Stuxnet: Computer Worm Targets Iran Nuke Plant?

Sports Journalists Forum – Media, Newsroom & Reporting Talk

Help Support Sports Journalists Forum:

YankeeFan

Well-Known Member
Joined
Nov 19, 2004
Messages
55,078
Not an expert on the subject by any means, but if we (or the Israelis or the Brits) were able to target Iran's nuclear plant, it seems like a stroke of genius to me.

A complex computer worm capable of seizing control of industrial plants has affected the personal computers of staff working at Iran's first nuclear power station weeks before the facility is to go online, the official news agency reported Sunday.

The project manager at the Bushehr nuclear plant, Mahmoud Jafari, said a team is trying to remove the malware from several affected computers, though it "has not caused any damage to major systems of the plant," the IRNA news agency reported.

It was the first sign that the malicious computer code, dubbed Stuxnet, which has spread to many industries in Iran, has also affected equipment linked to the country's nuclear program, which is at the core of the dispute between Tehran and Western powers like the United States.

Experts in Germany discovered the worm in July, and it has since shown up in a number of attacks — primarily in Iran, Indonesia, India and the U.S.

The malware is capable of taking over systems that control the inner workings of industrial plants.

In a sign of the high-level concern in Iran, experts from the country's nuclear agency met last week to discuss ways of fighting the worm.

http://www.google.com/hostednews/ap/article/ALeqM5jam2yTGb8W1t53gQ6S-RbSquSmiAD9IFORD00
 
"I gave it a cold."

images
 
Great, this means we're just a few steps away from the Geek Squad going nuclear.
 
As an Amazon Associate we earn from qualifying purchases. Product prices and availability are accurate as of the date/time indicated and are subject to change.
Was it the Israeli's or did someone try to frame them:

Deep inside the computer worm that some specialists suspect is aimed at slowing Iran’s race for a nuclear weapon lies what could be a fleeting reference to the Book of Esther, the Old Testament tale in which the Jews pre-empt a Persian plot to destroy them.

That use of the word “Myrtus” — which can be read as an allusion to Esther — to name a file inside the code is one of several murky clues that have emerged as computer experts try to trace the origin and purpose of the rogue Stuxnet program, which seeks out a specific kind of command module for industrial equipment.

Not surprisingly, the Israelis are not saying whether Stuxnet has any connection to the secretive cyberwar unit it has built inside Israel’s intelligence service. Nor is the Obama administration, which while talking about cyberdefenses has also rapidly ramped up a broad covert program, inherited from the Bush administration, to undermine Iran’s nuclear program. In interviews in several countries, experts in both cyberwar and nuclear enrichment technology say the Stuxnet mystery may never be solved.

There are many competing explanations for myrtus, which could simply signify myrtle, a plant important to many cultures in the region. But some security experts see the reference as a signature allusion to Esther, a clear warning in a mounting technological and psychological battle as Israel and its allies try to breach Tehran’s most heavily guarded project. Others doubt the Israelis were involved and say the word could have been inserted as deliberate misinformation, to implicate Israel.

“The Iranians are already paranoid about the fact that some of their scientists have defected and several of their secret nuclear sites have been revealed,” one former intelligence official who still works on Iran issues said recently. “Whatever the origin and purpose of Stuxnet, it ramps up the psychological pressure.”

So a calling card in the code could be part of a mind game, or sloppiness or whimsy from the coders.

http://www.nytimes.com/2010/09/30/world/middleeast/30worm.html?hp=&pagewanted=all
 
Some more information on what's a pretty cool story:

Experts dissecting the computer worm suspected of being aimed at Iran’s nuclear program have determined that it was precisely calibrated in a way that could send nuclear centrifuges wildly out of control.

...

The new forensic work narrows the range of targets and deciphers the worm’s plan of attack. Computer analysts say Stuxnet does its damage by making quick changes in the rotational speed of motors, shifting them rapidly up and down.

Changing the speed “sabotages the normal operation of the industrial control process,” Eric Chien, a researcher at the computer security company Symantec, wrote in a blog post.

