from opening a door, to increasing the flow of fuel inside a power plant.
Stuxnet is the first example of attackers targeting the specialized computers that control industrial operations, security experts say. "It goes down into the embedded device, inserts itself, and starts doing command-and-control," says Walter Sikora, vice president of security solutions for Industrial Defender, a security consultancy that focuses on critical infrastructure. "This is an area that was unprecedented in terms of a virus or a worm or any other kind of malware."A Way to Attack Nuclear Plants Industrial computer systems are typically far less secure than they should be, experts say. By Robert Lemos
 More at link
http://www.technologyreview.com/computing/26384/?nlid=3565&a=f
Enhanced by Zemanta

Sunday, September 26, 2010

Iran denies nuclear plant computers among 30,000 hit by worm

by Staff Writers Tehran (AFP) Sept 26, 2010 The malicious Stuxnet computer worm has hit 30,000 industrial computers in Iran, officials said on Sunday, but denied the Islamic republic's first nuclear plant at Bushehr was among those infected. So far, Stuxnet has infected about 30,000 IP addresses in Iran, Mahmoud Liayi, head of the information technology council at the ministry of industries, was quoted as saying by the government-run newspaper Iran Daily.
Stuxnet, which was publicly identified in June, was tailored for Siemens supervisory control and data acquisition, or SCADA, systems commonly used to manage water supplies, oil rigs, power plants and other industrial facilities.
The worm is able to recognise a specific facility's control network and then destroy it, according to German computer security researcher Ralph Langner, who has been analysing the malicious software.
Langner said he suspected Stuxnet was targetting Bushehr nuclear power plant, where unspecified problems have been blamed for delays in getting the facility fully operational.
Siemens said its software has not been installed at the plant, and an Iranian official denied the malware may have infected nuclear facilities.
"This virus has not caused any damage to the main systems of the Bushehr power plant," Bushehr project manager Mahmoud Jafari said on Iran's Arabic-language Al-Alam television network.
"All computer programmes in the plant are working normally and have not crashed due to Stuxnet," said Jafari, adding there was no problem with the plant's fuel supply.
The official IRNA news agency meanwhile quoted him as saying the worm had infected some "personal computers of the plant's personnel."
And he told Fars news agency that so far, five versions of the malware had been detected in Iran.
Echoing Jafari's denial, the deputy head of Iran's Atomic Energy Organisation in charge of safety and security, Asghar Zarean, said neither the plant nor the organisation's computers were affected.
"Due to the precautions we have already employed for our systems, in our investigations we have not come across any penetration by the virus into our systems," Zarean was quoted as saying by IRNA.
The self-replicating worm has been found lurking on Siemens systems mostly in India, Indonesia and Pakistan, but the heaviest infiltration appears to be in Iran, according to researchers.
Telecommunications minister Reza Taqipour said "the worm has not been able to penetrate or cause serious damage to government systems."
According to Iran Daily, telecoms official Saeed Mahdiyoun said "teams of experts had begun to systematically eliminate the virus."
Meanwhile Liayi said given its complexity, Stuxnet was "likely a (foreign) government project," without giving details.
The newspaper cited various experts who suggested the United States and Israel were behind the malware, evoking the "West's electronic warfare against Iran."
Liayi said industries were currently receiving systems to combat Stuxnet, while stressing Iran had decided not to use anti-virus software developed by Siemens because "they could be carrying a new version of the malware."
"When Stuxnet is activated, the industrial automation systems start transmitting data about production lines to a main designated destination by the virus," Liayi said.
"There, the data is processed by the worm's architects and then engineer plots to attack the country."
Iran's nuclear ambitions are at the heart of a conflict between Tehran and the West, which suspects the Islamic republic is seeking to develop atomic weapons under the cover of a civilian drive.
Tehran denies the allegation and has pressed on with its enrichment programme -- the most controversial aspect of its nuclear activities -- despite four sets of UN Security Council sanctions.http://www.spacewar.com/reports/Iran_denies_nuclear_plant_computers_among_30000_hit_by_worm_999.html

Enhanced by Zemanta

Saturday, September 25, 2010

Iran 'attacked' by computer worm Iran's nuclear agency trying to combat a virus capable of taking over systems that control power plants, media says.


