The Stuxnet worm may be the most sophisticated software ever written
quora.com
quora.com
We tend to ignore the sophistication of things we are familiar with, and hype those that surprise. But that's not a fair measure of anything.
In order for stuxnet to be effective, it was necessary to employ expertise in:
- Uranium enrichment methods and processes
- Capital equipment control systems and their development environments
- Theory of operation of centrifuge machines
- Corporate espionage of some sort
- Organizational management skills that can pull all that together
- and deep understanding of the operating systems referenced above
const int CENTRIFUGE_RPM = 500;
And then some other code written with a deep understanding of uranium enrichment: const int CENTRIFUGE_RPM = 1203;
Can you really say that the second bit of code is more "complex"? Same goes for stolen driver signing keys and some of the other things mentioned in the post.Other large software projects like operating systems or Google search involve much more complex software concepts which I think is the primary thing that should be measured when discussing the sophistication of software.
The threat analysts say, we need to destroy Iran's ability to make nuclear weapons. The nuclear weapons specialists say, the part where we can best do that is by somehow breaking their centrifuges. The centrifuge technician they call up says, "well, x RPMs will really ruin those things. And it would be hard to tell if they did it like this..." Then the software guys make the code that ruins the centrifuge, and the red team incorporates it into their fancy worm, with specs on what exactly to look for.
Ultimately, it was kind of a failure in that anyone found out about it. Maybe there were better programs, and because they were better we never heard about them at all. But still it's pretty amazing :)
I think this understates it; it required a deeper understanding of the vulnerabilities of those operating systems than anyone else in the world, including the creators of the operating systems
So the question of "sophistication" is both subtle and difficult to call.
Edit: And the production of a algorithm that's a conglomeration of ad-hoc processes might qualify as another sort of sophistication, see "the hardest program I ever wrote":
http://journal.stuffwithstuff.com/2015/09/08/the-hardest-pro... http://journal.stuffwithstuff.com/2015/09/08/the-hardest-pro...
Developing software for, say, jet engines requires sophisticated knowledge of jet engines, which is probably about equally complex. But it's manageable because programmers work with engineers who are subject matter experts.
You don't need to know classical mechanics to use a bike, or know about internal combustion engines to use a car.
Windows has to cover a huge area and a lot of "known" unknowns and be able to recover (somewhat) reliably. Stuff breaks, you get weird error messages, that driver for your Wi-Fi never really worked right, but at the end of the day you have a computer that works pretty well, and that's quite remarkable. The same is of course true of Linux and other operating systems.
Stuxnet is a hyper-specialized piece of software (malware) that cannot fail or it loses it's purpose. The authors clearly knew they had to have multiple fallbacks for every step of the process, but I find it very impressive that it reached it's end goal successfully and without being discovered. A lot of software (including malware) break because of regular software bugs, environments that differ from the expected, interference by the user, the list goes on. For Stuxnet to have avoided all of those, that is quite sophisticated.
It's the most sophisticated piece of malware, that's for sure (at least counting the ones we know of).
But calling it the most sophisticated piece of software is too big of a stretch.
That said, other answers to this question include what we would traditionally consider as contestants (like Linux kernel), it just happens that the submitter decided to submit this specific answer. I don't know was this the top answer before it exploded here, but it sure is now.
Isn't Stuxnet a part of a family of similar nation state malware that would also include Flame and Duqu?
Google Search was originally written by two guys in graduate school and has been refined and rewritten many times since then. I'm sure the code base is complicated and undoubtedly some of the greatest minds in software engineering and computer science have used it. The same goes for Linux, which was written by one guy and grew from there.
On the other hand, Stuxnet isn't something that a few brilliant graduate students could have put together. To even get this thing off the ground, you need people with backgrounds in nuclear physics and/or chemistry, operating systems specialists, people with knowledge of industrial equipment, networking experts, an espionage network and competent management to pull it all together. Plus, you need to keep the whole project secret. Oh, and funding. Lot's of funding.
I'd call that sophistication in that you can't even think about starting to tackle this problem if you're just two guys in a garage.
I doubt we could come close to solving the problem of "stopping Iran nuke production without killing anyone or starting a war"
It’s sort of like comparing a skyscraper to an iPhone. Sure the skyscraper requires a lot more manual labor, but the iPhone is more sophisticated. It took ~80 years from when the Empire State Building was built to when the iPhone was built. The iPhone is more sophisticated but it’d still take more time and resources to make another Empire State Building.
Sorry if that’s a poor analogy- it’s the best I got right now.
Stuxnet installed itself without cooperation, hid itself perfectly and still completed its objective flawlessly against a hostile user base.
For example - it might take years of research to develop a formula for calculating something, but the final code can be very simple one-liner.
the responsible party(ies) did not access to resources , man power or infra at google or even at an enterprise scale.
Not to be rude, but it really doesn't sound like you read the article.
Especially when you claim that Windows is more sophisticated. Stuxnet had to get past all of Windows security, and did so by using not just one or two or three never-before-known flaws, but a bunch of them.
