Pages

Welcome

Welcome to my Blog, Hope you enjoy it and share u your friend, collega, family or your bf/gf

Monday, March 7, 2011

" Know about Stuxnet Worm "

Stuxnet is a Windows computer worm discovered in July 2010 that targets industrial software and equipment..While it is not the first time that hackers have targeted industrial systems, it is the first discovered malware that spies on and subverts industrial systems, and the first to include a programmable logic controllerrootkit. (PLC)
The worm initially spreads indiscriminately, but includes a highly specialized malware payload that is designed to target only Siemens Supervisory Control And Data Acquisition (SCADA) systems that are configured to control and monitor specific industrial processes. Stuxnet infects PLCs by subverting the Step-7 software application that is used to reprogram these devices.
Different variants of Stuxnet targeted five Iranian organisations, with the probable target widely suspected to be uranium enrichment infrastructure in Iran; Symantec noted in August 2010 that 60% of the infected computers worldwide were in Iran. Siemens stated on November 29 that the worm has not caused any damage to its customers, but the Iran nuclear program, which uses embargoed Siemens equipment procured clandestinely, has been damaged by Stuxnet. Kaspersky Labs concluded that the sophisticated attack could only have been conducted "with nation-state support" and it has been speculated that Israel may have been involved.

A study of the spread of Stuxnet by Symantec showed that the main affected countries as of August 6, 2010 were

Country Infected computers
Iran 62,867
Indonesia 13,336
India 6,552
United States 2,913
Australia 2,436
United Kingdom 1,038
Malaysia 1,013
Pakistan 993

How Stuxnet Worm Operation ?
Unlike most malware, Stuxnet does little harm to computers and networks that do not meet specific configuration requirements; "The attackers took great care to make sure that only their designated targets were hit...It was a marksman’s job." While the worm is promiscuous, it makes itself inert if Siemens software is not found on infected computers. Stuxnet contains safeguards to prevent each infected computer from spreading the worm to more than three others, and to erase itself on 24 June 2012. The worm contains, among other things, code for a man-in-the-middle attack that fakes industrial process control sensor signals so an infected system does not shut down due to abnormal behavior.
The complexity of the software is very unusual for malware, and consists of a layered attack against three different systems:
  1. The Windows operating system,
  2. Step 7 industrial software application that runs on Windows and
  3. a Siemens PLC.

Windows infection

Stuxnet attacked Windows systems using an unprecedented four zero-day attacks (plus the CPLINK vulnerability and a vulnerability used by the Conficker worm. It is initially spread using infected removable drives such as USB flash drives, and then uses other exploits and techniques such as peer-to-peer RPC to infect and update other computers inside private networks that are not directly connected to the Internet. The number of zero-day Windows exploits used is unusual, as zero-day Windows exploits are valued, and hackers do not normally waste the use of four different ones in the same worm. Stuxnet is unusually large at half a megabyte in size, and written in different programming languages (including C and C++) which is also irregular for malware. The Windows component of the malware is promiscuous in that it spreads relatively quickly and indiscriminately.
The malware has both user-mode and kernel-mode rootkit capability under Windows,[31] and its device drivers have been digitally signed with the private keys of two certificates that were stolen from separate companies, JMicron and Realtek, that are both located at Hsinchu Science Park in Taiwan. The driver signing helped it install kernel-mode rootkit drivers successfully and therefore remain undetected for a relatively long period of time. Both compromised certificates have been revoked by VeriSign.
Two websites in Denmark and Malaysia were configured as command and control servers for the malware, allowing it to be updated, and for industrial espionage to be conducted by uploading information. Both of these websites have subsequently been taken down as part of a global effort to disable the malware.

Software Inflation :

                                Overview of normal communications between Step 7 and a Siemens PLC

According to German researcher Ralph Langner, once installed on a Windows system Stuxnet infects project files belonging to Siemens' WinCC/PCS 7 SCADA control software (Step 7), and subverts a key communication library of WinCC called s7otbxdx.dll. The purpose of this subversion is to intercept communications between the WinCC software running under Windows and the target Siemens PLC devices that the software is able to configure and program when the two are connected via a data cable. In this way, the malware is able to install itself on PLC devices unnoticed, and subsequently to mask its presence from WinCC if the control software attempts to read an infected block of memory from the PLC system.
The malware furthermore used a zero-day exploit in the WinCC/SCADA database software in the form of a hard-coded database password.

