Wednesday, November 17, 2010

  • Wednesday, November 17, 2010
  • Elder of Ziyon
Wired magazine reports:
New and important evidence found in the sophisticated “Stuxnet” malware targeting industrial control systems provides strong hints that the code was designed to sabotage nuclear plants, and that it employs a subtle sabotage strategy that involves briefly speeding up and slowing down physical machinery at a plant over a span of weeks.

“It indicates that [Stuxnet's creators] wanted to get on the system and not be discovered and stay there for a long time and change the process subtly, but not break it,” says Liam O Murchu, researcher with Symantec Security Response, which published the new information in an updated paper on Friday.

The Stuxnet worm was discovered in June in Iran, and has infected more than 100,000 computer systems worldwide. At first blush, it appeared to be a standard, if unusually sophisticated, Windows virus designed to steal data, but experts quickly determined it contained targeted code designed to attack Siemens Simatic WinCC SCADA systems. SCADA systems, short for “supervisory control and data acquisition,” are control systems that manage pipelines, nuclear plants and various utility and manufacturing equipment.

Researchers determined that Stuxnet was designed to intercept commands sent from the SCADA system to control a certain function at a facility, but until Symantec’s latest research, it was not known what function was being targeted for sabotage. Symantec still has not determined what specific facility or type of facility Stuxnet targeted, but the new information lends weight to speculation that Stuxnet was targeting the Bushehr or Natanz nuclear facilities in Iran as a means to sabotage Iran’s nascent nuclear program.

According to Symantec, Stuxnet targets specific frequency-converter drives — power supplies used to control the speed of a device, such as a motor. The malware intercepts commands sent to the drives from the Siemens SCADA software, and replaces them with malicious commands to control the speed of a device, varying it wildly, but intermittently.

The malware, however, doesn’t sabotage just any frequency converter. It inventories a plant’s network and only springs to life if the plant has at least 33 frequency converter drives made by Fararo Paya in Teheran, Iran, or by the Finland-based Vacon.

Even more specifically, Stuxnet targets only frequency drives from these two companies that are running at high speeds — between 807 Hz and 1210 Hz. Such high speeds are used only for select applications. Symantec is careful not to say definitively that Stuxnet was targeting a nuclear facility, but notes that “frequency converter drives that output over 600 Hz are regulated for export in the United States by the Nuclear Regulatory Commission as they can be used for uranium enrichment.”

“There’s only a limited number of circumstances where you would want something to spin that quickly -– such as in uranium enrichment,” said O Murchu. “I imagine there are not too many countries outside of Iran that are using an Iranian device. I can’t imagine any facility in the U.S. using an Iranian device,” he added.

The malware appears to have begun infecting systems in January 2009. In July of that year, the secret-spilling site WikiLeaks posted an announcement saying that an anonymous source had disclosed that a “serious” nuclear incident had recently occurred at Natanz. Information published by the Federation of American Scientists in the United States indicates that something may indeed have occurred to Iran’s nuclear program. Statistics from 2009 show that the number of enriched centrifuges operational in Iran mysteriously declined from about 4,700 to about 3,900 around the time the nuclear incident WikiLeaks mentioned would have occurred.

Researchers who have spent months reverse-engineering the Stuxnet code say its level of sophistication suggests that a well-resourced nation-state is behind the attack. It was initially speculated that Stuxnet could cause a real-world explosion at a plant, but Symantec’s latest report makes it appear that the code was designed for subtle sabotage. Additionally, the worm’s pinpoint targeting indicates the malware writers had a specific facility or facilities in mind for their attack, and have extensive knowledge of the system they were targeting.

Stuxnet is very specific about what it does once it finds its target facility. If the number of drives from the Iranian firm exceeds the number from the Finnish firm, Stuxnet unleashes one sequence of events. If the Finnish drives outnumber the Iranian ones, a different sequence is initiated.

Once Stuxnet determines it has infected the targeted system or systems, it begins intercepting commands to the frequency drives, altering their operation.

“Stuxnet changes the output frequency for short periods of time to 1410Hz and then to 2Hz and then to 1064Hz,” writes Symantec’s Eric Chien on the company’s blog. “Modification of the output frequency essentially sabotages the automation system from operating properly. Other parameter changes may also cause unexpected effects.”

“That’s another indicator that the amount of applications where this would be applicable are very limited,” O Murchu says. “You would need a process running continuously for more than a month for this code to be able to get the desired effect. Using nuclear enrichment as an example, the centrifuges need to spin at a precise speed for long periods of time in order to extract the pure uranium. If those centrifuges stop to spin at that high speed, then it can disrupt the process of isolating the heavier isotopes in those centrifuges … and the final grade of uranium you would get out would be a lower quality.”

O Murchu said that there is a long wait time between different stages of malicious processes initiated by the code — in some cases more than three weeks — indicating that the attackers were interested in sticking around undetected on the target system, rather than blowing something up in a manner that would attract notice.
Nice.

Let's hope that there are other specifically targeted Stuxnets out there that haven't been discovered yet.

