Showing posts with label HSIN. Show all posts
Showing posts with label HSIN. Show all posts

Tuesday, October 31, 2023

Review – 2 Advisories and 1 Update Published – 10-31-23

Today, CISA’s NCCIC-ICS published two control system security advisories for products from Zavio and INEA. They also updated an advisory for products from Mitsubishi Electric.

There is a discrepancy in the advisory numbers published today, the two advisories end in -03 and -02, CISA apparently skipped -01. While this could be an editorial mistake, it could mean that CISA published the ‘-01’ advisory to limited distribution on the Homeland Security Information Network (HSIN). This happens when CISA or the vendor has concerns about allowing critical infrastructure facilities a chance to mitigate a vulnerability before it is published. See the Baker Hughes advisory publicly published on February 24th, 2022.

Advisories

Zavio Advisory - This advisory describes five vulnerabilities in a number of Zavio IP Cameras.

INEA Advisory - This advisory describes two vulnerabilities in the INEA ME RTU.

Updates

Mitsubishi Update - This update provides additional information on an advisory that was originally published on July 27th, 2023 and most recently updated on August 3rd, 2023.

 

For more details about these advisories, including links to researcher reports with POC and a down-the-rabbit-hole look at CISA coordination efforts, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published-7b1 - subscription required.

Thursday, June 29, 2023

CISA Community Bulletin – June 2023

Yesterday, I received the most recent version of the mostly monthly CISA Community Bulletin email (available on-line). The lengthy email contains brief discussions (with links to longer form information) about topics of interest to those interested in cybersecurity or critical infrastructure protection. Topics of potential interest include:

• Are You Subscribed to the Homeland Security Information Network for Critical Infrastructure Security,

• Interactive Tools on the National Initiative for Cybersecurity Careers and Studies (NICCS) Website,

• Congratulations 2023 Graduates! Welcome to the Cybersecurity Workforce,

• Launch of National Survey on Emergency Communications,

• CISA and Partners Release Joint Guide to Securing Remote Access Software,

• Secure by Design, Secure by Default,

• 2023 Chemical Security Summit,

• Cyber Defense Education and Training (lots of courses here).

Note: I have discussed the HSIN system here on a number of occasions (most recently here in discussing the Baker Hughes advisory). Critical infrastructure facilities should certainly be signed up for this information resource.

Sunday, July 22, 2018

Classified ICS Security Information – An Example


Earlier this week I wrote a post on sharing of classified industrial control system (ICS) information sharing. As one of the ways to avoid the many complications of sharing classified information I mentioned preparing unclassified derivative works. This week the DHS US-CERT announced a series of web awareness briefings on one such derivative work; US-CERT Alert TA 18-074A, Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors.

The alert was issued in March of this year and includes a wealth of technical data including indications of compromise that could be used to search systems to see if similar attempts had been made to compromise those systems. But, being a technically oriented document, it does little to convince non-cybersecurity personnel about the existence and scope of the potential threat and who should be concerned about it. Hopefully, that is what these four web briefings (actually 1 briefing x 4) will address. The briefings will take place on:

• July 23rd, 2018, at 1:00 to 2:30 pm EDT;
• July 25th, 2018, at 1:00 to 2:30 pm EDT;
• July 30th, 2018, at 1:00 to 2:30 pm EDT; and
August 1st, 2018, at 1:00 to 2:30 pm EDT.

The webinar will be available via the Homeland Security Information Network (HSIN). An HSIN login is not required, but the Adobe Connect® application is being used so you need to allow time to download and install that before accessing one of the briefings. A dial-in audio link (1-888-221-6227) is also provided. Hopefully, this briefing will remain available after these dates for those of us who already have obligations at these dates and times.

Thursday, February 4, 2016

DHS Announces HSIN Advisory Committee Meeting

Today DHS published a meeting notice in the Federal Register (81 FR 6034-6035) for a public meeting of the Homeland Security Information Network (HSIN) Advisory Committee on February 16th, 2016 via a web conference on HSIN Connect.

The meeting agenda includes:

• Introduction of new members;
• An Introduction to the Information Sharing Environment Office (ISEO);
• State of HSIN; and
• Focused mission growth for HSIN.