PLC infection

The entirety of the Stuxnet code has not yet been understood, but its payload targets only those SCADA configurations that meet criteria that it is programmed to identify. Stuxnet requires specific slave variable-frequency drives (frequency converter drives) to be attached to the targeted Siemens S7-300 system and its associated modules. It only attacks those PLC systems with variable-frequency drives from two specific vendors: Vacon based in Finland and Fararo Paya based in Iran. Furthermore, it monitors the frequency of the attached motors, and only attacks systems that spin between 807 Hz and 1210 Hz. The industrial applications of motors with these parameters are diverse, and may include pumps or gas centrifuges.
Stuxnet installs malware into memory block DB890 of the PLC that monitors the Profibus messaging bus of the system. When certain criteria are met, it periodically modifies the frequency to 1410 Hz and then to 2 Hz and then to 1064 Hz, and thus affects the operation of the connected motors by changing their rotational speed. It also installs a rootkit—the first such documented case on this platform—that hides the malware on the system and masks the changes in rotational speed from monitoring systems.

                  Overview of Stuxnet hijacking communication between Step 7 software and a Siemens PLC

Latest stories about Stuxnet Worm :

US and Israel created Stuxnet worm: Researcher

The US and Israel created the Stuxnet worm that is believed to have sabotaged Iran's nuclear programme. Ralph Langner, one of the first researchers to show the working of the sophisticated malware, said that he believes Mossad is involved


Stuxnet threatens 'well secured systems'

By Robert Lemos | CSO | Published 09:25, 07 March 11 Companies infected by Stuxnet should not feel bad, even systems secured to industry best practices had little chance to dodge the pernicious programme, according to a recent report by Tofino Security 


US and Israel blamed for StuxnetIran's Bushehr reactor is believed to have been on of the intended targets for Stuxnet. Israel and the United States created the Stuxnet worm to sabotage Iran's nuclear programme, a leading security expert has claimed. Ralph Langner told a conference 



Researcher blames US, Israel for Stuxnet

German security researcher Ralph Langner has told an audience at this years TED conference that the United States and Israel were most likely behind the Stuxnet malware. He said that the malware was designed specifically to cripple systems related 


'Stuxnet Is the Hiroshima of Cyber War' by Alexis Madrigal

Michael Gross takes a stab at writing the definitive magazine piece about Stuxnet, a computer worm that presumably attacked Iranian nuclear facilities, in this month's Vanity Fair. He's done some great reporting and this piece is, you know, written. 



Did US Intelligence Mastermind The Stuxnet Cyber-Missile?

In this month's Vanity Fair, Michael Joseph Gross takes a long look at the origins and implications of the Stuxnet Worm, the now-infamous cyber-weapon that attacked Iran's nuclear program last year. Gross' piece points out holes in the commonly 

Secure best practices no proof against Stuxnet

By Robert Lemos, CSO A Tofino Security report shows that well-secured computer systems would still get infected with Stuxnet. Companies infected by Stuxnet should not feel bad -- even systems secured to industry best practices had little chance 


If Stuxnet Was Act of Cyberwar, is U.S. Ready for a Response?

The complex Stuxnet worm proved attacks on SCADA and other industrial control systems were possible. Are we ready if one comes our way? By George V. Hulme March 02, 2011 — With Stuxnet setting back Iran's disputed nuclear program, that country 

For futher more information check this web http://www.stuxnet.net/


 How to prevent Stuxnet infect with ur PC ?

First, u must to know what's software could function :

Summary

W32/Stuxnet-B is a worm for the Windows platform.
http://www.sophos.com/security/analyses/viruses-and-spyware/w32stuxnetb.html

 

W32/Stuxnet-B

Aliases
  • Trojan-Dropper.Win32.Stuxnet.a
  • TR/Stuxnet.l
  • W32.Stuxnet
  • Worm.Win32.Stuxnet.a
  • Worm/Stuxnet.A.9
Category
Type
What to do
Prevalence low high                                                                        

No comments:

Post a Comment