Attacks/Breaches
11/12/2012
02:30 PM
50%
50%

Cyber Weapon Friendly Fire: Chevron Stuxnet Fallout

Malware's jump from Iranian uranium enrichment facility to energy giant highlights the downside to custom-made espionage malware -- its capability to infect friends as well as foes.

Who Is Hacking U.S. Banks? 8 Facts
Who Is Hacking U.S. Banks? 8 Facts
(click image for larger view and for slideshow)
The pioneering Stuxnet computer virus, which was designed to attack a single Iranian uranium enrichment facility, went on to infect PCs around the world. Security experts have identified thousands of resulting Stuxnet infections. On Monday, multinational energy giant Chevron became the first U.S. company to admit that it, too, was infected by Stuxnet.

Chevron found that some of its systems had been infected by Stuxnet soon after security firms discovered the virus in July 2010. "I don't think the U.S. government even realized how far it had spread," Mark Koelmel, general manager of the earth sciences department at Chevron, told The Wall Street Journal. "I think the downside of what they did is going to be far worse than what they actually accomplished," he said.

But according to Chevron spokesman Morgan Crinklaw, Stuxnet caused no damage to Chevron's network. "We make every effort to protect our data systems from those types of threats," he told The Wall Street Journal.

[ Read Flame Malware Code Traced To Stuxnet. ]

Confirmation that Stuxnet was designed by the U.S. government -- reportedly working with Israel -- came in June 2012 via journalist David Sanger, who reported that Stuxnet was developed as part of a classified cyberweapons program codenamed "Olympic Games," which was begun under President Bush and accelerated by President Obama. The malware was designed to forestall Israeli airstrikes against Iran, instead using a virus that sabotaged the high-frequency convertor drives used in centrifuges inside the Iranian nuclear facility at Natanz.

Stuxnet reportedly did disable a number of centrifuges at Natanz, but it also spread. "The fundamental problem with the use of viruses as weapons is that once deployed, one loses control of it. It is as likely to damage one's friends as one's enemies," said William Hugh Murray, an executive consultant and trainer in information assurance who's an associate professor at the Naval Postgraduate School, in a recent SANS Institute newsletter.

People with knowledge of the Olympic Games program, speaking to Sanger, did say that the virus had unexpectedly gotten out of control. But many security experts have disputed the notion that Stuxnet somehow broke loose unexpectedly, given that it was a virus incorporating multiple infection techniques, including the ability to exploit four zero-day vulnerabilities.

"'Escaped' continues to be a puzzling term when applied to a virus that relied on numerous Microsoft zero-day vulnerabilities and propagation vectors," said Sean McBride, the director of analysis for Critical Intelligence, in a SANS newsletter. "On the other hand, if your system was not the single underground facility in Iran that Stuxnet was intended to disrupt, the infection was benign. Such collateral damage is part of the price industry gets to pay for -- what was then -- two more years of Iran [being] without a nuclear weapon."

What remains worrying about Stuxnet is the ease with which the custom malware was able to surreptitiously alter the behavior of programmable logic controllers (PLCs) used in industrial control systems. As the Chevron infection highlights, PLCs aren't just used in uranium refineries, but for a broad range of applications -- spanning oil and gas enrichment, manufacturing plant floors and even prisons. Furthermore, businesses might replace their industrial control systems only every 10 or 20 years.

In the interim, what could safeguard PLC environments against future attacks of the Stuxnet variety, especially if launched by foreign adversaries? "There are no automated defense systems that can protect power systems and other critical infrastructure resources against these advanced attacks," said Alan Paller, director of research at the SANS Institute, in a SANS newsletter. "The only defense -- admittedly imperfect -- is radically improved technical skills."

Recent breaches have tarnished digital certificates, the Web security technology. The new, all-digital Digital Certificates issue of Dark Reading gives five reasons to keep it going. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
moarsauce123
50%
50%
moarsauce123,
User Rank: Apprentice
11/18/2012 | 10:36:16 PM
re: Cyber Weapon Friendly Fire: Chevron Stuxnet Fallout
Stuxnet, Flame, and Duqu seem to be creations of the same entity based on their coding and methods of operation. For a quick rundown of how these worms and other malware work, have a look here:

http://dougvitale.wordpress.co...
kjhiggins
50%
50%
kjhiggins,
User Rank: Strategist
11/12/2012 | 9:54:55 PM
re: Cyber Weapon Friendly Fire: Chevron Stuxnet Fallout
Wonder why Chevron decided to go public about this.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2174
Published: 2015-05-24
Cisco TelePresence T, TelePresence TE, and TelePresence TC before 7.1 do not properly implement access control, which allows remote attackers to obtain root privileges by sending packets on the local network and allows physically proximate attackers to obtain root privileges via unspecified vectors,...

CVE-2015-0713
Published: 2015-05-24
The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco TelePresence IP VCR Series Software before 3.0(1.27), Cisco TelePresence ISDN Gateway Software before 2.2(1.94), Cisco TelePresence MCU Software befor...

CVE-2015-0722
Published: 2015-05-24
The network drivers in Cisco TelePresence T, Cisco TelePresence TE, and Cisco TelePresence TC before 7.3.2 allow remote attackers to cause a denial of service (process restart or device reload) via a flood of crafted IP packets, aka Bug ID CSCuj68952.

CVE-2015-1894
Published: 2015-05-24
Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Optim Workload Replay 2.x before 2.1.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVE-2015-1895
Published: 2015-05-24
IBM InfoSphere Optim Workload Replay 2.x before 2.1.0.3 relies on client-side code to verify authorization, which allows remote attackers to bypass intended access restrictions by modifying the client behavior.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.