Impact of stochasticity and time delay on stuxnet virus propagation in critical control systems
Abstract
A complex computer worm that was first discovered in 2010, Stuxnet targeted industrial control systems and led to physical sabotage of production processes all without being detected. Symantec estimates that over 100,000 computers were infected by the malware, with around 60% of infections occurring in Iran. The worm disrupted 900-1,000 uranium-enrichment centrifuges at Iran’s Natanz facility. In this paper, we propose a stochastic time-delayed compartment model to simulate the propagation process of the Stuxnet cyber-virus in critical industrial control systems. The total population of computing nodes is divided into susceptible, infected, and damaged compartments, denoted by S ( t ), I ( t ), and P ( t ). Additionally, removable storage media such as USB devices are classified into two infection states: susceptible and infected, represented by \(U_s(t)\) and \(U_i(t)\) . To capture realistic transmission dynamics, the model accounts for both stochastic perturbations and time delays, which reflect environmental fluctuations and latent infection effects. The malware-free and endemic equilibria are identified, and a coupled stochastic invasion threshold, \(\mathcal {R}_{0}^{S}\) , is derived from the joint dynamics of infected computers and infected removable storage devices. The threshold includes both direct computer-to-computer transmission and the indirect computer–USB–computer transmission cycle and is used to characterize local malware extinction and initial invasion. Real epidemiological data are incorporated to parameterize the model and support the numerical simulations. In numerical computations, we use the stochastic Euler scheme, the stochastic fourth order Runge-Kutta scheme and an original nonstandard finite difference scheme that is positivity and boundedness preserving. The findings of the simulations validate theoretical results and provide a way in which stochasticity and delays affect malware propagation. These findings can be considered a significant move towards achieving prevention and defense measures against advanced cyber threats on industrial infrastructures.
// Source
Authors: Ali Raza, Umar Shafique, Marek Lampart, Dumitru Baleanu, Emad Fadhal, Hadil Alhazmi
Institutions: University of Turku, Princess Nourah bint Abdulrahman University, King Faisal University, Lebanese American University, VSB - Technical University of Ostrava