Those fluctuations, nuclear analysts said in response to the report, are a recipe for disaster among the thousands of centrifuges spinning in Iran to enrich uranium, which can fuel reactors or bombs. Rapid changes can cause them to blow apart. Reports issued by international inspectors reveal that Iran has experienced many problems keeping its centrifuges running, with hundreds removed from active service since summer 2009.

...

But a study released Friday by Mr. Chien, Nicolas Falliere and Liam O. Murchu at Symantec, concluded that the program’s real target was to take over frequency converters, a type of power supply that changes its output frequency to control the speed of a motor.

The worm’s code was found to attack converters made by two companies, Fararo Paya in Iran and Vacon in Finland. A separate study conducted by the Department of Homeland Security confirmed that finding, a senior government official said in an interview on Thursday.

Then, on Wednesday, Mr. Albright and a colleague, Andrea Stricker, released a report saying that when the worm ramped up the frequency of the electrical current supplying the centrifuges, they would spin faster and faster. The worm eventually makes the current hit 1,410 Hertz, or cycles per second — just enough, they reported, to send the centrifuges flying apart.

In a spooky flourish, Mr. Albright said in the interview, the worm ends the attack with a command to restore the current to the perfect operating frequency for the centrifuges — which, by that time, would presumably be destroyed.

“It’s striking how close it is to the standard value,” he said.

...

Last month, researchers at Symantec also speculated that a string of numbers found in the program — 19790509 — while seeming random, might actually be significant. They speculated that it might refer to May 9, 1979, the day that Jewish-Iranian businessman Habib Elghanian was executed in Iran after being convicted of spying for Israel.

http://www.nytimes.com/2010/11/19/world/middleeast/19stuxnet.html?sq=stuxnet&st=cse&scp=2&pagewanted=all
 
The New York Times on Stuxnet:

The Dimona complex in the Negev desert is famous as the heavily guarded heart of Israel’s never-acknowledged nuclear arms program, where neat rows of factories make atomic fuel for the arsenal.

Over the past two years, according to intelligence and military experts familiar with its operations, Dimona has taken on a new, equally secret role — as a critical testing ground in a joint American and Israeli effort to undermine Iran’s efforts to make a bomb of its own.

Behind Dimona’s barbed wire, the experts say, Israel has spun nuclear centrifuges virtually identical to Iran’s at Natanz, where Iranian scientists are struggling to enrich uranium. They say Dimona tested the effectiveness of the Stuxnet computer worm, a destructive program that appears to have wiped out roughly a fifth of Iran’s nuclear centrifuges and helped delay, though not destroy, Tehran’s ability to make its first nuclear arms.

“To check out the worm, you have to know the machines,” said an American expert on nuclear intelligence. “The reason the worm has been effective is that the Israelis tried it out.”

Though American and Israeli officials refuse to talk publicly about what goes on at Dimona, the operations there, as well as related efforts in the United States, are among the newest and strongest clues suggesting that the virus was designed as an American-Israeli project to sabotage the Iranian program.

http://www.nytimes.com/2011/01/16/world/middleeast/16stuxnet.html?pagewanted=all
 
I love it, but I wish both the Americans and Israelis would keep their mouths completely shut about it instead of the "wink-wink, nod-nod" we're not doing it, but we are doing it routine.

Who do they think they're fooling?
 
Bubbler said:
I love it, but I wish both the Americans and Israelis would keep their mouths completely shut about it instead of the "wink-wink, nod-nod" we're not doing it, but we are doing it routine.

Who do they think they're fooling?
The perception that you can do something is almost as important as the ability to actually do it. Maybe we want to leave this impression, not only with Iran but the remaining point on the axis of evil, North Korea, as well as Venezuela, China and Russia.
 
heyabbott said:
Bubbler said:
I love it, but I wish both the Americans and Israelis would keep their mouths completely shut about it instead of the "wink-wink, nod-nod" we're not doing it, but we are doing it routine.

Who do they think they're fooling?
The perception that you can do something is almost as important as the ability to actually do it. Maybe we want to leave this impression, not only with Iran but the remaining point on the axis of evil, North Korea, as well as Venezuela, China and Russia.

