Experts: Stuxnet changed the cybersecurity landscape

The level of sophistication in the worm should serve as a wake-up call, cybersecurity experts say

The appearance of the Stuxnet worm in June should serve as a wake-up call to governments and businesses, especially those relying on Internet-based industrial control systems, a group of cybersecurity experts told U.S. lawmakers Wednesday.

The sophisticated Stuxnet is a "game changer" for companies and governments looking to protect their networks, said Sean McGurk, acting director of the National Cybersecurity and Communications Integration Center in the U.S. Department of Homeland Security. Stuxnet, likely developed by a well-financed team, modifies files of the software running industrial control systems and can also steal the data contained there without the owner knowing it, he told the U.S. Senate Homeland Security and Governmental Affairs Committee.

"We have not seen this coordinated effort of information technology vulnerabilities and industrial control exploitation completely wrapped up in one unique package," McGurk said.

Stuxnet illustrates the need for governments and businesses to adopt new approaches to cyberthreats, added Michael Assante, president and CEO of the National Board of Information Security Examiners. "Stuxnet is, at the very least, an important wake-up call for digitally enhanced and reliant countries, and at its worst, a blueprint for future attackers," he said.

As of last week, there were still about 44,000 computers infected with Stuxnet worldwide, with about 60 percent of them in Iran, said Dean Turner, director of Symantec's Global Intelligence Network. About 1,600 of the current infections are in the U.S., he said.

There has been some speculation, including some from Symantec, that Stuxnet targeted Iran's attempts to enrich uranium. But it's impossible to determine the target or the source of the worm, Turner said. While the sophistication of Stuxnet likely means there won't be huge numbers of similar attacks, more are coming, he added.

"Our level of preparedness to some degree -- certainly in the private sector -- is better than it ever has been, but still has a long way to go," Turner said. "It often is a cliché, but we don't know what we don't know. How vulnerable are industrial control systems ... in the United States and anywhere else? It's a difficult question to answer."

Despite the witnesses calling for swift action, the Senate is unlikely to act on a comprehensive cybersecurity bill this year, said Senator Joe Lieberman, a Connecticut independent and committee chairman. The Protecting Cyberspace as a National Asset Act, introduced by Lieberman and other committee members in June, will be a top priority for the committee next year, he said.

Assante criticized past cybersecurity efforts focused on complying with lists of requirements, naming reliability standards released by the North American Electric Reliability Corp., or NERC. The group's standards are focused on perimeter protection and don't take into account new types of threats, he said.

The standards also contain several gaps and have imposed requirements in a fast-changing environment, causing the industry to be polarized, he said. "The result has been a conscious and inevitable retreat to a compliance/checklist-focused approach to the security of the bulk power system," Assante said.

Instead, the U.S. government and businesses operating industrial control systems should focus on integrating forensic and security tools into the systems, pour more money into security research and spend more time training cybersecurity workers with attack simulations and other tools, Assante said.

Organizations operating industrial control systems also need to better enforce their IT policies and authenticate users, Turner said. The U.S. government and other entities also need to focus on cybersecurity education, from school classrooms to company boardrooms, he said.

"Stuxnet demonstrates that industrial control systems are more vulnerable to cyberattacks than in the past for several reasons, including their increased connectivity to other systems and the Internet," he said. "Further, as demonstrated by past attacks and incidents involving industrial control systems, the impact on a critical infrastructure could be substantial."

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's e-mail address is

Join the CSO newsletter!

Error: Please check your email address.

Tags North American Electric Reliability Corp.Joe LiebermansecuritySean McGurkU.S. Department of Homeland SecuritylegislationgovernmentMichael AssanteantivirusNational Board of Information Security Examinerssymantec

More about IDGSymantec

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Grant Gross

Latest Videos

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

  • 150x50

    IDG Live Webinar:The right collaboration strategy will help your business take flight

    Speakers - Mike Harris, Engineering Services Manager, Jetstar - Christopher Johnson, IT Director APAC, 20th Century Fox - Brent Maxwell, Director of Information Systems, THE ICONIC - IDG MC/Moderator Anthony Caruana

    Play Video

More videos

Blog Posts