What I see here is that the word "sophistication" is misunderstood by a lot of people.
Stuxnet took control of multiple layers of complex production environments. There are numerous "0day" kits in the code.
It's not like an effort like a search engine or most other organized software projects, because there are logistical dependencies of the worm itself in those exploits. If it was a US-israel effort (I think it almost definitely was, but who cares) then consider how much discipline and effort it takes to keep TWO govt groups of hackers coordinated enough to keep those exploits fresh, whilst simultaneously building a dependable worm.
Another thing, a lot of the actual machinery and shit isn't very well known, and this is worth mentioning because it's not like you can go spin up an emulator for this shit to test out your massively devastating two-country worm on.
Stuxnet of course made the best of this by using lots of different exploits in different situations, giving it the biggest attack surface it could, that's low hanging fruit anyways.
I think stuxnet doesn't impress people because maybe they think it's just a bunch of bugs in old shitty software, but it's so much more than that. It's bugs in software that only a few hundred or maybe a few thousand people have ever seen, much less pentested, on machinery that's rare and sometimes even unique to the location, the infrastructure of the place is based on rough intel at best, and oh by the way, your spy hackers need to coordinate with this other group on the other side of the planet.
Start brainstorming how you'd pull it off, and I think it'll become more imrpressive as you do.
Personally, I think it's the most incredible display of skill and prowess in malware thus far. The years I've spent disassembling, reversing, tracing, filtering, researching... A lifetime of hacking doesn't even knock the dust off of a project like that.
I wrote the quoted article about Stuxnet. And I've helped write multiple operating systems.
Your argument not an argument. It's just a random assertion with no technical knowledge of either Stuxnet or how to write an operating system.
Stuxnet specifically took advantage of Windows's lack of sophistication in order to replicate.
Thermonuclear Cyberwar
https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2836208
We have moved into uncharted domains. And herein lie demons. Past Rules of Engagement universally agreed upon regarding the use of kinetic weapons no longer apply. For wiser heads to prevail in the current global climate, the voice for peace must become the loudest one.
Rules of engagement for cyberspace operations: a view from the USA
https://academic.oup.com/cybersecurity/article/doi/10.1093/c...
a) at least two of these secret security teams exist, funded by different political superpowers
b) the one team behind this worm was funded by a group insisting on global denuclearization.
Imagine if what you say is true for every nuclear power, except one (likely the one that is behind this worm).
Have we heard of any other enrichment facilities that have been targeted? There are still a ton out there[0].
[0] https://en.wikipedia.org/wiki/Enriched_uranium#Global_enrich...
It's never been at 100% anyway. Read the book "Command and Control" if you are not convinced.
Imagine the different "peace" if instead we had overwhelmingly powerful defensive capabilities.
ummm... what?
Why does that 1% make such a big difference?
Remember, the Secret Service works for the US Treasury.
Has it? The last 60 years have been relatively peaceful, by historical standards.
As best we can tell, nukes actually did end large-scale war. I would call that at least a partially mitigated disaster.
In the days of WWII, an attacker could rightly feel confident that there could not be an immediate response that strikes anything of importance. The attacker might even believe that such a response could not be possible ever in the future. Poland could be invaded without any realistic worry that Berlin would be attacked that same day, and a bit of optimism turns that into Berlin being safe.
It makes more sense if you remember that nuclear weapons and delivery technology didn't reach the 'assured destruction' stage for awhile. Remember that in the Korean War, in the 1950s, General MacArthur was pushing to use nuclear weapons (IIRC); it wasn't as taboo then. Finally, remember that MAD applied only to the Soviet Union and U.S. (or the Warsaw Pact and NATO), while major international wars ended worldwide, for the most part. Remember that WWI and WWII were fought between future NATO members; the later peace between them wasn't due to MAD.
> At the beginning of the twentieth century it was looking like we'd have another world war every twenty years or so for the rest of time.
The victors of WWII were very concerned about that, and began planning to prevent it before the war ended. That resulted in the UN, the institutions that became the EU, a rejection of nationalism (as a significant cause of war), the spread of democracy and universal human rights as a peace-making policy (democracies generally don't start wars with each other), and U.S. leadership in the international order to maintain those things and to provide stability. My understanding is that those are the reasons for the relative but extraordinary peace. Here's a Churchill speech about it in Zurich in 1946 (the speech focuses on the future EU; remember he also was one of the architects of the United Nations):
http://www.churchill-society-london.org.uk/astonish.html
(I'll also note that they seemed to have worked so well that now people take the peace for granted and are tossing aside the things that make it happen.)
[0] The best credible source I can find quickly. If you hit a paywall, access it via a search engine: https://www.britannica.com/topic/nuclear-strategy#ref1224926
EDIT: Added a detail
Nuclear weapons create a requirement that you safety depends on the pragmatism and sanity of leaders and government. Not only of your own country but your enemies.
Who knows what kinds of software are still out there quietly doing their thing in the shadows.
