Showing posts with label Cyber Warfare. Show all posts
Showing posts with label Cyber Warfare. Show all posts

Monday, June 9, 2014

Full Committee Draft of FY 2015 DOD Appropriations Bill

Today the House Appropriations Committee published a draft version of the FY 2015 DOD spending bill that they will markup tomorrow. A copy of the draft bill is here and a draft of the Full Committee Report is here. I did not see any specific mention of cybersecurity or cyber-warfare issues in the draft bill.

There is a paragraph (pg 268) about cybersecurity research in the draft version of the Committee Report that concludes by recommending that:

Accordingly, the Committee encourages the Secretary of Defense to leverage information assurance and cyber defense research done through defense agencies, including the National Security Agency, as the Department plans and conducts interdisciplinary research to identify and close cybersecurity gaps.

Well, the good stuff is probably in the classified annex of the bill and report.


Tuesday, April 29, 2014

Bills Introduced – 4-28-14

House and Senate are both back in session after their two week Easter Recess and introduced 27 bills. Only one of those may be of specific interest to readers of this blog:

HR 4500 Latest Title: To improve the management of cyber and information technology ranges and facilities of the Department of Defense, and for other purposes. Sponsor: Rep Kilmer, Derek (D,WA)


Cyber warfare is not exactly cybersecurity, but this bill may contain some cybersecurity provisions of interest. We will just have to wait and see what it contains when it becomes available.

Saturday, May 19, 2012

House Passes HR 4310 with Cyber Measures


Yesterday, after two long days of debate including the consideration of over 100 amendments the House passed H4310, the National Defense Authorization Act for Fiscal Year 2013, by a bipartisan vote of 299 to 120. The cyber provisions of the bill that I described in an earlier blog remain in the bill (one with a floor revision). Three cyber-related amendments to the bill were considered during the floor debate; all passed by voice vote.

There is still nothing specifically addressing industrial cybersecurity or control system security, but it does offer a look at the expansion of congressional interest in cyber operations. The interesting thing about the votes on these three cyber-related amendments is that they were considered as part of three separate ‘en bloc’ votes containing 15 or more other amendments. Such groupings are made up of non-controversial amendments because significant opposition to even one of the members of the group could result in all of the amendments being voted down.

Amending Offensive Operations in Cyberspace


In the earlier blog I noted that the bill considered this week amended the current congressional authority to conduct operations in cyberspace to specifically authorize clandestine operations in support of congressionally cleared operations. Rep. Rogers (R,MI) offered an amendment that would clarify that while clandestine operations would be authorized nothing “in this section shall be construed to authorize a covert action” {§954(d)}. While there may be more sophisticated explanations for the difference between ‘clandestine’ and ‘covert’ here it appears to rest upon the type of Congressional authorization required for the action.

Air Force and Cyber Security


Rep. Hanna (R,NY) offered an amendment that would require the Secretary to report on Air Force cyber operations research, science, and technology. Most of this is amendment is focused on military operations in cyberspace, but the last sub-paragraph requires the inclusion of a review of the “potential benefit to the Air Force for collaboration with private industry and the development of cyber security technology clusters” {§245(9)}. While not specific to control system security, any additional research into cybersecurity will probably be beneficial to the ICS  processes.

Interagency Coordination


The final cyber-related amendment was offered by Rep. Thornberry (R,TX) that would require the establishment of an interagency organization that would “coordinate and deconflict full-spectrum military cyber operations for the Federal Government” {§1084(a)}. While this is probably directed at DOD agencies (it does refer to military ‘cyber operations’ after all), this could be expanded to include non-DOD agencies like DHS. Coordination of government cyber operations (coordination of anything, for that matter) is probably a good thing in general.

Moving Forward


Now that it has passed in the House we can expect that the Senate will start with its own version of the bill (which I haven’t seen yet) and then the two will get reconciled in conference. It’s anybody’s guess as to what will survive that process.

Tuesday, November 16, 2010

Vulnerability Disclosure

Andrew Ginter has an interesting posting on his Control System Security Blog (also posted on the Findings From the Field blog) talking about public disclosure policies for discovered cyber vulnerabilities. This is a recurring topic in the cyber security community, but Andrew adds a new dimension to the discussion after looking at the latest discoveries made by Symantec about the Stuxnet worm. Those discoveries seem to point even more firmly towards Stuxnet being a cyber weapon targeted at Iranian nuclear processing capabilities.

Control System Vulnerability Disclosure

Andrew does a very good job of describing the standard debate between security researchers (those who discover vulnerabilities) venders (those who create and must fix vulnerabilities) and system owners (who might get attacked via the vulnerabilities). I’ll summarize briefly here (and the summary is my fault not Andrew’s):

● Researchers – want their discovery released so that they get full and open credit for their prowess in detecting vulnerabilities.
● Venders – want to keep vulnerabilities quiet as they make them look bad and they have to take people away from new product development to fix something that they have already sold.
● Users – want to know about the vulnerabilities, want them fixed, but don’t want anyone telling potential attackers how to get inside their systems.
Weapon System Disclosure

When a cyber weapon (like maybe Stuxnet) is involved, as Andrew points out, the problem becomes even more clouded. First off we, presumably, add a government or two to the mix of players. The first is the target government and the second is the targeting government. Their motivations in the disclosure debate are even more complex.

When a cyber weapon is covert the government wielding the weapons does not even want its existence disclosed as that would decrease the potential effectiveness. They certainly don’t want the detailed mechanisms of the weapons disclosed as this would make it easier to defend against. And they probably don’t want their identity as the weapon wielder disclosed; it could expose them to retaliatory attacks (and not necessarily cyber attacks either).