I don't know about talking about it off the record and then wink winking, as Bubbler, put it. But one of the things I always admired about the Israelis (and there are so many things I detest), is that they have the best secret/covert/sabotage operations in the world, and then their way of handling the aftermath is to neither confirm or deny, or even talk about it. Just do the wink wink, nod nod. So there is no doubt they were the ones, but its just untraceable and so much about their means is left in a shadowy abyss. It's why I was so surprised when the Mosad screwed up that assassination in Dubai and left their finger prints all over it (and video of the perps). It was so uncharacteristic of them, and made me wonder if they had lost a bit off their fastball. If they were able to use intelligence to get enough info about the Iranian processing plants, then reproduce them, and then design and test computer worms that could render the centrifuges bad, they definitely recapture some of their aura (which to me extends only about to the mossad and its abilities; not to a lot of other dumbass things they do to incite even more discontent from the Palestinians and ensure the hostilities continue).
 
To me most interesting part of NY Times story was that it was George Bush who authorized development.
 
Stuxnet hits Bushehr again. Russia warns of nuclear explosion DEBKAfile Exclusive Report Feb 1, 2011 (AEST)
Moscow sources reveal that Iran's hand on the switch was held back at the last minute by Sergei Kiriyenko, chief of Rosatom (the Russian national nuclear energy commission which oversaw the reactor's construction. He came hurrying over to warn Tehran that Stuxnet was back and switching the reactor on could trigger a calamitous nuclear explosion that could cost a million Iranian lives and devastate neighboring populations. He complained to President Mahmoud Ahmadinejad that the Iranian nuclear and engineering staff were ignoring the presence of the malworm and must be stopped.

Kiriyenko told the Iranian president that the Russian engineers employed at the reactor notified Moscow that Stuxnet was again attacking the Bushehr systems after apparently taking a rest from its first onslaught last June. There was no telling which systems had been infected, because a key feature of the virus is that the systems' screens show they are working normally when in fact they have been fatally disarmed. Activating the reactor in these circumstances could cause an explosion far more powerful than the disaster at the Russian reactor at Chernobyl, Ukraine in April 1986, which released 400 times more radioactive material than the atomic bombing of Hiroshima.
The impression the Rosatom chief had gained from his staff at Bushehr was that the Iranian teams had been ordered to activate the reactor at any price to prove that the Islamic Republic had beaten Stuxnet. This concern overrode security. The consequences of ignoring this fearful hazard, said Kiriyenko, were unthinkable and would destroy the revolutionary Islamic regime in Tehran in their wake.
Kirienko began worrying when he heard the Iranian nuclear commission's spokesman Hamid Khadem-Qaemi claim on Jan. 17 that Bushehr had not been affected by Stuxnet.
Our Iranian sources report that, after seeing the Russian official off, Ahmadinejad ordered the reactor to stay shut down.

This week, Salehi, who is also Iran's foreign minister, hinted at the cause of the delay when he said: "The reactor has started its operation and the next step is to reach critical phase which will happen by the end of Bahman (February 20) in presence of Russians. We have said before that due to some tests, we may have to face delays but these delays are around a week or two." He added, "We aim at launching Bushehr nuclear reactor safely not to merely launch it."

In Jerusalem, Maj-Gen. Aviv Kohavi, the new head of IDF military intelligence - MI, who appeared before the Knesset Security and Foreign Affairs Committee for his first briefing on Jan. 25 said Bushehr could be quickly converted from producing electricity for civilian use to a military reactor and incorporated into Iran's weapons program.

The next day, Jan. 26, Moscow took the unusual step of demanding a NATO investigation into last year's computer attack on the Russian-built nuclear reactor in Iran.

Dmitry Rogozin, Russia's ambassador to the North Atlantic Treaty Organization, said: T"his virus, which is very toxic, very dangerous, could have very serious implications," he said, describing the virus's impact as being like "explosive mines".