Printfriendly

EoZTV Podcast

Podcast URL

Subscribe in podnovaSubscribe with FeedlyAdd to netvibes
addtomyyahoo4Subscribe with SubToMe

search eoz

comments

Speaking

Follow by Email

translate

E-Book

For $18 donation








Sample Text

EoZ's Most Popular Posts in recent years

Hasbys!

Elder of Ziyon - حـكـيـم صـهـيـون



This blog may be a labor of love for me, but it takes a lot of effort, time and money. For over 14 years and 30,000 articles I have been providing accurate, original news that would have remained unnoticed. I've written hundreds of scoops and sometimes my reporting ends up making a real difference. I appreciate any donations you can give to keep this blog going.

Donate!

Donate to fight for Israel!

Monthly subscription:
Payment options


One time donation:

subscribe via email

Follow EoZ on Twitter!

Interesting Blogs

Categories

#PayForSlay Abbas liar Academic fraud administrivia al-Qaeda algeria Alice Walker American Jews AmericanZionism Amnesty analysis anti-semitism anti-Zionism antisemitism apartheid Arab antisemitism arab refugees Arafat archaeology Ari Fuld art Ashrawi ASHREI B'tselem bahrain Balfour bbc BDS BDSFail Bedouin Beitunia beoz Bernie Sanders Biden history Birthright book review Brant Rosen breaking the silence Campus antisemitism Cardozo cartoon of the day Chakindas Chanukah Christians circumcision Clark Kent coexistence Community Standards conspiracy theories COVID-19 Cyprus Daled Amos Daphne Anson David Applebaum Davis report DCI-P Divest This double standards Egypt Elder gets results ElderToons Electronic Intifada Embassy EoZ Trump symposium eoz-symposium EoZNews eoztv Erekat Erekat lung transplant EU Euro-Mid Observer European antisemitism Facebook Facebook jail Fake Civilians 2014 Fake Civilians 2019 Farrakhan Fatah featured Features fisking flotilla Forest Rain Forward free gaza freedom of press palestinian style future martyr Gary Spedding gaza Gaza Platform George Galloway George Soros German Jewry Ghassan Daghlas gideon levy gilad shalit gisha Goldstone Report Good news Grapel Guardian guest post gunness Haaretz Hadassah hamas Hamas war crimes Hananya Naftali hasbara Hasby 2014 Hasby 2016 Hasby 2018 hate speech Hebron helen thomas hezbollah history Hizballah Holocaust Holocaust denial honor killing HRW Human Rights Humanitarian crisis humor huor Hypocrisy ICRC IDF IfNotNow Ilan Pappe Ilhan Omar impossible peace incitement indigenous Indonesia international law interview intransigence iran Iraq Islamic Judeophobia Islamism Israel Loves America Israeli culture Israeli high-tech J Street jabalya James Zogby jeremy bowen Jerusalem jewish fiction Jewish Voice for Peace jihad jimmy carter Joe Biden John Kerry jokes jonathan cook Jordan Joseph Massad Juan Cole Judaism Judea-Samaria Judean Rose Judith Butler Kairos Karl Vick Keith Ellison ken roth khalid amayreh Khaybar Know How to Answer Lebanon leftists Linda Sarsour Linkdump lumish mahmoud zahar Mairav Zonszein Malaysia Marc Lamont Hill max blumenthal Mazen Adi McGraw-Hill media bias Methodist Michael Lynk Michael Ross Miftah Missionaries moderate Islam Mohammed Assaf Mondoweiss moonbats Morocco Mudar Zahran music Muslim Brotherhood Naftali Bennett Nakba Nan Greer Nation of Islam Natural gas Nazi Netanyahu News nftp NGO Nick Cannon NIF Noah Phillips norpac NSU Matrix NYT Occupation offbeat olive oil Omar Barghouti Only in Israel Opinion Opinon oxfam PA corruption PalArab lies Palestine Papers pallywood pchr PCUSA Peace Now Peter Beinart Petra MB philosophy poetry Poland poll Poster Preoccupied Prisoners propaganda Proud to be Zionist Puar Purim purimshpiel Putin Qaradawi Qassam calendar Quora Rafah Ray Hanania real liberals RealJerusalemStreets reference Reuters Richard Falk Richard Landes Richard Silverstein Right of return Rivkah Lambert Adler Robert Werdine rogel alpher roger cohen roger waters Rutgers Saeb Erekat Sarah Schulman Saudi Arabia saudi vice self-death self-death palestinians Seth Rogen settlements sex crimes SFSU shechita sheikh tamimi Shelly Yachimovich Shujaiyeh Simchat Torah Simona Sharoni SodaStream South Africa Speech stamps Superman Syria Tarabin Temple Mount Terrorism This is Zionism Thomas Friedman TOI Tomer Ilan Trump Trump Lame Duck Test Tunisia Turkey UAE Accord UCI UK UN UNDP unesco unhrc UNICEF United Arab Emirates Unity unrwa UNRWA hate unrwa reports UNRWA-USA unwra Varda Vic Rosenthal Washington wikileaks work accident X-washing Y. Ben-David Yemen YMikarov zahran Ziesel zionist attack zoo Zionophobia Ziophobia Zvi

Best posts of the past 12 months


Nominated by EoZ readers

The EU's hypocritical use of "international law" that only applies to Israel

Blog Archive