Showing posts with label GPS Timing. Show all posts
Showing posts with label GPS Timing. Show all posts

Thursday, November 15, 2018

Senate Passes S 140 – 2018 CG Authorization


Yesterday the Senate adopted substitute language (S Amendment 4054) for S 140 which changed that bill to the Frank LoBiondo Coast Guard Authorization Act. The new version of this bill is basically a reorganization of the sections of the US Code that are applicable to the Coast Guard. Most of it is way over my head, but it will certainly mess with the way people will reference sections of the code that they have been working with for years.

There are two sections that caught my attention:

§ 514. Backup national timing system [pg S6849]; and
§ 602. Maritime Security Advisory Committees [pgS6853]

Section 514 looks very much like S 2220, the National Timing Resilience and Security Act of 2017. Like that bill it would require the Secretary of Transportation to establish a land-based alternative to the GPS timing signal generally based upon the old LORAN navigation system.

Section 602 would completely rewrite 46 USC 70112, the current authorizing language for both national and local MSACs. I do not follow the CG real closely, but the changes do not appear to be significant.

The revised bill goes back to the House. It is possible that the bill could be dealt with under the same unanimous consent process that was used earlier this week for HR 3359. It depends on if there are any controversial measures buried in the revised Senate language. It does not look like it from the way the bill slipped through the Senate.

Thursday, March 10, 2016

ICS-CERT Publishes Schneider Advisory

This afternoon the DHS ICS-CERT published an advisory for an improper Ethernet frame padding vulnerability in the Schneider Electric Telvent SAGE 2300 and 2400 remote terminal units (RTUs). The vulnerability was reported by David Formby and Raheem Beyah of Georgia Tech. A previously released software version mitigates the vulnerability. The researchers have validated the efficacy of the current software to fix the vulnerability.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to read the leaked packet data.

This is the same ‘IEEE conformance issue’ that this research team has reported in systems from other two suppliers (here and here). Interestingly the most recent other example (first one listed here) included an early release of the advisory on the US CERT Secure Portal, even though as in this case, the vulnerability had been corrected in a previously released version of the software.

GPS Timing Issue



While looking at the Schneider web site for information on this vulnerability (I did not find any) I came across a very interesting notice about a GPS timing issue that had been identified (no attribution of identification was provided) in the Trimble GPS card. Those cards are now reporting dates with year 1996 instead of 2016 and have been since February 14th, 2013 because of an error in the firmware. I suppose that system owners that actually use those affected 0x41 and 0x8F-20 messages will have already noticed this problem. According to Trimble (.PDF download) they are not able to update the firmware to correct this problem, so it has to be corrected in the software/firmware that uses the reported data. The Schneider notice reports that they have updated the firmware for their C3413 and C3414 CPU Cards.
 
/* Use this with templates/template-twocol.html */