Stuxnet's Secret Twin
foreignpolicy.com
foreignpolicy.com
Why THE FUCK are industrial controllers connected to the Internet still running Windows?
What is going on here? Why did anyone ever think this was a good idea? Your customers may use Windows, but you don't code your site as a batch script ...
I remember reading that one of the methods Stuxnet used to transmit data through the facility between two infected machines that were not networked: sound cards and microphones.
The "BadBIOS" (apparent) hoax/delusion claims machines are using that vector, though.
Better disable the usbstor service so that the USB ports are still working, only they don't make usb storage devices appear as disk drives :-).
(also some software might require a license-dongle to be plugged in)
And afaik they didn't have internet access directly for the control boxes at Natanz. Stuxnet got into the plant via USB sticks.
http://www.matrikonopc.com/products/opc-data-management/opc-...
DCOM is such a headache that these guys sell a $1000 program whose sole purpose is to make it easy to make remote DCOM connections. And I've recommended it as a screaming deal at that price. Given what it costs to get myself or a proper tech to a remote site for a day, I'd much rather use that and spend my time solving the actual problem than spend a day trying to get DCOM working before working on the actual problem.
http://philosecurity.org/2009/01/12/interview-with-an-adware...
Don't tell me you aren't familiar with this.
I do agree, though, Windows is a desktop machine OS and has a vastly larger exploitation surface area.
Selinux / apparmor, lxc (or similar), better aslr, daemons usually defaulting to separate users, many other things... There are many security layers so trivial to apply these days that it's really a failure not to. Sure - you can still find zero-days (or may be already sitting on a pile of them), but I get an impression that it's much harder to take over the whole system these days if anyone spent a couple of minutes just to tweak the defaults.
The level of defense - in this case an air gap - raised cost and risk. That added back bag job to plant the infection, or a bribed operator to the cost and risk. If the SCADA software ran in a VM as a guest OS, and booted from read-only media, stuxnet might not have taken hold, and the bribed operator might have been discovered by forensics on isolated infected systems.
At some point the cost and/or risk exceeds the value of the target or a reasonable threshold for the chance of success. Even when you have infinite money, you don't have infinite time or infinite risk tolerance.
Most of the people working on these devices are far from being computer experts. I went to an advanced class for them, where the instructor took pains to advise the class that it was an advanced class and you would probably be lost if you hadn't taken the beginner class. I hadn't, and I breezed right through all of their material. Not that I'm that much smarter than anyone there, just from having experience using and figuring out a lot of different types of computer systems. This type of software is made for people who are experts in stuff like chemical plant operations, but who think Excel would be a great way to program their control systems. I'd bet that not one of them have even heard of the Nataz attack.
Given the total lack of interest or experience in computer security that seems to be prevalent in the industry, I expect it will get a lot worse before it gets better.
The only real reason I've heard comes down to cost and support. It's easy to develop software for Windows, easy to find developers, easy to support the operating system, easy (debatable) to use in an industrial environment. It's a known factor.
Always remember that people on the shop floor (or hydrocarbons refinery equally) aren't interested in maintaining a PC they don't understand, and their management aren't interested in maintaining a well-educated IT department. It's a simple cost/benefit equation, and so far the benefits have been completely ignored.
Likewise, vendors of control systems don't want to put the time and effort in to develop their IDE's, display tools etc for a Unix variant. System integrators (ICS programmers and configurators)... well, we'd be cool with a Linux-based control system, if it worked well.
That's why you see Windows in industrial control environments. Couple this with the extremely conservative nature of industry, and you have a huge, glaring problem. We (ICS engineers) know it's a problem, clients are starting to realise it's a problem, but the wheels move slowly.
At least Stuxnet has made the wider industrial community aware of just how deep the shit is. Now begins the slow process of crawling back out of it.
That said, in this case I believe that the software to manage the centrifuges is made by Siemens (Germany) and it's written on Windows. So partially it wasn't the consumer's choice to use windows. Even if they used linux, is not hard to think that the NSA could have written a Linux clone worm. The only thing that can keep away such threats is "security" as Schneir mentions here[2] "security is a process" and that process can secure any operating system out there imho.
A followup question I have is this:
When all is said and done how much will autorun.inf cost humanity ? Seriously. Is it in the hundreds of billions ?
We're almost 20 years into the lifespan of that file and it's still making front page mainstream news.
A: Wrong. There are several other spreading mechanisms USB worms use. The LNK vulnerability used by Stuxnet would infect you even if AutoRun and AutoPlay were disabled.
Why SCADA doesn't have the equivalent of a write protect switch so that you can physically disable updates is the more interesting Q.
Fixed that for you.
Defense in depth is the only valid model of protection, but this requires intentional inclusion of cyber security concerns in the design stage of your plant, and on-going maintenance and auditing by a skilled IT team, and training of all your employees against social engineering, and...
This is a lot harder to do than just unplugging the Internets and giving a thumbs up.
Another bright idea was that rather than just collect the information and forward it to a central hub (the ultimate destination), the data would be transferred according to the organizational structure... first area level, then regional, etc.
The culture at this shop was like this... sales spec'd the software and there was no push-back allowed from the technical staff. Fortunately, I didn't work on that project.
Why were the control systems running Windows? Because it has a GUI. This helps when monitoring control systems, and of course is the only platform Siemens' monitoring systems run on.
https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&c...
2. "inspect element"
3. right-click highlighted html
4. "delete node"
5. ???
6. profit
This is the future of war.
When I was in college and the internet got big I and I was touting all this cool stuff you could do, he told me about this project they did way back in the 70's. He said it terrified him at the time because it took the human element out of the equation. If something went wrong, it could do some serious damage. A misplaced decimal point here and it could basically bring down an entire region of the power grid.
He always said the software was great, but it made the people using it lazy - which is where the real danger is.
A: Trick question. Nice. Next question.
I highly recommend downloading this extension for websites with crappy overlays like this one!
But that's a great service, I didn't know I could use it without registering. I will use the bookmarklet from now on, thanks!