HomeSecurityRalph Langner: Cracking Stuxnet the cyber weapon of the 21st century

Ralph Langner: Cracking Stuxnet the cyber weapon of the 21st century

When it was first discovered in 2010, the Stuxnet worm was a puzzle. Beyond its sophistication, another, more troubling mystery emerged: its purpose.

Ralph Langner
Stuxnet Ralph Langner

Ralph Langner and his team helped crack the Stuxnet code, revealing its ultimate goal. In a fascinating look inside cybercrime, he explains and guesses (and apparently does so quite correctly) the origins of Stuxnet.
The talk was presented at TED

Watch the video, below there are also translated subtitles.

The idea behind the Stuxnet worm is basically very simple. We don't want Iran to get the bomb. Their main nuclear weapons development facility is the uranium enrichment facility at Natanz. The gray boxes that you see are real-time control systems. Now, if we can get access to those systems that control speeds and valves, we can really cause a lot of problems in the centrifuge. The gray boxes don't run Windows - they're a completely different technology. But if we can get a good Windows virus onto a laptop that a maintenance engineer is using to set up that gray box, then something happens. That's the plan behind Stuxnet.

1:08 So we start with a Windows dropper. The payload (Stuxnet) is injected into the gray box, it damages the centrifuge, and the Iranian nuclear program is delayed — mission accomplished. Easy, huh? I want to tell you how we discovered this. When we started our research on Stuxnet, we had no idea what it was doing. All we knew was that the very complex part of Windows, the dropper part, used multiple vulnerabilities to do a zero-day attack. And it seemed to be trying to do something with these gray boxes, the real-time control systems. So that got our attention, and we started a lab program, where we infected our network with Stuxnet and started monitoring it. And then some really strange things happened. Stuxnet behaved like a lab mouse that didn't like our cheese — it smelled it, but it didn't want to eat it. I couldn't figure it out. And after we experimented with different flavors of cheese, I realized that it was doing a targeted attack. It's completely targeted. The "dropper" actively lurks in the gray box if a specific setting is found, even if the program it's trying to infect is running on the target itself. If not, Stuxnet does nothing.

2:34 This really piqued my curiosity, and we started working on it almost around the clock, because, I thought, we don't know what the target is. It could be, for example, a power plant in the United States or a chemical plant in Germany. So it would be better to find out who the target is soon. So we extracted and decoded the attack code, and we found that it's structured into two digital bombs -- a smaller one and a larger one. We also saw that they were professionally designed by people who obviously had inside information. They knew all the data that they had to attack. They probably even knew the operator's shoe size. So they know everything.

3:19 And if you've heard that the Stuxnet dropper is complex and high-tech, let me just tell you this: its payload is rocket physics. It's far superior to anything we've ever seen. Here's a sample of the actual code. We're talking about about 15,000 lines of code. It looks a lot like old-style assembly language code. And I want to tell you how we were able to understand this code. So what we looked for was all the system call functions, because we know what they do.

3:53 And then we were looking for timers and data structures and trying to relate them to real world, potentially real targets around the world. So we need target theories that we can prove or not. To develop target theories, we keep in mind that this is definitely a particularly serious sabotage, that it has to be a high-priority target, and it's very likely to be in Iran, because that's where most of the contaminations have been reported. There aren't thousands of targets in that area. Basically, we end up with the Bushehr nuclear power plant and the Nasrash fuel enrichment plant.

4:31 So I said to my assistant, "I want a list of all the power plant and centrifuge experts in our database." And I called them up and asked for their input in an attempt to combine their expertise with what we found in the code and the data. And that worked pretty well. So we were able to correlate the little digital bomb with the control of the rotor. The rotor is the moving part inside the centrifuge, the black thing that you see. And if you can manipulate the speed of the rotor, you can actually break it and even cause the centrifuge to explode. What we also saw was that the attack was intended to be done slowly and secretly -- obviously an effort that would drive the maintenance engineers crazy, because they wouldn't be able to figure out what was going on quickly.

5:20 The big digital bomb -- we got lucky on this by looking very closely at the data and the structures of it. So, for example, the number 164 really stands out in the code -- you can't miss it. I started looking into the scientific literature on how these centrifuges are built at Natanz, and I found that they're structured in what they call a stack array, and each stack has 164 centrifuges. So that made sense, we had a match.

5:49 And it got even better. These centrifuges in Iran are divided into 15, as they call them, stages. And guess what we found in the attack code? An almost identical structure. So again, that was a very good match. And that gave us a lot of confidence in what we were looking for. Now, don't get me wrong, it doesn't work that way. These results were obtained after many weeks of really hard work. And often we would hit a dead end and have to start over.

6:21 Anyway, we found that both digital bombs were actually targeting a single target, but from different approaches. The small bomb takes up one stack, and it increases or decreases the speed of rotation of the rotors, and the large bomb communicates with six stacks and controls the valves. So we're pretty confident that we've actually identified the target. It's Natanz and only Natanz. So we don't have to worry about other targets being hit by Stuxnet.

6:54 Here are some really interesting things that we saw, that really made me jump out of my seat. Down there is the gray box, and above you see the centrifuges. Now, what it does is it monitors the input values ​​from the sensors -- for example, from the pressure sensors and the vibration sensors -- and it provides reliable code, which runs even during the attack, with fake input data. And actually, these fake inputs are actually pre-recorded by Stuxnet. So it's like in Hollywood movies, where during the robbery the surveillance camera is fed with pre-recorded video. Pretty cool, huh?

7:35 The idea here is obviously not just to fool the control center operators. It's actually much more dangerous and aggressive. The idea is to bypass a secure digital system. We need digital safety systems where the human operator can't react fast enough. So for example, in a power plant, when the huge steam turbine gets too fast, the relief valves have to open within milliseconds. Obviously, that can't be done by a human operator. This is where we need digital safety systems. And when those are compromised, then a lot of bad things can happen. The plant can explode. And neither the operators nor the safety system will understand anything. This is scary.

8:20 But it gets even worse. And what I'm going to say is very important. Think about this: The attack is generic. It doesn't do anything specific to centrifuges, to uranium enrichment. So it could work, for example, in a power plant or in an automobile factory. It's very generic. And you don't have to, as an attacker, you don't have to inject the payload via a USB storage device, like we saw in the case of Stuxnet. You could also use conventional worm technology to spread it. Just spreading it as widely as possible. And if you do that, you end up with a cyberweapon of mass destruction. That's the consequence that we have to deal with. So unfortunately the largest number of targets for such attacks are not in the Middle East. They are in the US, Europe and Japan. So all the green areas are potential targets. We must face the consequences and it would be good to prepare now.

9:41 Thank you.

9:43 (Applause)

9:49 Chris Anderson: I have a question. Ralph, it's been widely reported that people believe that Mossad is the main entity behind this. Is that your view?

10:02 Ralph Langner: So, you definitely want to hear that? Yes. Okay. My point is that Mossad is involved in Stuxnet, but the leading force is not Israel. The driving force behind it is the cyber superpower. That's only one and it's the United States — fortunately, fortunately. Because otherwise, our problems would be even bigger.

10:28 Chris Anderson: Thanks for scaring us. Thanks Ralph.

10:32 (Applause)

 

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS