Bonanza Offer FLAT 20% off & $20 sign up bonus Order Now
CSI2450
AU
Edith Cowan University
The aim of this presentation is to investigate the OT attack such as Stuxnet, which was one of the vulnerable attacks. This study also investigates all the technical details of the Stuxnet attack. This prestation also provides the findings of the attacks and the consequences. In this presentation the recommendations related to the cyber security are also provided by considering the Stuxnet attack.
Stuxnet is the advance computer worm. It exploits several unknown windows zero-day vulnerabilities for infecting the computers. This attack was uncovered first in the year 2010 and this attack was thought to have been in the development stage at least in the year 2005. This virus targets the SCADA (supervisory control and data acquisition) system and this is believed for being responsible to cause the substantial damage to a nuclear program in Iran. The original Stuxnet attack targeted the PLC used for automating the machine process. The architecture and design of Stuxnet are not domain-specific and this can be tailored as the platform.
When the Stuxnet virus infects any computer, this checks for seeing if the computer in connected to any particular model of the PLC or not. The PLC are the process where the computers interact with as well as control the industrial machinery such as uranium centrifuges. Then the virus alerts the programs of the PLCs and then results in being spun for the centrifuges very fast and for so long. This also destroys or damages the delicate equipment in this process. At the time, PLC then commands the controller computer that everything is finely working by making this difficult for the users to diagnose or detect anything wrong with the system.
In June 2009, the first Stuxnet was seen, where this did not have the signed drivers. Then in the June 2010, the driver of Stuxnet was signed with the valid certificate, which belongs to the Realtek Semiconductors. The in June 2010, the Virusblokada reported about the W32.Stuxnet virus, where the verisign revoked the certificates of Realtek. In July 2010, Eset, one of the anti-virus vendors identified the new Stuxnet driver with the valid certificate, which belonged to the JMicron Technology Corp. Also in July 2010, the company Siemens reported that they are investigating on the SCADA system, where the verisign revoked the certificates of JMicron.
Stuxnet destroyed various centrifuges in the Natanz uranium enrichment facility in Iran, which provoked them to burn themselves. Then other groups modified the virus for targeting the facilities, which also includes the water treatment plans, gas line and powerplants. This virus travelled through the USB dives and was spread through the various elements of MS windows.
The Stuxnet virus searched the infected PC for the sign of the Step 7 software Siemens, where the industrial computers were serving as the PLCs for monitoring and automating the electro-mechanical equipment. After finding the PLC computers, the Stuxnet attack updated the code and then started to send the damage including the instructions to that electro-mechanical equipment, which the computer controlled. Then the Stuxnet worms sent the false the feedback to main controller. Anyone who were monitoring the equipment would have has not any indication of the problem until that equipment started self-destructing.
One of the exploited vulnerabilities was Google Chrome Browser: CVE-2021-21193. Zero-day flaw was found in the Google browser. The rank of the flaw was 8.8 out of 10 on the rating scale of the CVS vulnerability scale. This security flaw exploitation can occur, when any user runs the Google Chrome and then he or she clicks on any malicious link then it goes to the specially crafted webpage, which exploits the weakness.
Another exploited vulnerability was Google Chrome Browser: CVE-2021-21206. Two zero-day flaws were found in the chrome browser. The rank of the flaw was 7.3 out of 10 on the rating scale of the CVS vulnerability scale. In this case, the attacker executed arbitrary codes to the browser. Depending on privileges linked with any application, the intruder can view, delete or change the data and this vulnerability can be exploited if any user is redirected to any crafted webpage or the users visits himself or herself.
Followings are some of the OT specific weaknesses which can be exploited such as:
Followings are some of the human weaknesses, which can be exploited because of the cyber security risks such as:
Some of the operational process weakness, which can be exploited are as follows:
In recommendation, this can be said that the users must use the string passwords and should use user authentication for limiting the access for the unauthorized users. The organization should give proper training to the employees on the cyber security for making them capable for handling any vulnerability and risk. As the Stuxnet attack travelled through the USB sticks for accessing to the system, therefore, the users must restrict the access to the USB drives and the users should also use the patch maintenance system to reduce the potential attack or infection and the patch should be monitored multiple times every day.
We provide unmatched quality assignment writing services for all subjects in your curriculum. The most common subjects we cover include Maths, English, Humanities, Social Sciences, Management and more. Our experts have acquired their respective PhDs in specific disciplines from reputed universities. Tell us the subject you need ghostwriters for. We will assign a suitable ghostwriter accordingly. We are not restricted to writing assignments only. We also provide top-notch proofreading services and essay writing services. The essay writers are well-versed in all types of essays such as persuasive, expository, narrative, argumentative, persuasive, etc. Whether you need math homework help or English homework help, we have the right expert for you.
Upload your Assignment and improve Your Grade
Boost Grades