Showing posts with label Cybersecurity Research. Show all posts
Showing posts with label Cybersecurity Research. Show all posts

Saturday, June 25, 2022

GAO Reports – Response to Catastrophic Cyber Attack

This week the Government Accounting Office published a report looking at potential responses to address the financial fallout from a catastrophic cyberattack on critical infrastructure. It concludes that there are some major shortcomings in current insurance programs. It recommends that DHS and the Treasury Department take a concerted look at the situation and come up with potential program suggestions.

Specifically, the report notes (pg 1):

“Cyber insurance and the Terrorism Risk Insurance Program (TRIP)—the government backstop for losses from terrorism—are both limited in their ability to cover potentially catastrophic losses from systemic cyberattacks. Cyber insurance can offset costs from some of the most common cyber risks, such as data breaches and ransomware. However, private insurers have been taking steps to limit their potential losses from systemic cyber events. For example, insurers are excluding coverage for losses from cyber warfare and infrastructure outages. TRIP covers losses from cyberattacks if they are considered terrorism, among other requirements. However, cyberattacks may not meet the program’s criteria to be certified as terrorism, even if they resulted in catastrophic loss.”

Friday, April 23, 2021

Use and Misuse of CPE’s

Yesterday’s blog post dealt with problems with the current Common Platform Enumeration (CPE) system in keeping track of vulnerabilities that affect multiple systems. In writing that post I kind of glossed over how the CPE is used and how it could be used and misused in the cybersecurity environment.

Current CPE Use

Yesterday’s post was in response to a Twitversation initiated by Ron Brash (got it right today Ron). He was complaining that when a derivative vulnerability was reported using the CVE number from the original vulnerability, the CPE for the newly identified vulnerable devices were not being attached to the original CVE. This is a problem for folks like Ron because it prevents them from effectively using the intended use of the CPE. Let me explain.

If you own just a single control system device, it may be difficult to keep up with the vulnerabilities that affect that device. Some manufacturers do a good job of posting advisories to their web sites and folks like NCCIC-ICS and other CERTS do a good job of reporting on vulnerabilities coordinated through them or are reported to them by vendors. But if the vendor for your product does not publish advisories (an awful lot do not), and if a vulnerability is not reported through a CERT that you follow, it will be easy to miss vulnerability notices. The CPE system, in that case would help you keep track of your device vulnerabilities.

If you own hundreds of devices (not unusual in a manufacturing environment) with lots of different version numbers (again not unusual as equipment is added or replaced) that system of watching vendor web sites or CERT notifications gets a tad bit tiresome. This is where the CPE system really shines (when it is working right, see Ron’s complaint). All you have to do is to have a list of all of your devices and their respective CPE’s and you can write a script (okay I can’t actually write those scripts, but there are plenty of folks who can and that would be a valuable skill set to have in your security team) to periodically search the National Vulnerability Database (NVD) for vulnerabilities that reflect your specific devices.

Now that will not get all of the identified vulnerabilities as some countries do not fully report through the CVE system. But it will get the vast majority of vulnerabilities and should keep you up to date on the available mitigation measures that affect your devices. Then ALL you have to do is figure out how to implement those security measures.

Researcher CPE Use

Now if I were a cybersecurity researcher looking for vulnerabilities, one of the tools that I would use would be the CPE/CVE system. With a list of the devices that I had available to play with, I would write up the same script that I described above to track vulnerabilities in those devices.

I would then look at the CVEs for those identified vulnerabilities for other devices that had the same vulnerabilities. The CPE’s for those devices would then be added to a new script used to look for target vulnerabilities in those other devices that might also apply to the devices in my lab. There is not going to be a 100% overlap, but by careful reading of vulnerability descriptions you should be able to develop a significant list of potential vulnerabilities to search for.

For example, let’s look at the advisory that started this whole chain of blog posts, the NCCIC-ICS advisory for the Rockwell Automation Stratix Switches. If I had one of those switches in my (nonexistent) lab I would go back to CVE-2021-1392 in the NVD and note that that vulnerability was related to the “CLI command permissions of Cisco IOS and Cisco IOS XE”. Using that information, I would look at the CPE list at the bottom of the NVD CVE listing and then search those CPE’s (probably only a handful of the 214 available CPE’s) to see if there were any other ‘CLI command’ related vulnerabilities. I would place those vulnerabilities on my priority research list for the switch I had in my lab.

Adversary CPE Use

If you think that security tools are only used by the good guys (and yes cybersecurity researchers are definitely the good guys) you should not be working in the cybersecurity field. The same techniques that I outline above can by used by the bad guys. Actually, just remember, that adversarial researchers are considered to be the good guys by their side.

Wednesday, June 26, 2019

Bills Introduced – 06-25-19



Yesterday with both the House and Senate in session there were 66 bills introduce. Two of these may receive further attention in this blog:

HR 3462 To amend the Internal Revenue Code of 1986 to provide a credit against tax for disaster mitigation expenditures. Rep. Bilirakis, Gus M. [R-FL-12] 

HR 3484 To amend the Homeland Security Act of 2002 to authorize the Secretary of Homeland Security to establish a rotational cybersecurity research program, and for other purposes. Rep. Richmond, Cedric L. [D-LA-2]

I will watch HR 3462 for language that includes emergency response planning and/or exercises in the costs that could be covered by the tax credit.

Hopefully, HR 3484 will include language that includes control system security issues in the research program.

Friday, March 24, 2017

Bills Introduced – 03-23-17

Yesterday with both the House and Senate in session there were 59 bills introduced. Of those only one may be of specific interest to readers of this blog:

S 719 A bill to establish a grant program at the Department of Homeland Security to promote cooperative research and development between the United States and Israel on cybersecurity. Sen. Whitehouse, Sheldon [D-RI]


This bill will only receive further mention here if it includes specific language concerning control system security issues.

Sunday, February 12, 2017

S 278 Introduced – Cybersecurity Research

Earlier this month Sen. Daines (R,MT) introduced S 278, the Support for Rapid Innovation Act of 2017. The bill would require the DHS Science and Technology Directorate to support the research, development, testing, evaluation, and transition of cybersecurity technologies.

Cybersecurity Research


The bill would add a new §312, Cybersecurity Research and Development, to Title III of the Homeland Security Act of 2002 (6 USC 181 et seq). The new section outlines a number of areas of cybersecurity research, including {§321(b)}:

• Advancing the development and accelerating the deployment of more secure information systems;
• Improving and creating technologies for detecting and preventing attacks or intrusions;
• Improving and creating mitigation and recovery methodologies;
• Assisting the development and supporting infrastructure and tools to support cybersecurity research and development efforts;
• Assisting the development and support of technologies to reduce vulnerabilities in industrial control systems [emphasis added];
• Assisting the development and support cyber forensics and attack attribution capabilities;
• Assisting the development and accelerating the deployment of full information lifecycle security technologies to enhance protection, control, and privacy of information to detect and prevent cybersecurity risks and incidents;
• Assisting the development and accelerating the deployment of information security measures, in addition to perimeter-based protections;
• Assisting the development and accelerating the deployment of technologies to detect improper information access by authorized users;
• Assisting the development and accelerating the deployment of cryptographic technologies to protect information at rest, in transit, and in use;
• Assisting the development and accelerating the deployment of methods to promote greater software assurance;
• Assisting the development and accelerating the deployment of tools to securely and automatically update software and firmware; and
• Assisting in identifying and addressing unidentified or future cybersecurity threats.

The bill also specifies that no additional funding is provided to support these research efforts. It closes by noting that {§2(c)}: “Such requirements shall be carried out using amounts otherwise authorized.”

Moving Forward


Daines is a member of the Senate Homeland Security and Governmental Affairs Committee, the committee to which this bill was assigned for consideration. This means that there is at least the potential that the Committee will consider this bill. If the bill were considered, it is likely that it would be approved since there are no new regulations or spending authorized by the bill. Similarly, if the bill were to make it to the floor of the Senate, it would likely pass. It is too early to tell if there is the necessary political will to advance this bill.

Back on January 10th the House passed HR 240 by a voice vote with limited debate. HR 240 is a companion bill to S 278 according to the introductory speech (pgs S 657-8) by Daines. There was no committee action on HR 240 in the House Homeland Security Committee.

Commentary


It is a good thing that industrial control systems are specifically mentioned in the bill since the bill relies on the IT limited definition of ‘information system’ both in the bill {new §312(e)(4)} and as a part of the support for the definition of the term ‘incident’ {new §312(e)(4)}. That information system definition is found in 44 USC 35002(8).


