Aybody with Grammarly , please run it through grammarly and dont delete the coments . Needed in 20 minutes

Edulope
FinalCorrection.docx

Running head: STUXNET AND U.S INCIDENCE RESPONSE

STUXNET AND U.S INCIDENCE RESPONSE 9

Stuxnet and U.S Incidence Response

Student's Name

Institution Affiliation

Stuxnet and U.S Incidence Response

The U.S Computer Emergency Readiness Team is a body mandated to protect the country's internet infrastructure and to ensure the general welfare of all public entities on the internet. The team is responsible for devising methods to clearly respond to cyber security attacks that might pose a threat to the nation. They work alongside the Department of Homeland Security together with multiple other private and public companies in accomplishing this task (Techopedia, 2018).

The U.S CERT has a number of activities it engages in order to make the internet a safe place for the entire nation. It for instance devices means for the public to report any cyber threat or attack that they suspect to the body for appropriate actions to be taken. They also engage in educational ventures with the aim of making the public and industries aware of data security and threats.

The body also has the role of letting the general public aware of looming cybersecurity strikes and attacks. They gather information from various sources and analysis of these can actually help the point out possible security threats various bodies are facing or at risk of. By so doing they are able to prevent any loss that could have come about as a result of such attacks (ICS-CERT, 2015).

The emergency response team also takes part in coordinating the recovery activities in emergency situations in conjunction with other firms. These activities are aimed at reducing the impact that a cyber-attack makes and also try to restore any data or operations that might have been brought down as a result of the attack.

An analysis of the data gathered from security threats is also made by the firm in order to learn more about the nature of attacks and to prevent future attacks from happening. Additionally, they also conduct an evaluation of malware applications in order to better know which systems are at risk of attacks and how these attacks can be detected in a system (Ferran, 2012).

The response team also has the role of working hand in hand with other security agencies in the quest of coming up with mitigation steps aimed at preventing and dealing with cybersecurity threats. The bodies share data that they have individually gathered and by putting it together they are able to come up with a clearer picture as to how security attacks are manifested and how they can be able to better detect these security threats.

The U.S Computer Emergency Response Team follows the best guidelines when it comes to cyber-crime response and emergency response preparedness. They use the best approach when it comes to the collection of data relating to security threats by getting it from actual security occurrences. The feedback from the general public is also a rich source of information in matters concerning cybersecurity. By colluding with other security agencies they stand a better position to more effectively combat security threats and possible attacks (Brasso, 2016).

The body's initiative to inform and educate the general public on issues relating to data security and cyber-attacks is a crucial tool in enabling successful prevention of cyber-attacks. When the public is aware of the threat that they face in data security they are able to contribute in safeguarding themselves against such malicious security threats.

Stuxnet was a computer malware that was first noted in 2010, July. It exploited a zero-day vulnerability and attacked Windows PCs and also other industrial software and equipment (Techopedia, 2018). It is believed that the worm spread through flash drives that were infected with the malware. The worm was so sophisticated and is believed to have been made by a group of very talented professionals probably working for the government(s). It exploited a total of four unpatched vulnerabilities in the Windows PCs at the time of discovery (Ferran, 2012).

The industrial control systems computer emergency readiness team (ICS-CERT) was in charge of the mitigation process for the Stuxnet malware. It employed a number of steps in a bid to try and control the malware which was proving to be highly infectious having infected thousands of computers around the world.

One of the many steps that the U.S body has taken is to effect application of patches on host systems. As seen earlier the Stuxnet worm targeted windows pcs and used a total of four zero-day vulnerabilities in making possible its infection. The first step was, therefore, to address these unpatched vulnerabilities in the windows machines so as to prevent further infection by the malware. Organizations affected by the malware and running WinCC or step7 software should follow Siemens recommendations for applying the windows update.

USB drives being the main channels of the infection; the ICS-CERT recommends that the best practices are used when dealing with these flash drives. This is because attackers use the convenience and wide usage of these thumbs drives to enable propagation of the malware. Companies are asked to review their policies further to prevent any loopholes that might lead to infection by a malware such as the Stuxnet worm. By having strong policies on the usage of such material it is hoped that the transfer of malware from an infected computer to another one can be controlled and therefore stopped. Hence it is important for companies to enact such policies(Rouse, 2018).

