News


Anti-virus alert

April 2011 News

These days, anyone who has e-mail has probably received a phishing message at one time or another. Thinly disguised to try and trick you into divulging credit card details or other personal banking information, they are a constant reminder that the issue of cyber security is not one that should be taken lightly. However, until recently, it was not considered a serious threat to the health of industrial automation networks or the global operations of energy and petrochemical companies.

Enter the Stuxnet worm

A New York Times report suggests that the Stuxnet code was designed with a single purpose in mind – to subvert the PLCs that control the centrifuges critical to the uranium enrichment process. The report then puts forward the idea that this was not the work of a lone psychotic hacker or even a high-tech organised crime syndicate, but rather, the work of a nation (or nations) that stood to benefit from a disruption to the nuclear development programme in Iran.

Spread over the corporate network, the code is designed to seek out a specific industrial control configuration and then reprogram the PLCs to give the attached machinery a new set of instructions. Research by cyber security firm Symantec indicates that the idea was to disrupt the PLCs and frequency controllers used to regulate the speed of the centrifuge motors at the enrichment plant in Iran. In particular, Symantec said, it was designed to target those operating at frequencies between 807 and 1210 Hz, the typical range used for control in this type of application. It knew exactly what it was looking for, and, as an added sophistication, the code recorded what normal operation looked like and then ‘played’ these readings back to the operators while the centrifuges spun out of control and tore themselves to pieces.

Jim Pinto makes an interesting point in his e-newsletter of 28 January. He says that an Israeli intelligence agency, as well as Hillary Clinton, announced separately that they believed the incident had set Iran’s nuclear efforts back by several years.

Night Dragon – new-age industrial espionage

No sooner had I come to terms with the realisation that there is now pre-emptive ‘first-strike’ cyber capability out there, than I became aware that industrial espionage has not been slow to elevate itself to a similar level.

From an article that appeared on Automation World: “Cyber espionage hit the headlines recently with reports of a series of hacker attacks – dubbed Night Dragon – aimed at major global energy players. The sophistication is significantly lower than that of the notorious Stuxnet worm, but the Night Dragon attacks, believed to be largely the work of Chinese hackers, have nonetheless been successful in achieving their apparent objective – that of intellectual property theft from global oil and gas, energy and petrochemical companies.”

According to a McAfee report a series of coordinated covert and targeted cyber attacks have been conducted against global oil, energy and petrochemical companies since November 2009. These have involved social engineering, spearphishing attacks, exploitation of Microsoft Windows operating systems vulnerabilities, and the use of remote administration tools (RATs) to harvest sensitive proprietary operational and financial information relating to oil and gasfield bids and operations. In certain cases, the attackers were even able to reach down to a level where they could access and collect data from the companies’ scada systems.

The report goes on to say that in 2010 we entered a new decade in the world of cyber security that is setting up to be an exponential inflection point. Today’s hackers are leveraging productised toolkits that enable them to develop more sophisticated malware in a much shorter ‘time to market’ frame. Having matured from the previous decade, they look set to release the most insidious and persistent cyber threats ever known.

Along with contributing editor Andrew Ashton, I have been following these and other such stories with interest. While we both believe that South Africa probably is not under immediate threat of a pre-emptive cyber strike to any of its automation networks, the threat to sensitive company information is ever-present and should not be ignored, particularly if the attackers can infiltrate down to the level of the scada and PLC. Over the next few months we will be investigating the magnitude of these types of threat in a local industrial automation context – keep an eye on this space.

Process Expo 2011 show dates have changed

Due to a clash with the local government municipal elections on 18 May, Process Expo 2011 has been rescheduled for 24-26 May. The venue is still Nasrec (see “Urgent: Dates change for Process Expo 2011”).

Training is getting a higher profile this year, for the first time the Expo incorporates the Process Training Academy that will offer visitors 90 cutting-edge, industry specific workshops over the three show days. To register for training or as a visitor, please visit www.process-expo.co.za and complete your details. Entrance and training are both free of charge and the training schedule can be viewed at http://instrumentation.co.za/papers/training.xlsx.

Steven Meyer

Editor: SA Instrumentation & Control

[email protected]



Credit(s)



Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Reinstatement opportunity for ECSA registration
News
In 2023 the Engineering Council of South Africa (ECSA) announced a special opportunity for engineers in South Africa to reinstate their registration status if it had been cancelled. This exclusive offer is available until the end of August 2024.

Read more...
Africa Automation Indaba 2026
News
A bold new chapter in Africa’s industrial evolution begins with the launch of the Africa Automation Indaba, set to take place from 13 to 14 May 2026 at the prestigious Radisson Collection Hotel in Cape Town.

Read more...
EtherCAT Technology Group holds another Plug Fest
News
Recently, the EtherCAT Technology Group (ETG) once again invited its members to a Plug Fest, this time specifically targeting developers and manufacturers of devices with Safety over EtherCAT (FSoE) functionality.

Read more...
BMG powers up at Nampo 2025
News
The BMG team was highly prominent at this year’s Nampo agricultural show, held near Bothaville recently. This prestigious event, which is one of the largest agricultural exhibitions in the southern hemisphere, is a highlight for manufacturers and suppliers of farming equipment, as well as for farmers, families and the entire community.

Read more...
Epiroc rocks youth development programmes
News
Epiroc is not just building equipment - it’s building futures. Through its dynamic internship and learner programmes, the mining equipment and services specialist is shaping South Africa’s next generation of skilled professionals, equipping them with real-world experience, industry knowledge and the confidence to launch successful careers.

Read more...
Schneider Electric drives innovation in Africa
Schneider Electric South Africa News
Schneider Electric has officially launched its first Innovation Hub on the African continent, coinciding with the opening of its new regional headquarters in Midrand, South Africa.

Read more...
Schneider Electric South Africa certified as 2025 Top Employer
Schneider Electric South Africa News
Schneider Electric is proud to announce its South African operation has been awarded Top Employer 2025 certification by a global authority in HR excellence, Top Employers Institute.

Read more...
100 years of safety leadership
News
DEKRA Industrial and its adult-based education and occupational skills training division, the Institute of Learning (IOL) will showcase a milestone at A-OSH 2025, as the company celebrates DEKRA Global’s 100 years of safety leadership.

Read more...
Drakenstein Municipality aces Schneider Electric’s Sustainability Impact Award
Schneider Electric South Africa News
Drakenstein Municipality in the Western Cape has won a Sustainability Impact Award for Schneider Electric’s Anglophone Africa region, shining the spotlight on its unwavering commitment to sustainable leadership and its forward-thinking approach to ensuring a sustainable future for its coming generations.

Read more...
LH Marthinusen launches new industrial fan manufacturing and services factory
News
LH Marthinusen has launched its new industrial fan manufacturing and services factory in Ekurhuleni. THis is a major milestone for South African energy infrastructure growth.

Read more...









While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd | All Rights Reserved