2.1 Computer Viruses
119
work. The intruders most probably stole the signatures from Taiwan branches of
MicronJ and RealTek. This is indirectly indicated by the fact that headquarters of
these companies are located in the same building in Hsinchu. If it is not just a
coincidence, it means that somebody physically entered the rooms, logged in on the
necessary computers, and stole the keys—this is the work of a professional, not an
amateur.
It was clearly written by a large team of professionals, too—half a megabyte of
code in assembler, C, and C++.
Stuxnet was found not in the USA, China, or Europe, where most people work on
the Internet—60% of infection cases were registered in Iran, the country of Islamic
revolution.
It was able to receive commands and update itself in an autonomous manner, like
P2P. Classic botnets use central command systems.
The main difference is that this virus didn’t send out spam, format the drive, or
even steal bank data. It carried out industrial sabotage. To be precise, it attacked
industrial control and management systems using software called Simatic WinCC.
Even more sensational is the fact that Stuxnet secretly assigns itself to programmable
chips of controllers used directly for equipment management and production control,
disguises itself, and shuts down a specific production process, which returns a certain
code. Unfortunately, the meaning of this code is still unknown to experts at the time
of publication of this book. This, by the way, explains its method of distribution
through USB flash drives—for the purpose of security, all modern industrial systems
are extremely rarely connected to the Internet.
The infamous worm Stuxnet was discovered in 2010; however, it had been active
at least since 2009. The attack began with infecting systems in five hand-picked
organizations (Figs. 2.7, 2.8, and 2.9).
1. Infection
Stuxnet enters the system through a flash drive and starts infecting
all the devices running Microsoft Windows. By means of
obtrusively demonstrating the digital certificate, which seems to
indicate a reliable source company, the worm can escape
automatic detection systems.
2. Search
After that, Stuxnet checks whether the device is a part
of the target process control system created by
SIEMENS.
Similar systems are deployed in Iran to launch high -
speed centrifuges used to enrich nuclear fuel.
3. Update
If the system is not its target, Stuxnet stays
idle; otherwise, it attempts to connect to the
Internet and download the latest version of
itself
4. Hacking
After that, the worm damages logic controllers of
the target systems using zero day vulnerabilities -
weak software spots not yet found by security
specialists
5. Control
Initially, Stuxnet spies on operation of the target
system. After that, it uses the collected
information to take over centrifuges and make
them rotate uncontrolledly until failure
6. Deception and destruction. Moreover, Stuxnet sends
false response messages to external controllers, hiding
information from them until it is too late to undertake
anything
UPDATING FROM THE SOURCE
Fig. 2.7 Stuxnet operating principle
119
work. The intruders most probably stole the signatures from Taiwan branches of
MicronJ and RealTek. This is indirectly indicated by the fact that headquarters of
these companies are located in the same building in Hsinchu. If it is not just a
coincidence, it means that somebody physically entered the rooms, logged in on the
necessary computers, and stole the keys—this is the work of a professional, not an
amateur.
It was clearly written by a large team of professionals, too—half a megabyte of
code in assembler, C, and C++.
Stuxnet was found not in the USA, China, or Europe, where most people work on
the Internet—60% of infection cases were registered in Iran, the country of Islamic
revolution.
It was able to receive commands and update itself in an autonomous manner, like
P2P. Classic botnets use central command systems.
The main difference is that this virus didn’t send out spam, format the drive, or
even steal bank data. It carried out industrial sabotage. To be precise, it attacked
industrial control and management systems using software called Simatic WinCC.
Even more sensational is the fact that Stuxnet secretly assigns itself to programmable
chips of controllers used directly for equipment management and production control,
disguises itself, and shuts down a specific production process, which returns a certain
code. Unfortunately, the meaning of this code is still unknown to experts at the time
of publication of this book. This, by the way, explains its method of distribution
through USB flash drives—for the purpose of security, all modern industrial systems
are extremely rarely connected to the Internet.
The infamous worm Stuxnet was discovered in 2010; however, it had been active
at least since 2009. The attack began with infecting systems in five hand-picked
organizations (Figs. 2.7, 2.8, and 2.9).
1. Infection
Stuxnet enters the system through a flash drive and starts infecting
all the devices running Microsoft Windows. By means of
obtrusively demonstrating the digital certificate, which seems to
indicate a reliable source company, the worm can escape
automatic detection systems.
2. Search
After that, Stuxnet checks whether the device is a part
of the target process control system created by
SIEMENS.
Similar systems are deployed in Iran to launch high -
speed centrifuges used to enrich nuclear fuel.
3. Update
If the system is not its target, Stuxnet stays
idle; otherwise, it attempts to connect to the
Internet and download the latest version of
itself
4. Hacking
After that, the worm damages logic controllers of
the target systems using zero day vulnerabilities -
weak software spots not yet found by security
specialists
5. Control
Initially, Stuxnet spies on operation of the target
system. After that, it uses the collected
information to take over centrifuges and make
them rotate uncontrolledly until failure
6. Deception and destruction. Moreover, Stuxnet sends
false response messages to external controllers, hiding
information from them until it is too late to undertake
anything
UPDATING FROM THE SOURCE
Fig. 2.7 Stuxnet operating principle