The ICS-CERT outlines a due process to be followed in the incident that a system becomes infected by the Stuxnet malware. This though depends on the type of system that has been infected. A system that does not run or use Siemens products will have a relatively easier time handling the malware as compared to the system that uses products from Siemens. However, system administrators are advised to practice high discretion and caution before making any major system changes or using anti-virus products.

If a system is running Siemens WinCC or step 7software and is identified as to have been infected by the Stuxnet malware then Siemens customer care support and also ICS-CERT should be contacted. Additionally, Siemens advice that a Microsoft patch should be applied which runs the sysclean tool then the host system should also install the SIMATIC security update. Despite the usage of the SysClean tool does appear to prevent the worm from infecting new flash drives however it does not fully remove all files related to the malware. This is mainly attributed to the complexity of the malware.

Due to this, the ICS-CERT recommends that affected companies closely work with them so as to determine whether the total rebuild of systems is necessary. This rebuild can be effected through manual or automated means. In addition, the ICS-CERT also offer support to companies seeking further guidelines on how to deal with the Stuxnet threat or those that may require further analysis of the effects of the malware to their systems. Besides that, it is worthy to note that systems that do not run on the Siemens products will have an easier time dealing with the malware as it is inert and almost completely harmless in such systems (Brasso, 2016).

Alternate sites are not completely ideal for companies that run on the industrial systems control technologies. This is because these systems control critical infrastructures such as power, transport, gas, and water directly. As such any interruption to such system is really dangerous and high risk as it could mean total sabotage, failure or shutdown of the main processes or even the entire industry.

However, in some cases, many companies continue working with the original systems even after a malware infection has been detected. In such cases, to them, it is better to deal with the malware problem as they go on running normal industry processes as it is less risky that way.

Various other challenges also prevent a shift to a hot site. For example, many industries running on the industrial control systems only allow 5 minutes downtime a year hence it makes it extremely difficult to even carry out a forensic study or analysis in a bid to try and identify malware infection or other security breaches.

The fact that these systems also run on small processors makes it even more difficult since they would not be able to run basic antivirus software. Small processors have very limited computing capabilities and might just not be able to handle the antivirus software that could have been applied to the systems. Additionally, it is hard to apply changes to ICS systems since they were developed during the pre-internet era and do not allow for connectivity, hence it is difficult to apply any updates to them as there would be no means of authenticating commands given.

The challenge being faced here is that these systems only communicate point to point. The option of doing a complete replacement of such systems is also not feasible since these are legacy systems that have been in operation for 15 to 30 years or more. However, companies with such systems are also quite reluctant to overhaul these systems due to the fact that these systems have been operating error-free for a long duration of times. Besides that, an overhaul process if possible would have been too costly to run.

The fact that these systems have to adopt a connectivity plan has made some of them purchase off the shelf software products, for example, operating systems like Windows and Linux. This increases the security threat that is glaring at such systems. This is due to the fact that it is quite possible to infect systems that are interconnected in a network as there would be an actual channel through which the malware would be transmitted.

Companies running on the industrial control systems are thus required to practice complete discretion when it comes to handling the operations of their systems. For instance, if the systems are infected by a hazardous malware it would be havoc dealing with such a system that would be a daunting task. In addition, the fact that it is quite difficult to shift such systems to alternative sites makes it even more imperative to safeguard the original systems from malware attacks.

Therefore, there is significance in the need to engage more discussions involving the security of legacy systems and even newer systems that utilize the industrial control system technologies. This would position many industries in a place where they would be able to easily deal with and control any form of a malware attack that poses a danger to their systems.

The need becomes even more glaring with the onset of more frequent attacks on such systems. The mere fact that replacement of such systems or even shifting is impossible should make security researchers pay more attention to this field so as to come up with proper mitigation steps that will assist industries to easily secure their systems and prevent losses that would arise(Rouse, 2018).

A lot of planning has to go into securing industrial control systems in order to safeguard them from possible attacks, which can be quite fatal. Below are some of the necessary steps that could be taken to ensure that these systems are well protected from such attacks.

