Showing posts with label Ralph Langner. Show all posts
Showing posts with label Ralph Langner. Show all posts

Tuesday, November 8, 2011

A Precursor to War? As Washington Renews Military Threats Against Iran, Cyber Attacks Escalate

Global Research

Tom Burghardt

As evidence mounts that the U.S. secret state is launching cyber weapons against official enemies, while carrying out wide-ranging spy ops against their "friends," Gen. Keith Alexander, the dual-hatted overlord of the National Security Agency and U.S. Cyber Command, says that the Obama administration is "working on a system" that will "help" ISPs thwart malicious attacks.

Speaking at the Security Innovation Network (SINET) "Showcase 2011" shindig at the National Press Club in Washington, Alexander told security grifters eager to gouge taxpayers for another piece of lucrative "cybersecurity" pie: "What I'm concerned about are the destructive attacks. Those are the things yet to come that cause us a lot of concern."

That's rather rich coming from the head of a secretive Pentagon satrapy suspected of designing and launching the destructive Stuxnet virus which targeted Iran's civilian nuclear program.
According to fresh evidence provided by IT security experts it now appears that the same constellation of shadowy forces which unleashed Stuxnet are at it again with the newly discovered Duqu spy Trojan.

In a follow-up analysis, Kaspersky Lab researcher Alex Gostev wrote that "the highest number of Duqu incidents have been recorded in Iran. This fact brings us back to the Stuxnet story and raises a number of issues."

Not least of which is the continuing demonization of the Islamic Republic by an unholy alliance of U.S. militarists, their Israeli pit bulls and congressional shills hyping the "Iran threat."

War Drums Beating

With the United States and the other capitalist powers incapable of digging the world economy out from under the slow-motion meltdown sparked by 2008's market collapse, and with tens of millions of enraged citizens rejecting austerity measures that will further enrich financial elites at their expense, will the Obama administration "go for broke" and set-off a new conflagration in the Middle East?

Ratcheting up bellicose rhetoric, John Keane, a retired four-star general, former Vice Chief of Staff of the U.S. Army now currently perched on the board of General Dynamics, a major purveyor of cyber attack tools for the government, told the House Homeland Security Committee October 26, "We've got to put our hand around their throat now. Why don't we kill them? We kill other people who are running terrorist operations against the United States."

Saturday, October 8, 2011

Security Expert: U.S. 'Leading Force' Behind Stuxnet

WGBH
Tom Gjelten

One year ago, German cyber security expert Ralph Langner announced he had found a computer worm designed to sabotage a nuclear facility in Iran. The Stuxnet worm is now recognized as a cyber super weapon, and it could end up harming those who created it.

One year ago, German cyber security expert Ralph Langner announced he had found a computer worm designed to sabotage a nuclear facility in Iran. It's called Stuxnet, and it was the most sophisticated worm Langner had ever seen.

In the year since, Stuxnet has been analyzed as a cyber super weapon, one so dangerous it might even harm those who created it.

In the summer of 2010, Langner and his partners went to work analyzing a malicious software program that was turning up in some equipment. Langner Communications is a small firm in Hamburg, Germany, but Langner and the two engineers with whom he works know a lot about industrial control systems. What they found in Stuxnet left them flabbergasted.

"I'm in this business for 20 years, and what we saw in the lab when analyzing Stuxnet was far beyond everything we had ever imagined," Langner says.

It was a worm that could burrow its way into an industrial control system, the kind of system used in power plants, refineries and nuclear stations. Amazingly, it ignored everything it found except the one piece of equipment it was seeking; when the worm reached its target, it would destroy it.

Langner says that the more his team analyzed the Stuxnet worm, the more they knew they were onto something big.

"We were pretty much working around the clock," he says, "because after we had the first impression of the magnitude of this, we were just like on speed or something like that. It was just impossible to go back to sleep."

Langner also realized after analyzing the Stuxnet code that it was designed to disable a particular nuclear facility in Iran. That's serious business, he figured. Some Iranian nuclear scientists, he remembered, had been mysteriously killed. Langner published his findings anyway.

Wednesday, April 27, 2011

West is at Mercy of Stuxnet, German Analyst Hints

by Gil Ronen
Thu Ugly Truth

Nuclear Reactors in the United States
German cyber-security expert Ralph Langner, who helped unravel the Stuxnet virus, told a global audience in March that the worm could be used as a weapon of mass destruction against targets in the West. At the end of his presentation on the subject, Langner arguably seemed to hint at the possibility that Israel is part of the danger, although in correspondence a few months ago he named an unspecific “hacker underground” as the possible threat.

