Stuxnet - a cool look at fact versus fiction
No-one could have missed the media blitz about the Stuxnet worm in late 2010, but the IT industry is well-known for hyping such events; just think Y2K ?bug'. So what's the real story with Stuxnet? Is it an isolated threat to Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS), or a much broader threat to organisations that manage critical infrastructure? In this paper, we examine:
? The actual threat that Stuxnet poses to critical infrastructure and industrial plants;
? Why Industrial Control Systems (ICS) are vulnerable to cyber attacks;
? The parallels between Stuxnet in ICS and targeted Trojans in other IT networks; and
? How best to protect your enterprise against these emerging threats.
NOT AN ISOLATED THREAT
Stuxnet isn't last year's threat. ?It was merely the first volley in what may amount to a cyber arms race,' security consultant Eric Byres explained at AusCERT 2011. Others agree that Stuxnet could serve as a ?deployment platform for follow-on worms.' Indeed, a new worm clearly related to Stuxnet was reported in April 2011 and given the name STAR.
We've seen how quickly new threats are adopted by cyber criminals against cyber security. ?Although Stuxnet was designed to penetrate SCADA systems, those who don't manage critical infrastructure can't be complacent,' says Michael Davis of Dark Reading. ?They must understand how Stuxnet works and the potential damage this type of malware can do in more broad-based attacks on IT networks.'
A TICKING TIME BOMB?
First, some background: Stuxnet is malware specifically designed to target SCADA systems built by Siemens and running Simatic WinCC software, usually in combination with Siemens' PCS 7 control system. Stuxnet was discovered in mid 2009, and its ability to exploit un-patched Windows systems was soon demonstrated. As more was revealed about the worm, questions were raised about the vulnerability of National Critical Infrastructure (CNI) to Stuxnet. In July 2010, the Black Hat Security Conference in Las Vegas spawned headlines that warned of ?a ticking time bomb'.
Stuxnet contained a number of carefully crafted components - including a Trojan and a rootkit - which experts said required insider knowledge, stolen design documents and security certificates for its development. German security researcher Ralph Langner wrote that Stuxnet had been ?assembled by a highly qualified team of experts' and suggested that ?the resources needed to stage this attack pointed to a nation state.
Soon after, the BBC confirmed that Stuxnet had hit computers at Iran's Bushehr nuclear plant, and repeated that the worm could only have been created by a ?nation state'. Security guru Eugene Kaspersky said of Stuxnet, ??.this is the turning point; this piece of malware was designed to sabotage plants, to damage industrial systems. I am afraid this is the beginning of a new world ... a new era of cyberwars and cyberterrorism.'
Links:
SD Card is often used by people and when you encounter your SD card is broken what do you plan to do? If you throw away just waste money. sd card files recovery will help you to rescue corruptedSD card.
retrieve deleted photos from corrupted SD card in 3 Steps. Download and install sd card files recovery, click recover and everything will be back. So easy to use. how to recover photos from sd card supports nearly all file formats, all digital camera brands and all removable devices. So are you worried about your corrupted SD card? Just have a try sd card recovery.
In modern society, Dr Watson Errors is really frustrating and difficult to fix. Downloading Smart Dr Watson Errors Fixer Pro, the World's most multi-functional computer error fixer and Windows registry cleaner, and you will enjoy many automatic fixes and can manually fix all system problems! Smart Dr Watson Errors Fixer Pro monitors processes and boosts performance by managing Startup items, cleaning the Windows registry and optimizing System settings. With a few easy steps Smart Dr Watson Errors Fixer Pro will scan your entire computer including Windows registry for any invalid or obsolete entries and provide a list of the registry and other errors found and provides users method about how to fix Dr Watson Errors.
Communication Articles - Download Lagu Terbaru 2012
Photo Loss In Data Transfer
How to Sell Your App on Salesforce AppExchange?
Online Computer Repair Providers - Get Your Personal computer Revamped The Hassle-free Way!
SAMSUNG laptop akku AA-PB9NC6B 4400mah 11.1V
没有评论:
发表评论