28
1 Information Weapon: Concepts, Means, Methods …
– Means of creating false objects in the information space;
– Technical intelligence equipment.
There is an interesting story behind the creation and introduction of Stuxnet.
Stuxnet was part of US and Israeli intelligence operation called “Operation Olympic
Games,” which was carried out in several stages from 2007 to 2013. The purpose of
the operation was to prevent Iranian uranium enrichment. Various solutions to this
problem were considered, including the possibility of a missile attack and bombing,
but in the end it was decided to conduct a special operation using elements of
information weapons (cyberweapons).
Below is an outline of the main stages (technical aspects) of preparing and
conducting a cyberattack on the Iranian nuclear plant located in the city of Natanz
[1].
In 2007, by joint efforts of programmers from the NSA and Israeli intelligence
(Unit 8200) malicious software was created (Stuxnet, the first version of a malicious computer worm—a type of software spreading in local and global computer
networks) to put production equipment (in this case, centrifuges) at the uranium
enrichment facility out of service.
It took eight months to develop the worm.
This worm specifically targeted special-purpose computers used to control the
centrifuges (industrial controllers). It had to introduce the malicious code while
remaining undetected. At a certain point, the introduced malicious software was
activated, causing the centrifuges to accelerate excessively or slow down sharply,
eventually breaking them down.
At the same time, everything looked normal on the centrifuge operator’s console.
The introduction of the malicious software in the production facility’s local control
network isolated from the WAN (the Internet) was carried out in two stages.
Initially, a special agent (an Iranian technician) who had access to the facility’s
computers damaged the unprotected internal system design of the Siemens controllers
(directly controlling the centrifuges) by inserting a flash drive containing the first
version of the computer worm into a USB port of the computer connected to the
internal computer network for production cycle management. Then the German engineers who operated these controllers, unaware of the computer worm in the software,
involuntarily provided the updated software and practical results of introducing the
first version of the worm in the local network of the Iranian facility to the NSA and
Israeli intelligence developers.
Then, based on this information, the NSA and Israeli intelligence experts finalized
the first version of the Stuxnet worm using the standard Siemens controllers, similar
to those controlling Iranian centrifuges. The modified version was successfully tested
on samples of centrifuges identical to those used by Iranians. In a similar fashion,
with the help of an agent, a new version of the Stuxnet worm was introduced to
the Natanz facility. When activated, the Stuxnet worm began to relay the recorded
signals to the consoles, used by the operators to control the centrifuges, which led
to their extreme acceleration to inconceivable speeds, hard braking, and breakdown.
Précédent

- 50/839

Suivant