In addition, the Advisory Committee will receive three new taskings to develop recommendations on the issues of:

• How HSIN achieves growth in its user base and/or mission application, and the business process enhancements the Program must make to advance its requirements management processes and governance for HSIN's users;

• Support for procurement activities around advanced security and cybersecurity testing to ensure protection of the system and its growing user base; and

• Upcoming infrastructure and system support enhancements with the goal of reducing the risk of system downtime due to aging equipment and older support models, as well as, mitigate funding gaps for these enhancements and future development activities


The public may access the web cast by going to https://share.dhs.gov/hsinac and logging in as ‘Guest’. Public comments are being solicited and may be submitted in writing via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2016-0007). Comments must be submitted by February 10th.

Tuesday, March 4, 2014

DHS Announces HSINAC Meeting – 4-10-14

Today DHS published a meeting notice in the Federal Register (79 FR 12209-12210) announcing the meeting of the Homeland Security Information Network Advisory Committee on April 10th and 11th, 2014. The public meeting will be held in Washington, DC and will be accessible via web conference and teleconference modes.

The agenda of this meeting is focused on the deployment of the HSIN R3 Platform. Specific topics of discussion will include:

• HSIN program updates;
• HSIN R3 platform optimization;

DHS is soliciting public attendance the meeting. The public may physically attend the meeting or participate by web conference via HSIN Connect (available to non-HSIN registered individuals) or teleconference. Actual participation will be limited to HSINAC members or via submission of written comments. Written comments would be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2013-0037).


BTW: The HSIN web site does a poor job of keeping up-to-date information available on the HSINAC. For instance there is nothing on the site about last December’s meeting.

Saturday, November 30, 2013

Publishes HSINAC Meeting Notice – 12-17-13

Yesterday the DHS Office of Operation Coordination and Planning published a meeting notice in the Federal Register (78 FR 70631-70632) for a teleconference to be held by the Homeland Security Information Network Advisory Committee (HSINAC) on December 17th. The meeting will be open to the public either by telephone or via HSIN Connect, an online web-conferencing tool.

The agenda for the meeting includes:

HSIN Program Update, including:

• New hires;
• New development contract;
• New outreach contract, and
• Budget/Investment requirements.


• Improving system performance and service operations;
• Interoperability and Federation;
• Large list user validation;
• New development environment; and
• DHS suspicious activity reporting.

The Committee is expected to vote on:


Public participation is being solicited. A public comment period will be held at the end of the conference. Written comments on the topics outlined above may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2013-0037) and should be submitted by December 13th.

Saturday, June 8, 2013

HSIN Advisory Committee Meeting – 6-25-13

DHS published a meeting notice in Monday’s Federal Register (78 FR 34665-34666, available on line today) for a public teleconference of the Homeland Security Information Network Advisory Committee (HSINAC) to be held on June 25th, 2013. The major topic of the meeting will be the implementation of Release 3 of the Homeland Security Information Network (HSIN).

HSIN R3

Specific topics to be addressed will be:

• Review the HSINAC members' HSIN Release 3 (R3) registration experiences;
Discuss the results of the HSIN Policy/HSIN Development informal analysis and capture feedback from the HSINAC members;
Identity Proofing (IDP) Process;
HSIN Legacy to HSIN Release 3 Migration Process; and
• HSIN Release 3 Value Proposition.

Identity Proofing

Since one of the main purposes of the HSIN is the dissemination of sensitive but unclassified (SBU) information the system must have a means of verifying personal identity. According to this notice, HSIN R3 will use “knowledge-based questions pertaining to their [individual’s] personal financial history, credit history, etc. in order to successfully verify their identity before gaining access into HSIN Release 3”.

Now, for reasons pertaining my gadfly status (you have to agree not to release SBU information) I have not and will not seek access to the restricted information portions of HSIN, so this does not apply to me. Still, I would be very leery of sharing this information with DHS and would be concerned if DHS was collecting this information from other sources to ‘verify my identity’. I’m certainly not a privacy activist, but you do have to draw the line somewhere.

