http://www.computerworld.com/s/article/9212818/If_Stuxnet_was_act_of_cyberwa
r_is_U.S._ready_for_a_response_

 


If Stuxnet was act of cyberwar, is U.S. ready for a response?


George V. Hulme

 

 

March 3, 2011 (CSO) <http://www.csoonline.com>  

With Stuxnet setting back Iran's disputed nuclear program, that country has
vowed to take "pre-emptive" strikes against the powers it believes launched
the attack, a recent news story in the Tehran Times reported
<http://www.tehrantimes.com/Index_view.asp?code=236455> .

"An electronic war has been launched against Iran," an official was quoted
as saying.

Accurate or not, most reports and expert conjecture peg the responsibility
for the creation of Stuxnet
<http://www.csoonline.com/article/602165/stuxnet-industrial-worm-written-a-y
ear-ago>  with the United States and Israel. If Iran retaliates and attacks
industrial controls or the Supervisory Control and Data Acquisition (SCADA)
systems, are our systems prepared and secure enough to withstand an advanced
and targeted attack?

The short answer is no.

Also see
<http://www.csoonline.com/article/662596/exiled-iranian-programmer-my-life-w
as-in-danger-> "Exiled Iranian programmer: My life was in danger"

"The biggest challenge we face isn't that we're not ready for a Stuxnet. The
biggest problem we face is that we're not really ready for anything. If you
were to do a pen test -- and there's plenty of research out there to support
this -- most utility companies are extremely vulnerable," says Eric Knapp,
director of critical infrastructure markets at NitroSecurity.

That begs the question: How far away are utilities and other critical
infrastructures from where they need to be? "Some [utilities] are way, far
away from where they need to be," says one security assessor who has
recently completed a number of assessments on utility companies and
requested not to be quoted by name. "They're making many poor assumptions
about their risk," he says. "They believe that because their communications
between devices are encrypted, or because they have some type of access
control that they're secure. In many ways they're acting like software
companies did about a decade or so ago. They just don't want to see the
reality of things."

Knapp says, while lackadaisical in many areas, it's not consistently bad.
"We work with a lot of utilities and a lot of industrial manufacturing
facilities, and for every comment like that I hear, there are other
utilities that take it very seriously," says Knapp.

Also see
<http://www.csoonline.com/article/659377/telecom-infrastructure-faces-daunti
ng-risks-tata-cso-says> "Telecom infrastructure faces daunting risks, TATA
CSO says"

Mike Sconzo, principal security consultant, NetWitness, believes that
industries in the critical infrastructures, such as utilities and
manufacturing, are starting to take the steps necessary to become more
resilient.

"Critical infrastructures are going through the same kind of growing pains
as the IT industry did over the years," Sconzo says. "For instance, the
first version of NERC's CIP (North American Electric Reliability
Corporation's Critical Infrastructure Protection) standard consisted of
primarily of security box checking. Meaning if you do X, Y, and Y you are
supposedly secure. I'm hearing more interest now, however, in moving toward
more risk-based assessments. A lot of people are realizing that risk-based
security management is not such a horrific idea," he says.

"The key is getting everyone up and down the stack to realize that security
is a continuous process, and just as software developers learned basic best
practices a decade ago and built from there, so must utilities and other
critical infrastructures," says Sconzo.

Sure enough, but with many experts believing it's only a matter of time
before a Stuxnet-like worm is targeted toward U.S. interests, one has to
wonder if there's enough time.

George Hulme writes about security and technology from his home in
Minneapolis. After spending more time researching critical infrastructure
security, he's been often spotted pricing gas and solar-powered backup
generators. He can be found on Twitter as @georgevhulme. 

 



[Non-text portions of this message have been removed]



------------------------------------

--------------------------
Want to discuss this topic?  Head on over to our discussion list, 
[email protected].
--------------------------
Brooks Isoldi, editor
[email protected]

http://www.intellnet.org

  Post message: [email protected]
  Subscribe:    [email protected]
  Unsubscribe:  [email protected]


*** FAIR USE NOTICE. This message contains copyrighted material whose use has 
not been specifically authorized by the copyright owner. OSINT, as a part of 
The Intelligence Network, is making it available without profit to OSINT 
YahooGroups members who have expressed a prior interest in receiving the 
included information in their efforts to advance the understanding of 
intelligence and law enforcement organizations, their activities, methods, 
techniques, human rights, civil liberties, social justice and other 
intelligence related issues, for non-profit research and educational purposes 
only. We believe that this constitutes a 'fair use' of the copyrighted material 
as provided for in section 107 of the U.S. Copyright Law. If you wish to use 
this copyrighted material for purposes of your own that go beyond 'fair use,' 
you must obtain permission from the copyright owner.
For more information go to:
http://www.law.cornell.edu/uscode/17/107.shtmlYahoo! Groups Links

<*> To visit your group on the web, go to:
    http://groups.yahoo.com/group/osint/

<*> Your email settings:
    Individual Email | Traditional

<*> To change settings online go to:
    http://groups.yahoo.com/group/osint/join
    (Yahoo! ID required)

<*> To change settings via email:
    [email protected] 
    [email protected]

<*> To unsubscribe from this group, send an email to:
    [email protected]

<*> Your use of Yahoo! Groups is subject to:
    http://docs.yahoo.com/info/terms/

Reply via email to