There are potential reasons that the targeted government would not want it disclosed that they were the target of a cyber attack. The disclosure of an attack almost requires a knee-jerk requirement for a retaliation; the more effective the attack the stronger the required response. If a government does not think that it has the where-with-all to mount an effective response, it might not want the attack exposed. Or it may want to use a period of non-disclosure for planning and mounting an appropriate counter attack. If it didn’t look like they knew they were being attacked, perhaps the attacker would be less diligent in looking for the counter-attack.

The innocent bystanders, in this case other control system owners not involved in either the attack from either side, also have a complex outlook about disclosure. At first it would seem obvious that they would want disclosure about the attack vector/method so that they could consider deploying defenses to defend their system from similar attacks. The argument against disclosure from this view point is a bit more convoluted, but still potentially very real.

Stuxnet is a large and convoluted piece of software. According to most commentors it required a lot of assets and knowledge to put together and deploy. The list of countries with the in-house expertise to construct this cyber weapon is fairly limited, by some estimates no more than a half-dozen countries; most of whom the United States considers friendly to our interests. That keeps us relatively safe against a similar attack, or at least common wisdom would seem to hold that point of view.

The problem is that ‘weapons’ like Stuxnet, once they are understood, are relatively easy to duplicate and modify; the hard work has been done. The key word there is, of course, ‘understood’. So, full disclosure here would almost certainly increase the number of countries (and potentially groups) that could file off the serial numbers and re-direct Stuxnet type weapons at whom ever they desired.

Pandora’s Box is Open

Unfortunately, Andrew’s valuable discussion is about two months too late. The details about Stuxnet that have been released by Langner and Symantec are almost certainly enough to increase the number of Stuxnet capable countries by a factor of at least two. The cyber weapon arms race has almost certainly begun and there is no non-proliferation agreement.

To make matters worse there is already an international arms market in existence for the ‘small arms’ in this weapons race. There is also a growing ‘small arms’ independent research establishment in existence supporting that arms market. Both will almost certainly realize that scaling up their research and weapons development to the industrial scale is not only possible, but certainly profitable.

We better start building better defenses quick. The offense always has the benefit in the arms race between offense and defense. We better not get too far behind.

Tuesday, September 21, 2010

Stuxnet and the Future

Late yesterday Dale Peterson at DigitalBond.com posted “[o]ne more Stuxnet post before we move on.” As typical, Dale’s blog post provides us with some valuable in-sight into Stuxnet. I certainly hope, though, that he isn’t implying that this will be the last post on the matter. He has been a good source of updated information about Stuxnet, explaining things that he and others have found out about the operation of Stuxnet.

Stuxnet Response

In this post Dale isn’t really looking at the details of Stuxnet; rather he is looking at how the industrial control system network responded to one of the most creative and complex assaults on system security. In his analysis ICS-CERT and Siemens come off looking bad while Langner Communications and Symantec received some well deserved praise.

Dale’s complaints about ICS-CERT are particularly important. This DHS office is the one charged with supporting cyber security activities in the industrial control sector. Since most companies using these control systems do not have the resources to watch out for, investigate, and formulate a response to sophisticated attacks like Stuxnet we turn to the Government for this type of support.

Dale points at possible political issues hampering a more aggressive public ICS-CERT response to Stuxnet. Unfortunately he doesn’t explain what stopped them from being able to “clear the bureaucratic hurdles required to release more information”. If Stuxnet was actually an Israeli attack on Iranian nuclear fuel processing as Dale and others have suggested as being a plausible explanation for the sophistication of the attack (and I agree that it does sound extremely plausible), then the intelligence community would have been reluctant to see that information released.

That would have been a piss poor (though entirely predictable) reason to restrict the spread of information about Stuxnet. Once Iran was identified as having an unusually large number of Stuxnet infections it didn’t require a great deal of ‘jumping to conclusions’ to start to think that Israel might have discovered a new means to execute offensive operations against a target that they have publicly warned that they intend to attack before Iran could produce a nuclear weapon.

Actually I suspect that the ICS-CERT failure in this situation was more based upon resources and a lack of imagination than the lack of political will. While DHS is a large organization their manpower is spread thin. Their lack of depth is further aggravated by the political necessity of having a huge amount of manpower involved in the symbolic protection of commercial air traffic. We continue to see understaffed agencies ‘protecting’ high-risk chemical facilities, Hazmat pipelines, and toxic freight rail targets. Until those targets are actually hit, the politicians will continue to only provide token monies to support those programs.

Cyber Weapons

As we continue to hear discussions about cyber warfare and governmental cyber attacks, this Stuxnet incident points out a unique problem with cyber weapons, once they are employed in the wild, they become public property. While Langner Communications and Symantec have done some valuable work explaining what Stuxnet does and how it works, we must not forget that every government in the world with a modicum cyber expertise has been hard at work doing the same thing.

Dale touches briefly on this in his posting, but I think that this deserves more attention. The developers of Stuxnet (Mosad, the Russian Mob, a bored pimply-faced kid, who ever) has done the hard work. They developed the tools to attack Siemens-based control systems. Those installed systems will now be forever suspect of being vulnerable to attack. And any government, any large criminal organization, will have access to the tools necessary to execute those attacks.

We are now at the cyber equivalent of August 1945, with the Stuxnet shaped cloud rising on the horizon, proclaiming that the world will never be the same again. If this was an attack on the Iranian nuclear program, the irony is totally appropriate. With the potential ability to conduct anonymous attacks on civilian and military infrastructure at will we are heading into a dangerous new era of international politics.

Unfortunately, it will be the private sector in the United States that will bear the brunt of the damage and cost of this new type of warfare. The targets will largely be owned by private companies and they will bear the brunt of both defending against and responding to the results of those attacks.

The world has become an even more dangerous place and there’s not much we can do about.
 
/* Use this with templates/template-twocol.html */