Previously, Symantec found that Stuxnet was able to modify the code on programmable logic controllers (PLCs) used in industrial control systems. The goal of such alterations, however, wasn't known, though it was curious that Iran seemed to be hardest hit by the malware.
But now, with the help of an unnamed Dutch expert in the Profibus communications module -- also targeted by Stuxnet -- Eric Chien, technical director of Symantec Security Response, said that Symantec had unraveled "the purpose of all of Stuxnet's code."
Here's how it works: Stuxnet watches for frequency converter drives (used to control motor speeds) operating at certain, very high frequencies -- between 807 Hz and 1210 Hz. Once spotted, Stuxnet hijacks the PLC code and begins altering how the drives operate. "In addition to other parameters, over a period of months, Stuxnet changes the output frequency for short periods of time to 1410 Hz and then to 2 Hz and then to 1064 Hz," meaning that it speeds up and slows down the motors, said Chien. "Modification of the output frequency essentially sabotages the automation system from operating properly."
What uses high-frequency drives? With the disclaimer that they're not industrial control system experts, the authors of Symantec's report into Stuxnet said that "efficient low-harmonic frequency converter drives that output over 600 Hz are regulated for export in the United States by the Nuclear Regulatory Commission as they can be used for uranium enrichment."
Another piece of the puzzle is that Stuxnet only targets drives from two vendors -- one based in Finland, and the other in Tehran, Iran. In short, Stuxnet appears designed to foil Iran's ability to enrich uranium to the point where it could be used to build a bomb.
As that suggests, Symantec said that whoever built Stuxnet likely had substantial backing. First, they would have required a complete test environment to mirror their target. In addition, they would have required substantial reconnaissance of the target systems. In fact, they may have used malware to map the schematics of targeted industrial control systems, as well as the configurations of each PLC, which are unique.
In short, Stuxnet was built to work. "Each feature of Stuxnet was implemented for a specific reason," said Symantec.
Security Job #1 For FedsThe 2014 InformationWeek Government IT Priorities Survey shows federal IT pros care about security - itís rated as very important by 69% of respondents, 30 percentage points ahead of the No. 2 priority, disaster recovery. Will the upcoming NIST cyber-security framework help manage risk?
InformationWeek Must Reads Oct. 21, 2014InformationWeek's new Must Reads is a compendium of our best recent coverage of digital strategy. Learn why you should learn to embrace DevOps, how to avoid roadblocks for digital projects, what the five steps to API management are, and more.