Kaspersky developing new secure SCADA operating system

Russian anti 'super-virus' developing rapidly.
  • Liam Tung (CSO Online)
  • — 07 August, 2012 09:19

Russian antivirus firm Kaspersky Lab is on the hunt for developers to complete a secure operating system that could fend off the next Stuxnet attack on industrial control systems.

The company, which earlier this year reported the discovery of ‘super-weapon’ malware Flame, is seeking a developer and analyst to help create an operating system that prevents untrusted items from executing on process control systems (PCS), according to Russian recruitment site, HeadHunter.

The postings say the Kaspersky Lab project “is developing rapidly”. It wants recruits with experience programming PCS and Supervisory Control And Data Acquisition (SCADA) systems, implementing industrial networking and communications protocols, and knowledge of Siemens, Emerson, Omron, ABB and other programmable logic controllers.

Some of the core software flaws Stuxnet exploited to attack Iran's Natanz nuclear enrichment facility were the Siemens Simatic STEP 7 and Simatic PCS 7 that the German company patched (PDF) last month.

Recruits would also need knowledge of Windows, Linux and QNX, which is used in industrial control systems and more recently has been put to work in RIM’s PlayBook.

Russian news site CNews last week reported the two roles on offer at Kaspersky Lab, noting the project was likely a response to Stuxnet that could fill a gap in the field of Windows-based process virtualisation security.

The company has not commented on the job postings, but Kaspersky Lab chief, Eugene Kaspersky, dropped a big hint at the AusCERT conference in May, telling the audience SCADA was “not possible to protect” and that these systems could be “very easy victims”.

“The only way to protect critical infrastructure – is to redesign SCADA systems based on a secure operating system. It is possible to do, but it requires a redesign of all the software for industrial systems,” CSO.com.au reported at the time.

Cyber security researcher and CEO of Taia Global, Jeffrey Carr, said a Kaspersky-made secure operating system for industrial control systems “makes a lot of sense” and would probably be in high demand, but he also points to Kaspersky’s “close relationship to Russia’s security services”.

“Under Russian law, the FSB could ask Kaspersky to include a backdoor in its secure O/S and the company would be required to comply. In fact, I can't imagine the FSB missing out on such an opportunity for intelligence collection against potential customers among the Commonwealth of Independent States, India, China, South Africa and others.”

Taia’s analysis (PDF) of Russian law and the implications for Kaspersky Lab products was linked-to in a recent [[XREF: http://www.wired.com/dangerroom/2012/07/ff_kaspersky/all/ |Wired profile|]] of Mr Kaspersky that highlighted his connections to the Kremlin and its security arm, the FSB.

Kaspersky responded to the piece with a lengthy list of corrections, including that the company provided ‘expertise and nothing more’.

Follow @CSO_Australia and sign up to the CSO Australia newsletter.

Google introduces Chrome 'factory reset' pop-ups to tackle extensions hijacks

READ THIS ARTICLE
DO NOT SHOW THIS BOX AGAIN [ x ]
Comments are now closed.
CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Fraud Management Solutions

Reduce fraud losses regardless of channel by preventing cybercrime, identity theft, and other threats targeting your customers.

Latest Jobs
Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.