There are other ways of verifying identity for the level of security necessary to protect SBU. The CFATS program, for example, has a fairly effective method of providing access to their Chemical Security Assessment Tool (CSAT), a communications network for the sharing of Chemical-Terrorism Vulnerability Information (CVI), a specific subset of SBU. Surely the folks at the DHS Office of Operations Coordination and Planning can come up with a better method than collecting financial information on participants.

Public Participation

Public participation in this teleconference is being solicited by DHS. The public can monitor the teleconference via phone ( 1-800-320-4330 Conference Pin: 673978) or at a meeting room in Washington. Public comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2013-003). There is a 15-minute period near the end of the meeting set aside for oral public comments’ registration is required (Michael.brody@hq.dhs.go).


BTW: The notice does indicate that a more detailed agenda will be published on the HSIN web site. Don’t hold your breath; they still have not added the minutes from an August, 2010 meeting and there are no minutes/agendas for any meetings in 2011, 2012, or 2013. 

Sunday, May 12, 2013

Critical Information Sharing


I’ve kind of been sitting on an interesting if incomplete story since Thursday evening. Part of the delay is an interest in allowing the intelligence and counterintelligence folks a chance to operate I obscurity (where they do work best), but another part is an effort to protect my access to sensitive information. That plus the fact that I don’t have access to the whole story meant that there was no urgent need to share the information that I do have. Enough time has now passed that I think I can address the implications of what I do know; so here goes….

An Evolving Energy Sector Threat

On Thursday there was a brief and generic article in the Washington Post about DHS warning of “of a heightened risk of a cyberattack that could disrupt the control systems of U.S. companies providing critical services”. About the same time that this article appeared there were messages going out through various information sharing portals. One such message read:

“Energy sector asset owners are strongly encouraged to contact ICS-CERT at ics-cert@hq.dhs.gov and request access to the ICS Cert portal regarding a current non-public advisory. This advisory has to do with a significant active threat detected in the wild in which threat actors are seeking access to control system networks of energy asset owners via the corporate networks of target entities.”

Now, anyone that has been following control system security matters with any level of concern knows that there has been an ongoing attempt to infiltrate energy sector IT networks over the last year or so. This has been discussed by ICS-CERT in many of their open source publications, but most of the details have been kept under closer held distribution to DHS, the intelligence community and the affected organizations in the private and public sector via the restricted Homeland Security Information Network (HSIN). All of the open source information has made it clear that the ‘attacks’ have been targeted on IT networks and not control system networks, though there has been oblique mention that information about control systems may have been exfiltrated in these attacks.

It would seem that the probing of energy sector computer networks may have expanded to include actual penetration of control system networks, not just exfiltration of information about those networks. The actual extent of that penetration is not clear, though any reasonable person would conclude that there has been no attempt made to disable, disrupt, or deny access to any significant portion of the energy network. The government would not be able to keep the lid on anything that major.

Information Sharing Tools

I would be willing to bet that the informal information sharing effort initiated last Thursday was effective at reaching a large percentage of the potentially affected organizations. After all, ICS-CERT and US-CERT have been actively reaching out to these same organizations for a while now. Still, the fact that DHS felt compelled to utilize these secondary information sharing portals to reach this specific audience says a great deal about the current state of information sharing in the energy sector specifically and all critical infrastructure in general.

DHS should have been able to specifically contact an action person at each of the potentially affected organizations and directed them to contact ICS-CERT via HSIN. Or perhaps ICS-CERT should have been able to contact the action person themselves. Obviously neither was possible and that is very scary. If this had been about an actual attack on these organizations, the delay in having to use tertiary communications means could mean the difference between mitigating an attack in progress or coordinating a massive restoration action.

This is going to have to be a primary activity in the establishment of the President’s Cybersecurity Framework. There must be a positive, active, and responsive communication linkage between DHS and each critical infrastructure organization and/or facility. DHS must be able to reach out to each and every one of these facilities in a timely and targeted manner when active intelligence information becomes available. It is not appropriate nor effective to try to establish communications protocols and points of contact when perishable actionable intelligence is available.

No NTAS Alert

There are going to be the inevitable complaints that there has not yet been an alert posted on the National Terrorism Alert System (NTAS) for this cyber-incident. These complaints will be an unfortunate holdover from the bad old days of the over-reactive color-coded warning system. First off there is no indication in any of the information that I have heard that this has anything to do with terrorism; it is almost certainly an intelligence operation conducted by a nation-state.