I know quite a few Russians. Almost all act defensive over how people treat Russia as a politically homogeneous (evil) unit, when it's mainly a few oligarchs at the top. To the point of defending the political explanations espoused by state TV, which of course is heavily biased towards the narrative said oligarchs want the Russian people to believe.
Remind you of anything? I for one have stopped trusting Dutch news for "being honest with itself".
Your comment doesn't specify the us or them so it can apply to virtually any group.
Imagine Venezuela, but much much worse.
Picture a society that doesn't know how to create institutions, conduct trade and collaborate with the people around them without the aid of a computers.
Now, I don't know if disabling their computers would result in an incredibly dysfunctional society that would starve, but it's not unthinkable. If it did, the suffering could be far beyond the instant obliteration of millions of people.
I'm already unsure of what the most possible damage someone could do with over-the-air automobile firmware updates is today, just to take one example. What would it be like if someone put out a virus that at 11:32:42am on March 3rd, 2036 causes every GM, Ford, and Tesla self-driving car to lock all the doors, floor the accelerator, and let the chips fall where they may?
Consider not just the immediate impact of the crashes, but the fact that you just completely obliterated emergency services (they couldn't hope to serve but a tiny fraction of the victims), choked every major road and most of the minor roads with wreckage, wrought a catastrophe so large that while I don't predict what the effects would be, we're talking something more defining for a generation that would handily compete with both World Wars combined for psychological effect, with the Great Depression tossed in for good measure... it would be astonishing.
I'm not even sure we couldn't get close to that in 2018, to be honest. What if by some horrors the Stuxnet authors were set the task of making this happen? How close could they get?
Software which say opened the throttle and disabled the brakes on millions of vehicles simultaneously would be in the ballpark for total destruction in a short time. With self-driving cars, the total destruction can be optimized, hunting down pedestrians and hitting vulnerable infrastructure.
If you can pull this off for a continental scale, you're looking at potentially months to restore power to everywhere.
https://en.wikipedia.org/wiki/December_2015_Ukraine_power_gr...
https://www.bloomberg.com/graphics/2018-food-trade-chokepoin...
It highlights the shipping "chokepoints" where disruption causes potential food crisis for where the ship had intended to deliver its payload. If the infrastructure which manages these pathways is attacked, the security of these regions is in jeopardy.
Incidentally, my impression has always been that, at least with the comparatively low-yield atomic weapons that have actually been used, it's not the instant obliteration that's the biggest problem, but rather the lingering effects of fallout and radiation sickness.
I know hackers hate the word cyber because grandma uses it, but it's the right word for it. The stand-in "computer based" almost works, but it doesn't cover things like hacking radios.
But now, everyone's wiser, so the game just got more complex.
Its mission was to destroy some expensive industrial centrifuges and set back Iran's nuclear program. And it destroyed some centrifuges precisely as it was designed to. At that point discovery is inevitable, but whatevs because "mission accomplished".
I think it might be considered a partial success, but mostly failure. It did successfully set back Iran's nuclear program and destroy some centrifuges, but it spread too widely so it was probably detected much more quickly than desired.
Also, if it had been discovered only at the nuclear fuel plant, Iran might have kept quiet about it out of embarrassment, allowing it to be deployed elsewhere. Instead it was picked up by a major AV vendor and dissected very publicly.
https://www.forbes.com/sites/jamesconca/2018/03/16/russia-ha...
The same was also reported by MI5, Europol and of course within Ukraine.
1) The legal, ethical, technical challenges of creating the software.
2) The ability of the software to remain hidden in (sophisticated) environments rich with (sophisticated) organizations looking for exactly this kind of thing.
3) The stealth of the entire research, design, development, and deployment phases of the project.
4) The highly specialized nature of the target.
5) The scale of the entities involved.
6) All of this sophistication and we can't even see the source code (decompilation doesn't count).
This is frankly some impressively sophisticated software. Also, incidentally, the Quora poster's company looks like a fun place to work (with good programmers on the team). Some of his other answers are thoughtful and interesting to read, too, if you get the chance.
In response, the US introduced an integer overflow bug that was uptime dependent, and took something like 6 months to hit. The bug simultaneously cranked up the pumps and closed all the valves in the network.
It was known that the Soviet economy would crash in under a year without the ability to cheaply move natural gas, so they couldn’t test long enough to find this.
A year or so later, the DoD’s seismographs detected the largest non-nuclear explosion in human history.
The main impact wasn’t the explosion or the short-term economic damage. The main impact was that the USSR stopped trusting stolen software, which set them way further back, economically and militarily.
Arguably, that ~one line of code was infinitely more sophisticated than stuxnet.
http://jeffreycarr.blogspot.com/2012/06/myth-of-cia-and-tran...
Also, this story seems to be taking on a life of its own. You have some details that were not in previous rounds. Integer overflow based on uptime was not in the original unverified story.
I think this account might be a bit wrong. The one I read said that the CIA acquired a "shopping list" of Western technology that the USSR wanted to acquire. It included the pipeline control software, so they arranged for a trojaned version to become available to the Soviet shoppers.
