18 Oct 2011
The US government has warned that Anonymous could be planning to launch attacks on industrial control systems (ICS) that are vital to the safe operation of key facilities including water, chemical and energy plants.
An unclassified bulletin from the US Department of Homeland Security's (DHS) National Cybersecurity and Communications Integration Center points to several examples apparently highlighting "a recent interest Anonymous has developed in exploiting ICS".
These include a Tweet by an Anonymous member in July that showed the "results of browsing the directory tree for Siemens SIMATIC software", a type of industrial automation software.
While the DHS said that Anonymous appears to currently have "limited ability" when it comes to the knowledge and skills necessary to attack ICS systems, it warned that these capabilities could be developed "to gain access and trespass on control system networks very quickly".
"Free educational opportunities (conferences, classes), presentations at hacker conferences, and other high-profile events have raised awareness of ICS vulnerabilities, and likely shortened the time needed to develop sufficient tactics, techniques and procedures to disrupt ICS," it added.
In addition, exploits for control systems are found in common pen testing software, while some control systems can be accessed directly from the internet, increasing the risk of attack, said the bulletin.
"These systems could be easily located and accessed with minimal skills in order to trespass, carry out nefarious activities, or conduct reconnaissance activities to be used in future operations," the DHS said.
"Asset owners and operators of critical infrastructure control systems are encouraged to engage in addressing the security needs of their control system assets."
Industrial control system flaws hit the headlines with the discovery of the infamous Stuxnet worm, believed to have been designed to target Siemens Scada systems in Iranian nuclear facilities.
Since then there have been frequent disclosures of vulnerabilities in similar industrial control systems. For example, in April 52 new Scada threats were revealed by security management firm Idappcom.
Researchers at NSS Labs were then involved in a very public spat with Siemens arguing that the firm was not doing enough to fix known vulnerabilities.
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Java, J2EE Agile Senior Developer, Warrington, Cheshire...
Location: Geneva Client: A well established world...
Location: Geneva Client : A well known company Job...
Location: Lausanne Client: A well established world...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Conspiracy
The US government tolerates 'Anonymous' because they can use the group to launch cyber attacks by proxy, in the same way the Chinese gov controls the Honker Union.
Posted by: Ralph 09 Nov 2011
Crock of S**T
What a crock of s**t. Unable to use the bin laden bogey story anymore ("cause he's dead"), they are attacking anonymous. Funny how this all happens when the 1% start to lose control of the 99%. Who ever believes this is a nonce!
Posted by: james 18 Oct 2011