'Shamoon' computer virus attack marked new height in international cyber conflict

Feb 13, 2013 by Jeff Falk

The deployment of the "Shamoon" computer virus against the Saudi Arabian Oil Co. last year was an important new development in international cyber conflict. Shamoon must put all providers of critical services on alert and requires concerted action by governments and private interests, according to a new working paper from Rice University's Baker Institute for Public Policy and the International Institute for Strategic Studies (IISS) in Manama, Bahrain.

The paper, "Hack or Attack? Shamoon and the Evolution of Cyber Conflict," was co-authored by Christopher Bronk, a fellow in at the Baker Institute, and Eneken Tikk-Ringas, a senior fellow for cybersecurity at the IISS. The paper documents the Shamoon case and considers its impact on broader policymaking regarding the Middle East, energy and cybersecurity issues. The paper has been approved for publication in the March issue of the journal Survival, and Strategy.

"Although the Shamoon attack did not result in any physical damage to in the Middle East, there has been a secondary impact on risk assessment for providers of critical services worldwide," Bronk said. "Shamoon is a reminder that enterprises need to be alert about the possibility of becoming the target of a politically motivated cyberincident."

On Aug. 15, 2012, the Saudi Arabian Oil Co. (also known as Saudi Aramco) was struck by a that possibly spread across as many as 30,000 Windows-based personal computers operating on the company's network. The company is Saudi Arabia's national petroleum concern and a producer, manufacturer, marketer and refiner of crude oil, natural gas and . According to news sources, it may have taken Aramco almost two weeks to fully restore its network and recover from the disruption of its daily business operations caused by data loss and disabled workstations resulting from the incident. The computer security research community dubbed the virus Shamoon.

While Aramco leadership has asserted that production was unaffected, the authors said there are important questions from the Shamoon case germane to other players in oil and gas and elsewhere in industry. "But the critical point for policy is how government, commercial actors, the international system and other players share and manage cyberincident risk," Bronk said. "Shamoon identifies just how broadly a major cyberattack can impact key national capabilities and concerns."

The authors argue that the Shamoon incident calls for a review and refinement of critical infrastructure policies (CIP) and joint efforts between governments and private interests.

"Developing working public-private partnerships in CIP is a challenging task, as it requires very careful consideration by government of relevant business goals and processes as well as appreciation of the governmental threat assessment logic and the required supervisory steps by the private sector," Tikk-Ringas said. "Although the need for public-private protection and defense models has been acknowledged, the policy goals and business routines are difficult to marry without resistance." She said a plan of action for achieving a working CIP model will need a balanced role division.

The authors said cyberattacks against critical infrastructure are unlikely to go unnoticed, and therefore, an appropriate response is in order. "This raises the questions of strategic communications, decision-making about who responds to which aspects of the incident and how," Tikk-Ringas said. "Such transgressions challenge national security and raise the questions of use of force considered by lawyers of international conflict. Therefore, responses to CI cyberincidents matter from both national authority and general deterrence perspectives and, in the light of the Aramco-Shamoon incident, require special attention by enterprises, governments and international organizations alike."

Explore further: LinkedIn membership hits 300 million

More information: "Hack or Attack? Shamoon and the Evolution of Cyber Conflict" working paper: www.bakerinstitute.org/publications/ITP-pub-WorkingPaper-ShamoonCyberConflict-020113.pdf

add to favorites email to friend print save as pdf

Related Stories

Cyber war targets Middle East oil companies

Oct 22, 2012

Middle Eastern oil and gas companies have been targeted in massive attacks on their computer networks in an increasingly open cyber war where a new virus was discovered just this past week.

Virus origin in Gulf computer attacks in question

Sep 04, 2012

(AP)—Security technicians are beginning to suspect that highly targeted virus attacks were behind the recent crippling of computer systems at two major Gulf energy companies, even as questions swirl about ...

Recommended for you

LinkedIn membership hits 300 million

Apr 18, 2014

The career-focused social network LinkedIn announced Friday it has 300 million members, with more than half the total outside the United States.

Researchers uncover likely creator of Bitcoin

Apr 18, 2014

The primary author of the celebrated Bitcoin paper, and therefore probable creator of Bitcoin, is most likely Nick Szabo, a blogger and former George Washington University law professor, according to students ...

White House updating online privacy policy

Apr 18, 2014

A new Obama administration privacy policy out Friday explains how the government will gather the user data of online visitors to WhiteHouse.gov, mobile apps and social media sites. It also clarifies that ...

User comments : 1

Adjust slider to filter visible comments by rank

Display comments: newest first

frajo
not rated yet Feb 14, 2013
[1]
Such transgressions challenge national security and raise the questions of use of force considered by lawyers of international conflict

Saudi Arabia is a tyranny - anti-democratic, violator of human rights, with Shariah based laws, suppressor of the freedom fighters in Bahrain.
So who is to consider the "use of force" against whom?

[2]
struck by a computer virus that possibly spread across as many as 30,000 Windows-based personal computers
Congratulations. This was the first virus related PhysOrg article I read that did not omit the Windows aspect.

More news stories

Ex-Apple chief plans mobile phone for India

Former Apple chief executive John Sculley, whose marketing skills helped bring the personal computer to desktops worldwide, says he plans to launch a mobile phone in India to exploit its still largely untapped ...

Airbnb rental site raises $450 mn

Online lodging listings website Airbnb inked a $450 million funding deal with investors led by TPG, a source close to the matter said Friday.

Health care site flagged in Heartbleed review

People with accounts on the enrollment website for President Barack Obama's signature health care law are being told to change their passwords following an administration-wide review of the government's vulnerability to the ...

A homemade solar lamp for developing countries

(Phys.org) —The solar lamp developed by the start-up LEDsafari is a more effective, safer, and less expensive form of illumination than the traditional oil lamp currently used by more than one billion people ...

NASA's space station Robonaut finally getting legs

Robonaut, the first out-of-this-world humanoid, is finally getting its space legs. For three years, Robonaut has had to manage from the waist up. This new pair of legs means the experimental robot—now stuck ...

Filipino tests negative for Middle East virus

A Filipino nurse who tested positive for the Middle East virus has been found free of infection in a subsequent examination after he returned home, Philippine health officials said Saturday.

Egypt archaeologists find ancient writer's tomb

Egypt's minister of antiquities says a team of Spanish archaeologists has discovered two tombs in the southern part of the country, one of them belonging to a writer and containing a trove of artifacts including reed pens ...