Stuxnet Central
The Stuxnet malware worm has been called an incident “that marks a new age of cyber warfare”. Stuxnet Central provides a hub for the information that Byres Security has created regarding Stuxnet, along with links to key industry material.
(Note: you must be a member of tofinosecurity.com and be logged in to have access to these documents. If you are not already a member, register here)
Stuxnet Presentations
September 21, 2011
"Mission Critical Security in a Post-Stuxnet World Part 1" (3MB)
"Mission Critical Security in a Post-Stuxnet World Part 2" (1MB)
March 21, 2011
"What Does Stuxnet Mean for ICS" (588kb)
This presentation summarizes a lot of information about the Stuxnet malware and discusses what it means for the future of SCADA and ICS security. It is ideal for anyone needing a crash course on Stuxnet, or as a tool for informing management about the implications of it.
Stuxnet White Papers
Feb 22, 2011
How Stuxnet Spreads - A Study of Infection Paths in Best Practice Systems, version 1.0 (5MB)
Authors: Eric Byres, CTO of Byres Security Inc., Andrew Gintner, CTO of Abterra Technologies, Joel Langill, CSO of SCADAhacker.com
This paper details how Stuxnet could infect a control system site protected by a high security architecture using modern, vendor-recommended best practices. The paper shows that current best practices are insufficient to block advanced threats. It then discusses what operators of control and SCADA systems need to do to protect their critical systems from future threats of this type.
ISSSource.com has a series of articles about this White Paper:
Stuxnet Report: A System Attack
Stuxnet Report II: A Worm's Life
Stuxnet Report III: Worm Selects Site
Stuxnet Report IV: Worm Slithers In
Stuxnet Report V: Security Culture Needs Work
October 14, 2010
Analysis of the Siemens WinCC / PCS7 “Stuxnet” Malware for Industrial Control System Professionals, version 3.2 (83kb)
Authors: Eric Byres, CTO and Scott Howard, Technical Services Manager, both of Byres Security Inc.
This paper summarizes the current known facts about the Stuxnet worm. It also summarizes the actions that operators of SCADA and ICS systems can take to protect their critical operations.
Tofino Security / Stuxnet Application Note
Nov 8, 2010
Using Tofino to Control the Spread of the Stuxnet Malware - Application Note describes how to divide the control network into security zones and how to use the Tofino Industrial Security Solution to prevent the spread of the Stuxnet worm.
Eagle Tofino Stuxnet Technical Bulletin - English (1MB) - describes how to use the EAGLE Tofino Industrial Security Solution to prevent the spread of the Stuxnet worm in both Siemens and non-Siemens network environments.
Eagle Tofino Stuxnet Technical Bulletin - German (1MB) - describes how to use the EAGLE Tofino Industrial Security Solution to prevent the spread of the Stuxnet worm in both Siemens and non-Siemens network environments.
Feb 8, 2011
Siemens S7 Clear Memory - Application Note (728kb) - describes how to clear the memory on the S7 controllers and remove the Stuxnet worm.
Stuxnet Mitigation Matrix
Oct 21, 2010
Stuxnet Mitigation Matrix by Byres Security shows mitigation measures by Windows operating system and it includes dynamic links to detailed information on each of the patches and mitigations.
“Practical SCADA Security” blog posts on Stuxnet
Subscribe to the "Practical SCADA Security" news feed
Stuxnet Videos
June 19, 2011
Stuxnet: Anatomy of a Computer Virus
An infographic dissecting the nature and ramifications of Stuxnet, the first weapon made entirely out of code. This was produced for Australian TV program HungryBeast on Australia's ABC1
(Note: this animation is excellent at conveying the uniqueness of Stuxnet, however, it contains a few technical inaccuracies. For example Stuxnet had 7 zero day vulnerabilities, not 20.)
Direction and Motion Graphics: Patrick Clair
Written by: Scott Mitchell
March 29, 2011
Ralph Langner: Cracking Stuxnet, a 21st-century cyber weapon
When first discovered in 2010, the Stuxnet computer worm posed a baffling puzzle. Beyond its unusually high level of sophistication loomed a more troubling mystery: its purpose. Ralph Langner and team helped crack the code that revealed this digital warhead's final target -- and its covert origins. In a fascinating look inside cyber-forensics, he explains how.
Joel Langill's Stuxnet Infection Video
This video was created by
Joel Langill
CEH, CPT, CCNA
CSO, SCADAhacker.com
www.scadahacker.com
Stuxnet News Coverage
Major news stories on the Stuxnet malware are listed for your convenience.
Key Stuxnet References
Microsoft Security Bulletins
http://www.microsoft.com/technet/security/bulletin/MS08-067.mspx
http://www.microsoft.com/technet/security/bulletin/MS10-046.mspx
http://www.microsoft.com/technet/security/bulletin/MS10-061.mspx
Microsoft Security Advisory (2286198)
http://www.microsoft.com/technet/security/advisory/2286198.mspx
http://support.microsoft.com/kb/2286198
http://support.microsoft.com/kb/2347290
Microsoft Malware Protection Center
http://blogs.technet.com/b/mmpc/archive/2010/07/16/the-stuxnet-sting.aspx
http://blogs.technet.com/b/mmpc/archive/2010/07/30/stuxnet-malicious-lnks-and-then-there-was-sality.aspx
Siemens Automation
http://support.automation.siemens.com/WW/view/en/43876783
US-CERT
http://www.us-cert.gov/control_systems/pdf/ICSA-10-201-01C - USB Malware Targeting Siemens Control Software - Update C.pdf
http://www.us-cert.gov/control_systems/pdf/ICSA-10-272-01.pdf
http://www.us-cert.gov/control_systems/pdf/ICSA-10-238-01B%20-%20Stuxnet%20Mitigation.pdf
Symantec Security Focus
http://www.securityfocus.com/bid/31874
http://www.securityfocus.com/bid/41732
http://www.securityfocus.com/bid/43073
CVE References
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4250
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2568
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2729
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2772
Detailed discussion on the malware and how it works:
http://isis-online.org/uploads/isis-reports/documents/stuxnet_FEP_22Dec2010.pdf
http://www.fas.org/sgp/crs/natsec/R41524.pdf
http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_stuxnet_dossier.pdf
http://www.langner.com/en/
http://www.symantec.com/connect/blogs/w32stuxnet-dossier
http://www.eset.com/resources/white-papers/Stuxnet_Under_the_Microscope.pdf
http://findingsfromthefield.com/
http://www.industrialdefender.com/reg/downloads_register.php