Apparently this was a pretty common Soviet activity. Their electronics technology was behind the West's, in general. IIRC, many US semiconductor designs has little cartoons on the dies to taunt the Soviet reverse engineers.
I find it very satisfying to understand a problem so well, up to the point you can find a simple and elegant solution to it. It makes the solution easier to reason about with other team members, and easier for the team to maintain it later. I see this as making your domain expertise available as a framework for the other team members.
This is my idea of sophistication in the software development world.
1. Get the code to work 2. Clean up the code 3. Simplify the code
1 is self explanatory. 2 involves removing any logical redundancy, separating and cleaning the logic into methods, etc. 3 involves simplifying logic and logical mechanisms.
Most developers only do step 1 and maybe step 2. Step 3 is where beauty comes in.
If I could organize my thoughts around this concept, it would probably make a pretty good article. I don't know who the source is but a good quote goes something like this, "real genius isn't solving the complex, it's solving the complex in a simple way."
I made a poster with this for my office wall.
I'm asking in honesty, not using the question to merely attack your opinion. I recognize there are things I have probably not considered.
It would be impressive if it was the work of a teenager but it's not.
A really creative hack, so to speak. (or destructive? anti-destructive? shrug)
It explains in great detail how Stuxnet worked and, which I found the most exciting, how it was discovered and reverse engineered.
Whilst I enjoyed the multiple viewpoints it provides (some claim that Stuxnet was actually quite sloppily written, depending on numerous factors), it happened to be one of those books which wrote 100 pages worth of information in 400 pages instead and dragged every little point on. YMMV.
That being said, I read it mostly for entertainment and I think the author did a good job of packaging a lot of factual information into a captivating story.
That being said, not all parts are created equal. There are quite a few pages dedicated to looking at the number of centrifuges Iran was installing and amount of gas they enriched, as this were the metrics Stuxnet was affecting. To me, that was as exciting as reading a company's monthly inventory report.
But I guess that's to be expected in a book that tells a true story instead of just being based on true story.
Looks good! Might have to check it out tonight.
What I am seeing lately with malware is increasing decline in sophistication, today malware is lame compared to the malware created around 2000. I would think that level of low level knowledge is rapidly dropping. When there were still real file infectors, there were some serious nasty technologies involved (btw, todays ransomware is a very old concept (http://virus.wikidot.com/onehalf) but it was used to prevent virus removal instead of making money).
For those not aware of Mistfall: typical viruses simply append their code to the target. To avoid detection, polymorphism was introduced: viruses generate permutations of decryption logic for the actual static but encrypted virus body. The next step was metamorphism: the virus body itself got permuted. Mistfall was one step further: it disassembled the host, merged in its own permuted body and rebuilt the host. Here is an article by the author himself [1]. This was in 2000.
In general, before hacking and cybercrime became a commercial activity, there was a lively virus writing scene, where highly skilled people played the cat and mouse game with anti virus producers, created magazines with the sources of their creations and wrote articles.
Too bad that z0mbie disappeared. Sometimes when news about elite Russian hackers hits the news I wonder if it's him.
https://web.archive.org/web/20110205151357/http://www.rootki...
> "merged in its own permuted body and rebuilt the host."
Actually it was even more sophisticated, it not only merged its permutated body into the host, but rather rearanged the host in a way to merge chunks of its body between the chunks of host original code, using jmp instructions to keep the code flow, where entry point was inserted on random. If he would further armored it by additional polymorphism layers for each chunk this would make it even algorythmicaly impossible to detect (on the other side, even now, no one can claim it can detect all the permutations, while the disinfection is limited to "delete infected files"). This was work of art (I was a malware analyst), todays malware is a joke compared to what z0mbie was doing (even if I could argue that there is lot to do on windows, infecting MBR and owning the Windows by serving them the calls to yourself is still (maybe I am outdated?) something to be seen. I would really love to shake his hand even if we were on oposite sides :)
http://dsr.segfault.es/stuff/website-mirrors/29A/
And mirror of z0mbie (mistfall author) site http://z0mbie.daemonlab.org/
I am really interested what happened with z0mbie... he just vanished at some point...
Sometimes how you do it is far more interesting than what you do (but it might be a tad more complex to understand).
> Later, whoever wrote that driver started signing it with secret keys from JMicron, another big Taiwanese company. Yet again, the authors had to figure out how to break into the most secure location in that company and steal the most secure key that that company owns, without JMicron finding out about it.
Oh come on... "most secure location"? I'd wager it would be harder to break into the janitor's closet and steal his toilet paper supply than it would be to get those signing certs. If this was most companies it was stored on a public file share used by software engineers or in an open source control repository. They either got someone hired as a contractor or bribed an engineer they found on LinkedIn a couple thousand dollars.
These keys are usually stored on a HSM. Even if you want to, you wouldn't be able to access the keys stored inside. This is specifically designed to protect against rogue/bribed personnel.
So it's highly unlikely that the stuxnet developers had possession of the key. I'd bet that they somehow had access to the HSM, to have it sign the driver for them.