Given the funding limitation in this bill and the long list of cybersecurity research activities to be supported, it is extremely unlikely that the bill will result in any new significant cybersecurity research support. But passing the bill would make it look like Congress is doing something; appearances are everything.

Wednesday, February 1, 2017

House Passes Three Homeland Security Bills

Yesterday the House took up 17 homeland security related bills under the suspension of rules process and passed all of them. Of these, three are probably of interest to readers of this blog:

HR 437, the Medical Preparedness Allowable Use Act;
HR 612, the United States-Israel Cybersecurity Cooperation Enhancement Act of 2017; and
HR 677, the CBRN Intelligence and Information Sharing Act of 2017.

HR 437 passed by a voice vote after less than 10 minutes of ‘debate’; no one spoke in opposition to the bill.

HR 612 passed by a voice vote after about 16 minutes of ‘debate’; no one spoke in opposition to the bill.

HR 677 passed by a voice vote after about 5 minutes of ‘debate’; no one spoke in opposition to the bill.

All three of these bills would almost certainly pass in the Senate if they make it to the floor for consideration. Since earlier versions of all three of these bills passed in the House in the 114th Congress, but were not taken up by the Senate, it is obvious that consideration by the Senate is not a given.


With these bills being passed in the first 30-days of the 115th Congress, time constraints will not be a factor in whether or not they make it to the floor. What matters is whether or not there is a champion in the Senate with enough political influence with the leadership to bring them to the floor. If any of these bills are considered, they will most likely be considered under the Senate’s unanimous consent procedure with no debate and no actual vote. A single Senator can block a bill under this procedure.

Sunday, January 29, 2017

HR 612 Introduced – Cybersecurity Research

Earlier this week Rep. Langevin (D,RI) introduced HR 612, the United States-Israel Cybersecurity Cooperation Enhancement Act of 2017. The bill would establish a grant program to support joint cybersecurity research by US and Israeli organizations. The bill is essentially the same as HR 5843 that was passed in the House in the 114th Congress (not covered in this blog).

The bill provides no new funding to support the grants.

The bill could cover industrial control system cybersecurity research projects. This is based upon the definition of ‘cybersecurity threat’ used in the bill {§2(d)(3)}. It uses the definition from Cybersecurity Information Sharing Act of 2015 {Title I of Division N, PL 114-113; 6 USC 1501(5)} which in-turn relies on the broader definition of ‘information system’ from the same source.

Moving Forward


This bill is currently scheduled for a vote on Tuesday under the House suspension of the rules procedure. This provides for limited debate, no floor amendments and a super majority for passage. Consideration under this process signifies that the House leadership expects broad, bipartisan support for the bill.


If the bill makes it to the floor in the Senate (an open question as it is too early in the new Congress to tell how well the Senate is going to work), the bill would almost certainly be considered under the unanimous consent process.

Tuesday, January 24, 2017

Bills Introduced – 01-23-17

With both the House and Senate in session yesterday there were 34 bills introduced. Of those, only one may be of specific interest to readers of this blog:

HR 612 To establish a grant program at the Department of Homeland Security to promote cooperative research and development between the United States and Israel on cybersecurity. Rep. Langevin, James R. [D-RI-2] 


As with a similar bill last session (HR 5843) I will only be following this bill if it includes specific control system security provisions.

Wednesday, January 11, 2017

House Passes HR 239 – Cybersecurity Research

Yesterday the House passed HR 239, the Support for Rapid Innovation Act of 2017 by a voice vote. The bill was considered under the suspension of the rules process with only 9 minutes of debate. It would require the DHS Science and Technology (S&T) directorate to support the conduct of a variety of cybersecurity research; including research on “technologies to reduce vulnerabilities in industrial control systems” {new 6 USC 321(b)(6)}.

This bill is nearly identical to HR 5388 that was passed in the House last June. It was never taken up in the Senate.

HR 239 shares the same shortcoming of the earlier bill, it specifically {§2(c)} does not include additional funding for the new research requirements. This means that the existing grant monies distributed by S&T for research will be diluted by any amount spent on cybersecurity research.