http://english.aljazeera.net/news/middleeast/2010/09/2010925135358149112.html

Foreign media has speculated that the worm is aimed at disrupting the Bushehr nuclear plant [EPA]
Iran's nuclear agency is trying to combat a complex computer worm that has affected industrial sites throughout the country and is capable of taking over the control systems of power plants, Iranian media reports have said.
Experts from the Atomic Energy Organisation of Iran met this week to discuss how to remove the malicious computer code, or worm, the semi-official Isna news agency reported on Friday.
No damage or disruption of nuclear facilities has yet been reported, however.
The computer worm, dubbed Stuxnet, can take over systems that control the inner workings of industrial plants.
Experts in Germany discovered the worm in July, and it has since shown up in a number of attacks - primarily in Iran, Indonesia, India and the US.
'Disrupting Bushehr'
Isna said the malware had spread throughout Iran, but did not name specific sites affected.
Foreign media reports have speculated the worm was aimed at disrupting Iran's first nuclear power plant, which is to go online in October in the southern port city of Bushehr.

The Russian-built plant will be internationally supervised, but world powers remain concerned that Iran wants to use its civil nuclear power programme as a cover for making weapons.
Iran denies such an aim and says its nuclear work is solely for peaceful purposes.
The destructive Stuxnet worm has surprised experts because it is the first one specifically created to take over industrial control systems, rather than just steal or manipulate data.
Speaking to Al Jazeera, Rik Ferguson, a senior security adviser at the computer security company Trend Micro, described the worm as "very sophisticated".
"It is designed both for information theft, looking for design documents and sending that information back to the controllers, and for disruptive purposes," he said.
"It can issue new commands or change commands used in manufacturing.
"It's difficult to say with any certainty who is behind it. There are multiple theories, and in all honesty, any of of them could be correct."
Western experts have said the worm's sophistication - and the fact that about 60 per cent of computers infected looked to be in Iran - pointed to a government-backed attack.
Washington is also tracking the worm, and the Department of Homeland Security is building specialised teams that can respond quickly to cyber emergencies at industrial facilities across the US.
Enhanced by Zemanta

Iranian nuclear plants likely target of foiled cyber sabotage Speculation grows that Israeli hackers were behind operation – but analysts say it may be impossible to identify perpetrators

Who Is Trying To Hack Into Iran's Nuclear Plants?

Image: from Red Orbit

Iranian Nuclear Plants Likely Target Of Foiled Cyber Sabotage -- The Guardian

Speculation grows that Israeli hackers were behind operation – but analysts say it may be impossible to identify perpetrators

Iran was the likely target of a sophisticated computer worm designed to sabotage factories and infrastructure which was almost certainly the work of a national government agency, security experts told the Guardian yesterday.

According to the security company Symantec, 60% of the computers infected by the Stuxnet computer worm are in Iran, which is where the malicious software, known as malware, was discovered by a Belarussian computer security company.

Read more
....http://www.guardian.co.uk/world/2010/sep/25/iran-cyber-hacking-nuclear-plants

More News On The Stuxnet Computer Worm

Iran's nuclear agency trying to stop computer worm -- AP
Cyber attack 'targeted Iran' -- Al Jazeera
'Stuxnet' Attack May Have Been Aimed At Iran: Experts -- Red Orbit
Stuxnet worm mystery: What's the cyber weapon after? -- Christian Science Monitor
Analysis: Iran "attack" points to rising cyber warfare risk -- Reuters
Enhanced by Zemanta

Monday, August 30, 2010

Nation’s Nuclear Power Plants Prepare for Cyber Attacks By Martin Matishak Global Security Newswire

WASHINGTON -- The threat to digital systems at the country's nuclear power plants is considerable, but the sector is better prepared to defend against potentially devastating cyber attacks than most other utilities, according to government and industry officials and experts
Cyber attacks have been an increasing source of concern in recent years but the threat was highlighted last month by the first discovery of malicious code, called a worm, specifically formulated to target the systems that direct the inner operations of industrial plants. To date the malware is thought to have infected more than 15,000 computers worldwide, mostly in Iran, Indonesia and India.
The issue is critically important for new nuclear power facilities that would be built in the United States and throughout the world as control rooms would employ digital systems to operate the plants. Those state-of-the-art instruments and systems make them targets for hackers.
More at:
http://gsn.nti.org/gsn/nw_20100827_1692.php
Enhanced by Zemanta