An Operating System for the Cyber War Era
As I wrote last week and today, there is rising concern that the control systems of infrastructure such as power grids and nuclear plants are dangerously naive in an era of targeted attack software (see “Old-Fashioned Control Systems Make U.S. Power Plants a Hacking Target” and “Preparing for Cyber-War, Without a Map”). Now one computer security company says it is building a new operating system that will protect such systems, wrapping out-dated control software in a protective barrier.
Eugene Kaspersky, founder of the Russian company Kaspersky, which has led discovery and analysis of state-backed malware such as Stuxnet, wrote in a blog post today that the project was needed to protect “defenseless” industrial control software.
“Ideally, all ICS [industrial control system] software would need to be rewritten, incorporating all the security technologies available and taking into account the new realities of cyber-attacks. Alas, such a colossal effort coupled with the huge investments that would be required in testing and fine-tuning would still not guarantee sufficiently stable operation of systems.”
Creating a secure operating system onto which industrial control systems can be installed is feasible, claims Kaspersky, who added that his company’s researchers are on the road to completing it. However, while those motivations seems reasonable, one of Kaspersky’s claims for the as-yet-unfinished OS will be difficult to meet:
“To achieve a guarantee of security it must contain no mistakes or vulnerabilities whatsoever in the kernel, which controls the rest of the modules of the system. As a result, the core must be 100% verified as not permitting vulnerabilities or dual-purpose code.”
That will be challenging. Techniques exist that can prove code is without vulnerabilities or bugs, but they are impractical on more than just small chunks of code (see “Crash-Proof Code”). Even a limited operating system designed only for a small range of software to be installed will take considerable efforts to exhaustively check out.
Keep Reading
Most Popular
A Roomba recorded a woman on the toilet. How did screenshots end up on Facebook?
Robot vacuum companies say your images are safe, but a sprawling global supply chain for data from our devices creates risk.
A startup says it’s begun releasing particles into the atmosphere, in an effort to tweak the climate
Make Sunsets is already attempting to earn revenue for geoengineering, a move likely to provoke widespread criticism.
10 Breakthrough Technologies 2023
The viral AI avatar app Lensa undressed me—without my consent
My avatars were cartoonishly pornified, while my male colleagues got to be astronauts, explorers, and inventors.
Stay connected
Get the latest updates from
MIT Technology Review
Discover special offers, top stories, upcoming events, and more.