Ralph Langner: Decoding Stuxnet's Industrial Target
In the summer of 2010 the world's antivirus companies were looking at a strange new worm called Stuxnet and shrugging. It didn't steal credit cards or send spam. It just spread, and hunted for something.
The man who worked out what it was hunting ran a three-person consultancy in Hamburg and didn't have an internet connection at home. Ralph Langner knew Siemens industrial controllers better than most people at Siemens, and when he read the worm's code he saw a weapon aimed at one building.
Saying so out loud, in September 2010, made him either a crank or the most important security analyst of the decade. It took a few months to find out which.
Ralph Langner at a Glance
- Self-taught on computers, Langner founded his company in Hamburg in 1988, writing device drivers for industrial automation before specializing in the security of control systems.
- When Stuxnet surfaced in 2010, his three-man firm reverse-engineered its payload while the big security vendors and Siemens stayed quiet about what it did.
- On September 16, 2010, he published a blog post declaring Stuxnet a targeted sabotage attack on Iran's nuclear program, a claim colleagues thought was nuts until the evidence piled up.
- His March 2011 TED talk, "Cracking Stuxnet, a 21st-century cyber weapon," made him the public face of the story, and he named the United States as the leading force behind it.
- In 2013 he published "To Kill a Centrifuge," showing that Stuxnet was really two weapons, and that the earlier, stealthier one was the more dangerous.
- He wrote a book on robust control networks, advised the White House, the Pentagon, the Senate and the United Nations, and spent time as a Brookings Institution expert.
- Today he's founder and CEO of OTbase, the asset-inventory software his firm built after concluding that you can't defend industrial systems you can't see.
The Life of Ralph Langner
Langner's Early Years
Ralph Langner taught himself computers and in 1988 founded a company in Hamburg that wrote device driver software for industrial automation. It was unglamorous work that gave him two decades of intimate knowledge of programmable logic controllers, the boxes that run factories, pipelines and power plants.
By 2010 he and two engineers, Ralf Rosen and Andreas Tim, were a boutique consultancy focused entirely on control-system security. They knew Siemens equipment so well that they sometimes trained Siemens's own staff. "There are probably only a handful of Siemens employees who know this stuff better than we do," Langner said.
He kept his distance from the rest of the computer world. He had no internet connection at home.
A Worm Nobody Wanted
Stuxnet was found in June 2010 by a small antivirus firm. It used four zero-day vulnerabilities and two stolen digital certificates, and spread through Windows networks and USB sticks.
Symantec's researchers eventually published that the worm was tampering with Siemens PLCs, then waited for the industry to react. "Silence like crickets," one of them recalled.
In Hamburg, Langner read the post with fascination. "That was the point when Stuxnet got our attention," he said. "We thought, okay, now this is going to get interesting."
Siemens, he felt, should've been telling its customers what the code did to their controllers. Siemens said almost nothing. So Langner decided his team would do it themselves.
Inside the Lab
The three huddled around a panel of monitors in their small office, testing theories about what the code did to the controllers it infected. "We were pretty much working around the clock," Langner told NPR, "because after we had the first impression of the magnitude of this, we were just like on speed or something like that. It was just impossible to go back to sleep."
What they found was a dossier. Stuxnet carried a precise description of the facility it wanted, and any system that didn't match was left untouched.
"I was expecting some dumb DoS type of attack against any Siemens PLC," Langner recalled. "To see that somebody built such sophisticated piece of malware—using four zero-day vulnerabilities, using two stolen certificates—to attack one single installation? That's unbelievable."
The Phone Call
Langner had no doubt what kind of target it was. "This is about taking out Bushehr," he announced to Rosen and Tim, naming an Iranian nuclear plant. His colleagues stared at him.
He phoned a German client who worked for a leading maker of uranium-enrichment equipment and asked one question: "Is it possible to destroy a centrifuge just by manipulating the controller code?"
