Showing posts with label Chemical Facility Security. Cyber Security. Show all posts
Showing posts with label Chemical Facility Security. Cyber Security. Show all posts

Thursday, May 12, 2011

Congressional Hearing Updates 5-11-11

Mid-week brought some changes to the Congressional Hearing schedule that may be of interest to the chemical security community. Two hearings were postponed and a new one was added.

Postponed Hearings

The House Energy and Commerce Committee got bogged down in their mark-up of HR 5 so they did not get a chance to work on HR 908, the CFATS extension bill proposed by members of that Committee. That mark-up was postponed until a date to be announced next week.

The Senate Commerce, Science and Transportation Committee did not provide a reason when they postponed their hearing today on cyber security. No future date was given. Last minute postponements are getting to be a habit with this Committee.

New Mark-up Scheduled

The House Homeland Security Committee announced yesterday that its Transportation Security Subcommittee will hold a markup hearing today on HR 1690, the MODERN Security Credentials Act. This bill is apparently being fast-tracked by the Homeland Security Committee as it was just introduced last week.

Tuesday, March 29, 2011

IGSS White Paper Published

Yesterday Eric and Joel published the second white paper in their series of publications dealing with the multiple-system vulnerabilities discovered/publicized by Luigi last week. This document, published on TofinoSecurity.com, deals with the vulnerabilities identified in the 7-Technologies IGSS platform.

There will be some that will point out the similarities between this white paper and initial publication on the ICONICS Genesis vulnerabilities. This was to be expected on a couple of levels; there are common vulnerabilities in the two systems, and many of the security responses would be the same for a variety of vulnerabilities. A closer look at this new publication shows the work done on identifying the differences between the vulnerabilities in the two systems.

One of the main differences here is that the vulnerable system is not just a HMI program, but is an actual Supervisory Control and Data Acquisition (SCADA) system. Additionally, the vulnerabilities affect two different executable programs within the systems communicating on two different ports.

This new white paper also includes six ‘compensating controls’ that owners/users should take to protect their systems pending the publication of patches by 7-Technologies. Five of these controls are the same as those found in the initial white paper, which is not surprising since they should already be in place in any ICS security program.

The one new control replaces the recommendation to change the default port used in the Genesis system. The new control recommends the installation of an intrusion detection system to help the user/owner to detect someone trying to exploit these (and any other un-reported) vulnerabilities. This recommendation was made possible by the recent release of IDS signatures for the IGSS platform by the two IDS systems identified in this white paper (and no, neither is produced by Byres Security).

Another good piece of work by Joel and Eric. I look forward to seeing the two white papers on the remaining systems identified by the Luigi vulnerability release.
 
/* Use this with templates/template-twocol.html */