The first step would be to secure the networks. A well-secured network entails having a good network design and well-defined boundaries. Additionally, the networks should be segmented by implementing the ISA IEC 62443 standard. The wireless applications should also be secured as well and also deployment of secure remote access solutions should be carried out. The firms should then conduct regular inspection and monitoring of their industrial network infrastructure equipment.

Another important step would be to secure all endpoints. Having firewalls, using proprietary software, imposing protocols and even air gaps is not enough. All these are bypassed when employees, contractors or anyone else bring their laptop, flash drives or other equipment into the corporate network.

These devices can compromise the security measures that have been put in place by providing loopholes for security breaches. It should, therefore, be the policy in all firms that personal equipment like laptops or thumb drives should not be connected to the corporate network.

Organizations are urged to carry out asset discovery. This well helps them map out and actually come up with an inventory of all the endpoints available. Once this is done the necessary configurations should be applied to these endpoints to make them secure from attacks. Constant monitoring of these endpoints should then be done to ensure that they are protected and in the correct state at all the time. This will enable the firm to detect any unauthorized changes that might be made to this points and act accordingly before the newly created weak point is exploited by an intruder (Ashford, 2014).

An important activity that industrial control systems have done in order to prevent attacks is securing the industries controllers. These are computers that bridge the gap between programming instructions and commands given to the system and the actual components that interact with the physical world. These include sensors for temperature, pressure, calibration devices, valves etc. In this regard, a successful intrusion into such computers would deal a serious blow to a firm. This is because a malicious actor would be able to wreak havoc if they were to actually get in control of these systems. In this regard, it becomes extremely important to secure these points (Authier, 2018). Therefore, organizations should implement security features on vulnerable controllers; monitor the rest for any changes that could spell a security threat.

Besides that, it is important for control systems to review their password policies from time to time in order to make them secure and hack-proof. Weak passwords could be a loophole for malware to gain control of critical system components. In addition, the hardware and software element of many ICS systems is also outdated something that has to be looked into if the security of such systems is to be guaranteed (Rouse, 2018).

There should also be traditional penetration testing conducted frequently on such systems by simulating real attacks so that any loophole that has not been addressed can be discovered and patched or rectified. The approach of using a red team can be considered as one of these procedures in order to increase the effectiveness of such tests in establishing the weak points in a system. Even for air-gapped systems, it is still crucial to conduct such tests since it is possible for attacks to be carried out on such systems. For instance, through the use of infected flash drives.

In summary, malware virus can cause very detrimental effects on the operating systems of any company. However, frequently scrutiny and running of anti-malware can really help in solving these problems. In addition, if the above steps are followed correctly they can to a very large extent prevent and protect industrial control systems from cyber-attacks from criminals seeking to access important documents of the industry.

References

Ashford, W. (2014 October, 15). Industrial control systems: What are the security challenges? Retrieved from https://www.computerweekly.com/news/2240232680/Industrial-control-systems-What-are-the-security-challenges

Authier, G. (2018 February, 4). A Solid Approach to Protect your ICS Systems: Simple as 1-2-3.Rerieved from https://www.tripwire.com/state-of-security/ics-security/3-simple-steps-securing-ics-systems-digital-threats/

Brasso, B. (2016 May, 26). Taking Steps to Prevent Critical Infrastructure Cyber Attacks. Retrieved from https://www.fireeye.com/blog/executive-perspective/2016/05/taking_steps_to_prev.html

Ferran, L. (2012 June, 29). When Stuxnet Hit the Homeland: Government Response to the Rescue. Retrieved from http://abcnews.go.com/News/when-stuxnet-hit-the-homeland-government-response-to-the-rescue/blogEntry?id=16680284

Gerbarding ,K.(2017,May9).ICS Security: Is Your Industrial Control System Prepared for Malware Attacks ? Retrieved from: https://www.hitachi-systems-security.com/blog/ics-security-is-your-industrial-control-system-prepared-for-malware-attacks/

ICS-CERT. (2010 September, 15). Stuxnet Malware Mitigation (Update B). Retrieved from https://ics-cert.us-cert.gov/advisories/ICSA-10-238-01B

Rouse, M. (2018) hot and cold site. Retrieved from https://searchcio.techtarget.com/definition/hot-site-and-cold-site

Techopedia (2018). Stuxnet. Retrieved from https://www.techopedia.com/definition/15812/stuxnet