Studi Strategici ed Intelligence… for dummies

Un viaggio all’interno di Stuxnet

Published by Silendo on Novembre 22, 2013

Tra i tanti studi realizzati sul famoso malware questo, appena pubblicato da Ralph Langner, del Langner Group, è forse quello che più mi ha colpito (qui una sintesi). Per la profondità dell’analisi e per alcune conclusioni che, se corrette, rimetterebbero in discussione un paio di certezze maturate in questi ultimi due anni.
Ad esempio, secondo l’autore, il worm non sarebbe realmente sfuggito al controllo, propagandosi ed infettando tramite internet. Scrive Langner:

Legend has it that in the summer of 2010, Stuxnet “escaped” from Natanz due to a software bug that came with a version update, and that the roughly 100,000 Stuxnet-infected computer systems worldwide became infected because the malware now self-propagated via the Internet much like a conventional worm. According to the story, Patient Zero was a mobile computer that a control system engineer at Natanz plugged to an infected controller, the laptop got infected and set the malware free when later connected to the Internet.
While that is a good story, it cannot be true. An infected controller contains only Stuxnet’s payload and no dropper component whatsoever, making the alleged jump from controller to computer technically impossible.
All propagation routines in Stuxnet’s dropper (introduced with the rotor speed attack) are carefully crafted, with the problem to be solved apparently being that physical contact to a trusted carrier had been lost. But propagation can only occur between computers that are attached to the same logical network or that exchange files via USB sticks. The propagation routines never make an attempt to spread to random targets for example by generating random IP addresses. Everything happens within the confined boundaries of a trusted network.
However, these days such a trusted environment isn’t necessarily local anymore. Contractors working at Natanz work for other clients as well, and they will have carried their Stuxnet-infected laptop computers to those clients and connected them to their (maybe even air-gapped) “local” networks. Patient One, let’s say a cement plant, will have other contractors besides the one that employs Patient Zero, who also connect their mobile computers to the now-infected “local” network. Those will carry the malware farther. At some link in the chain, infected contractors and/or asset owners will use remote access via VPN, allowing the virus to travel over continents. All of a sudden, Stuxnet made its way around the globe, but not because of the Internet, but because trusted network connections are tunneled through the Internet these days, extending to shared folder access, however ill-advised that may be from a security perspective.

Posted in: Blog
Tagged:
cyber-mf, iran, stati uniti

Chi Sono

Silendo

Un appassionato di relazioni internazionali e studi strategici. In particolar modo di questioni connesse con l'intelligence.
Per contattarmi:
info@silendo.org

Leggi tutto...

Accedi

Tweet di @Silendo_org

Archivio

Categorie

Tags

affari strategici afganistan algeria al qaeda arabia saudita australia cina criminalità organizzata cyber-mf difesa egitto estremismo francia germania gran bretagna guerriglia hamas hezbollah india intelligence iran iraq ISIS israele italia Leadership e classe dirigente libano libia libri medio-oriente minkiate nato nucleare e risorse energetiche pakistan palestina russia sentimenti sicurezza nazionale siria somalia stati uniti strategic foresight studi di intelligence terrorismo turchia

