← The journal

September 27, 2010

Cyberwar. No, Really. Cyberwar!


So even Bruce Schneier, who is often dismissive of the Security Armageddon of the Week, is alarmed about the Stuxnet Worm:

The Stuxnet worm is a “groundbreaking” piece of malware so devious in its use of unpatched vulnerabilities, so sophisticated in its multipronged approach, that the security researchers who tore it apart believe it may be the work of state-backed professionals.

“It’s amazing, really, the resources that went into this worm,” said Liam O Murchu, manager of operations with Symantec’s security response team.

“I’d call it groundbreaking,” said Roel Schouwenberg, a senior antivirus researcher at Kaspersky Lab. In comparison, other notable attacks, like the one dubbed Aurora that hacked Google’s network and those of dozens of other major companies, were child’s play.

Or, as the New York Times put it today:

Security experts say Stuxnet attacked the software in specialized industrial control equipment made by Siemens by exploiting a previously unknown hole in the Windows operating system.

The malware is the first such attack on critical industrial infrastructure that sits at the foundation of modern economies.

It also displays an array of novel tactics — like an ability to steal design documents or even sabotage equipment in a factory — that suggest its creators are much more sophisticated than hackers whose work has been seen before. The malware casts a spotlight on several security weaknesses.

Eric Chien, the technical director of Symantec Security Response, a security software maker that has studied Stuxnet, said it appeared that the malware was created to attack an Iranian industrial facility. Security experts say that it was most likely staged by a government or government-backed group, in light of the significant expertise and resources required to create it. The specific facility that was in Stuxnet’s crosshairs is not known, though speculation has centered on gas and nuclear installations.

The Times goes on to say: . . . malware experts say it could have been designed to trigger such Hollywood-style bedlam as overloaded turbines, exploding pipelines and nuclear centrifuges spinning so fast that they break.

Stuxnet uses security flaws in Windows to enter and control Siemens software systems, specifically something called Organizational Block 35. It’s the first piece of malware ever to contain its own PLC rootkit.  It can also be updated peer-to-peer, as (for example) the botnet I invented for This Is Not a Game.   Stuxnet is an awesome piece of work.

And oddly enough, Iran’s Bushehr nuclear reactor suffered some unexplained delays last year, after the worm was released.  Wikileaks reported there was a serious accident.

Iran Daily reported: “An electronic war has been launched against Iran… This computer worm is designed to transfer data about production lines from our industrial plants to locations outside Iran.”

Colossally malefic as Stuxnet is, however, did its designers actually intend for it to spread around the world via infected USB memory drives?  Because it’s now all over the place, infecting places like telephone systems in Greece, and security professionals all over the world are trying reverse-engineering it.

Which means that the first known state-sponsored cyberwar tool may soon be in everyone’s hands.  Won’t that make for an interesting world?

In fact it will make it more like the world in my novel Deep State, which will be out in February, and which also features an awesome cyberwar tool doing some major Frankenstein blowback upon its creators.

Sometimes I wish the Zeitgeist would stop rummaging around in my head for its ideas, but I’ll settle for its waiting for the book to actually appear. After that, Herr Z can do whatever it likes.

Reader responses

Comments

0 published

Be the first to respond.

Comments are moderated before publication. Please keep responses thoughtful and on topic.