Langner heads an independent German cyber-security firm that bears his name, which specializes in control systems — electronic devices that monitor and regulate other devices. Langner’s website says that his team analyzed Stuxnet as part of “a global effort to decode the mysterious program,” without naming his client.
 
In a March presentation at Ted2011, an elite yet globally public intellectual platform, Langner spoke admiringly of the ingeniousness behind Stuxnet, but also employed an ominous tone, speaking of “the plot behind Stuxnet” and calling its mode of operation “creepy.” 
 
Stuxnet’s programming is “rocket science,” he said, presenting some lines of code from the cyber-virus before his high-tech audience. “It’s way above everything that we have ever seen before.” The people behind it were “very professional, they knew all the bits and bytes,” he explained. “They probably even knew the shoe size of the operator [at the Natanz plant],” he added.
 
The virus was designed to work stealthily, Langner added. The idea was to take over the uranium-enrichment cascades at Iran’s Natanz plant “slowly and creepily” and “to drive maintenance engineers crazy.”
 
“When we started our research on Stuxnet six months ago, it was completely unknown what the purpose of this thing was,” he said. “We started to work on this around the clock because I thought, well, we don’t know what the target is, it could be, let’s say for example, a U.S. power plant or a chemical plant in Germany. So we better find out what the target is soon.”
 
He went on to describe the risk that Stuxnet could be used to blow up power plants:

“The idea here is not only to fool the operators in the control room. It actually is much more dangerous and aggressive. The idea here is to circumvent a digital safety system…. when they are compromised, then real bad things can happen. Your plant can blow up and and neither your operators nor your safety system will notice it. That’s scary. But it gets worse – and this is very important, what I am going to say. Think about this: this attack is generic. It doesn’t have anything to do with specifics with centrifuges, with uranium enrichment. So it would work as well, for example in a power plant or in an automobile factory. It is generic. And as an attacker you don’t have to deliver this payload by a USB stick, as we saw it in the case of Stuxnet. You could also use conventional worm technology for spreading. Just spread it as wide as possible. And if you do that, what you end up with is a cyberweapon of mass destruction.”

“That’s the consequence that we have to face,” he said, deliberately, while showing a map that marked Western countries (Israel not included) in green. “So unfortunately, the biggest number of targets for such attacks are not in the Middle East. They are in the United States, in Europe and in Japan. So all the green areas, these are your target-rich environments. We have to face the consquences and we better start to prepare right now.”



The caption on the slide says “This way, Pandora.”

In what was most likely a “pre-ordered” question from the conference presenter at the end of his lecture, Langner was asked if he thought Israel was behind the attack. His response sounded a dramatic tone:

“My opinion is that the Mossad is involved, but that the leading force is not Israel, so that… the leading force behind that is the cyber superpower. There is only one, and that is the United States. Fortunately… fortunately… Because otherwise, our problems would even be bigger.”

The “even bigger” danger Langner is hinting at was deliberately left vague. Based on the presentation alone, and the concluding sentence, it seems possible that he thinks Israel could use the worm against Western targets. Why the German consultant thinks Israel would want to do this, one can only speculate.

However, in a correspondence with cyber-security firm Symantec some six months ago, Langner named a “hacker underground” as the possible threat:

“You fail to understand that the hacker underground has been studying control systems for years without any success. You fail to understand that this community will eagerly dismantle Stuxnet as a blueprint for how to cyber-attack installations from the cookie plant next door to power plants.”

So – does Langner think the threat is Mossad or the “hacker underground”? Is the “hacker underground” he fears Jewish, Muslim, or other? Is there an anti-Semitic tinge to the description of the virus as “creepy” and to its inception as a “plot”? Why is Israel not included in the green areas that could come under the Stuxnet threat? Was he hinting that if Mossad and not the U.S. were the leading force behind Stuxnet, the West’s problems would be bigger? Is he concerned about a targeted attack or an uncontrolled worldwide attack? These are questions that cannot be answered at this point.

Over the decades since Israel’s acquisition of nuclear technology, there has occasionally been speculation over the Jewish state’s options in case it were faced with a lethal attack. One possible course of action that has been floated is known as the “Samson Option,” in which Israel would take down its (past and present) enemies with it, like the Biblical hero.

The New York Times recently reported that the Stuxnet virus could possibly still be infecting Iranian systems and that it may unleash additional havoc on new targets. Iranian civil defense commander Gholamreza Jalali said Monday the Islamic Republic’s nuclear program has fallen prey to a new computer virus called “Stars.”