Actionable Intelligence for Malware Defense.

Blog » USB Drives Continue to Infect Sensitive ICS Machines
Blog
USB Drives Continue to Infect Sensitive ICS Machines
2013.01.29 | By John Dennis | 0 comments

There have been many articles about infected USB drives spreading malware to sensitive systems. Recently, ICS-CERT assisted a power generation facility where both common and sophisticated malware had invaded the ICS environment.

The discovery happened perchance. An employee was having issues with the USB drive’s operation and asked the IT team to have a look. The employee routinely used the drive to back up control system configurations within the control environment.

ICS-CERT determined that several computers were likely infected by the USB drive and conducted an in-depth analysis of the drives. There were signs of sophisticated malware on two engineering workstations, both important to the operation of the facility. Neither machine was backed up regularly, so it was critical for ICS-CERT successfully scrub the workstations.

Clearly, a more thorough defense-in-depth strategy would have significantly increased the chances of discovering the tainted USB drive prior to it infecting any workstations.

At another company, managers contacted ICS-CERT to report an infected turbine control system, which impacted 10 computers on the control system network. After an investigation, it was clear that a third-party technician used an infected USB drive to upload software updates. The infection caused the control system to be nonfunctional for three weeks.

Once again, a robust defense system, including up-to-date antivirus software, would have prevented this infection and downtime.

To read more about these incidents, click here: http://www.us-cert.gov/control_systems/pdf/ICS-CERT_Monthly_Monitor_Oct-Dec2012.pdf

Security solution leaders, such as Norman Shark, offer multiple solutions for threat discovery and analysis that help IT departments and security teams protect networks from infection, and minimize the impact on internal systems once an attack is discovered.

Sometimes, IT teams realize they don’t have the expertise, budget or time to strategize and implement a comprehensive defense-in-depth approach, and end up shelving the project entirely. Even installing basic antivirus software and creating a partial solution is better than having no protection at all. Automated solutions, such as those offered by Norman Shark, can form a highly-effective, cost efficient approach for extending basic antivirus protection and the capabilities of overstretched teams.

“In today’s climate of persistent threats, network defense alone is no longer enough. In order to protect networks from the proliferation of targeted attacks and unknown threats, analysts need dynamic malware intelligence capabilities that allow them to respond quickly in the event of an incursion.”