0

Posting Changes Effective 01 September 2010

Effective Wednesday, 01 September 2010, my blog posts will only appear at Forbes Firewall. In addition, GreyLogic, Inc. will be shuttered so that I may focus full-time on launching Taia Global, Inc. This will have no bearing on services provided to GreyLogic clients, which will be transferred to the new company and continue uninterrupted. If you’re a subscriber to this blog, please subscribe to my articles at Forbes Firewall instead.

0

Zero Day Attack Targets SCADA Systems

On June 17, 2010, researchers at VirusBlokAda, an anti-virus software company in Belarus, published a report (.pdf) on a trojan which was specifically designed to target process conrol server software (commonly referred to as SCADA software) used in critical infrastructure. Further work by Frank Boldewin uncovered a snippet of code (figure 2) which specifically calls the Siemens WinCC SCADA system (figure 1).

Figure 1: Siemens software targeted in this attack

Figure 2: WinCC Code Snippet

This malware is delivered via a USB flash drive which exploits a newly discovered vulnerability (known as a Zero day or 0day) affecting all versions of Windows.
NOTE: If your operating system is Windows XP Service Pack 2 or older, Microsoft no longer supports it and a patch will not be issued.
A technical description of the malware can be found at the following sources:
US CERT: http://www.kb.cert.org/vuls/id/940193
VirusBlokAda: http://anti-virus.by/en/tempo.shtml
F-Secure: http://www.f-secure.com/weblog/archives/00001987.html
—–
This is an abstract of this week’s IntelFusion FLASH Traffic weekly brief. The full article includes the following data:
  • Global coverage broken out by country
  • Seimens business dealings with RF and PRC
  • GreyLogic’s threat analysis identifies 3 key characteristics of this APT attack

Subscription information is available by request.

Unlike the United States, the European Union and other Western nations, Russian and Chinese military writers generally do not use the term “Cyber Warfare”, preferring “Information Warfare” or “Informatized Warfare” instead. This is a significant difference; understanding it may better inform those who are still struggling to fit the round peg of Cyber Warfare into the square hole of the Western way of war.

As our nation honors the many sacrifices made by those who have died in service to our country, it occurred to me that there is one trans-formative principal understood by combat veterans that could re-vitalize our moribund Congress and White House.