Saturday, September 25, 2010

Some Thoughts On The Stuxnet Worm

This, in blinding 20/20 hindsight is the next step of malware, not as a destructive nuisance or financial gain spammer, but as a designed weapon. The only reassuring (HA!) thing about it, is that apparently it takes a nation state to achieve such a thing, according to the article I read.  How BIG of a nation state? Could a large multinational company be capable of having the personnel, knowledge and money to do the same thing to a rival's software?

This is A. The first KNOWN instance. Perhaps we should be reviewing records?

B. It's awfully wasteful not to use it again, because they have infiltrated many industrial systems using the same software, (apparently unintentionally).  I'm sure they (who so ever this mysterious nation state is) have other enemies.

C. How much of an effort is it to crack another software program? Considering this system was NOT connected to the net, but was infected by datastik, which is how it spread outside the intended target (which is how we came to know of it)! It wasn't necessarily cracking the software that was the problem for these guys, but the delivery of the worm

We will being seeing more of this, I'm sure.

Solutions, bad solutions. . .completely proprietary software designed for each company. This would be VERY expensive, and I'm not even sure it would work. It would have to have no net connection and be completely controlled as to access. IT would and maybe will come to look very different, also became very boated. Also, good chance of working for same company for entire career will come back. Japan going to have an advantage. They already have components of this kind of social system in their society.

I think open archatech is going to take a dump. Maybe a two layered system? First layer, open, connected to the net, second layer, internal, closed and perhaps hand entered information only? In other words a drawbridge between the open and closed, that can filter out malware. I don't think this will work. And, I don't know enough about this subject to even speculate on it in any reasonable way.

No comments: