Stuxnet is a Windows computer worm discovered in July 2010 that targets industrial software and equipment..While it is not the first time that hackers have targeted industrial systems, it is the first discovered malware that spies on and subverts industrial systems, and the first to include a programmable logic controllerrootkit. (PLC)
The worm initially spreads indiscriminately, but includes a highly specialized malware payload that is designed to target only Siemens Supervisory Control And Data Acquisition (SCADA) systems that are configured to control and monitor specific industrial processes. Stuxnet infects PLCs by subverting the Step-7 software application that is used to reprogram these devices.
Different variants of Stuxnet targeted five Iranian organisations, with the probable target widely suspected to be uranium enrichment infrastructure in Iran; Symantec noted in August 2010 that 60% of the infected computers worldwide were in Iran. Siemens stated on November 29 that the worm has not caused any damage to its customers, but the Iran nuclear program, which uses embargoed Siemens equipment procured clandestinely, has been damaged by Stuxnet. Kaspersky Labs concluded that the sophisticated attack could only have been conducted "with nation-state support" and it has been speculated that Israel may have been involved.
| Country | Infected computers |
|---|---|
| Iran | 62,867 |
| Indonesia | 13,336 |
| India | 6,552 |
| United States | 2,913 |
| Australia | 2,436 |
| United Kingdom | 1,038 |
| Malaysia | 1,013 |
| Pakistan | 993 |
How Stuxnet Worm Operation ?
The complexity of the software is very unusual for malware, and consists of a layered attack against three different systems:
- The Windows operating system,
- Step 7 industrial software application that runs on Windows and
- a Siemens PLC.
Windows infection
Stuxnet attacked Windows systems using an unprecedented four zero-day attacks (plus the CPLINK vulnerability and a vulnerability used by the Conficker worm. It is initially spread using infected removable drives such as USB flash drives, and then uses other exploits and techniques such as peer-to-peer RPC to infect and update other computers inside private networks that are not directly connected to the Internet. The number of zero-day Windows exploits used is unusual, as zero-day Windows exploits are valued, and hackers do not normally waste the use of four different ones in the same worm. Stuxnet is unusually large at half a megabyte in size, and written in different programming languages (including C and C++) which is also irregular for malware. The Windows component of the malware is promiscuous in that it spreads relatively quickly and indiscriminately.The malware has both user-mode and kernel-mode rootkit capability under Windows,[31] and its device drivers have been digitally signed with the private keys of two certificates that were stolen from separate companies, JMicron and Realtek, that are both located at Hsinchu Science Park in Taiwan. The driver signing helped it install kernel-mode rootkit drivers successfully and therefore remain undetected for a relatively long period of time. Both compromised certificates have been revoked by VeriSign.
Two websites in Denmark and Malaysia were configured as command and control servers for the malware, allowing it to be updated, and for industrial espionage to be conducted by uploading information. Both of these websites have subsequently been taken down as part of a global effort to disable the malware.
Software Inflation :
Overview of normal communications between Step 7 and a Siemens PLC
According to German researcher Ralph Langner, once installed on a Windows system Stuxnet infects project files belonging to Siemens' WinCC/PCS 7 SCADA control software (Step 7), and subverts a key communication library of WinCC called
s7otbxdx.dll. The purpose of this subversion is to intercept communications between the WinCC software running under Windows and the target Siemens PLC devices that the software is able to configure and program when the two are connected via a data cable. In this way, the malware is able to install itself on PLC devices unnoticed, and subsequently to mask its presence from WinCC if the control software attempts to read an infected block of memory from the PLC system.The malware furthermore used a zero-day exploit in the WinCC/SCADA database software in the form of a hard-coded database password.
PLC infection
The entirety of the Stuxnet code has not yet been understood, but its payload targets only those SCADA configurations that meet criteria that it is programmed to identify. Stuxnet requires specific slave variable-frequency drives (frequency converter drives) to be attached to the targeted Siemens S7-300 system and its associated modules. It only attacks those PLC systems with variable-frequency drives from two specific vendors: Vacon based in Finland and Fararo Paya based in Iran. Furthermore, it monitors the frequency of the attached motors, and only attacks systems that spin between 807 Hz and 1210 Hz. The industrial applications of motors with these parameters are diverse, and may include pumps or gas centrifuges.Stuxnet installs malware into memory block DB890 of the PLC that monitors the Profibus messaging bus of the system. When certain criteria are met, it periodically modifies the frequency to 1410 Hz and then to 2 Hz and then to 1064 Hz, and thus affects the operation of the connected motors by changing their rotational speed. It also installs a rootkit—the first such documented case on this platform—that hides the malware on the system and masks the changes in rotational speed from monitoring systems.
Overview of Stuxnet hijacking communication between Step 7 software and a Siemens PLC
Latest stories about Stuxnet Worm :
US and Israel created Stuxnet worm: Researcher
The US and Israel created the Stuxnet worm that is believed to have sabotaged Iran's nuclear programme. Ralph Langner, one of the first researchers to show the working of the sophisticated malware, said that he believes Mossad is involved
Stuxnet threatens 'well secured systems'
By Robert Lemos | CSO | Published 09:25, 07 March 11 Companies infected by Stuxnet should not feel bad, even systems secured to industry best practices had little chance to dodge the pernicious programme, according to a recent report by Tofino Security
US and Israel blamed for StuxnetIran's Bushehr reactor is believed to have been on of the intended targets for Stuxnet. Israel and the United States created the Stuxnet worm to sabotage Iran's nuclear programme, a leading security expert has claimed. Ralph Langner told a conference
Researcher blames US, Israel for Stuxnet
German security researcher Ralph Langner has told an audience at this years TED conference that the United States and Israel were most likely behind the Stuxnet malware. He said that the malware was designed specifically to cripple systems related
'Stuxnet Is the Hiroshima of Cyber War' by Alexis Madrigal
Michael Gross takes a stab at writing the definitive magazine piece about Stuxnet, a computer worm that presumably attacked Iranian nuclear facilities, in this month's Vanity Fair. He's done some great reporting and this piece is, you know, written.
Did US Intelligence Mastermind The Stuxnet Cyber-Missile?
In this month's Vanity Fair, Michael Joseph Gross takes a long look at the origins and implications of the Stuxnet Worm, the now-infamous cyber-weapon that attacked Iran's nuclear program last year. Gross' piece points out holes in the commonly
Secure best practices no proof against Stuxnet
By Robert Lemos, CSO A Tofino Security report shows that well-secured computer systems would still get infected with Stuxnet. Companies infected by Stuxnet should not feel bad -- even systems secured to industry best practices had little chance
If Stuxnet Was Act of Cyberwar, is U.S. Ready for a Response?
The complex Stuxnet worm proved attacks on SCADA and other industrial control systems were possible. Are we ready if one comes our way? By George V. Hulme March 02, 2011 — With Stuxnet setting back Iran's disputed nuclear program, that country
For futher more information check this web http://www.stuxnet.net/
How to prevent Stuxnet infect with ur PC ?
First, u must to know what's software could function :
Summary
W32/Stuxnet-B is a worm for the Windows platform.http://www.sophos.com/security/analyses/viruses-and-spyware/w32stuxnetb.html
W32/Stuxnet-B
| Aliases |
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Category | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Type | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| What to do |
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Prevalence | low |


No comments:
Post a Comment