Showing posts with label Stuxnet. Show all posts
Showing posts with label Stuxnet. Show all posts

Friday, 29 September 2023

IT and OT - a relationship?

The recent annual national conference of Cyber|Ireland, the national cyber security cluster organisation that brings together Industry, Academia and Government to represent the needs of the Cyber Security Ecosystem in Ireland was held in Galway city last week (27 September 2023).

Cybersecurity is of course on everybody's lips these days, particularly hear in Ireland after the criminal attach on the health services systems in the midst of the COVID 19 emergency forcing our already overburdened health professionals back to using pen and pencil as the Information Technology (IT) people struggled to bring the software systems up and running again. Many attending the conference were worried about this type attack on their IT systems. Some were also interested in the workings of their factory, Operational Technology (OT) and how exposed they were to attack. This vulnerability can be, and usually is, very different to that of IT.

The day before the actual conferences there were a number of special meeting examining various sectors effected in different ways by this ever-present threat of infiltration or disturbance, malicious (isn't it always?) or otherwise.

Automation professionals became acutely aware of a threat to their systems in July 2010 when we first heard the word Stuxnet. We first heard about it from an Americal pioneer in security, Eric Byres. Semantic's Liam Ó Murchú, one of the first to understand it described his reaction, “Everything in it just made your hair stand up and go, this is something we need to look into.” The Signpost instituted a page as a guide to developments and articles on STUXNET, "the little varmint!" as Byres called it. This ran from July 2010 to 2013 and is still accessible.

Of course things have progressed since then and most, if not all, of the major process and manufacturing entities are aware of the threat and are taking steps to defend themselves. The International Society of Automation, the automation Standards organisation in particular sprang into action and quickly strengthened their security committee developing over time the Cybersecurity Series of Standards now adopted by the IEC - ISA/IEC 62443.

Speakers at Cyber|Ireland OT Forum
LtoR: Damian White, Billy O'Connor, Ita O'Farrell, Dónal Óg Cusack, Eoin Byrne.

The OT Forum.

Cyber|Ireland, as one might expect,  has established a special OT Security Special Interest Group, The Cyber Ireland OTSec SIG,   under Dónal Óg Cusack (yes the hurler!) of DePuy Synthes as chair, with members from industry, vendors and other experts. One of the meetings was organised by this group. The introduction gave an interesting break down of the leading manufacturers/processes in the country and where they stand in the European marketplace (see slide reproduced above).

The first speaker, Ita O’Farrell, Head of Compliance, National Cyber Security Centre (NCSC), outlined the work of the NCSC, set up by the Government, and outlined the law and clarified those responsible or answerable. The political agreement (NIS2) was formally adopted by the European Parliament and then the European Council in November 2022. It entered into force in January. Member States now have until 17 October 2024, to transpose its measures into national law. The NCSC are expanding their services now to small and medium-sized enteprises(SMEs) through the development of an SME Cyber Security Document. 

Dónal Óg Cusack introduced
the OT Forum

Damian White, of DataLogiX Solutions, specialists in securing OT networks used by manufacturers and processes. He stressed the importance of ensuring that management were aware of the importance and the very different challenges facing the production process in their factories.

The view of the user was presented by Johnson & Johnson's Billy O'Connor. Again he spoke of the importance understanding of the differences experience from the IT perspective and the operators' integrity. There has always bee a tension here and his final comment was humorous but emphasises the importance of dialogue. "The IT people are trying to break away from their relationship with OT and the OT didn't know that there was a relationship!"

Perhaps the real answer is communication and trust.

Cyber|Ireland OT Security Special Interest Group

@CyberIreland @ncsc_gov_ie @DataLogiX #CINC2023 #PAuto #Cybersecurity #Ireland

Thursday, 7 September 2017

Digital attacks on control systems!

Boulting Technology, has released an infographic detailing history’s top five industrial computer viruses. The infographic educates industries that rely on computer control systems on how the lack of preventative measures against viruses and hackers can lead to costly downtime due to lost or stolen data.

The infographic is free to download here from Boulting Technology’s website.

Many industry sectors, such as manufacturing, rely on technology and the data it produces to aid production. Lost or corrupt data can lead to expensive downtime and can be difficult to restore.

Boulting Technology understands the importance of using preventative measures to avoid the consequences of leaving computer systems open to viruses. Its new infographic explains how some of the most notorious viruses of the digital age, such as Stuxnet, Flame and the Blackout Worm, have impacted businesses across a variety of sectors.

“Cyber security has become top of the agenda for many businesses over recent weeks, following the Wanna Decryptor (WannaCry) ransomware attack in May, which crippled the NHS and many other organisations across the globe.