Second, there does not appear to be anything that would require any action by any member of the public, or even conventional law enforcement or emergency response personnel. Again, everything that I have seen or heard indicates that this is an intelligence operation, not an attack, or even necessarily a precursor to an attack. Thus there is no need for an NTAS alert.

Finally, an alert would have been counterproductive for the same reason that I held off mentioning this any sooner. The intelligence and counterintelligence folks needed to have time to determine the extent of the potential control system breach and identify mitigating controls to put into place before the adversary involved knew that the penetration had been detected. Prematurely announcing the intrusion would allow the adversary to potentially withdraw their probes undetected or otherwise reduce the information that might be gleaned about the probe.

For now, move along, there is nothing to see here.

Friday, February 22, 2013

DHS Privacy Impact Assessment Publication Change


DHS published a notice in today’s Federal Register (78 FR 12337-12343) announcing a change in the availability status of 38 Privacy Impact Assessments (PIA) that were published between June 1st and November 30th, 2012. Those PIAs are currently published on various Department web sites, but after April 23, 2013, they will only be available upon request from the issuing agency.

PIAs of Interest

These PIAs are required by government regulation because the Department collects, stores and uses personally identifiable information (PII) in the supported programs and the PIAs outline the steps the Department takes to protect that information. Four of the programs listed in this notice may be of specific interest to readers of this blog; they are [Note: links are to the description of the PIA in this notice]:

DHS/OPS/PIA-008 Homeland Security Information Network R3 User Accounts (HSIN);
DHS/OPS/PIA-007 Homeland Security Information Network 3.0 Shared Spaces;
DHS/NPPD/PIA-009 Chemical Facility Anti-Terrorism Standards (CFATS);
DHS/USCG/PIA-001(b) Homeport Internet Portal.

There is no centralized location for finding these PIA’s on the DHS web site. Each organization maintaining PIAs has a separate web site where the current links can be found to the actual PIA. The above listed PIAs can be found at the listed links:

CFATS

According to the Office of Operations Coordination and Planning web site the HSIN 3.0 Shared Spaces PIA was updated in January of this year. I suppose that the updated PIA is not going to be removed from the site this April.

Interestingly the NPPD , the  Office of Operations Coordination and Planning, and the Coast Guard PIA web sites all provide links to a number of PIAs that predate the June 1st, 2012 start of the period covered by this notice. Why the particular PIAs listed in this notice will be removed from the web site and not the earlier ones is not clear.

Why?

Actually, the whole purpose of removing the PIAs from the DHS web site is not clear. In fact, it appears to me to be counterproductive to the whole PIA process. PIAs are produced to ensure, and document for the public, that PII collected by the government is collected for legitimate purposes and is appropriately protected by the collecting agencies. Making these documents less available inevitably leads to questions of the need for collecting the data and the viability of the measures to protect that data.

This is especially confusing since no reason or justification is provided for the action.

Tuesday, December 7, 2010

HSIN and Wikileaks

Bob Radvanovsky at SCADASEC List published an email from the people that manage the Homeland Security Information Network (HSIN) reminding folks that potentially have legitimate access to classified information that the Wikileaks publication of classified documents does not make them unclassified. Specifically, the email notes:
“Executive Order 13526, Classified National Security Information (December 29, 2009), Section 1.1.(c), states ‘Classified Information shall not be declassified automatically as a result of any unauthorized disclosure of identical or similar information.’”
They also remind HSIN users that “if any classified material that has not been declassified by proper authority is uploaded in HSIN, it is considered a security incident as serious as any other and will be treated as such”. It wouldn’t matter if the information was obtained from an unclassified source (Wikileaks), it would still be a violation of the rules since HSIN is not cleared for the discussion of classified information.

The Rules are Rules

Those of us who are familiar with the standards for handling and declassifying classified information are well familiar with these rules. In part those rules were designed to protect classified information that was published in limited release from further being publicized, particularly if the released information was not identified as being classified.