Companies of this size are audited regularly, so access to the HSM is expected to be strictly controlled.
So yes, it is a pretty secure location, and a highly guarded secret. The fact that they pulled it of to break into not one, but two of those secrets is extremely impressive on it's own.
No, you could unfortunately get around that very easily (or rather, ignore recommendations) at least a few years ago. So I bet there are a lot of certificates and private keys lying around on disks, build servers, version control systems and probably even on developer USB sticks.
The cert and key just needs to be something signtool can access. Signtool doesn't care whether it's relatively unprotected key in system software based key store or on a HSM.
Windows 10 1607+ enforces a much stricter standard, especially if you want your driver to work in Secure Boot mode. There are also stricter requirements for driver testing and static analysis, although those depend on the driver type. Microsoft requires and checks testing tool output as a part of the driver submission before finally signing it with their cert.
Tip: If you run Windows 10 and value security (and system stability), use Secure Boot.
(I've developed Windows kernel drivers.)
Or were able to duplicate the HSM before it was delivered. You know, like how the NSA intercepted shipments of internet routers in transit and inserted backdoors.
Sure now they often are - after many security failures 10 years ago before HSMs were widely deployed. A decade ago a much more common ‘secure’ mechanism was to store the keys on an airgapped machine that had never been connected to a network and use sneakernet to get binaries signed.
HSMs. Lol.
The developers would need access to the private key to sign the drivers they're deploying. Convenience is the ultimate foil of most good security intentions.
Did they break into them? Stuxnet had government backing, most articles I've read assume American or Israeli.
If it was the American government (on its own or on Israel's behalf), then it might have 'simply' applied its considerable influence to get the Taiwanese government to get Realtek and JMicron to hand over the HSMs.
[1] https://www.sslshopper.com/microsoft-authenticode-certificat...
If you manufacture hardware and distribute drivers you are an even bigger target than a telco.
Personally I doubt that retrieving this key involved required some act of super ninja skills espionage. I suspect somebody high up in the US government simply picked up the phone and called somebody high up in the Taiwanese government. The reality is Taiwan's security at the end of the day is wholly dependent upon US defense. There are no other options, there are no other cards in their hand. They absolutely need the US military to secure the continued existence of their nation.
This is the lesson of Stuxnet: "private" actors aren't. At the end of the day the US government has demonstrated again and again that it can compel cooperation from virtually every technology firm in the "free world." It's not a card to be played lightly but it's absolutely there. Thanks to Snowden we know the NSA regularly compromises Cisco telecom equipment created for export [1][2] and that the US government is working closely with all the major tech firms[3].
And this is why the US does not want China exporting Chinese phones, electronics, telcom kit, chips and social software. There's absolutely no problem when "private companies" in the US, Korea, Japan and Taiwan export this equipment and technology because these companies are squarely under the thumb of the US. Now that China is getting in on the game everybody is freaking the fuck out precisely because they understand perfectly what it means for "private companies" in China to have a significant chunk of the market.
Of course the Chinese also understand exactly what's going on here and this is why they've established the Great Firewall and why they're absolutely determined to homegrow all their technology needs. Right now China imports an absolutely extraordinary amount of chips and it is probably their greatest security weakness [4].
So this is what it comes down to: every large corporation that matters is likely a phone call and/or secret warrant away from literally giving its private keys to some government actor, likely the US or China. Any data stored by these corporate systems should be considered readable and writable by the government. Any service secured by these corporate systems should be considered accessible and ultimately under the control of these governments. These corporations will not risk either their continued existence or the possibility of fat government contracts in order to protect their customers from these governments. Individuals who depend upon these corporations are therefore completely at the mercy of these government actors.
All of this is a long way of saying that security of digital assets cannot be outsourced.
[1] https://arstechnica.com/information-technology/2016/08/cisco...
[2] https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...
[3] https://en.wikipedia.org/wiki/PRISM_(surveillance_program)
[4] http://nationalinterest.org/feature/how-china-will-benefit-a...
You don't know anything at all about the design of your targeted system and networks.
Even getting a little information about it requires writing sophisticated malware, using various spy capers to get the malware near the target systems, and somehow exfiltrating data from airgapped systems over the internet, where the whole mission is blown if anyone detects your data movement.
You may need dozens of iterations of adjusting the software to try and dive a little bit deeper, getting it snuck into the target systems (hopefully by a built-in update over the net), gathering information on the network architecture, then exfiltrating that data back out.
Always a tough balance of spread-happy enough to infect highly protected airgapped systems in a top-secret facility, but not so spread-happy to get out on the open net and infect half of the world, where it will inevitably be discovered eventually. This is probably where they eventually screwed up.
How long to detect that they're using this particular model of PLC with this particular centrifuge, buy your own copy of them, dig up someone who actually knows about these things, collaborate with them to figure out a sneaky way to screw things up just a little bit, build ways to get your virus onto the target system to do its damage, etc.