Blogroll

  • Affari Internazionali
  • Agentura
  • American Enterprise Institute
  • ANSSI
  • AOL Defense
  • Arms Control Wonk
  • Asia Centre
  • Asia Times
  • Aspen Institute Italia
  • ASPI
  • Atlantic Council
  • Baker Institute
  • Banca d'Italia
  • BBC
  • Belfer Center
  • Bellingcat
  • Bertelsmann Foundation
  • BESA Center
  • Bibliografia sull'intelligence
  • Bloomberg
  • Bloomberg View
  • Brookings Institution
  • Bruegel
  • Carnegie Endowment
  • Carnegie Middle East Center
  • Carnegie Moscow Center
  • CASD
  • Center for a New American Security
  • Center for Economic Policy Research
  • Center for European Reform
  • Center for Naval Analyses
  • Center for Nonproliferation Studies
  • Centre d'Analyse Stratégique
  • Centro Einaudi
  • Centro Studi Confindustria
  • CEPR
  • CF2R
  • Chatham House
  • China Leadership Monitor
  • CISAC
  • Combating Terrorism Center
  • Comparative Strategy
  • COPASIR
  • Corriere della Sera
  • Council on Foreign Relations
  • CSBA
  • CSFRS
  • CSI – CIA
  • CSIS
  • CSS
  • CSS Strategic Trends Analysis
  • Danger Room
  • DCAF
  • Defence News
  • East online
  • ECFR
  • ECIR
  • Economist
  • Egmont Institute
  • Epistemes
  • EsadeGeo
  • ESPAS
  • EU Institute for Security Studies
  • Eurasianet
  • European Policy Centre
  • Fareed Zakaria
  • FAS
  • FAS – CRS
  • FAS – DNI
  • Fas – Strategic Security Blog
  • Financial Times
  • Foreign Affairs
  • Foreign Policy
  • Foreign Policy – National Security
  • FPRI
  • FRS
  • FSI – Stanford
  • Geneva Centre for Security Policy
  • German Council on Foreign Relations
  • German Marshall Fund
  • Global Trends 2030
  • Globalsecurity.org
  • Governo italiano
  • H-Net
  • Harvard International Review
  • HCSS
  • Heritage Foundation
  • Horizon Scanning Centre
  • Horizon Scanning Centre – Toolkit
  • House Armed Services Committee
  • House Committee on Homeland Security
  • House Committee on International Relations
  • House Intelligence Committee
  • HSPI
  • https://sinocism.com/
  • Hudson Institute
  • IAEA
  • IDSA
  • IEA
  • IFRI
  • IHEDN
  • IISS
  • IMF
  • INET
  • Infinity Journal
  • Infoguerre
  • INSS – Israele
  • INSS – USA
  • Institute for Government
  • Intelligence & National Security
  • Intelligence Studies Section
  • IntellNews
  • International Crisis Group
  • International Journal of Intelligence and Counterintelligence
  • International Security
  • International Security Studies
  • IRIS
  • ISIS
  • Istituto Affari Internazionali
  • Istituto Italiano di Studi Strategici
  • Jamestown Foundation
  • JFK School of Government
  • JFQ
  • Joshua Rogin
  • Journal of Military and Strategic Studies
  • Journal of Strategic Security
  • Journal of Strategic Studies
  • Kings of War
  • Lowy Institute
  • LSE IDEAS Blog
  • Macro Polo
  • McKinsey Global Institute
  • Mercator Institute
  • Merlin
  • Military Review
  • Miller Center
  • MIT Center
  • Munich Security Conference
  • National Bureau of Asian Research
  • National Defense Intelligence College
  • National Intelligence Council
  • National Interest Online
  • National Security Archive
  • National Security Journal
  • Naval War College Review
  • NCTC
  • New America Foundation
  • New York Times
  • Newsweek
  • Nixon Center
  • Notre Europe
  • OCSE
  • ODNI
  • On Think Tanks
  • Orbis
  • Oxford Analytica
  • Oxford Intelligence Group
  • Papers – APSA
  • Papers – ISA
  • Parameters
  • Perspectives on Terrorism
  • Peter Bergen
  • Peterson Institute
  • Phillips P. Obrien
  • Proceedings
  • Project 2049
  • Project Syndicate
  • Public Intelligence
  • RAND
  • Real Instituto Elcano
  • Reuters
  • Robert Kaplan
  • RSIS
  • RUSI
  • Secrecy News
  • Security Studies
  • Senate Armed Services Committee
  • Senate Committee on Foreign Relations
  • Senate Committee on Homeland Security
  • Senate Committee on Intelligence
  • Sentinel
  • SGDSN
  • Silicon Continent
  • SIPRI
  • SISR – Intelligence italiana
  • Source&Methods
  • South Asia Analysis Group
  • Spiegel International
  • Stephen Walt
  • Stimson Center
  • Strategic & Defence Studies Centre
  • Strategic Studies Institute
  • Strategic Studies Quarterly
  • Strategika
  • Stratfor
  • Studies in Conflict & Terrorism
  • Terrorism and Political Violence
  • The Back Channel
  • The Diplomat
  • The Interpreter
  • The Overoholt Group
  • The Strategist
  • The Strategy Bridge
  • Time
  • Transatlantic Academy
  • U.S.-China Commission
  • UN Millennium Project
  • Venus in Arms
  • VOX
  • Wall Street Journal
  • War on the Rocks
  • Washington Institute for Near East Policy
  • Washington Post
  • WCFIA – Harvard
  • Wilson International Center
  • World Economic Forum
Locations of visitors to this page
© 2025 SILENDO Design & Dev by Artemida Srl