"These 'mines' could lead to a new Chernobyl," he said.
http://www.debka.com/article/20611/
 
Stuxnet returns to bedevil Iran's nuclear systems
Exclusive Report July 20, 2011, 4:35 PM (GMT+02:00) Tags: Stuxnet Iran nuclear Intelligence Natanz Fordo enrichment site IAEA The Stuxnet malworm - at it againdebkafile's intelligence sources report that the Stuxnet malworm which played havoc with Iran's nuclear program for eleven months was not purged after all. Tehran never did overcome the disruptions caused by Stuxnet or restore its centrifuges to smooth and normal operation as was claimed. Indeed, Iran finally resorted to the only sure-fire cure, scrapping all the tainted machines and replacing them with new ones.
Iran provided confirmation of this Tuesday, July 19 in an announcement that improved and faster centrifuge models were being installed.
Iran would clearly not have undertaken the major and costly project of replacing all its 5,000-6,000 centrifuges with new ones if they were indeed functioning smoothly. The announcement was made by the Iranian Foreign Ministry spokesman at a press briefing although no one present had raised the nuclear issue. He said: "The installation of new centrifuges with better quality and speed is ongoing… this is another confirmation of the Islamic republic's successful strides in its nuclear activities."

Britain and France immediately condemned the announcement. It proved, official spokesmen commented, that Iran plans to triple the amount of uranium it enriches in contravention of six UN Security Council Resolutions and defiance of ten International Atomic Energy Agency decisions in Vienna. The announcement also "confirmed suspicions that the Iranian nuclear program had no credible civilian application."

In recent months, Iran has taken advantage of the West's preoccupation with the Arab revolt to quietly forge ahead unnoticed with its weapons program. So if everything was moving smoothly forward why did Tehran suddenly decide to raise the touchy subject again?
Indeed, by doing so, the official spokesman placed in doubt the three major strides Iran was generally presumed to have made while the West was otherwise engaged:

1. The dramatic speeding-up of uranium enrichment and expansion of the quantities produced.
The West has no credible information, whether from intelligence, research, or nuclear watchdog inspections, as to how much enriched uranium Iran has produced and how much it has in stock.
For the past six months, Iran managed to keep the full scope of its enrichment activities hidden from IAEA inspections. Although inspectors were allowed to visit Iran's acknowledged enrichment facility at Natanz, they were unable to gauge how many active centrifuges were present and how many removed to unknown site or sites. The sophisticated cameras supposed to monitor the Natanz facility were unable to record all of Iran's enrichment activities because key production sites were moved out of range.

2. The glitches bedeviling their centrifuge machines were overcome and all 5,000 were spinning away without interruption. After expunging the Stuxnet virus which first struck in June 2010, all their nuclear program's control systems and installations, including Natanz and the Russian-built Bushehr reactor, were functioning perfectly. It took Iranian and Russian computer and cyber-terrorism experts a year to cleanse the system. This gave security agencies their first indicator of the time it takes to overcome a large-scale, sophisticated cyber attack.
On July 5, Lt. Gen. Aviv Kochavi, head of Israeli military intelligence, said that Iran is currently running 5,000 active centrifuges and aiming for 8,000. He made no reference to their replacement with newer and faster machines - which the Iranian spokesman disclosed suddenly last Tuesday.
3. The Iranians are engaged in the relocation of the centrifuges spinning 20-percent grade enriched uranium to a new underground facility at Fordo, 100 kilometers away near Qom. Tehran has rejected every European and IAEA demand to install monitoring and inspection equipment at the new facility which is therefore functioning without international oversight.
Those presumptions are now largely suspect.

Western intelligence sources tell debkafile that until recently, the Iranians believed they had a clear road for enriching large quantities of high-grade uranium after solving technical obstructions and beating back the cyber attack. But then, they were stunned to discover that the Stuxnet virus, far from being eradicated, was back with a vengeance and on the offensive against their centrifuges. Iran was forced to adopt a course it had avoided last year, namely to destroy the entire plant of approximately 5,000 working centrifuges and replace them all with new machines.
This decision led to the foreign ministry spokesman's one-sentence announcement. He delivered it to pre-empt Iran's enemies from picking up on the installation of the new centrifuges
http://www.debka.com/article/21133/
 

Latest posts

Back
Top