I'd assume that there was a team somewhere with a big library of zero-day exploits and a bunch of ace developers, but no starting knowledge of the target. Someone gave them the order to figure out a way to hack and screw up the Iranian nuclear program, maybe with the helper that some other org has a guy that can deliver any product near the program. They must have spent years devising ways to get in, slowly gathering info about their target, figuring out a way to achieve the assigned goal of screwing things up without getting detected. Now that would be a hell of a project to work on.
>They must have spent years devising ways to get in, slowly gathering info about their target, figuring out a way to achieve the assigned goal of screwing things up without getting detected.
I'd speculate that given who the intended targets were (Iran, North Korea) and who would have an interest in disrupting their enrichment operations (Israel, US), and given the level of intelligence gathering activity that both of these nation can (and ostensibly do) engage in, that the team tasked with creating this virus had plenty of information to go on from the start.
Centrifuge models with firmware revision, network topologies, deployed server configuration, etc were likely known in advance.
> that driver started signing it with secret keys from JMicron
I think this is the scariest part of the worm. Not only do the people writing it have access to zero-days, they also somehow have (possibly physical) access to the private keys of two large corporations.
https://arstechnica.com/information-technology/2012/06/flame...
This isn't stealing a cert or burning four zero-days. This is dropping a zero-day cryptographical attack, which hasn't been reverse engineered yet.
He's also one of the minds behind shattered.io ; which happened because Google decided to invest some resources on his research (estimated at around ~300k). Imagine if he "simply" took a job working for an intelligence agency ?
The author sensationalizes the effort of the creators, painting a Holywoodesque scenario where they break into every possible software company to steal keys to misrepresent the software, going undetected by every possible security company etc. Since this is a Quora post, I can live with him playing to the gallery.
Given the amount of speculation of involvement of US and Israeli intelligence agencies, and the task this worm was assigned, the real effort might have been just about writing a USB worm that identifies specific machines and handing the USB-0 to a double agent (I stopped watching Homeland after season 5 and am rusty with the jargon). The rest of it would have been simply asking all the associated software and hardware companies, politely, to cooperate.
If any of this is true, stuxnet is anything but sophisticated. Its just lots and lots of specific API calls.
That brings up the question: what is sophistication as applied to software?
[0]: https://www.amazon.com/Countdown-Zero-Day-Stuxnet-Digital/dp...
What keeps this cooperation secret? It would only take one weak link at any one of those companies to reveal -- accidentally or otherwise -- that they were coerced into providing their signing keys. As soon as that got out, speculation runs amok: Are all products from said company compromised? This would be ruinous to a company, so no one in charge would agree to that without something significant -- which would be even harder to hide from the public -- in return. Then, who asked for the key and why? Could that be traced back to the (presumably) agency in question? That weak link was weak once, there's nothing to assume that he/she won't be weak again, etc., etc.
The sophistication of this software is that it did all this undetected.
Everything's an API at the end of the day.
There was an article on here recently about the practical effects of the TLS 1.3 drafts, and how they broke proxies. I can't find it. It was talking about how the proxies choked because so many variable wire bits in TLS 1.2 stayed static for so long they rusted in place in proprietary implementations, and the proxies crashed once the values changed (despite this being a concrete protocol violation). This situation reminds me of that.
[0]: "(of a machine, system, or technique) developed to a high degree of complexity", according to google: https://www.google.com/search?q=define+sophisticated
IIRC, its sequel actually used certain directory listings (registry keys or filesystem) of a target system as input to a KDF that is used to generate an AES key that is used to decrypt the next stage payload. That is, if you don’t have the exact specific system configuration that is being targeted (program names, versions, et c) then the primary function of the worm remains entirely opaque.
Driver signing keys are not nearly as difficult to steal as the answer implies; not only are they shoddily managed in most hardware vendors, they could also be purchased on the black market for about 50k$ at the time. They are still not very difficult to come by.
Zero-days (e.g. security vulnerabilities and their corresponding exploits) can be purchased on the grey market, and some are developed by government-internal teams. These are little marvels of strange engineering, but they are also a relatively common occurrence. The total market prices of the exploits in Stuxnet will have amounted to perhaps a few million $ at the time.
The Stuxnet worm’s code showed all the artifacts you would have in a large software project - including but not limited to “handwriting” where you could see that a small team of engineers and architects were excellent developers who delegated the implementation of less-important parts to engineers of lesser ability.
There have been leaner, more elegant, and similarly powerful / crazy pieces of malware.
In general, though, these things are not made of magic, and they are not the most brilliant software ever made. They are usually well-engineered by decent engineers, built by a motivated team with decent funding. Even then, mistakes creep in (Stuxnet had an infamously broken mechanism to limit propagation), multiple versions need to be rolled out, and problems & bugs plague any software system.
Now, comparing something like Stuxnet — a relatively small, well-engineered but ultimatively not terribly innovative assembly of known methods — to something like Google’s data center infrastructure (Borg/Flume/Mapreduce/Bigtable/Spanner), the Windows or Linux Kernel etc. and concluding Stuxnet is somehow superior or more sophisticated is simply false.
Stuxnet was cool etc., but I can assure you the level of sophistication is less than the Windows Kernel, the Linux Kernel, or Google’s data processing infrastructure, by far.