“While it is difficult to predict the likelihood of a virus targeting a computer, companies should take preventative measures, like installing antivirus software, to ensure they are not at risk of losing data,” explained, Nick Boughton, sales manager at Boulting Technology.

“Legacy systems can present numerous problems as they do not contain as many safeguards as newer systems. At Boulting Technology we develop and install bespoke control systems which aid in both highlighting and resolving potential problems."


“Our infographic highlights the importance of protecting against hacking and viruses. Computer security researchers are constantly developing ways to enable antivirus solutions to more effectively detect, prevent and destroy new viruses, however it is up to businesses themselves to ensure they are protected.”

@BoultingTech #PAuto #Cybersecurity @StoneJunctionPR

Wednesday, 26 September 2012

Running out of space!

First came Stuxnet with the gradual realisation that this was a serious threat to industrial automation. And remember that was only in July 2010! As the ramifications of this started to set in more and more articles, blogs and opinions on it were published.
Professor Peter Frohlich of Beldon expressed it well, “Stuxnet has demonstrated what experts have long feared – the entry and penitration of embedded computer systems into all areas of industry means that we now all face a potential risk from computer malware.”

We commented a few times in our blogs as the realisation of what a threat this represented for the first time to industrial processes. There were so many papers, and opinions being published that we decided to inaugurate a page entitled "Stuxnet-process-cyber-security-threat-links!"

Soon however we learned of various sons and daughters of Stuxnet and so we renamed our page rather unwieldingly, if there is such a word, "Stuxnet, Duqu, Flame, Gauss and all that!" But our hackers are producing new dangers with various names that to continue adding the name of the latest threat as it occured would lead an impossibly long page name.

So what are we doing about it?

We've decided to rename the page yet again as "ICS & SCADA Security" and leave it at that.

We've just added a link to Tofino's latest item which is on the distructive Shamoon virus which has wreaked havoc in Saudi Arabia.

Wednesday, 22 June 2011

Stuxnet breakthrough company expands

Symantec's is creating  60 jobs at its European Operations Centre in Dublin
'New authentication services mandate is a strong vote of confidence in Symantec's Irish Operation'

Richard Bruton TD
Ireland's Minister for Jobs, Enterprise and Innovation, Richard Bruton, TD, has announced that Symantec, the global leader in security, storage and systems management, is to establish a new team within its European Operations Centre in Dublin, creating 60 high quality jobs. The investment is supported by the Irish Government with the aid of IDA Ireland.

This is the company discovered that Stuxnet actually modifies code on PLCs in a potential act of sabotage and publishers earlier this year of the W32 Stuxnet Dossier.

The new team will be focused on three specific areas relating to Symantec's Identity and Authentication offerings, part of Symantec's Authentication Services business. These areas are customer authentication and verification, technical support and client services. The team will form part of Symantec's "follow the sun" model, with services and support being provided to customers across the Americas, Europe, Middle East and Africa (EMEA) and Asia Pacific and Japan in over 20 languages on a 24/7 basis. Symantec's VeriSign Authentication Services provide organisations with strong proof that a user, device, or website is genuine and that information is protected. This new team is key in ensuring security through a stringent authentication and verification process and team members will speak a minimum of two European languages in order to provide services to Symantec customers across the markets they serve.

Welcoming the announcement, Minister for Jobs, Enterprise and Innovation, the Minister said: "A significant part of the real Irish economic miracle in the mid/late 1990s was our ability to tap into the global ICT boom that was going on at that time. If we are to get growth in employment and in the economy again, one part of that will involve relying on our traditional strengths, and today's announcement is a great vote of confidence in our policies. We must be far-reaching in our ambitions in this area, and I am determined to build on those traditional strengths to ensure that we can reap great rewards from the new global tech boom and get our country working again".

Commenting on the announcement, Enrique Salem, President and Chief Executive Officer of Symantec said, "Today's announcement is a major step forward for Symantec enabling us to better serve our customers by utilising local talents. Following Symantec's acquisition of VeriSign's authentication business in 2010, authentication is a key growth area for the company. The VeriSign check mark is the most recognised symbol of trust online with more than 650 million impressions every day on more than 100,000 websites in 160 countries.


The decision to locate this investment in Dublin comes as a result of the success to date of Symantec in Ireland. I would like to thank staff and management here in Dublin for making this operation such a success, and the Irish Government and IDA Ireland for their support. I look forward to seeing the continued growth of Symantec in Ireland."


Barry O'Leary, CEO of IDA Ireland said, "Symantec first established an operation in Ireland in 1991 and its transformation involves new mandates, increasing the strategic importance of Symantec Ireland within its parent corporation. Transformation of this nature is in keeping with IDA's goals as outlined in our strategy, Horizon 2020. Ireland is benefiting from the overall growth in the technology sector and this investment from Symantec, a leading company in this sector, is very welcome news for the industry in Ireland. I would like to offer Symantec IDA Ireland's continued support as the company further embeds its operations here in Ireland."

