Showing posts with label computer. Show all posts
Showing posts with label computer. Show all posts

Friday, August 17, 2012

Shamoon virus targets energy sector infrastructure

A new threat targeting infrastructure in the energy industry has been uncovered by security specialists.

The attack, known as Shamoon, is said to have hit “at least one organisation” in the sector.

Shamoon is capable of wiping files and rendering several computers on a network unusable.

On Wednesday, Saudi Arabia’s national oil company said an attack had led to its own network being taken offline.

Although Saudi Aramco did not link the issue to the Shamoon threat, it did confirm that the company had suffered a “sudden disruption”.

In a statement, the company said it had now isolated its computer networks as a precautionary measure.

The disruptions were “suspected to be the result of a virus that had infected personal workstations without affecting the primary components of the network”, a statement read.

It said the attack had had “no impact whatsoever” on production operations.

Rendered unusable

On Thursday, security firms released the first detailed information about Shamoon.

Experts said the threat was known to have had hit “at least one organisation” in the energy sector.

“It is a destructive malware that corrupts files on a compromised computer and overwrites the MBR (Master Boot Record) in an effort to render a computer unusable,” wrote security firm Symantec.

The attack was designed to penetrate a computer through the internet, before targeting other machines on the same network that were not directly connected to the internet.

Once infected, the machines’ data is wiped. A list of the wiped files then sent back to the initially infected computer, and in turn passed on to the attacker’s command-and-control centre.

During this process, the attack replaces the deleted files with JPEG images - obstructing any potential file recovery by the victim. More

 

Monday, May 28, 2012

Security researcher: I found secret reprogramming backdoors in Chinese microprocessors

Sergei Skorobogatov, a postdoc in the Security Group at the Computer Laboratory of the University of Cambridge has written up claims that reprogammable microchips from China contained secret back-doors that can be used to covertly insert code:

Claims were made by the intelligence agencies around the world, from MI5, NSA and IARPA, that silicon chips could be infected. We [Canbridge Computer Lab]

developed breakthrough silicon chip scanning technology to investigate these claims. We chose an American military chip that is highly secure with sophisticated encryption standard, manufactured in China. Our aim was to perform advanced code breaking and to see if there were any unexpected features on the chip. We scanned the silicon chip in an affordable time and found a previously unknown backdoor inserted by the manufacturer. This backdoor has a key, which we were able to extract. If you use this key you can disable the chip or reprogram it at will, even if locked by the user with their own key. This particular chip is prevalent in many systems from weapons, nuclear power plants to public transport. In other words, this backdoor access could be turned into an advanced Stuxnet weapon to attack potentially millions of systems. The scale and range of possible attacks has huge implications for National Security and public infrastructure.

Key features of our technology:

* scans silicon/hardware for backdoors, Trojans and unexpected behaviour

* low cost

* very fast result turnaround time

* high portability

* adaptable - scale up to include many types of chip

Further funding is needed for us to progress to testing further silicon chips and to develop better search algorithms which would allow us to detect possible spy systems or vulnerabilities in a greater range of systems.

Currently there is no economical or timely way of ascertaining if a manufacturer's specifications have been altered during the manufacturing process (99% of chips are manufactured in China), or indeed if the specifications themselves contain a deliberately inserted potential threat. More

Cambridge Paper here PDF