This is unsurprising: Stuxnet is a much smaller operation. Building Windows has probably cost many billion dollars by now. Stuxnet, on the other hand, was likely running on a shoestring budget in comparison.
Assembling a highly impactful worm is much cheaper and simpler than people think; most of our IT infrastructure is not very robust.
It’s not really a secret anymore.
I find that misconception worse!
Appendix C is my favorite part: a look at all the things that can be gleaned from television footage of the facilities, brief glances at control screens, etc.
Just like a biological virus, it replicates itself, it hijacks a pretty secure environment, like a cell, and uses it, first to replicate even more, and second, to alter its behaviour in order to accomplish its "goals", meaning deeply hidden instructions that only activate, and this is amazing, only in certain conditions, just how a certain piece of DNA is only activated in certain conditions in the cell.
The intelligent part, in a more humane uderstanding of the term, comes when it is able to act and update in a distributed fashion orchestrated by a central command and control.
This is not just a sophisticated form of software. This is a sophisticated form of life, albeit a distructive one.
Shame the author didn't mention Flame (or any of the other since-discovered super-viruses) at the end.
Everything else are reported and blocked.
Would it be enough to prevent such worm?
It would be interesting exercise to take an old exploitable OS (Win XP, or 10 years old Linux with known issue) add such layer to it. Put it on internet as honeypot and see what other kind of inflections it might get.
The simplest approach though is if you're running Chrome, and I exploit Chrome, I'm now running as Chrome and could persist in memory at least until you shut down.
Facebook's graph database!
Consider, Facebook has modeled:
* All our PII (face scans, key dates and times in our lives (birth to death), employment history, and on and on)
* All our activities (web, real-world)
* All our relationships/interactions (facebook, web, person-to-person, person-to-business, business-to-business, face recognition over practically all digital photos, chat, audio capture from mobile? what else?)
* Data appropriately tagged and categorized: Geo-location and a million other things
* Place information
* And then, the coup de gracie ... how all that data changes over the time dimension
And it's all searchable! A search of that database must be thrilling. You can know what's going on at every level of society at any point in time. You could quantify moods, trends, money, stars and governments currently rising and falling, etc. Consider the unholy power of that graph database, nothing else must come close! Sometimes, I want to get a job there as a data researcher just so I could query it.
The problem is how civilians will end up being the victims of it. What can be scary is how data can mess around the links of trust that is making society work. I hope there are people who are able to think about the problem of preventing online psy ops and other nasty things that can not cause threat, but do damage on the "data" of how society operates. As long as this problem is not fixed and the public is not educated about how computers work, I'm for limiting the use of computers in sensitive areas of society, would it be money, finance, the military, electricity and water networks, infrastructure, computers as a work tool, etc.
Funny that a couple of months a ago I received a paper mail written in russian. There are no way in hell this was not related to my address getting leaked online, this must have been related to the internet somehow.
Stuxnet was discovered because it accidentally spread too far, and ended up on a malware analysts desk.
There was a targeted supplier, an upstream vendor as the insertion point, but it spread outside of that chain.
Also, read this: https://www.theguardian.com/world/2012/jan/11/iran-nuclear-c...
2: In my opinion Stuxnet is an act of war. If Iran doesn't consider itself to be at war with Israel and the US (even though there has been no formal declaration of war) then they are not thinking straight.
If I were to enrich uranium I wouldn't let a Windows PC within a mile of the centrifuges, I'd only use locked down versions of Linux.
So, when China or Russia are building windows exploits, they just demand Microsoft hand over source?
Also, the idea that “locked down” Linux would do any better than windows is ridiculous. The Linux codebase is enormous and complex and full of bugs. At least if you’d said some type of high security microkernel, you could put forward forward some logical arguments.
Yes in fact they do. https://download.microsoft.com/download/B/C/A/BCAFF3F5-5DB5-...
“Throughout the history of the company, Microsoft has worked with national governments around the world to help them build and deploy more secure IT infrastructure and services to protect their citizens and national economies. In 2003, Microsoft built on these efforts to create the Government Security Program (GSP). The scope of the program has grown over time, and continues as a cornerstone of Microsoft’s efforts to help address the unique security requirements of more than 30 national governments around the world.” (Russia and China included) https://www.zdnet.com/article/does-microsofts-sharing-of-sou...
> Also, the idea that “locked down” Linux would do any better than windows is ridiculous. The Linux codebase is enormous and complex and full of bugs. At least if you’d said some type of high security microkernel, you could put forward forward some logical arguments.
It's not a `logical' argument, it's a pragmatic argument. A sufficiently tech-savvy admin can dictate the hardware on the network, roll their own kernel so that USB drivers cannot be loaded, have that image as the boot image, and use TPM if totally necessary. The reason you wouldn't want to run a high security microkernel is because those can't run regular desktop software like LibreOffice and what have you.
https://www.symantec.com/connect/blogs/stuxnet-using-three-a...
I'm curious.
