Experts: Stuxnet changed the cybersecurity landscape

The level of sophistication in the worm should serve as a wake-up call, cybersecurity experts say

The appearance of the Stuxnet worm in June should serve as a wake-up call to governments and businesses, especially those relying on Internet-based industrial control systems, a group of cybersecurity experts told U.S. lawmakers Wednesday.

The sophisticated Stuxnet is a "game changer" for companies and governments looking to protect their networks, said Sean McGurk, acting director of the National Cybersecurity and Communications Integration Center in the U.S. Department of Homeland Security. Stuxnet, likely developed by a well-financed team, modifies files of the software running industrial control systems and can also steal the data contained there without the owner knowing it, he told the U.S. Senate Homeland Security and Governmental Affairs Committee.

"We have not seen this coordinated effort of information technology vulnerabilities and industrial control exploitation completely wrapped up in one unique package," McGurk said.

Stuxnet illustrates the need for governments and businesses to adopt new approaches to cyberthreats, added Michael Assante, president and CEO of the National Board of Information Security Examiners. "Stuxnet is, at the very least, an important wake-up call for digitally enhanced and reliant countries, and at its worst, a blueprint for future attackers," he said.

As of last week, there were still about 44,000 computers infected with Stuxnet worldwide, with about 60 percent of them in Iran, said Dean Turner, director of Symantec's Global Intelligence Network. About 1,600 of the current infections are in the U.S., he said.

There has been some speculation, including some from Symantec, that Stuxnet targeted Iran's attempts to enrich uranium. But it's impossible to determine the target or the source of the worm, Turner said. While the sophistication of Stuxnet likely means there won't be huge numbers of similar attacks, more are coming, he added.

"Our level of preparedness to some degree -- certainly in the private sector -- is better than it ever has been, but still has a long way to go," Turner said. "It often is a cliché, but we don't know what we don't know. How vulnerable are industrial control systems ... in the United States and anywhere else? It's a difficult question to answer."

Despite the witnesses calling for swift action, the Senate is unlikely to act on a comprehensive cybersecurity bill this year, said Senator Joe Lieberman, a Connecticut independent and committee chairman. The Protecting Cyberspace as a National Asset Act, introduced by Lieberman and other committee members in June, will be a top priority for the committee next year, he said.

Assante criticized past cybersecurity efforts focused on complying with lists of requirements, naming reliability standards released by the North American Electric Reliability Corp., or NERC. The group's standards are focused on perimeter protection and don't take into account new types of threats, he said.

The standards also contain several gaps and have imposed requirements in a fast-changing environment, causing the industry to be polarized, he said. "The result has been a conscious and inevitable retreat to a compliance/checklist-focused approach to the security of the bulk power system," Assante said.

Instead, the U.S. government and businesses operating industrial control systems should focus on integrating forensic and security tools into the systems, pour more money into security research and spend more time training cybersecurity workers with attack simulations and other tools, Assante said.

Organizations operating industrial control systems also need to better enforce their IT policies and authenticate users, Turner said. The U.S. government and other entities also need to focus on cybersecurity education, from school classrooms to company boardrooms, he said.

"Stuxnet demonstrates that industrial control systems are more vulnerable to cyberattacks than in the past for several reasons, including their increased connectivity to other systems and the Internet," he said. "Further, as demonstrated by past attacks and incidents involving industrial control systems, the impact on a critical infrastructure could be substantial."

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's e-mail address is grant_gross@idg.com.

Join the PC World newsletter!

Error: Please check your email address.

Tags North American Electric Reliability Corp.Joe LiebermansecuritySean McGurkU.S. Department of Homeland SecuritylegislationgovernmentMichael AssanteantivirusNational Board of Information Security Examinerssymantec

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Grant Gross

IDG News Service
Show Comments

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?