Slashdot Mirror


Iran's Oil Industry Hit By Cyber Attacks

wiredmikey writes "Iran disconnected computer systems at a number of its oil facilities in response to a cyber attack that hit multiple industry targets during the weekend. A source at the National Iranian Oil Company (NIOC) reportedly told Reuters that a virus was detected inside the control systems of Kharg Island oil terminal, which handles the majority of Iran's crude oil exports. In addition, computer systems at Iran's Oil Ministry and its national oil company were hit. There has been no word on the details of the malware found, but computer systems controlling several of Iran's oil facilities were disconnected from the Internet as a precaution. Oil Ministry spokesman Ali Reza Nikzad-Rahbar told Mehr News Agency on Monday that the attack had not caused significant damage and the worm had been detected before it could infect systems."

3 of 115 comments (clear)

  1. Re:how long? by arglebargle_xiv · · Score: 5, Interesting

    before Iran retaliates and the whole thing escalates into WW3

    There's almost nothing of any note on Kharq Island any more, most of it was destroyed during the Iran/Iraq war and never rebuilt. Have a look on Google Maps/Earth, there's a handful of oil storage tanks down the southern end, most of them completely empty, and one single ship that's almost certainly a bulk carrier (not an oil ship) docked there. The only reason Iran bothers to maintain a presence there is to extend their territorial claims into the Persian Gulf.

    This is some sort of political shenanigans being played by Iran, nothing more.

  2. Re:Quite by ledow · · Score: 4, Interesting

    You can have Internet access on the computer next to it - what's that got to do with having critical control systems accessible over the Internet?

    1) Separate the two PHYSICAL networks.

    2) Make sure that there are only authorised devices sit on the control network and NEVER anything else (big, huge, red lights and warnings when something new is detected).

    3) Make sure that even pulling the Internet cable out does not in any way affect the control system, and that tampering with the control system or even detecting a single packet destined for or originating from anything other than authorised devices sets off so many warnings people wouldn't even try.

    4) IF YOU REALLY MUST - make the control system expose only the absolute minimum of controls (i.e. don't trust user input and act only on a given, set, limited protocol of commands) over an encrypted protocol to only authorised devices from authorised networks that know all the one-time-passwords and whatever else you want to use to secure it. And never expose any interface that has the potential to be compromised autonomously (e.g. web interfaces etc.) - there's no need for it and the interface should NEVER be able to do anything but issue valid commands with all appropriate normal safeguards applied to them.

    You do NOT need a general purpose operating system to run a nuclear reactor - it's not only an incredibly bad idea, they warn you against doing things like that in the OS EULA itself because it's JUST NOT GOOD ENOUGH and provides too much scope for mischief.

    One day, someone is going to end up running a nuclear reactor on Windows or something because they're just too thick to realise that's a problem and the slow creep of GPOS's into our lives will mean they will see nothing wrong with it.

  3. Re:Cold war by AmiMoJo · · Score: 4, Interesting

    To those who modded me -1 Troll:

    What is your explanation for this behaviour? The US and Israel are at war with Iran, invading their air space with drones, surrounding them with military bases and the US Navy, and launching cyber-attacks against their infrastructure. Do they think that if they keep at it Iran will just give up and abandon all nuclear and space research, give up their arms and become a placid non-threatening nation? With Israel still right next door?

    How do you think this is going to end? What possible sequence of events could lead to a peaceful resolution? How will attacking Iran make them decide to stop developing nuclear weapons?

    --
    const int one = 65536; (Silvermoon, Texture.cs)
    SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC