hertz
Posts: 1315
Joined: 8/7/2010 Status: offline
|
quote:
ORIGINAL: DomKen Writing this virus required 1) Finding an otherwise unknown vulnerability in the way USB devices work 2) Detailed knowldege of siemens industrial control products 3) Detailed knowledge of the precise industrial process to be attacked 4) Sophisticated encryption techniques That's a very broad and unlikely skill set for a single individual. The size and sophistication of the software functionally rules out it being the work of a single coder. 1. Writing almost any worm or virus requires knowledge of unknown vulnerabilities in computer software and hardware. This is, often enough, how these sorts of malware programmes work. 2. Detailed knowledge of Seimens industrial control products may be important, it may not. Certainly a knowledge of their vulnerability to attack is important. And it might be useful, although not necessary, to understand the real world mechanisms the software instruction set corresponds to. At this stage, we don't know enough about what is going on to be sure of much. The experts tell us that Stuxnet looks like it is precisely targeted at a specific plant configuration. If this is the case, I wonder why it is apparently causing problems in China, India, Iran and elsewhere? I suspect the reporting is somewhat ahead of the knowledge curve. 3. Knowledge of the precise industrial process to be attacked would be helpful if this were an attack on a specific installation. Unfortunately, the facts suggest it is attacking many different systems all around the world. Evidence that it was specifically designed to go for an Iranian target is not as watertight as many suggest. 4. Knowledge of the design and deployment of 'sophisticated encryption techniques' are two a penny in hacking circles. I remember the Blaster worm. It caused chaos, and it was, for the period, easily as beautiful a piece of software design as Stuxnet is. But that was almost a decade ago. I seriously cannot see any reason, given the knowledge we have now, to assume that Stuxnet is beyond the reach of an individual or group with no state funding. I still say the Jury is out.
|