Showing posts with label national security. Show all posts
Showing posts with label national security. Show all posts

Wednesday, July 27, 2011

DHS Fears a Modified Stuxnet Could Attack U.S. Infrastructure



Wired - One year after the discovery of a sophisticated worm that was used to attack centrifuges in Iran’s nuclear program, the U.S. Department of Homeland Security told Congress it fears the same attack could now be used against critical infrastructures in the U.S.

DHS “is concerned that attackers could use the increasingly public information about the code to develop variants targeted at broader installations of programmable equipment in control systems. Copies of the Stuxnet code, in various different iterations, have been publicly available for some time now,” Bobbie Stempfley, acting assistant secretary for the DHS Office of Cybersecurity and Communications, told the House Subcommittee on Oversight and Investigations (.pdf) on Tuesday.

The testimony comes in the wake of accusations that the U.S. was itself responsible, along with Israel, for developing and unleashing Stuxnet into the wild, thereby making it possible for the hackers, nation-state attackers and terrorists that DHS fears, to now repurpose the malware for use against critical infrastructure systems in the U.S.

Stuxnet, considered to be the first cyberweapon discovered in the wild, was found on a computer in Iran in June 2010 and was believed to have been launched in June 2009.

Private researchers who spent months digging through the code, discovered that the sophisticated malware was designed to target a specific industrial control system made by Siemens, and replace legitimate commands in the system with malicious ones. But Stuxnet wasn’t out to destroy just any Siemens system – it sought out the specific system believed to be installed at Iran’s nuclear enrichment plant at Natanz. Any system that didn’t have the same configuration as the system Stuxnet targeted would go unharmed.      More

Friday, July 15, 2011

Critics: U.S. cybersecurity plan has holes, few new items

IDG News Service - The new Strategy for Operating in Cyberspace issued by the Department of Defense on Thursday covers a collection of topics that have been discussed for years and leaves a number of important unanswered questions, critics said.

Deputy Secretary of Defense William Lynn unveiled the new strategy during a speech on Thursday, and a transcript of the speech was made available online.

"Our strategy's overriding emphasis is on denying the benefit of an attack. Rather than rely on the threat of retaliation alone to deter attacks in cyberspace, we aim to change our adversaries' incentives in a more fundamental way. If an attack will not have its intended effect, those who wish us harm will have less reason to target us through cyberspace in the first place," Lynn said.

The plan contains a handful of initiatives, including treating cyberspace as a domain like land and sea; introducing new network defenses that include sensors, software and signatures to detect and stop malicious code; coordinating with the Department of Homeland Security and the private sector; and working with other countries.      More