HR 5388 was introduced so late in the 114th Congress that the failure of the Senate to take up the bill does not signify any specific opposition to the bill. The calendar toward the end of the session was crowded with too many ‘must pass’ pieces of legislation that lower priority bills such as this were easily overlooked. I suspect that HR 239 will be taken up by the Senate under their unanimous consent process sometime in the coming weeks.

Tuesday, June 14, 2016

HR 5312 Passes in House – Cybersecurity Research

Yesterday the House passed HR 5312, the Networking and Information Technology Research and Development Modernization Act of 2016. The bill was ‘debated’ for twenty minutes, but nary a negative word was heard. The final vote was a strongly bipartisan 385-7, with most of the negative votes coming from Republicans.

The bill does add the term ‘cyber-physical system’ to the definition to the High-Performance Computing Act of 1991 (15 USC Chapter 81), but it limits it to large, complex systems “whose networking and information technology functions and physical elements are deeply integrated”. No additional funding is provided for the research that this bill supports. This means that the existing funding is being diluted by expanding the areas of research authorized.


With no serious opposition to the bill, it is likely that, if the bill is considered in the Senate (not a forgone conclusion by any means), it would likely be considered under the unanimous consent process.

Saturday, September 26, 2015

HR 3578 Introduced – DHS S&T

Two weeks ago Rep Ratcliffe (R,TX) introduced HR 3578, the DHS Science and Technology Reform and Improvement Act of 2015. The bill amends the authorizing language of the Homeland Security Act of 2002 as it pertains to the operations of the DHS Science and Technology (S&T) Directorate. One of the new sections being added to the 2002 Act deals specifically with the cybersecurity responsibilities of S&T.

Cybersecurity Provisions

The new §322 directs the Department to “support research, development, testing, evaluation, and transition of cybersecurity technology, including fundamental, long-term research to improve the sharing of information related to cybersecurity risks and incidents” {new §322(a)}. The expected R&D activities would include new {new §322(b)}:

• Advance the development and accelerate the deployment of more secure information systems;
• Improve and create technologies for detecting attacks or intrusions, including real-time continuous diagnostics and real-time analytic technologies;
• Improve and create mitigation and recovery methodologies, including techniques and policies for real-time containment of attacks, and development of resilient networks and information systems;
• Develop and support infrastructure and tools to support cybersecurity research and development efforts, including modeling, testbeds, and data sets for assessment of new cybersecurity technologies;
• Assist the development and support of technologies to reduce vulnerabilities in industrial control systems; and
• Develop and support cyber forensics and attack attribution.

Paragraph (d) provides a series of definitions used in this new section. The defined terms include:

• Cybersecurity risk;
• Homeland security enterprise;
• Incident; and
• Information system.

The only definition of consequence to readers of this blog is the last one. The bill uses the restrictive definition from 44 USC 3502 that specifically limit it to “a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information” {§3502(8)}. Interestingly the term is never actually used in the new section.

Moving Forward

Ratcliffe is the Chair of the Cybersecurity, Infrastructure Protection, and Security Technologies Subcommittee of the House Homeland Security Committee. As such he has oversight responsibility for S&T and certainly has the political pull to move this bill forward. I expect that we will see a markup hearing before his Subcommittee in the coming weeks and there is a good possibility that this bill will move forward to the full House before the end of the year.

It is strongly possible that this bill will be considered under suspension of the rules with minimal debate and no amendments. We will know better when we see how the Committee votes when this bill is marked up.

Commentary

I am glad to see that industrial control systems are finally getting the Congressional recognition they deserve separate from the larger information systems that they have been lumped in with in the last couple of years.

One problem, however, with this belated recognition of the control system security issue, is that Congress still does not understand the real scope of the problem. For example §322(c) provides a list of agencies with whom S&T should coordinate their cybersecurity research program. Unfortunately, it fails to list a number of Federal agencies that have some oversight responsibility for control systems issues, including:

• Department of Transportation (automobiles, PTC, aircraft, etc);
• Food and Drug Administration (medical devices); and
• Department of Energy (energy production and transmission)

Coordinating and sharing control system security research with these other agencies would certainly help make the Federal research dollar go much further. This is particularly important since this bill does not provide any additional funding to S&T.


BTW: Have I mentioned how much I detest the new House Homeland Security Committee website? It is set up on the infographic model instead of the ‘old fashioned’ web site model with easy to find links to specific information on the site. Whoever designed this site needs to be banished from government service until they learn how to provide information rather than making something that looks pretty.

