Previously, Symantec found that Stuxnet was able to modify the code on programmable logic controllers (PLCs) used in industrial control systems. The goal of such alterations, however, wasn't known, though it was curious that Iran seemed to be hardest hit by the malware.
But now, with the help of an unnamed Dutch expert in the Profibus communications module -- also targeted by Stuxnet -- Eric Chien, technical director of Symantec Security Response, said that Symantec had unraveled "the purpose of all of Stuxnet's code."
Here's how it works: Stuxnet watches for frequency converter drives (used to control motor speeds) operating at certain, very high frequencies -- between 807 Hz and 1210 Hz. Once spotted, Stuxnet hijacks the PLC code and begins altering how the drives operate. "In addition to other parameters, over a period of months, Stuxnet changes the output frequency for short periods of time to 1410 Hz and then to 2 Hz and then to 1064 Hz," meaning that it speeds up and slows down the motors, said Chien. "Modification of the output frequency essentially sabotages the automation system from operating properly."
What uses high-frequency drives? With the disclaimer that they're not industrial control system experts, the authors of Symantec's report into Stuxnet said that "efficient low-harmonic frequency converter drives that output over 600 Hz are regulated for export in the United States by the Nuclear Regulatory Commission as they can be used for uranium enrichment."
Another piece of the puzzle is that Stuxnet only targets drives from two vendors -- one based in Finland, and the other in Tehran, Iran. In short, Stuxnet appears designed to foil Iran's ability to enrich uranium to the point where it could be used to build a bomb.
As that suggests, Symantec said that whoever built Stuxnet likely had substantial backing. First, they would have required a complete test environment to mirror their target. In addition, they would have required substantial reconnaissance of the target systems. In fact, they may have used malware to map the schematics of targeted industrial control systems, as well as the configurations of each PLC, which are unique.
In short, Stuxnet was built to work. "Each feature of Stuxnet was implemented for a specific reason," said Symantec.
How Enterprises Are Attacking the IT Security EnterpriseTo learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
IT Strategies to Conquer the CloudChances are your organization is adopting cloud computing in one way or another -- or in multiple ways. Understanding the skills you need and how cloud affects IT operations and networking will help you adapt.