Zero days in stuxnet

16
ZERO DAYS IN STUXNET

Transcript of Zero days in stuxnet

Page 1: Zero days in stuxnet

ZERO DAYS IN STUXNET

Page 2: Zero days in stuxnet

INTRODUCTION OF STUXNET

• SURFACED: in Belarus, at WILDERS SECURITY FORUMS on 17 JUNE 2017,BY ERGEY ULASEN.

• SAID: “VIRUS INFECTS O.S. IN UNUSUAL WAY THROUGH VULNERABILITY. VERY DANGEROUS.”

Page 3: Zero days in stuxnet

INTRODUCTION OF STUXNET

• SCENARIO:

Page 4: Zero days in stuxnet

AGENCIES INVOLVED IN UNEARTHING THE TRUTH

1. ERIC CHAN FROM SYMENTEC.2. LIAM O’MURCHU FROM SYMENTEC.3. EUGENE KASPERSKY

Page 5: Zero days in stuxnet

MECHANISM

• Spread:

• Zero days:

• Isolated network:

• Version: 0.3 TO 1.1

Page 6: Zero days in stuxnet

MECHANISM

• DIGITAL SIGNATURE THEFT OF MICROSOFT TO IMPLEMENT ZERO DAYS.

Page 7: Zero days in stuxnet

MECHANISM

• PROGRAMMABLE LOGIC CONTROLS(PLCs) ARE IN CROSS HAIR.

• USE MAGIC NUMBERS.

Page 8: Zero days in stuxnet

MECHANISM

• PAYLOAD IS DESIGNED TO MANUPULATE FREQUENCY IN STEALTHY AND SMART MANNNER.

Page 9: Zero days in stuxnet

PAYLOAD

Page 10: Zero days in stuxnet

WHY ZERO DAYS WITHIN STUXNET?

• CAUSE IT WAS MOST AGGERESSIVE AND MORE COMMUNICABLE WITH 4 ZERODAYs IN IT.

Page 11: Zero days in stuxnet

MAJOR SPECULATIONS

• INVOLVEMENT OF NATION STATE. CAUSE IT HAVE KILL DATE.

WHY?

• SUCH COMPLEX AND MARBLE FEET “ONLY FOR SPECIFIC PURPOSE”.

• RESOURCE NEEDED TO MAKE BEYOND REACH OF NORMAL PEOPLE.

Page 12: Zero days in stuxnet

MAJOR SPECULATIONS

• FIRST 5 INFECTIONS TRACED, ALL 5 IN NATANG NUCLEAR FACILITY OF IRAN.

Page 13: Zero days in stuxnet

THREAT FROM NEW REALM: critical infrastructure

Page 14: Zero days in stuxnet

STUXNET THAT MADE NOISE!• VERSION 1.1

• HAD 4 ZERO DAYS.

• BLEW THE COVER.

• WAS CAUGHT BY ANTIVIRUS COMPANIES.

• Still in AIR.

Page 15: Zero days in stuxnet

CONCLUSION

• REQUIRES A CYBER WEAPON TREATY, JUST LIKE WE HAVE FOR NUCLEAR,BIOLOGICAL,CHEMICAL WEAPONS.

• HIDE SECRECY, BUT DON’T HIDE BEHIND SECRECY.

Page 16: Zero days in stuxnet

REFERANCE:-

• Mark Clayton. Stuxnet cyberweapon looks to be one on a production line, researcherssay. Technical report, World WideWeb,http://www.csmonitor.com/USA/2012/0106Stuxnet-cyberweapon-looks-to-be-%one-on-a-production-line-researchers-say,January 2012.

• Ralph Langner et. al. The blog of langner.com. Technical report, WorldWideWeb,http://www.langner.com/en/blog/.

• Nuclear Threat Initiative. Iran’s profile. Technical report, WorldWideWeb,http://www.nti.org/countryprofiles/iran/nuclear/, March 2012.