A computer virus with an entirely new purpose
news.yahoo.com
news.yahoo.com
Is it interesting that there's a piece of malware out there that targets industrial controllers? Absolutely it is. It's probably not just some bored college kid.
Is it a "cyber missile" aimed at the heart of Iran's nuclear weapons program? Probably not. Among other things, the IP ranges it's "targeting" aren't specific to Iran. Also, there's no evidence connecting it to Iran.
Whenever you see a better-than-average piece of offensive computing technology, your first thought should be "extortion", and your second (distant second) thought should be "competitive subterfuge". Extortion happens all the time, and you rarely read about it, because the targets don't want to talk about it. And, while there's never been a corroborated story about an actual cross-state offensive strike using IT technology, there have in fact been cases where industry leaders have whacked on each other using security flaws.
The reporting on Stuxnet seems too captive to tidy and palatable narratives for me to take seriously. It doesn't help that these stories are sourced mostly to SCADA security experts. There are some great people working on SCADA problems, but that field takes everything annoying about computer security PR and amplifies it.
This kind of plausibly deniable attack sounds just like what Israel has been wanting. And they have the talent to get the job done.
So why not? A nation state sabotaging an enemy's nuclear weapons without it being traced back to them. That's a pretty nice thing to have.
While what you're talking about is of course the most common scenario, it seems like a no-brainer to me that the NSA/DOD/IDF would spend money on preparing to make these kinds of attacks even if they rarely or never implement them. I don't see why the author's theory is implausible.
As a professional matter, nothing in any of the reporting or analysis of Stuxnet suggests to me that this would have cost more than low-six figures to build cold (meaning, what it would cost to have a contractor familiar with malware and runtime security but not familiar with the particular software targeted here). It'd be significantly cheaper if you had devs with industrial controller backgrounds assisted by an exploit-dev contractor.
So, yes, Israel could have been behind this attack. And the NSA could have been behind the Twitter XSS worm. It could be Putin ordering all those DDoS extortion attempts on gambling websites. But I doubt it; it's probably just someone's scheme to make money. Talk to banking security people sometime; crazy stuff is happening every day.
Means, motive, opportunity.
Putin has no motive to extort pennies from gambling websites. He has better ways to make money. The NSA has no motive to make the Twitter worm.
But Israel has a gigantic motive to make something that would sabotage a nuke plant in Iran. That's the difference.
I agree that it's speculation - I just think it's plausible speculation.
It's pretty simple, if we go with the idea that Stuxnet was built to attack the nuclear program, then the circumstantial evidence points to Israel. Motive, Means, Opportunity.
There is equally compelling evidence that this worm came with a ransom demand. And that's a more plausible story.
On its own, it is the nature of circumstantial evidence for more than one explanation to still be possible. Inference from one piece of circumstantial evidence may not guarantee accuracy. (from wikipedia)
If there was direct evidence, this would be a different discussion entirely.
Oh, and as for 'why Iran?', that's from: http://news.ycombinator.com/item?id=1712296
As for your circumstantial evidence... what is it? I think you've conflated supposition with evidence.
I'm pretty sure that what the parent means is that you could buy a plugin, or rather the company that writes a plugin. say, adblock (okay, adblock might be more than six figures... a less popular plugin that is still fairly widely used.) along with the rights and credentials to upload a new version. (of course, you'd pretend to be a legitimate business to do this.) Now, I don't know how IE works, but FireFox has a mechanism to automatically update plugins to their latest versions. You now insert your malicious code into the plugin and cause the auto-update to run. Assuming the infection isn't immediately obvious, you will, within a few days, infect nearly all users of that plugin.
(Which is not to say that your way wouldn't work too.)
EDIT: Mention Full-Disclosure somewhere.
(I agree that the hyperbole is a bit much, though)
Right, the article seems to imply that a nuclear reactor's control system (or whatever it uses) runs Windows, and is connected to the internet. I really hope that that isn't true...
Allegedly an explosion of a Soviet gas pipeline was caused by a bug intentionally inserted into control software stolen from the United States. http://en.wikipedia.org/wiki/Siberian_pipeline_sabotage
Not a cyber weapon, but close enough in spirit, I think.
But why would someone have written it then? It's not like they were using it to try and steal credit card numbers of send spam emails.
It had a very specific purpose, and according to the linked article didn't seem to require manual intervention to turn on (or off?). It seems to have been a one-shot thing - wait for a specific set of events, and then run that mystery command.
