Eric Byres, Joel Langill and I have just released a new whitepaper: How Stuxnet Spreads - A Study of Infection Paths in Best Practice Systems. The paper details how the worm moves through what appear to be well-protected enterprise, plant and control system networks and firewalls on the way to its objective - the PLCs controlling the physical process. Existing best-practice security measures are shown to be insufficient to the task of deflecting attacks as sophisticated as this one. A Well-Defended Network The paper describes a "high security" network protected as recommended by the Siemens whitepaper: Siemens Security Concept PCS 7 and WinCC - Basic Document. We chose this network architecture for a number of reasons:
Note that our choice of the Siemens architecture is not meant to be critical of that architecture. The authors of the Stuxnet worm designed the worm to compromise Siemens systems only because their target site was running a Siemens system. If the target facility had run some other control system, some other vendor would be sweating in the spotlight these last few months. Siemens is not the story here - the agencies who are today's advanced threats can compromise any site protected by today's "best practice" systems. The Compromise The bulk of the paper details the different ways the worm bypasses these protections. Take the anti-virus protections for example:
Looking Forward Everyone looks for the quick fix, and unfortunately there doesn't seem to be one this time. Defending against advanced threats takes real determination. The whitepaper discusses at some length the kinds of cultural changes that need to take place at industrial sites. Some kinds of new technology do help. For example:
The message to take from the paper is that today's best-practice defenses are not enough to stop today's advanced threats. Defending against advanced threats takes a new kind of awareness and determination that is only just starting to emerge in critical infrastructure sectors. |
NEWS, TECHNOLOGIES, PRACTICES, AND EXPERIENCE
Note: Comments in this blog are blocked for any posting 14 days old, or older
2011-02-22
How Stuxnet Spreads |
Subscribe to:
Post Comments (Atom)
Very comprehensive report the three of you wrote, with lots of usefull info for those interested in protecting industrial control environments. Keep up the good work!
ReplyDelete