English   Deutsch

Martin Kuppinger: Duqu follows Stuxnet - the next attack on the industry

Duqu follows Stuxnet - the next attack on the industry
Zeroing in on new targets
by Martin Kuppinger
mk@kuppingercole.com

It was the special characteristic of Stuxnet that the attack did not occur at the level of popular operating systems. Stuxnet targeted the control systems of industrial plants. The alleged target was the control technology of Iran's nuclear power plants. They are used for instance to control the speed of motors in many industrial plants.
According to the available information the Siemens Simatic S - an essential component for frequency conversion - was affected in particular.  They are used for example to control the speed of motors and many industrial plants.

Both the authors of Stuxnet and their sponsors have not been uncovered, nor has been their actual intention.  At least to the general public it remained unknown. After a closer look at the way the Stuxnet attacks had been carried out, it however becomes rather clear, that that they can be considered as something which is known as an APT (Advanced Persistent Threat).

Such attacks are carried out selectively and over a longer period using various attacking techniques. To smuggle Stuxnet into the systems alone, the organization in the background had to exploite vulnerabilities in other systems.

The recently discovered Duque is a new Trojan with some worm-functionality. Its relationship to Stuxnet is evident as parts of the Stuxnet code are used. Duque is classified as APT too. It can safely be assumed that the attacker behind Duque has to be looked for among governmental agencies.

Unlike Stuxnet Duque seems to be only the precursor for the real attack. Its job was to gather information which it has sent to a server in India. This server has since been taken down. Duque also had a limited life time. The goal of Duque seems to be to gather information for a new wave of attacks.

It becomes clear that the risks in IT have reached a new level. It's no longer just about access to data. It is about the intrusion into industrial plants like power generation facilities or others to takeover control.

Stuxnet was reportedly transported via infected USB drives. Increased networking also opens up new, more direct routes. IT security concepts have to deal with all systems and all communication channels – not in all cases it appears useful to link systems via networks.

Some kind of healthy suspicion is therefore appropriate.

Moreover it is important to note that even the digital certificates can no longer be trusted to the same extent as before. The attacks on DigiNotar and probably more CAs (Certificate Authorities, issuers of digital certificates which are used for example for SSL or for code-security) as well as the attacks via Stuxnet (where stolen certificates were used) indicate that we need to deal with this issue more seriously.

This includes the need for a more effective protection of private keys and of the use of digital certificates, in order to enable a faster reaction. However, before you begin implementing individual measures, you need to know what objects actually have to be protected and what the risks are.

Created: 15.11.11, modified: 18.11.11

top
KuppingerCole Select
Register now for KuppingerCole Select and get your free 30-day access to a great selection of KuppingerCole research materials and to live trainings.
Register now
Research
KuppingerCole CIO GPS
The KuppingerCole CIO GPS shows the nine areas CIOs should focus on for IT Spend Optimization, Business IT/Alignment, and Strategic Procurement, when looking at GRC (Governance, Risk Management, Compliance) and Information Security. GPS stands for Governance, Privacy and Data Protection, and Security.
KuppingerCole BII: The Business Impact Indicator
The KuppingerCole BII is a Business Impact Indicator for Information Technology. It shows the business value a particular technology or initiative can deliver, in a single and clearly laid out graphic. It complements other KuppingerCole research methodology that shows which technologies are best for achieving the targets in IT Spend Optimization, Business/IT Alignment, and Strategic Procurement.
Services
KuppingerCole Analyst Services
In the networked economy of the 21st century, digital identities play a key role in establishing trust, achieving security, lowering costs and making business processes more efficient. Things like Identity and Access Management (IAM) or...
KuppingerCole Vendor Services
The market for Identity and Access Management (IAM), governance, risk management, and compliance (GRC) and cloud computing is expanding by leaps and bounds. In fact, no other segment of the IT market can boast such dynamic growth rates. At the...
KuppingerCole Briefings
KuppingerCole welcomes the opportunity to hear from IT companies when they launch a new product or service or have other interesting progress to announce. Please fill in the request form , and we will contact you shortly. 
Links
 KuppingerCole News

 KuppingerCole on Facebook

 KuppingerCole on Twitter

 KuppingerCole on Google+

 KuppingerCole at LinkedIn

 Our group at LinkedIn

 Our group at Xing

 GenericIAM
Imprint Terms and conditions Privacy policy
© 2003-2013 KuppingerCole