New Stuxnet clues suggest sabotage of Iran's uranium enrichment program
Symantec says Stuxnet worm monkeys with electrical motor controls, like those used by gas centrifuges to enrich uranium
Computerworld - Researchers have uncovered new clues that the Stuxnet worm may have been created to sabotage Iranian attempts to turn uranium into atomic bomb-grade fuel.
According to Eric Chien, one of three Symantec researchers who have dug into Stuxnet, the worm targets industrial systems that control very high speed electrical motors, such as those used to spin gas centrifuges, one of the ways uranium can be enriched into fissionable material.
One expert called Symantec's discovery "very interesting indeed."
Chien reported Symantec's new findings in a blog post last Friday and in a revised paper first published in September.
Stuxnet, considered by many security researchers to be the most sophisticated malware ever, targeted Windows PCs that managed large-scale industrial-control systems in manufacturing and utility companies. Those control systems, called SCADA, for "supervisory control and data acquisition," operate everything from power plants and factory machinery to oil pipelines and military installations.
Since the worm was first detected in June, researchers have come to believe that it was crafted by a state-sponsored team of programmers, and designed to cripple Iran's nuclear program.
In September, Iran officials confirmed that Stuxnet infected 30,000 PCs in the country, but have denied that the worm had caused any significant damage or infiltrated the SCADA systems at the Bushehr nuclear reactor.
Symantec's latest analysis indicates that the reactor was not the target. Instead, Stuxnet aimed to disrupt uranium enrichment efforts.
Stuxnet looks for devices called "frequency converter drives" connected to a SCADA system, said Chien. Such drives take electrical current from a power grid, then change the output to a much higher frequency, typically 600 Hz or higher.
"The high-frequency output from the frequency changer is fed to the high-speed gas centrifuge drive motors (the speed of an AC motor is proportional to the frequency of the supplied current)," states the Federation of American Scientists (FAS) in an explanation of uranium production on its Web site. "The centrifuge power supplies must operate at high efficiency, provide low harmonic distortion, and provide precise control of the output frequency."
Stuxnet, however, monkeys with the output frequency over a period of months, Symantec said in its revised paper (download PDF).
When it finds converter drives operating between 807 Hz and 1210 Hz, the worm resets the frequency to 1410 Hz, then after 27 days, drops the frequency to just 2 Hz and later bumps it up to 1064 Hz. It then repeats the process.
"Interfering with the speed of the motors sabotages the normal operation of the industrial control process," said Chien.
Sabotaging centrifuge motor speed will do more than that, said Ivanka Barzashka, a research assistant with the Strategic Security Program of FAS, and an expert on gas centrifuges. "A centrifuge is a delicate piece of equipment and operating a centrifuge at the right frequency is extremely important," Barzashka said in an e-mail Sunday. "Problems controlling the operating frequency can cause the machines to fly apart."


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Driving Secure Enterprise File Sharing and Syncing in the Enterprise
- GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
- The Enterprise File Sharing Option
- Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
- Security Strategies to Virtualizing Internet-Facing Applications
- The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
- Cloud Security Planning Guide
- Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
- Cloud Security Vendor Round Table
- This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions... All Security White Papers
- Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
- FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
- BlackBerry PlayBook OS 2.0 Security Overview
- The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
- BlackBerry NFC Security Overview
- The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts