Siemens: Update on Stuxnet virus, Simatic WinCC SCADA systems

It has been more than two weeks since Siemens last received a report of an attack on customer systems by Stuxnet. From mid-July to late August, a total of 15 cases were reported to Siemens where the Stuxnet virus was detected in various plants, roughly one third of which were in Germany. Siemens is not aware of any instances where production operations have been influenced or where a plant has failed; the virus has been removed in all cases known to Siemens.

09/22/2010


Siemens Industry Inc. provided this Sept. 22, 2010, update on Stuxnet:

Siemens was notified about the malware program (Trojan) that is targeting the Siemens Simatic WinCC and PCS 7 software on July 14, 2010. On July 22 Siemens provided its customers with a tool for download, which detects and removes the virus without influencing plant operations. All of the main virus scanners are now able to detect the Trojan. On Aug. 8, Microsoft closed the security breach in the operating system, and the threat of the Trojan spreading uncontrolled through industrial environments has consequently been averted.

It has been more than two weeks since Siemens last received a report of an attack on customer systems by Stuxnet. From mid-July to late August, a total of 15 cases were reported to Siemens where the Stuxnet virus was detected in various plants, roughly one third of which were in Germany. Siemens is not aware of any instances where production operations have been influenced or where a plant has failed; the virus has been removed in all cases known to Siemens.

Siemens has isolated the virus on a test system to carry out more extensive investigations. Based on previously analyzed properties and the behavior of the virus in the software environment of a test system, this does not appear to be the random development of one hacker, but the product of a team of experts. The company suspects that this team is comprised of IT experts with corresponding engineering knowledge of industrial controls based on the virus deployment in industrial production processes.

The extent of the threat to industrial systems still posed by Stuxnet following the implementation of the security updates will, however, remain uncertain until further investigations into the Trojan and its mode of operation are complete. Siemens does not yet have any leads as to the source and origin of this malicious software, but analyses are ongoing.

Additional Information:

• Investigations in July showed that Stuxnet can recognize WinCC and Step 7 programs from Siemens and communicate with certain websites/servers. Stuxnet exploits a security gap in the Microsoft Windows operating system and infects computers via USB sticks and networks. It then specifically seeks out Siemens WinCC and PCS 7 installations. 

• The malware carries its own blocks (for example, DB890, FC1865, 1874) and tries to load them into the CPU and integrate them into the program sequence. If the above-mentioned blocks are already present, the malware does not infiltrate the user program. If the above-mentioned blocks were not present in the system and are now detected, the virus has infected the system. In this case, Siemens urgently recommends restoring the plant control system to its original state.

• Further investigations have shown that the virus can theoretically influence specific processes and operations in a very specific automation or plant configuration in addition to passing on data. This means that the malware is able, under certain boundary conditions, to influence the processing of operations in the control system. However, this has not yet been verified in tests or in practice.

•Siemens experts are working with Microsoft and the distributors of virus scan programs to analyze the likely consequences and the exact mode of operation of the virus.

•Siemens continues to remind customers of the importance of securing their IT systems and computers against virus attacks, using the latest virus scanners, such as Trend Micro, McAfee and Symantec, and installing the most recent patches from software vendors like Microsoft.

Also read from Control Engineering:

Stuxnet is a ‘Weapon’

Cyber security forensics tool for industrial control systems

Cyber security for control systems: More tips, warnings from INL

 



No comments
The Top Plant program honors outstanding manufacturing facilities in North America. View the 2013 Top Plant.
The Product of the Year program recognizes products newly released in the manufacturing industries.
The Engineering Leaders Under 40 program identifies and gives recognition to young engineers who...
The true cost of lubrication: Three keys to consider when evaluating oils; Plant Engineering Lubrication Guide; 11 ways to protect bearing assets; Is lubrication part of your KPIs?
Contract maintenance: 5 ways to keep things humming while keeping an eye on costs; Pneumatic systems; Energy monitoring; The sixth 'S' is safety
Transport your data: Supply chain information critical to operational excellence; High-voltage faults; Portable cooling; Safety automation isn't automatic
Case Study Database

Case Study Database

Get more exposure for your case study by uploading it to the Plant Engineering case study database, where end-users can identify relevant solutions and explore what the experts are doing to effectively implement a variety of technology and productivity related projects.

These case studies provide examples of how knowledgeable solution providers have used technology, processes and people to create effective and successful implementations in real-world situations. Case studies can be completed by filling out a simple online form where you can outline the project title, abstract, and full story in 1500 words or less; upload photos, videos and a logo.

Click here to visit the Case Study Database and upload your case study.

Maintaining low data center PUE; Using eco mode in UPS systems; Commissioning electrical and power systems; Exploring dc power distribution alternatives
Synchronizing industrial Ethernet networks; Selecting protocol conversion gateways; Integrating HMIs with PLCs and PACs
Why manufacturers need to see energy in a different light: Current approaches to energy management yield quick savings, but leave plant managers searching for ways of improving on those early gains.

Annual Salary Survey

Participate in the 2013 Salary Survey

In a year when manufacturing continued to lead the economic rebound, it makes sense that plant manager bonuses rebounded. Plant Engineering’s annual Salary Survey shows both wages and bonuses rose in 2012 after a retreat the year before.

Average salary across all job titles for plant floor management rose 3.5% to $95,446, and bonus compensation jumped to $15,162, a 4.2% increase from the 2010 level and double the 2011 total, which showed a sharp drop in bonus.

2012 Salary Survey Analysis

2012 Salary Survey Results

Maintenance and reliability tips and best practices from the maintenance and reliability coaches at Allied Reliability Group.
The One Voice for Manufacturing blog reports on federal public policy issues impacting the manufacturing sector. One Voice is a joint effort by the National Tooling and Machining...
The Society for Maintenance and Reliability Professionals an organization devoted...
Join this ongoing discussion of machine guarding topics, including solutions assessments, regulatory compliance, gap analysis...
IMS Research, recently acquired by IHS Inc., is a leading independent supplier of market research and consultancy to the global electronics industry.
Maintenance is not optional in manufacturing. It’s a profit center, driving productivity and uptime while reducing overall repair costs.
The Lachance on CMMS blog is about current maintenance topics. Blogger Paul Lachance is president and chief technology officer for Smartware Group.