Friday, January 18, 2013

Malicious virus shuttered US power plant: DHS


A computer virus attacked a turbine control system at a US power company last fall when a technician unknowingly inserted an infected USB computer drive into the network, keeping a plant off line for three weeks, according to a report posted on a US government website.


The Department of Homeland Security report did not identify the plant but said criminal software, which is used to conduct financial crimes such as identity theft, was behind the incident.


It was introduced by an employee of a third-party contractor that does business with the utility, according to the agency.


DHS reported the incident, which occurred in October, along with a second involving a more sophisticated virus, on its website as cyber experts gather at a high-profile security conference in Miami known as S4 to review emerging threats against power plants, water utilities and other parts of the critical infrastructure.


In addition to not identifying the plants, a DHS spokesman declined to say where they are located.


Interest in the area has surged since 2010 when the Stuxnet computer virus was used to attack Iran's nuclear program. Although the United States and Israel were widely believed to be behind Stuxnet, experts believe that hackers may be copying the technology to develop their own viruses.


Justin W. Clarke, a security researcher with a firm known as Cylance that helps protect utilities against cyber attacks, noted that experts believe Stuxnet was delivered to its target in Iran via a USB drive. Attackers use that technique to place malicious software on computer systems that are "air gapped," or cut off from the public Internet.

"This is yet another stark reminder that even if a true 'air gap' is in place on a control network, there are still ways that malicious targeted or unintentional random infection can occur," he said.

AGING SYSTEMS


Many critical infrastructure control systems run on Windows XP and Windows 2000, operating systems that were designed more than a decade ago. They have "auto run" features enabled by default, which makes them an easy target for infection because malicious software loads as soon as a USB is plugged into the system unless operators change that setting, Clarke said.

The Department of Homeland Security's Industrial Control Systems Cyber Emergence Response Team (ICS-CERT), which helps protect critical U.S. infrastructure, described the incident in a quarterly newsletter that was accessed via its website on Wednesday.

The report from ICS-CERT described a second incident in which it said it had recently sent technicians to clean up computers infected by common as well as "sophisticated" viruses on workstations that were critical to the operations of a power generation facility.

No comments:

Post a Comment

Categories

3G 4G Aakash Acer Aircel Airtel Amazon Android OS Apple Laptop Apple News Applications Ashok Leyland Aston Martin Cars Asus Asus Laptop Audi Audi Car Bajaj Bikes Bing Bitcoin Black Berry BMW Bose Browser BSNL Camara Camera Canon Car Chevrolet Computer Cyber Crimes Data Card Datsun Dell Dot DRDO Dropbox Ducati Ericsson Facebook News Ferrari Fiat Cars Ford Cars Four Wheeler Fujifilm G-mail Gadget Game Gameloft Gatget Gionee GM Gmail Google News Google Tablet Google Watch Hangouts Harley-Davidson HCL HCL Laptop HCL Tablet Hero Bikes Honda Bikes Honda Car HP HP Laptop HP Smartphone HP Tablet HTC Mobile Huawei Hyundai Cars iBall IBM Idea Indian IT Information Information Infosys Inmobi Innovations Intel Internet Intex Mobiles Ipad iPhone Isuzu Motors IT Information Jaguar Cars Jeep Joint Venture Karbonn Mobile Karbonn Tab Kawasaki Bikes Lamborghini Car land rover Laptop Lava Lava Phone Lava Tablet Law Suit Lemon Mobile Lenovo Lenovo Laptop Lenovo Mobile Lenovo Tablet LG LG Mobile LG Televisions Linked in info Mahindra Mahindra Car Mahindra Tractor Malware Maruti Suzuki Maxx Mobile McAfee Mercedes Benz Micromax Mobile Micromax News Microsoft News Microsoft Websites Mitsubishi Mobile Mobile Networks Moschips Motorola Motorola Watch MTS New Technology Nexus NIIT Nikon Camera Nissan Nokia Mobile Oracle OS Other Tablet Panasonic Panasonic Mmobile Passport Phablet Philips Piaggio Play Station Quadricycle Range Rover Reliance Renault Renault Scala Robot Rolls Rolls Royce Salora Mobile Samsung Samsung Mobile Samsung News Samsung Tablet Sandisk Scooter Sistema Skoda Car Smart Watch Smartphone smoking Snapdeal Software Sony Sony Mobile spice SUV Suzuki T-Mobile Tablet Tata Docomo Tata Motors Toyota car TRAI TVS Twitter Two Wheeler Unilever Verizon Vespa Videocon Viper Vizio Vodafone Volkswagen Volvo Website Wechat Whatsapp Wickedleak Inc Wifi Wikipedia Windows 8 Windows News Windows Phone Wipro Xbox Xolo Mobile Xolo Tablet Xperia Yahoo Yahoo News Yamaha Bikes Zen Mobile ZTE Mobiles Zync Mobiles