"I can't tell you that, Ralph, it's classified information," the man replied. That was all the answer Langner needed.
On September 16, 2010, he published a blog post declaring Stuxnet a targeted attack on Iran's nuclear program and sent press releases to German and international media.
"There was silence all around us," he said later. "Everybody was thinking, This guy is nuts. We always knew that Ralph is an idiot, and now we have the proof for it."
Mouths Open
Two weeks later Langner was due to speak at a closed-door industrial-security conference run by the American expert Joe Weiss, on a different topic. He asked to talk about Stuxnet instead. "I told him, I don't know whether to tell you yes or hell yes," Weiss recalled.
He was given 45 minutes and took an hour and a half. "All of us were sitting with our mouths open while he was talking," Weiss said.
Langner followed up with a series of posts laying out exactly how Stuxnet intercepted and injected commands into the controllers, along with a checklist for administrators. "With the forensics we now have it is evident and provable that Stuxnet is a directed sabotage attack involving heavy insider knowledge," he wrote. His website was flooded with traffic, including from US government domains.
He'd guessed the wrong plant. Other analysts argued for Natanz, Iran's enrichment site, and they were right: by December Symantec had tied the code to the frequency converters that spin centrifuges, and the physicist David Albright matched Stuxnet's target frequency, 1,064 hertz, to the centrifuges at Natanz, as Wired's Kim Zetter later reconstructed.
Cracking Stuxnet on Stage
In March 2011 Langner gave a ten-minute TED talk, "Cracking Stuxnet, a 21st-century cyber weapon," that's since been watched more than 300,000 times on YouTube alone. That spring and summer he said in interviews what most analysts would only whisper: the leading force behind Stuxnet was the United States.
"I'm in this business for 20 years," he told NPR that September, "and what we saw in the lab when analyzing Stuxnet was far beyond everything we had ever imagined." He hadn't been scared to publish, he said, though he'd thought about the Iranian nuclear scientists who'd been mysteriously killed.
His real worry was imitators. "In the long run it has opened Pandora's box," he told the Christian Science Monitor.
Stuxnet's Secret Twin
In November 2013 Langner published "To Kill a Centrifuge," the most detailed public analysis of the attack, and summarized it in an essay for Brookings, which by then counted him among its experts.
"Stuxnet is not really one weapon, but two," he wrote. The version the world knew, which sped centrifuges up and slowed them down, was the later and cruder one. An earlier variant had quietly attacked the plant's cascade protection system to over-pressurize the centrifuges, and "it was far more dangerous than the cyberweapon that is now lodged in the public's imagination."
He was writing policy for Brookings too, arguing in a 2013 paper that the cyber risk to infrastructure couldn't be "managed" away and needed real engineering rules.
From Consultant to Software Vendor
Langner's 2011 book, Robust Control System Networks, laid out how to build industrial networks that don't fall over when attacked. He consulted for the White House, the Pentagon, the US Senate and the United Nations, and former Navy Secretary Richard Danzig called him "the global authority on cyber-physical attacks."
In 2017 he set up Langner Inc. in the United States, and the firm changed shape, from consultancy to software company. Its product, OTbase, inventories every device, network and piece of software in an industrial plant, on the theory that nobody has ever secured a system they couldn't see.
Langner remains its founder and CEO. He's also revisited his own legend: a video on the company's channel is titled "Stuxnet TED talk 10 years ago: What I got completely wrong."
Ralph Langner: The Man Who Said It Out Loud
Plenty of people could read Stuxnet's code by the autumn of 2010. Langner was the one who understood what the code was for, said so in public, and kept saying it while the industry waited for someone more important to agree.
The lesson he drew wasn't about Iran. People had connected the machines running the physical world to networks, assuming nobody would bother to attack them. Stuxnet ended that assumption.
Sixteen years later he's still selling that lesson, one asset inventory at a time.
QUOTE:
"Amateurs hack systems, professionals hack people."