Showing posts with label ICS-CERT Monitor. Show all posts
Showing posts with label ICS-CERT Monitor. Show all posts

Monday, January 15, 2018

ICS-CERT Publishes November-December 2017 Monitor

Today the DHS ICS-CERT published the last ICS-CERT Monitor (for November and December of 2017). According to the opening editorial the next issue will become the (National Cybersecurity and Communications Integration Center) NCCIC Monitor; which will be broadened to include reporting from the three divisions of the NCCIC (ICS-CERT, NCC, and USCERT).

This issue continues the ‘color glossy’, corporate report feel (with 10 full-color photographs) that I have grown to dislike and disparage. While any organization deserves to be proud of their accomplishments and government agencies have a special duty to provide information about what they are doing; the flashy graphics and photographs of industrial facilities have a tendency to make this look more like an organizational selfie that is designed to make the agency feel good about itself.

Physical Security Issues


Even when the reporting is on a topic of interest to critical infrastructure owners and operators, there are some glaring inconsistencies in the information being reported. For example, in the article on the FY 2017 Assessment Summary, the opening paragraph (pg 4) reports that: “While the assessment teams identified weakness across all control families, six categories represented roughly 33 percent of the [753] total vulnerabilities discovered across assessed CI sectors.”

The article then went on to describe the number 4 vulnerability category, physical access control. It notes that:

“Maintaining visibility in the top discoveries this year were problems related to physical access. While this is not something the ICS-CERT focuses on during assessments, the team often sees this issue during assessments. ICS components and infrastructure should only be accessible to authorized personnel as necessary to maintain the system.”

There are two disturbing aspects about that “not something the ICS-CERT focuses on during assessments”. The first is the probability that if ICS-CERT had formally included ‘physical access’ in the assessment process, they might have (probably would have) found many more disturbing instances of poor physical security of control system devices. The second (and more disturbing to my mind) is the fact that ICS-CERT found the same problems in their FY 2016 assessments, AND DID NOT FORMALLY ADDRESS THE PROBLEM IN THE ASSESSMENT PROCESS IN 2017. The first is the result of a not unusual disconnect between cyber security and physical security personnel; a problem that certainly needs to be addressed. The second is a criminally negligent level of professional malfeasance upon the part of ICS-CERT.

ICS-CERT and NCCIC


As I alluded to in the opening paragraph, the editorial leading the publication addresses the changing roles of the NCCIC and its constituent divisions. Specifically, it reports that:

“Recently, the NCCIC went through an organizational realignment to consolidate and enhance the effectiveness of its mission-essential functions, which includes changes to the structures of the ICS-CERT, NCC, and USCERT divisions. This realignment has no impact to the technical expertise and services our stakeholders rely on us to provide….”

There have been a couple of interesting social media conversations about this ‘realignment’ (see here for example). For those of us on the outside looking in, it is really hard to tell what is going on. Having said that, I would like to point to the NCCIC web site (updated on June 22nd, 2017) and its description of ICS-CERT:

“ICS-CERT works to reduce risks within and across all critical infrastructure sectors by partnering with law enforcement agencies and the intelligence community and coordinating efforts among Federal, state, local, and tribal governments and control systems owners, operators, and vendors. Cybersecurity and infrastructure protection experts from ICS-CERT provide assistance to owners and operators of critical systems by responding to incidents and helping restore services, and by analyzing potentially broader cyber or physical impacts to critical infrastructure. Additionally, ICS-CERT collaborates with international and private sector Computer Emergency Response Teams (CERTs) to share control systems-related security incidents and mitigation measures.”

Looking at it from Columbus, GA it seems as if ICS-CERT is definitely continuing with its vulnerability coordination and reporting role. What is less clear is whether or not it is going to be the go-to Federal agency for incident reporting and investigation. It seems to me that with the rise in apparent nation-state attacks and economic attacks (ransomware) on control systems that it is going to be more important to have criminal investigative or federal intelligence agencies more involved in incident response rather than an agency of techno-geeks who may be more suited to understanding the nuts and bolts of an attack, but are probably less familiar with forensic reporting or courtroom testimony.


Forensics-reporting and effective testimony are more necessary for successfully prosecuting attackers than with protecting control systems from future attacks. Letting the techno-geeks muddy the waters of chain-of-custody and forensics reporting will likely make prosecutions more difficult, but will help other organizations learn how to deal with similar attacks. It is an interesting dichotomy that needs to be addressed in appropriate congressional forums.

Thursday, November 30, 2017

ICS-CERT Publishes Latest Monitor – Sep-Oct 2017

Yesterday the DHS ICS-CERT published the latest version of the ICS-CERT Monitor. Long time readers of this blog will no doubt understand that I have become less than enamored with this periodical in recent years. It has become more of a corporate selfie than a real communications tool, but occasionally there is an information gem that is worthy of note.