Also, “less interest” is irrelevant when we are talking about nation states picking a specific target and throwing considerable engineering resource at exploitation.
On the other hand, if you or your organization is the victim of a targeted hack, it makes no difference what OS you're running. Any sufficiently motivated and skilled attacker will eventually find a way to exploit it.
As long as new software continues to be released, there will always be bugs. There is no security panacea.
... and centralized updates for all software and libraries and make it hard to use old libraries and selinux and ...
Of course any software has bugs, but "only reason" is very much false equivocation.
But it is widely believed that Stuxnet was initiated from the US, and Microsoft is a US company, so...
Also the author leave a few details out such as the intermitted activation ,for example it was only activated on day 7 and day 21. and other stuff like size of this.
err, no. The companies gave the US access. as for all the 'unknown windows vulnerabilities' it exploited, I wouldn't be 100% surprised if Microsoft left the vulnerabilities for what ever security agency that made it.
- remember systems evolve, these failures aren't hard to harden, both at the electromechanical and human level.
- raw network and electronic activity can be monitored
- is there a way to render MITM UI (the fake display loop) impossible ? a feedback loop pc -> devices, and if deltas are too high ALERT ?
ps: is IBM refining radioactive material ? ;)
If Stuxnet's discovery was a "bug" and that hole has since been plugged, then there's likely plenty we aren't aware of.
Minor, but still important to note (for context).
people make mistakes, it is innate feature of human being. Bugs exist because it is not economically effective to find them. Bugs, given unlimited amount of resources, is possible easy to find whenever they are. Google how one guy hacked infamous HackingTeam alone. He provided some estimates how long it took him. Does it make his software the most sophisticated one on the planet? If his software is the most sophisticated, can he develop Windows alone?
References (National Instruments):
There is likely far more complex and sophisticated software elsewhere.
But even the integration is impressive.
* Somebody periodically in person checking what happening and cross-checking results with operator
* Have alternative monitoring system, even amateur arduino system with rs-422/485 network and independent sensors, can become impenetrable wall for Stuxnet type worms.
Zero days
But from reading the article it seems the author is aiming more for complex than elegant.
It would be elegant if they could accomplish what they did with less code, relying on fewer exploits and perhaps even without the reliance on stolen private keys from other corporations.
Having stolen private keys from hardware vendors is pretty brute force to me.
Don't get me wrong, but "sophisticated" doesn't exactly mean obscure and stealth which is what stuxnet worm is all about. With access to all those vulnerabilities, i would call the worm implementation straighforward & stealth rather than sophisticated. Most likely the engineers didn't have much choice than to proceed in one possible way to be able to make it work. If one of the vulnerabilities didn't then stux.net wouldn't exist.
When on the other hand we have the state-sponsored military grade/purpose viruses used to attack other nations/regions (Flume attacked a large number of targets and countries) and nobody blinks an eye.
Stuxnet is considerably more sophisticated and technologically more brazen, but won’t get the same reporting. But it’s also worth it to consider whether the lack of awareness/awe over Stuxnet vis a vis Russian election tampering is simply due to technology illiteracy, or whether media is not considering the notability of the means, just the effect of the ends.
No, it's because the media is ultimately subservient to power regardless of what they might think of themselves. US attacks on countries designated by power as enemies -- Iran, Venezuela, Russia, etc., are only to be discussed in clinical terms, marveling at their technological sophistication, for example, never in moral terms. Bringing up any introspection of what American reaction would be if Iran did the same thing to us is virtually career suicide for a mainstream media professional. Trying to draw parallels between Russia meddling and Stuxnet, noting that Stuxnet was an attack many times worse, is cutting it dangerously close.
What we just saw was a public alpha. There will be a beta and a final version of this system. The rewards are too great for every state-level actor to ignore and fail to develop election manipulation tools using any new technology they can get their hands on. Big data may have doomed democratic process in an irreversible way. The next couple of decades will be telling.
What we saw was the first export version for the West. Authoritarian regimes have been honing many of the same propaganda techniques on their own populations for some time.
See:
https://en.wikipedia.org/wiki/Internet_Research_Agency (they were involved in the 2016 election interference, but they've long been doing similar in Russia and Eastern Europe).
https://en.wikipedia.org/wiki/50_Cent_Party (Chinese equivalent)
I think it's important for Westerns to study the details of these propaganda programs, so we can recognize and respond to the export versions.
More links:
https://www.rand.org/pubs/perspectives/PE198.html
https://www.nytimes.com/2016/05/20/business/international/ch...
https://chinadigitaltimes.net/2011/06/future-banned-on-sina-...
https://www.buzzfeed.com/maxseddon/documents-show-how-russia... (from 2014!)
Like Watergate, but by a foreign actor.
Isn't this hyperbole? I'd grant that Stuxnet is probably the most sophisticated malware ever written, but calling it the most sophisticated software is a big stretch.
Stuxnet seems to be the product of a competent, professional, and well-funded software engineering organization that writes malware and understands the domain of computer espionage. That was unprecedented in the malware space, but it's not if you include other domains.