Infiltrating Critical Infrastructures with Next-Generation Attacks W32.Stuxnet as a Showcase Threat
Infiltrating Critical Infrastructures with Next-Generation Attacks W32.Stuxnet as a Showcase Threat
复制标题
通过下一代攻击渗透关键基础设施 W32.Stuxnet 作为展示威胁
DOI:
--
复制
发表时间:
2010
期刊:
影响因子:
--
通讯作者:
S. Todt
中科院分区:
文献类型:
--
作者:
Martin Brunner;H. Hofinger;Christopher Roblee;P. Schoo;S. Todt
The W32.Stuxnet attack, which first gained widespread media attention in July 2010, highlights the dangers, complexity and technical sophistication of malware targeting society’s critical infrastructures. Attacks of its nature have potentially wide-ranging implications for the operation of Industrial Control Systems (ICS), including Supervisory Control And Data Acquisition (SCADA) systems. After reviewing W32.Stuxnet’s architecture and functionality, we offer unique insights and best practice recommendations based on our expertise and competencies in the IT security domain. We discuss applicable technical and administrative implications for systems operators as well as lessons learned to prevent future compromises. This paper is intended for technical and non-technical audiences interested in or responsible for the operation of ICS environments, and who may be vulnerable to attacks exploiting an inadequate IT security posture. We invite readers to contact SIT for site-specific guidance. NES Research Department at Fraunhofer SIT Munich The Network Security and Early Warning Systems (NES) research department of the Fraunhofer-Institute for Secure Information Technology SIT Munich1 is researching and developing solutions for the secure operation of networks and network infrastructure services. One focus of research of this group is IT early warning, which requires significant, in-depth knowledge of IT systems security defences, and consequently up-to-date information on the techniques used by attackers. A core competency of NES is the transfer of IT security domain expertise into other domains, for example Smart Metering, Smart Grid and Wireless Sensor Networks. 1http://www.sit.fraunhofer.de/ Fraunhofer SIT Infiltrating Critical Infrastructures with Next-Generation Attacks 3