Selfie Components


The Monitor starts with a Trumpian, “look how great I am”, article on a recent training program conducted by ICS-CERT in Japan. It then goes on to announce the publication of a 2-page, color glossy ‘fact sheet’ looking back at last year’s “Recommended Practice: Improving Industrial Control System Cybersecurity with Defense-in-Depth Strategies” update.

There is one page dedicated to ICSJWG news, including an announcement of the Spring meeting dates; April 10–12 in Albuquerque, NM. Unfortunately the ICSJWG web site still does not include an agenda for the fall 2017 meeting, nor is there any mention of the rumored announcement that was made about the reorganization/abolishment/fusion of ICS-CERT.

Finally, we have the standard elements that we have come to know and ignore:

• ICS-CERT Assessment Activity;
• Recent Product Releases;
• Coordinated Vulnerability Disclosure; and
• Upcoming Events

The Gem


Okay, this may be more of a sparkler than a true precious stone, but there is an interesting and worthwhile full-page article on updating of antivirus software in ICS systems. The core assumption in this article is found in the second paragraph:

“The recommended secure network architecture for ICS (Figure 1) places the antivirus, Windows Server Update Services (WSUS), and patch server(s) in the control center LAN DMZ. In this architecture, each level should only send or receive traffic to any directly adjacent level, which precludes the antivirus/WSUS/patch server from communicating directly with either the vendor antivirus servers or the organizational antivirus servers.”

This, of course, leads to the need for downloading the daily AV signature update onto removable media, checking that media for malware, checking the hash, running the update on test environment, and finally, updating the AV on the appropriate ICS systems. All very neat and tidy, and security compliant; I wonder how many folks actually do this. Or is this really the reason that so many folks are starting to talk about how outdated/useless AV is?


Of course, the same process would be required for updates for all Windows OS, control systems, and device software. Again, does this explain the apparently widespread practice of overlooking/ignoring system updates?

Thursday, May 4, 2017

ICS-CERT Publishes 4 Advisories

Today the DHS ICS-CERT published 4 control system security advisories for products from Rockwell, Advantech, Dahua Technology and Hikvision. The Rockwell advisory was previously published on the NCCIC Portal on April 4, 2017.

ICS-CERT also published the latest version of their ICS-CERT Monitor. Not worth reviewing, but it is out there.

Rockwell Advisory


This advisory describes a resource exhaustion vulnerability in Rockwell ControlLogic and CompactLogic controllers. This vulnerability was apparently self-reported. Rockwell has provided updated versions to mitigate the vulnerability.

ICS-CERT reports that an uncharacterized attacker could remotely exploit the vulnerability to cause the device that the attacker is accessing to become unavailable.

Advantech Advisory


This advisory describes an absolute path traversal vulnerability in the Advantech WebAccess. The vulnerability was reported by Zhou Yu via ZDI. Advantech has produced a new version to mitigate the vulnerability. ICS-CERT reports that Yu has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to traverse the file system and gain access to files or directories, which could result in the device becoming unavailable.

Dahua Technology Advisory


This advisory describes two password vulnerabilities in the Dahua Digital Video Recorders and IP Cameras. Bashis disclosed these vulnerabilities without coordination with ICS-CERT (see Brian Krebs and ThreatPost articles for more information).

The two reported vulnerabilities are:

• Use of password hash instead of password for authentication - CVE-2017-7927; and
• Password in configuration file - CVE-2017-7925

ICS-CERT reports that a relatively low skilled attacker could use publicly available exploits to remotely exploit the vulnerabilities to allow the attacker to obtain user credentials, including password hashes, and use these credentials to bypass authentication.

Hikvision Advisory


This advisory describes two password vulnerabilities in the Hikvision cameras. The vulnerability was reported by IPcamtalk user “Montecrypto”. Hikvision has published a new version to mitigate one of the two vulnerabilities. There is no indication that Montecrypto was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Improper authentication - CVE-2017-7921; and
• Password in configuration file - CVE-2017-7923

In Passing



Please remember that when ICS-CERT publishes their 2017 stats that they will almost certainly include the Dahua and Hikvision vulnerabilities in their count of control system advisories for the year.

Saturday, September 10, 2016

ICS-CERT Publishes Jul-Aug 2016 Monitor

Yesterday the DHS ICS-CERT published the latest version of their ICS-CERT Monitor. Lots of DHS ‘corporate’ type news in this issue, but nothing about any industrial control system incidents.

The opening article, which usually describes a recent incident, provides an overview of what types of services ICS-CERT provides when responding to a control system security incident. I had really been hoping to see some more details about the Navis WebAccess problem that resulted in an alert, an incident response alert and an advisory back in August. This was apparently a very limited in application (very small number of systems) incident, but it was an SQL injection attack on a maritime control system in the wild.

Other corporate news included:

• Presidential Policy Directive on Cyber Incident Coordination;
• US-CERT Portal moving to HSIN, changing name in Fall 2016;
• CSET 8.0;
• ICSJWG Fall 2016 Meeting preview;
• NCCIC team wins 1st Place at FIRST Conference in Seoul; and
• ICS-CERT Training pursuing status as accredited provider of Continuing Education Units;


For those readers that really pay attention to ICS-CERT operations, this issue does provide some interesting information. But, if you were hoping to learn something about industrial control system security issues, this is probably a waste of time.

