Stuxnet: The attack does not end at the Windows PC
Summary
Using early Stuxnet analyses, Brian Krebs shows how several Windows vulnerabilities, stolen signatures and PLC manipulation made a targeted attack on industrial plants possible. Stuxnet used at least four Windows vulnerabilities that were unknown at the time. Microsoft closed the printer sharing vulnerability with MS10-061.
Ideas
- Stuxnet used Windows systems as a route to programmable logic controllers.
- Several unknown vulnerabilities increased the reach and reliability of the attack.
- Stolen digital signatures made malicious files look trustworthy at first.
- The PLC rootkit hid manipulated code blocks from the operators.
- Malware can adapt its behaviour to the network environments it detects.
- Missing logging in industrial networks makes detection and reconstruction difficult.
Insights
- IT security only protects processes if their physical effect is also understood.
- Trust in control system displays itself becomes the target of a sophisticated attack.
- Air gaps lose their effect as soon as removable media and maintenance computers bridge the boundaries.
Quotes
We don’t even know which controllers are trusted and which ones aren’t trusted.
– Joe Weiss
Habits
- Krebs combines vendor statements, researchers’ analyses and expert comments into a technical picture of the situation.
Facts
- The malicious code could load its own blocks onto Siemens PLCs and hide them.
References
- Brian Krebs: Stuxnet Worm Far More Sophisticated Than Previously Thought
- MS10-061: Microsoft update for the abused print spooler.
- Siemens SCADA and PLC: the target environment of the malicious code described.
Critique
- The early report could not yet conclusively explain the objective and authorship.
- Some figures and assessments come from vendor and researcher reports of the time.
Remarks
- The text captures the decisive shift in perspective from a Windows pest to process manipulation.
- Later investigations clarified Stuxnet’s target and state background considerably.
Recommendations
- Monitor engineering workstations and control logic together.
- Check signed files additionally for origin and expected behaviour.
- Log changes to PLC programs outside the respective engineering workstation.
Links to the original source and the Web Archive open in a new tab.