78
1 Information Weapon: Concepts, Means, Methods …
theft of the drawings and technical data on the company’s reactors with further
blackmailing about getting the ransom for them to abstain from putting his data
online.
So far the experts do not have clear understanding what may happen if the
virus enters directly into reactor control system. Among potential consequences, the
experts specify failure in active area cooling system or any other critical subsystem
of nuclear power station, and each of them could have resulted in temporal forced
shutdown of the entire facility as minimum. Evidently should any traces of cyberstrike are detected, checking of all systems will take very long time (up to a few
months). Therefore even simulation of contaminating nuclear power station systems
with virus may result not only in unscheduled closedown but in delay of the power
block commissioning as it could have been the case in Iran.
It cannot be excluded that the virus attack may be not more that an imitation strike
masking actual malicious impact of other nature.
Even more dangerous is the fact that as Stuxnet revealed, when strike by means of
software virus at the facilities of critical infrastructure occurs hackers involved may
resortt to the most unexpected ways of intrusion and impact. The authors of the Report
are of the opinion that key effect of the accident with the software virus that attached
Iranian facilities of nuclear infrastructure is that the ideas, some specific solutions
for program code, intrusion tactics and methods of latent influence developed by
properly sponsored team of pros got readily available and in this or that extent have
inspired the rest of hackers’ community for search of exotic uncommon solutions
when creating malicious software.
Hence, there are sufficient reasons to believe that cyberattacks targeted at the facilities of critical infrastructure will assume more and more holistic character beginning
from unusually sophisticated infrastructure of program codes and finishing with more
and more unobvious effects of impact. Thus terror groups anxious to obtain splitting
materials (for instance, as spent nuclear fuel from nuclear power plants) to make
the so-called dirty bomb ay proceed to planning not armed attack and seizure in
the course of frontal assault at nuclear power plant but attempts to breach corporate
network to learn freighting logistics, to alter route schedule, to forge transfer documents, i.e., withdraw the sensitive materials from control area facilitating in such a
way their potential seizure or stealth. Obviously, as long as computerization of technological processes enhances the risks of such unreal on first glance and fantastic
scripts are on rise and counter measures need to be estimated and elaborated well in
advance.
Either threats or attempts to carry out subversive actions at nuclear power plant
took place before as well. The hazards in the majority of cases arrived from outside
and were successfully handled with [4]. However, the elaborated measures for
protecting the facilities of nuclear energy industry fail to prevent in full unconventional kinds of threats, particularly when threat is coming not from outside but
from inside.
It is important to assess correctly the threat for nuclear power plant which is created
by malicious software of the kind. If such threat is very much real and it is safe to talk
Précédent

- 100/839

Suivant