Tuesday, 22 February 2011

How Stuxnet spreads!

Eric Byres, CTO of Byres Security Inc., Andrew Ginter, CTO of Abterra Technologies and Joel Langill, CSO of SCADAhacker.com announce today the release of their joint White Paper “How Stuxnet Spreads – A Study of Infection Paths in Best Practice Systems.”  It is the first paper to detail how Stuxnet could infect a control system site protected by a high security architecture using modern, vendor-recommended best practices. The paper shows that current best practices are insufficient to block advanced threats. It then discusses what operators of control and SCADA systems need to do to protect their critical systems from future threats of this type.

• Click on image for more on Stuxnet!
Stuxnet is the first known malware to have been designed specifically to compromise a control system and sabotage an industrial process. It has been described by Symantec's forensic experts as the “most sophisticated” piece of malware they have ever seen.

The paper follows the progress of the worm as it moves through a hypothetical control system, configured according to vendor-recommended security best practices. In spite of strong security measures, the worm is able to compromise a sequence of machines, culminating in the compromise of the PLC devices which directly control the physical process.

While Stuxnet is presumed to have targeted the Siemens WinCC and PCS7 systems used at Iran’s uranium enrichment plants, its existence creates a new cyber security standard for all automation and critical infrastructure sites around the world.

Andrew Ginter remarked “The Stuxnet worm is the best-documented example of an advanced threat designed to sabotage an industrial control system. Other recent attacks have targeted control systems for industrial espionage. Control systems are now targets of advanced threats and today's best-practice defenses must be improved before they can stand against these kinds of adversaries.”

“By explaining how Stuxnet works, our paper helps security professionals understand what it takes to properly secure a state-of-the art industrial control system,” said Joel Langill. “The reality is that the majority of critical facilities are protected much less thoroughly than the hypothetical site described in our paper, and now they need to step up and protect against Stuxnet-like malware.”

“Our paper goes into great detail on Stuxnet infection pathways and highlights the difficulty of preventing infection from an advanced threat. While best practices for prevention should be implemented, control system operators should also put into practice early detection, mitigation, and containment strategies,” remarked Eric Byres. “Such strategies include putting into practice zone-based security as described in ANSI/ISA-99 Standards, paying particular attention on securing last line of defense critical systems, and understanding the unique security challenges of control systems versus IT systems.”

The paper concludes that changes to improve the cyber security of industrial control systems are urgently needed.

Monday, 8 November 2010

Controlling spread of Stuxnet

New application note:  Preventing the spread of the Stuxnet worm in both Siemens and non-Siemens network environments.


One of the key things Byres Security have learned in their test lab (and confirmed by INL at the ICSJWG  - US Industrial Control Systems Joint Working Group - meeting last week) is that the Stuxnet worm is very aggressive once it accidentally gets into a control system. And once it is in, it is almost impossible to remove, since the worm just keeps popping up as it re-infects PCs.

We have a number of links to Stuxnet related articles at the bottom of our blog "Stuxnet – not from a bored schoolboy prankster!"
To counteract this they wanted to create a document to give specific guidance on how to prevent Stuxnet and Stuxnet-like worms from migrating between ANSI/ISA-99 security zones in a control system. Of course the configuration examples they use are based on their Tofino Industrial Security Solution, but the concepts are generally applicable to other firewalls.

The paper (pdf) is available on the Tofino Blog from Monday 7th September 2011.

Friday, 15 October 2010

Stuxnet paper updated

Stuxnet Paper

The single most visited page in the Read-out Blogs is that written by Nick Denbow last month (Sept 2010) which we entitled: Stuxnet – not from a bored schoolboy prankster! (21/9/2010). We have endevoured to add links from other sources to this from time to time. This one will also be added to it.

Now Byres Security has issued the latest version of their Stuxnet White Paper and we consider it important enough to add it as a separate blog.

Basically they have massively updated the original paper, published at the start of the Stuxnet event (back in July - see Security threat to the control system world!) to focus on specific mitigations that are recommended for all control systems, regardless of whether Siemens product is used or not.
  • A new summary of what Stuxnet is, what its consequences are, and how it is spreading

  • A revision of the list of vulnerable systems

  • An expanded analysis of the available Detection and Removal tools

  • A new Prevention/Mitigation section that covers both patchable and non-patchable systems


The paper, which is Version 3.0 of this Stuxnet White Paper has been renamed to: 'Analysis of the Siemens WinCC / PCS7 “Stuxnet” Malware for Industrial Control System Professionals' and may be downloaded from their Tofino Website.