Saturday, March 2, 2013

HR 756 – Cybersecurity R&D


As I noted two weeks ago Rep. McCaul (R,TX) introduced HR 756, the Cybersecurity Enhancement Act of 2013. The GPO finally made a copy available so that we can see the actual language for the bill and it is, as I suspected, virtually identical to the version of HR 2096 adopted by the House in the last session in a bipartisan vote.  

Reauthorization

This is essentially a bill to reauthorize a number of cybersecurity R&D programs. It provides a three year authorization for spending on the following National Science Foundation (NSF) cybersecurity research and development programs:

• Computer and network security research grants, at $90,000/year {§105(b)};
• Computer and network security research centers, at $4,500,000/year {§105(c)};
• Computer and network security capacity building grants, at $19,000,000/ year {§105(d)};
• Scientific and advanced technology act grants, at $2,500,000/year {§105(e)}; and
• Graduate traineeships in computer and network security, $24,000,000/year {§105(f)};

International Standards

Title II of the bill takes on a new level of importance now that the President’s cybersecurity Executive Order has been published as it addresses coordination of federal agencies working on the development of international standards “related to information system security” {§202(a)(1)}. Since the EO emphasizes the adoption of consensus international standards where practical, the US government’s participation in the development of those standards becomes more important.

No Control System Research

While “critical infrastructures for electric power, natural gas and petroleum production and distribution, telecommunications, transportation, water supply, banking and finance, and emergency and government services” {§2 adds to 15 USC 7401(1)} is clearly mentioned in the congressional ‘findings’ that justify the bill, there is no mention of control systems anywhere within the bill. This bill is clearly focused on the larger portion of cybersecurity, information technology.

Moving Forward

HR 2096 passed easily in the House in the last session (most of the opposition came from anti-spending Republicans) and would have passed as easily in the Senate if Sen. Reid hadn’t been so focused on passing a comprehensive cybersecurity bill. With the EO in place to take the heat off in the Senate, this bill should pass as quickly as the leadership decides to bring it to the floor.

Monday, February 6, 2012

HR 3834 Introduced – Cyber Security Research

Late last month Rep Hall (R,TX), the Chair of the House Science, Space and Technology Committee, introduced HR 3834, the Advancing America’s Networking and Information Technology Research and Development Act of 2012. This bill amends the High-Performance Computing Act of 1991 to authorize activities for support of networking and information technology research.

Cyber-Physical Systems


While the bill spends a great deal of time substituting the words ‘networking and information’ for the term ‘high-performance computing’ there are some changes made to the research priorities outlined in the original act. One of those changes deals with the introduction of a new research topic, cyber-physical systems. That is defined in §2(f)(1) as:

“physical or engineered systems whose networking and information technology functions and physical elements are deeply integrated and are actively connected to the physical world through sensors, actuators, or other means to perform monitoring and control functions”.

I cannot find anywhere in the bill where the term ‘industrial control system’ is used, but this ‘cyber-physical system’ certainly sounds like the definition, in the broadest sense, of an industrial control system.

Sec 4(a)(3) amends Section 101(a)(1) of the High-Performance Computing Act of 1991 (15 U.S.C. 5511) calling for a collaborative research and development effort that provides “for increased understanding of the scientific principles of cyber-physical systems and improve the methods available for the design, development, and operation of cyber-physical systems that are characterized by high reliability, safety, and security”.

Finally §4(b) requires the establishment a temporary university-industry task force “to explore mechanisms for carrying out collaborative research and development activities for cyber-physical systems, including the related technologies required to enable these systems, through a consortium or other appropriate entity with participants from institutions of higher education, Federal laboratories, and industry. The task force would prepare a report to Congress on its findings and then disband.

No Funding


The bill does not provide any specific authorization for funding this collaborative research and development effort. The existing 15 USC 5511 language calls for the President’s budget to allocate funding for the National High-Performance Computing Program (to be renamed by this bill as the Networking and Information Technology Program) from the various agencies that support the Program.

The only hope that the research activities outlined for cyber-physical systems would get some specific future funding would be if a future Congress were to provide that funding after receiving, reviewing and acting on the task force recommendations called for above. So hold your breath and hope for the best.
 
/* Use this with templates/template-twocol.html */