Blackmail/Ransom theories are easier to believe than a state-run cyber war program - but the reported logic of the program seems to make it pretty hard to blackmail someone with. It appears to have been designed to cause maximum damage once, with as little warning as possible. That's the opposite of what you want with a ransom/blackmail situation.
People can imitate the techniques and develop on them, but as long as copies from and to USB drives maintain their multiple-9s accuracy there won't be much spontaneous change outside of the deployer's control. Instead, the big uncertainty factor with worms and viruses has usually been emergent behavior when the infected computers network into one very large system, leading to behaviors that don't show up in small-scale tests. The way it's described, Stuxnet is inherently limited both by its transmission method - USB sticks - and by its target systems - large embedded systems, typically not network-connected, and with a very standard configuration provided from Siemens.
You have PLC's, (programmable logic controllers) often redundant sets of them for critical systems, that run the code that controls the facility. They are networked together via proprietary data networks with no internet involved. These units do not run windows, or any operating system usually. They have no USB ports, hard drives, or monitors. They are hardened against temperature, dust, and power fluctuations. Once the facility is running properly, the PLC's do everything. No human's need to make any decisions about facility operation.
However, sometimes, humans want to tweak a setpoint or override a safety interlock because they know a sensor is bad, or they want to run a certain automatic operation in manual, because something has changed in their process. For this, they have windows based graphics interfaces with pretty animated pictures of valves and motors and pumps and fans and reactors and pipes and ductwork, all of which change their state based on the status of the actual valve or motor or pump or fan. To do that, these windows based PC's are networked to the PLC's, to query them for state information. So nobody is "running a factory on windows". Think of these as terminals into your webserver. If you lose the terminal the webserver keeps on trucking. Also, just like terminals, you can have as many windows PC's as you want tied into the PLC network, so if you lose a couple, you still have others, in case there's something that you really don't want to lose visibility of.
At no point is this network tied to the internet, for obvious reasons. Usually, the drives are locked out on these systems using physical locks, so only engineering staff can load anything on them. USB is trickier, as I can imagine people hooking up legitimate devices such as sirens and flashing lights and even just speakers for audible alarms, all via USB, which exposes the USB ports to the operators.
Perhaps we were working on systems of a different scale. Most of the facilities I controlled had on the order of 2000 - 5000 I/O points and stretched over several multistory buildings. It sounds like you're doing motion control of a pick and place machine or something similar. That's also fun, especially now that you can do so much with optical recognition.
Stuxnet infects Windows systems in its search for industrial control systems, often generically (but incorrectly) known as SCADA systems. Industrial control systems consist of Programmable Logic Controllers (PLCs), which can be thought of as mini-computers that can be programmed from a Windows system. These PLCs contain special code that controls the automation of industrial processes—for instance, to control machinery in a plant or a factory. Programmers use software (e.g., on a Windows PC) to create code and then upload their code to the PLCs.
Previously, we reported that Stuxnet can steal code and design projects and also hide itself using a classic Windows rootkit, but unfortunately it can also do much more. Stuxnet has the ability to take advantage of the programming software to also upload its own code to the PLC in an industrial control system that is typically monitored by SCADA systems. In addition, Stuxnet then hides these code blocks, so when a programmer using an infected machine tries to view all of the code blocks on a PLC, they will not see the code injected by Stuxnet. Thus, Stuxnet isn’t just a rootkit that hides itself on Windows, but is the first publicly known rootkit that is able to hide injected code located on a PLC.
In particular, Stuxnet hooks the programming software, which means that when someone uses the software to view code blocks on the PLC, the injected blocks are nowhere to be found. This is done by hooking enumeration, read, and write functions so that you can’t accidentally overwrite the hidden blocks as well.
...
Fascinating: http://www.symantec.com/connect/blogs/stuxnet-introduces-fir...
http://en.wikipedia.org/wiki/Sneakernet
In this case through USB keys. Presumably people updating software on the machines or running diagnostics. Possibly USB dongles to unlock the machines.It doesn't take an inside man - only an inside snippet of code, which you can foist on an unsuspecting worker or consultant. Also, the chain of transmission can be indirect, so that even if you can't get a physical item into the target, you can plant it somewhere else where it eventually spread to the target (only so many degrees of separation between any two power plants, it seems)
Life imitates fiction.
As far as I know, ram doesn't generally hold memory after it's been powered down. Ram sticks don't make sense as a vector for a virus as far as I can tell.