bk99.de entertain the web since 1997

Stuxnet: The attack does not end at the Windows PC

Summary

Using early Stuxnet analyses, Brian Krebs shows how several Windows vulnerabilities, stolen signatures and PLC manipulation made a targeted attack on industrial plants possible. Stuxnet used at least four Windows vulnerabilities that were unknown at the time. Microsoft closed the printer sharing vulnerability with MS10-061.

Ideas

  • Stuxnet used Windows systems as a route to programmable logic controllers.
  • Several unknown vulnerabilities increased the reach and reliability of the attack.
  • Stolen digital signatures made malicious files look trustworthy at first.
  • The PLC rootkit hid manipulated code blocks from the operators.
  • Malware can adapt its behaviour to the network environments it detects.
  • Missing logging in industrial networks makes detection and reconstruction difficult.

Insights

  • IT security only protects processes if their physical effect is also understood.
  • Trust in control system displays itself becomes the target of a sophisticated attack.
  • Air gaps lose their effect as soon as removable media and maintenance computers bridge the boundaries.

Quotes

  • We don’t even know which controllers are trusted and which ones aren’t trusted. – Joe Weiss

Habits

  • Krebs combines vendor statements, researchers’ analyses and expert comments into a technical picture of the situation.

Facts

  • The malicious code could load its own blocks onto Siemens PLCs and hide them.

References

Critique

  • The early report could not yet conclusively explain the objective and authorship.
  • Some figures and assessments come from vendor and researcher reports of the time.

Remarks

  • The text captures the decisive shift in perspective from a Windows pest to process manipulation.
  • Later investigations clarified Stuxnet’s target and state background considerably.

Recommendations

  • Monitor engineering workstations and control logic together.
  • Check signed files additionally for origin and expected behaviour.
  • Log changes to PLC programs outside the respective engineering workstation.

Read the original article

Search the Web Archive