About Me

I'm John Huntington, author of Control Systems for Live Entertainment, the first book on show control and entertainment control systems. This site covers entertainment, technology, severe weather, photography and combinations of all of those things.

Search The Blog
Contact Me
Blog Feed/Digg/Technorati
This area does not yet contain any content.
Twitter
« World Maker Faire NYC | Main | The Mattituck-Shoreham Biathalon »
Thursday
Sep232010

Stuxnet Worm Targets Siemens Industrial Control Systems

In control systems (and entertainment control systems especially), we've long benefited from a security standpoint from being a small, relatively obscure field. If you want to write a virus or malware, you wouldn't likely get much of a result if you targeted show systems. And if you really were that good of a hacker and interested in shows, you'd probably already be hacking for an audience (the name of a talk I gave at The Next Hope hacker conference over the summer--audio and slides posted here).

Listening to the podcast from last night's Off the Hook show, I heard about a very powerful worm that specifically targets Siemens industrial control systems, which are used to control the machinery on many large shows. The virus is spread using USB drives, and may have been written by a nation-state to target Iranian reactors (which apparently use Siemens control systems).  The stuxnet worm was discovered over the summer, and noted security blogger Bruce Schneier posted some interesting links here.

This brings up, once again, the vulnerability of USB drives which I wrote about recently here.  Coincidentally, at school right now we're suffering from USB-spread malware that Symantec Endpoint Protection will not find or address, and this makes me want to just cement up those USB ports.

PrintView Printer Friendly Version

Reader Comments (2)

The name of the company mentioned on the article http://www.bbc.co.uk/news/technology-11388018 is "Siemens", not "Seimens"
Siemens is a well known manufacturer if industrial control systems and there has been some issues lately found on their systems security.

I have not heard of company "Seimens" and Google did not give anything either....

September 24, 2010 | Unregistered CommenterTomi Engdahl

D'Oh! My mistake--that's what I get for writing a post in the middle of the day when I was doing 12 other things at once. Of course it is Siemens, http://www.siemens.com/entry/cc/en/. I've been using their stuff since the 1980's so I should have known better. I've corrected it now, but unfortunately that also broke the link to this page.

Thanks for pointing this out.

September 24, 2010 | Registered CommenterJohn Huntington
Comments for this entry have been disabled. Additional comments may not be added to this entry at this time.