Showing posts with label Siemens. Show all posts
Showing posts with label Siemens. Show all posts

Friday, December 3, 2010

Siemens

Strange I cannot find anything on the Siemens website about Stuxnet.

Thursday, December 2, 2010

Stuxnet again

Reading the heavily technical Symantec report on Stuxnet. It gets stranger and stranger ...

From what I understand first the Siemens PLC needs to be infected via Siemens proprietary Step 7 Windows-based software. Then the PLC needs to connect to "Command and Control" servers via an Internet link. Only then can a programmer change the code in the PLC. Symantec has monitored infections through connections to these Command and Control servers.

The apparent sudden cessation of Iranian infections in August is probably due, according to Symantec, to the Iranians shutting down Internet connections between PLCs and the C & C servers, rather than a real end to infections.

What I haven't fathomed yet is why/how come Iran bought so heavily into Siemens PLC and Step 7 technology and why other countries with the same Siemens PLCs have not been so affected ... is Siemens marketshare so much smaller? ... surely other countries are just as prone to IT security lapses as Iran? ... was Siemens part of the story? ... is there something in Symantec's technical discussion missing e.g. deliberate geographical targetting?


More as I read more ...

Tuesday, November 30, 2010

Stranger and stranger ...

So Iran denied that Stuxnet affected its nuclear power plants ... and now President Ahmadinejad says it did. According to the Symantec report about Stuxnet I cited yesterday, most of the Stuxnet attacks were targetted at Iran but abruptly ceased in August ... but Stuxnet infections continued in other parts of the world principally the US.

Now Iran is claiming that the Wikileak US State Department cables claiming that Arab states wanted the US to finish off Iran's nuclear capabilities are in fact CIA fabrications!

Meanwhile an Iranian physicist is assasinated and another wounded in separate attacks in Tehran.

So get your fill of conspiracies ... I'm sure there are more to come!

Monday, November 29, 2010

Stuxnet

Amidst all the news of Wikileak exposure of US government documents (and I'd be much interested how all this data was obtained - the Guardian says it comes down to one lowly US army private - I cannot believe one lowly private leaked so many documents! ), much has been made in the last couple of weeks of the Stuxnet v¡rus which targets industrial control systems through Siemens Programmable Logic Controllers and its Windows Step 7 control software.

Conspiracy theories abound.The principal one being that the virus is an attempt by an unnamed government to subvert Iran's nuclear program which has backfired to lead other governments to get worried about their own industrial control systems - anything from power stations, electrical grids, water purification and distribution, factory automation etc etc.

I am sceptical but also surprised for a variety of reasons:

1. News of the Stuxnet virus has been around several months. Only now is the press picking up on it saying it is an attempt to subvert the timing on Iran's nuclear centrifuges.

2. It is only aimed at Siemens PLCs.

3. What the hell is Siemens doing exporting PLCs for use in Iranian nuclear centrifuges? I will admit that a bog standard PLC is hardly rocket science and could control the timing of many industrial processes. However, I thought there were export limitations on technologies that could be used in "rogue" nuclear states such as Iran and North Korea.

4. The Iranians deny that any of their nuclear powerplants have been infected by Stuxnet. So would the USA.

5. PLC software from my limited experience would seem to be very easy to hack. I have only very limited experience but in a previous job a one megawatt powerplant was controlled by simple GEFanuc PLC hard and software, the latter written in a generic form of Basic called MegaBasic.

6. Why would you use a Windows-based program to control your nuclear powerplant?

7. And leading on from 5) and 6) why hasn't PLC software been targeted before? I cannot quite believe that Stuxnet is the first given the importance of PLCs in the functioning of the modern world.

Complete technical report here.