Power Generation and Distribution Blog Blog

Power Generation and Distribution Blog

The Power Generation and Distribution Blog is the place for conversation and discussion about electrical power generation, designing and installing power systems, high voltage power lines, power distribution, design & installation services, and anything else related to the power generation industry. Here, you'll find everything from application ideas, to news and industry trends, to hot topics and cutting edge innovations.

Previous in Blog: Did Your Power System Survive the Hurricanes?   Next in Blog: Extending the Life of Nuclear Reactors
Close
Close
Close
6 comments
Rate Comments: Nested

Have You Seen the StuxNet Worm Yet?

Posted November 03, 2010 7:06 AM
User-tagged by 1 user

The StuxNet computer worm began in Iran and the Middle East, and is sweeping the world, apparently targeting power plants that use Siemens PLCs. It enters a power plant's control system via a memory stick, so firewalls and antivirus software can't protect a plant. Its origin and purpose remain a mystery, but it is spreading like wildfire. Have you heard about it, and have you taken steps to protect your plant?

The preceding article is a "sneak peek" from Power Generation & Distribution, a newsletter from GlobalSpec. To stay up-to-date and informed on industry trends, products, and technologies, subscribe to Power Generation & Distribution today.

Reply

Interested in this topic? By joining CR4 you can "subscribe" to
this discussion and receive notification when new comments are added.

"Almost" Good Answers:

Check out these comments that don't yet have enough votes to be "official" good answers and, if you agree with them, vote them!
Guru
Technical Fields - Technical Writing - New Member Engineering Fields - Piping Design Engineering - New Member

Join Date: May 2009
Location: Richland, WA, USA
Posts: 21017
Good Answers: 795
#1

Re: Have You Seen the StuxNet Worm Yet?

11/03/2010 9:10 PM

How many people do you have sneaking memory sticks into your plant? How does this virus get onto the memory sticks in the first place?

Inquiring minds wanna know.

__________________
In vino veritas; in cervisia carmen; in aqua E. coli.
Reply Score 1 for Good Answer
Guru

Join Date: Sep 2007
Location: Defreestville, NY
Posts: 1072
Good Answers: 87
#3
In reply to #1

Re: Have You Seen the StuxNet Worm Yet?

11/04/2010 10:00 AM

The worm spreads among Windows PCs that run the Siemens WinCC PLC programming software. The PC can contract it from an infected USB memory stick or from other infected computers on the network. Any USB memory stick inserted into an infected machine becomes a carrier. So if an engineer modifies some PLC code on their infected desktop using WinCC, then saves the new PLC code to a USB stick, then goes down to the plant and uses a laptop to load the new code onto the PLC both the PLC and the laptop are now infected.

http://en.wikipedia.org/wiki/Stuxnet

__________________
Charlie don't surf.
Reply
Anonymous Poster
#2

Re: Have You Seen the StuxNet Worm Yet?

11/04/2010 2:09 AM

My Anti Vir fixed a lots of Memory sticks already, so once the pattern are established what will keep Powerplants from being save?

Reply
Power-User
Engineering Fields - Petroleum Engineering - Rig Electrician United States - Member - the Oil Patch Engineering Fields - Power Engineering - Drives & Gen's Engineering Fields - Instrumentation Engineering - Drive Control Popular Science - Cosmology -

Join Date: Jan 2010
Location: Houston off/on-shore @ Oil Patch
Posts: 223
Good Answers: 2
#4

Re: Have You Seen the StuxNet Worm Yet?

11/04/2010 10:58 AM

This is an IMPORTANT question: has anyone seen StuxNet? Which leads to the most IMPORTANT question: has anyone seen it affect anything in their operations?

Langner (http://www.langner.com/english/) has dropped off the radar after his October 19 post, can't be a part of his Open Letter to Symantec (http://www.langner.com/english/?p=249) where he accuses the Stuxnet Dossier (http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_stuxnet_dossier.pdf) of drawing dangerous misleading conclusions about Stuxnet's dangers to the world.

If Langner is right some of us should be seeing something in our PLC's and HMI's.

If Symantec is right it's all over, no PLC's affected, just a matter of cleaning your HMI's operating system.

__________________
Why do they make manhole covers round? so they won't fall in [before asking "Who is John Galt?"]
Reply
Guru

Join Date: Sep 2007
Location: Defreestville, NY
Posts: 1072
Good Answers: 87
#5
In reply to #4

Re: Have You Seen the StuxNet Worm Yet?

11/04/2010 11:20 AM

This is one of the big problems with Stuxnet, it is very good at hiding itself.

If you go to examine some of the built in code on the PLC (library) where stuxnet is known to live, stuxnet will intercept the query and report back what should be there in the hex editor, not what is actually there (the original code plus the infection). So unless you have access to an uninfected hex editor and do a checksum on the installed code it is very difficult to know whether or not the PLC is infected.

__________________
Charlie don't surf.
Reply Score 1 for Good Answer
Anonymous Poster
#6
In reply to #5

Re: Have You Seen the StuxNet Worm Yet?

11/05/2010 12:13 PM

Yes, it's hard to imagine that anyone, no matter what their agenda is, would want to hurt a lot of innocent people. But then, that's the nature of anger and violence.

Reply
Reply to Blog Entry 6 comments

"Almost" Good Answers:

Check out these comments that don't yet have enough votes to be "official" good answers and, if you agree with them, vote them!
Copy to Clipboard

Users who posted comments:

Anonymous Poster (2); kwcharlie (1); stevem (2); Tornado (1)

Previous in Blog: Did Your Power System Survive the Hurricanes?   Next in Blog: Extending the Life of Nuclear Reactors

Advertisement