Infiltrating Critical Infrastructures with Next-Generation Attacks W32.Stuxnet as a Showcase Threat

Infiltrating Critical Infrastructures with Next-Generation Attacks W32.Stuxnet as a Showcase Threat
复制标题

通过下一代攻击渗透关键基础设施 W32.Stuxnet 作为展示威胁

DOI:
--
复制
发表时间:
2010
期刊:
影响因子:
--
通讯作者:
S. Todt
S. Todt
中科院分区:
--
文献类型:
--
作者:
Martin Brunner;H. Hofinger;Christopher Roblee;P. Schoo;S. Todt

文献摘要

被引文献

相似文献

W32.Stuxnet攻击于2010年7月首次引起媒体的广泛关注,突出了针对社会关键基础设施的恶意软件的危险性,复杂性和技术复杂性。这种性质的攻击对工业控制系统(ICS)的运行具有潜在的广泛影响,包括监控和数据采集(SCADA)系统。在审查了W32.Stuxnet的架构和功能之后,我们根据我们在IT安全领域的专业知识和能力提供了独特的见解和最佳实践建议。我们讨论了适用的技术和管理系统运营商的影响,以及经验教训,以防止未来的妥协。本文面向对ICS环境的操作感兴趣或负责ICS环境操作的技术和非技术受众,这些受众可能容易受到利用不充分的IT安全态势进行攻击的攻击。我们邀请读者与SIT联系,以获得特定网站的指导。慕尼黑弗劳恩霍夫安全信息技术研究所的内斯研究部门慕尼黑弗劳恩霍夫安全信息技术研究所的网络安全和预警系统(内斯)研究部门1正在研究和开发网络和网络安全操作的解决方案基础设施服务基础设施服务。该小组的研究重点之一是信息技术预警,这需要对信息技术系统安全防御有深入的了解,因此需要关于攻击者所使用技术的最新信息。内斯的核心竞争力是将IT安全领域的专业知识转移到其他领域,例如智能计量、智能电网和无线传感器网络。1http:www.sit.fraunhofer.de/ Fraunhofer SIT通过下一代攻击渗透关键的网络结构3
The W32.Stuxnet attack, which first gained widespread media attention in July 2010, highlights the dangers, complexity and technical sophistication of malware targeting society’s critical infrastructures. Attacks of its nature have potentially wide-ranging implications for the operation of Industrial Control Systems (ICS), including Supervisory Control And Data Acquisition (SCADA) systems. After reviewing W32.Stuxnet’s architecture and functionality, we offer unique insights and best practice recommendations based on our expertise and competencies in the IT security domain. We discuss applicable technical and administrative implications for systems operators as well as lessons learned to prevent future compromises. This paper is intended for technical and non-technical audiences interested in or responsible for the operation of ICS environments, and who may be vulnerable to attacks exploiting an inadequate IT security posture. We invite readers to contact SIT for site-specific guidance. NES Research Department at Fraunhofer SIT Munich The Network Security and Early Warning Systems (NES) research department of the Fraunhofer-Institute for Secure Information Technology SIT Munich1 is researching and developing solutions for the secure operation of networks and network infrastructure services. One focus of research of this group is IT early warning, which requires significant, in-depth knowledge of IT systems security defences, and consequently up-to-date information on the techniques used by attackers. A core competency of NES is the transfer of IT security domain expertise into other domains, for example Smart Metering, Smart Grid and Wireless Sensor Networks. 1http://www.sit.fraunhofer.de/ Fraunhofer SIT Infiltrating Critical Infrastructures with Next-Generation Attacks 3