Additionally, the current rules designed to prevent an open dialog that would confirm that an isolated document purporting to be a classified document was really and truly what it purported to be. Keeping the in-government discussion of the document classified would allow the government to deny the legitimacy of the document by ignoring it.

The current classified document rules have procedures in place for a review of a compromised document to determine if the classification should be reduced or removed. As one might expect the review procedure is a tad bit bureaucratic. It will be a long time before all of the Wikileaks documents have been so reviewed.

Obviously these rules were never designed to deal with a security breach the size of the Wikileaks fiasco. Unfortunately, just because the rules were not designed for this probably to be repeated problem does not mean that they can be ignored. The rules will almost certainly have to be revised for this type of security breach, but until they are the rule enforcers will still have to enforce those rules.

Unenforceable Rule

There is a more controversial part of the same email that requires some thought. The email states:

“HSIN contractors and users must not knowingly access, download or attempt to download, from any unclassified system, any information from a public web-site that is believed to be classified, nor should they comment [on] or confirm the degree of sensitivity of such information, or, discuss the content in a potentially classified document with persons who would not otherwise be authorized access.”
There are three distinct portions of this legalistic sentence. The last two parts are the easiest to understand. The reason for ‘commenting on or confirming the degree of sensitivity’ goes along with the standard reasoning that without this type of confirmation, the ‘enemy’ will never really be sure that it is a legitimate document, providing some small measure of information protection. Discussing the content with unauthorized personnel is easy to understand.

If you understand the last two parts, you can begin to understand why the first part, the controversial part, of the paragraph came into being. If someone with routine access to unclassified government communications networks, like HSIN, were to access the Wikileaks cables, there might be some confusion as to its security classification status in that person’s mind. That confusion could lead to the type of problems identified as being prohibited in the last two parts of the sentence.

Now, I certainly understand the intention of this complex directive from HSIN and I even agree to a certain degree with its intent. Unfortunately, from a practical view point it is unenforceable (I’ll leave the issue of legal enforceability to the lawyers; I AM NOT A LAWYER). There are just too many devices with which one could conduct such a search or download that the government would never have the opportunity to ensure that such searches were not done; particularly considering that so many of the documents have been reposted on so many different sites..

Now, one of the first leadership lessons that I learned as a young NCO was that you should never give an order that you know will be disobeyed; it makes you look stupid and undermines your authority. This is especially true when, as in this case, there are so many legitimate reasons for ignoring the prohibition. For example, many HSIN users will have a real interest in determining if one or more of the projects that they might be working on may have become compromised by one or more of the leaked documents.

Now I am not going to advocate ignoring this directive. I understand the reason for it being issued, and if it is followed there will be less chance of an inadvertent disclosure or discussion of the classified information in an inappropriate setting. I also understand the reasons and motivations for ignoring the rule. I will warn my readers though, if you do violate it, you are going to have to take some precautions to ensure that you can still identify the information as being classified. Other wise you will inevitably make a mistake that could result in your loosing access to classified information; a very negative mark on one’s career in the security industry.

Wednesday, June 10, 2009

DHS Accepting Applications for HSINAC

Yesterday the Department of Homeland Security posted a notice in the Federal Register soliciting applications for membership in the Homeland Security Information Network Advisory Committee (HSINAC). The twenty members of this advisory committee advise the Director, Office of Operations Coordination and other members of DHS leadership about the requirements of the end users of the HSIN. Members typically serve a two to three year term on the HSINAC, attending at least two meetings per year. Members are considered to be ‘special government employees’ and receive travel and per diem allowances. Applications need to be submitted by July 24th.

Wednesday, January 7, 2009

HSIN Teleconference 01-13-09

DHS published a notice in today’s Federal Register that the Homeland Security Information Network Advisory Committee would be conducting a teleconference at 2:00 pm EST on January 13th, 2009. The purpose of the call is “to discuss implementation efforts associated with the Next Generation of the Homeland Security Information Network” (74 FR 722). The actual discussion of these issues will be limited to invitees, but the public is welcome to listen to the discussions. The phone number is: 1-800-882-3610; the PIN is: 1782344. There are only a limited number of lines available and they will be given out on a first come first serve basis on the day of the teleconference.
 
/* Use this with templates/template-twocol.html */