Implications of recent Stuxnet disclosures

June 12, 2012
I believe the recent disclosures by the New York Times about Stuxnet can be very harmful for the following reasons:
- It removes any ambiguity about the origin of Stuxnet pointing a finger directly at the US for initiating cyber attacks against another nation's critical infrastructure.
- The recent Iranian paper about Stuxnet and Anti-virus published in Control On-Line demonstrates Iranian expertise in control system cyber security and knowledge of the latest Anti-Virus products.

I believe the recent disclosures by the New York Times about Stuxnet can be very harmful for the following reasons:
- It removes any ambiguity about the origin of Stuxnet pointing a finger directly at the US for initiating cyber attacks against another nation's critical infrastructure.
- The recent Iranian paper about Stuxnet and Anti-virus published in Control On-Line demonstrates Iranian expertise in control system cyber security and knowledge of the latest Anti-Virus products.
- US critical infrastructure, particularly electric, are unprepared for a sophisticated cyber attack. The NERC Critical Infrastructure Protection (CIP) cyber security standards exclude the unique issues exploited by Stuxnet and Aurora; allow utilities to exclude most of their assets from any cyber assessment; and provide a roadmap to an attacker in terms of what is excluded, what is included, and when those assets included will be addressed. The just completed NERC Cyber Attack Task Force report excluded Stuxnet and Aurora. Without being flippant, if piles of paper are not adequate to prevent a cyber attack, the electric industry including nuclear, has little to no protection.

The impact of a sophisticated cyber attack against the critical infrastructures can be devastating. There isn't adequate control system cyber forensics to detect such attacks or identify the attacker. The utilities have demonstrated they will not address security only compliance. What does Congress intend to do?

Joe Weiss

Sponsored Recommendations

2024 Industry Trends | Oil & Gas

We sit down with our Industry Marketing Manager, Mark Thomas to find out what is trending in Oil & Gas in 2024. Not only that, but we discuss how Endress+Hau...

Level Measurement in Water and Waste Water Lift Stations

Condensation, build up, obstructions and silt can cause difficulties in making reliable level measurements in lift station wet wells. New trends in low cost radar units solve ...

Temperature Transmitters | The Perfect Fit for Your Measuring Point

Our video introduces you to the three most important selection criteria to help you choose the right temperature transmitter for your application. We also ta...

2024 Industry Trends | Gas & LNG

We sit down with our Industry Marketing Manager, Cesar Martinez, to find out what is trending in Gas & LNG in 2024. Not only that, but we discuss how Endress...