Stuxnet

Stuxnet

Stuxnet is the malware discovered in 2010 that specifically sabotaged the uranium enrichment facility at Natanz in Iran, destroying around a thousand centrifuges in the process. It is regarded as the first known digital weapon to cause physical damage in the real world. With it began the era of targeted attacks on industrial control systems.

History & facts. Stuxnet overcame the isolation of the facility, which was not connected to the internet (air gap), spread among other routes via USB media and used no fewer than four previously unknown Windows vulnerabilities as well as stolen digital certificates. On the Siemens Step7 systems it manipulated the programmable logic controllers (S7-300/400) and altered the speed of the frequency converters while continuing to feign normal operation to the operators. The result was destroyed centrifuges with seemingly inconspicuous readings. Stuxnet is widely attributed to state actors.

Outlook & recommendation. Stuxnet proved that an air gap is no absolute protection and that controllers possessed no integrity check of their code — an insight that helped shape the development of standards such as IEC 62443 — Security for Industrial Automation and Control Systems (IEC 62443). For practice this entails: visibility down to the control level, strict control of removable media and remote access, segmentation and passive Operational Technology (OT) monitoring. This very unobtrusive observation of industrial environments, without disrupting operations, is part of NEOSEC's service profile.

Stuxnet — Stuxnet