Home » Siemens Updates News on Stuxnet Virus
Siemens Updates News on Stuxnet Virus
ControlGlobal.com
09/23/2010
ATLANTA, Ga. -- Siemens was notified about the malware program (trojan) that is targeting the Siemens Simatic WinCC and PCS 7 software on July 14, 2010. On July 22, Siemens provided its customers with a tool for download that detects and removes the virus without influencing plant operations. All of the main virus scanners are now able to detect the trojan. On Aug. 8, Microsoft closed the security breach in the operating system, and the threat of the trojan spreading uncontrolled through industrial environments has consequently been averted.
It has been more than two weeks since Siemens last received a report of an attack on customer systems by Stuxnet. From mid-July to late August, a total of 15 cases were reported to Siemens where the Stuxnet virus was detected in various plants, roughly one- third of which were in Germany. Siemens is not aware of any instances where production operations have been influenced or where a plant has failed; the virus has been removed in all cases known to Siemens.
Siemens has isolated the virus on a test system to carry out more extensive investigations. Based on previously analyzed properties and the behavior of the virus in the software environment of a test system, this does not appear to be the random development of one hacker, but the product of a team of experts. The company suspects that this team is comprised of IT experts with corresponding engineering knowledge of industrial controls based on the virus deployment in industrial production processes.
The extent of the threat to industrial systems still posed by Stuxnet following the implementation of the security updates will, however, remain uncertain until further investigations into the trojan and its mode of operation are complete. Siemens does not yet have any leads as to the source and origin of this malicious software, but analyses are ongoing.
Additional Information:
• Investigations in July showed that Stuxnet can recognize WinCC and Step 7 programs from Siemens and communicate with certain websites/servers. Stuxnet exploits a security gap in the Microsoft Windows operating system and infects computers via USB sticks and networks. It then specifically seeks out Siemens WinCC and PCS 7 installations.
• The malware carries its own blocks (for example, DB890, FC1865, 1874) and tries to load them into the CPU and integrate them into the program sequence. If the above-mentioned blocks are already present, the malware does not infiltrate the user program. If the above-mentioned blocks were not present in the system and are now detected, the virus has infected the system. In this case, Siemens urgently recommends restoring the plant control system to its original state.
• Further investigations have shown that the virus can theoretically influence specific processes and operations in a very specific automation or plant configuration in addition to passing on data. This means that the malware is able, under certain boundary conditions, to influence the processing of operations in the control system. However, this has not yet been verified in tests or in practice.
•Siemens experts are working with Microsoft and the distributors of virus scan programs to analyze the likely consequences and the exact mode of operation of the virus.
•Siemens continues to remind customers of the importance of securing their IT systems and computers against virus attacks, using the latest virus scanners, such as Trend Micro, McAfee and Symantec, and installing the most recent patches from software vendors such as Microsoft.
More News:
-
05/21/2013
SANS Control Security Training Coming to Houston
SANS Institute will hold ICS Security Training event on June 10-15 in Houston
-
05/21/2013
ISA Training Through June in Houston
Technician training, engineering survival and SIS boot camps for condensed, intense, comprehensive educational experience.
-
05/20/2013
NIST Releases Initial Cyber Security Framework Comment Analysis
The National Institute for Standards and Technology has released an initial analysis of the hundreds of comments by industry and the public they have received on the Obama Administration's "Improving Critical Infrastructure Cyber Security" executive order.
-
05/20/2013
Past Time to Upgrade Your DCS?
Upgrading Your DCS: Why You May Need to Do It Sooner Than You Think
-
05/20/2013
Metso Provides New Heating Solution for Finnish Utility
Finland's largest pellet-fired heating plant produces environmentally friendly energy in Tampere
-
05/20/2013
K-BIM Consortium Selects Siemens' Parasolid for New AEC Applications
-BIM, a consortium of commercial, academic and government organizations wants the new application suite to help create a national standard for building information management (BIM)
-
05/17/2013
Friday p.m. Wrap-Up:This Week on ControlGlobal and Elsewhere
Some of the week's biggest stories in process automation
-
05/16/2013
What's Bad Weather Costing Us?
U.S. taxpayers paid nearly $100 billion responding to damages caused by last year’s extreme weather events associated with climate change, about $1,100 per taxpayer, according to an analysis by the Natural Resources Defense Council (NRDC).
-
05/16/2013
BP, Shell, Statoil Raided by EC
European Commission investigators raided the offices of oil companies BP, Royal Dutch Shell and Statoil as well as data collector Platts as part of a larger inquiry into price manipulation of the global crude market.
-
05/15/2013
What We Can Learn About Safety from the Titanic Hearings
This report from the U.K. publication The Engineer is instructive. It reprints a report from the May, 1912 hearings on the sinking of the Titanic.
- All news »
Sponsored Links
Control Digital Edition
Access the entire print issue on-line and be notified each month via e-mail when your new issue is ready for you. Subscribe today.
- Featured White Papers
Print page