Thursday, May 5, 2016

ICS-CERT Publishes March-April 2016 Monitor

Late yesterday the DHS ICS-CERT published the latest edition of their Monitor; a periodic report on the activities of the organization. This is one of the better issues with some interesting topics.

Incident Response


As we have come to expect, ICS-CERT leads off the publication with a brief piece discussing a recent anonymized attack. Also, as we have come to expect, the attack being used in the discussion is on an organization that would be expected to have an extensive industrial control system operation (a water utility in this case), but the attack never apparently reached the control system.

The attack was a ransomware attack on the utility, so this is a timely issue. The author uses the mixed response from the utility (one system with good backup recovery and a second system with a backup recovery with significant gaps) to explicate the need for timely backups to respond to this type of attack. Unfortunately, the discussion never reaches beyond IT systems and the topic of backups for control systems is never broached.

The second article also addresses incident response, this time giving an overview of the role of ICS-CERT in incident response. The discussion is somewhat marred however by the apparently fictional response to a water utility incident that could be used as a story proposal for a CSI Cyber television episode. While my cybersecurity application talents are more than a little out-of-date, I would be really surprised if the ICS-CERT team could remotely start an effective whitelisting application on a system before they had even seen network logs.

Protected Critical Infrastructure Information


The third major article is a brief overview of the importance of the PCII program. This is an important information sharing tool that allows a covered entity to submit data to a federal agency while protecting that information from public disclosure. The article does a good job of providing a description of the importance of the program and an overview of its protections.

The article does fall short, however, in failing to discuss the major problem with the program; facilities must use a very specific phrase at the start of any document that attempts to claim PCII protection. Failure to include the Express Statement (and two the other key pieces of information discussed on that page) will mean that the information will not be protected by the PCII program. While the article does provide a link to the extensive PCII web site failure to explicitly mention that there are specific requirements for claiming PCII protections does a disservice to the readers.

To be fair this problem is not limited to this ICS-CERT article about the PCII program. I have not yet seen a government discussion of the PCII program that really emphasized the importance of properly claiming PCII protection.

NOTE: Remember that DHS is in the process of trying to revise the PCII regulations (see here and here).

Strong Passwords


No discussion of cybersecurity would be complete without the topic of passwords being addressed. The fourth (and last) major article of this issue of the Monitor addresses this important topic. While there have been periodic discussions in the industry of replacing passwords with some neat new technology, ICS-CERT apparently remains a strong proponent of strong passwords. Their definition of a strong password is now 12 characters using: caps, lower case, numbers and symbols. Remember it must be unique, but easily remembered as you should never write it down. Sharing passwords or multiple users using the same password are both strictly verboten.

There is an important caveat in the article that should be remembered by everyone:

“There is only one proven method to prevent your password from being cracked: leave your device sealed in the box in which it was shipped. Otherwise, all passwords can be cracked. Given enough time and processing power, even the longest most random password can be cracked.”

Standard Features


This issue includes all of the standard blurbs that we have come to expect, including:

• Onsite Assessments Activity;
• ICS-CERT News;
• Recent Product Releases;
• Coordinated Vulnerability Disclosure;
• Open Source Situational Awareness Highlights; and
• Upcoming Events

It is nice to see three chemical sites listed in the Onsite Assessments Activity chart. At the risk of offending the increasing number of businesses that provide a for-fee assessment (a valuable service that should be encouraged) any facility that is being regulated by the federal government program that addresses cybersecurity of control systems (not many to be sure) would be foolish not to avail themselves of the free assessments provided by ICS-CERT. That assessment should be supplemented by the best fee-based assessment that the budget allows, but an ICS-CERT assessment has got to look good to any Federal inspector.

The ICS-CERT news piece in this issue was yet another non-update on the December Ukraine attacks. Apparently ICS-CERT has no new information that can be shared with the general control system community. It does plug the latest update to IR-ALERT-H-16-043-01BP, “Cyber-Attack Against Ukrainian Critical Infrastructure”. This is only available on the US CERT Secure Portal. You can request access through ICS-CERT (see the ‘I Want To’ box on the bottom of their landing page).

There is an ironic touch in the discussion of coordinated disclosures this month. The first name on the list of personnel being praised for coordinated disclosures is none other than Reid Wightman for his work on the Moxa vulnerabilities. I am sure that this mention makes Reid very happy.

Thumbs Up


The nits picked above notwithstanding, I really did enjoy this issue of the Monitor. I would recommend it to anyone in the control system security community.

Thursday, March 3, 2016

ICS-CERT Publishes Moxa Advisory and Latest Monitor

This afternoon the DHS ICS-CERT published an advisory for multiple vulnerabilities in equipment from Moxa, thus updating an Alert from August. It also published the latest version of the ICS-CERT Monitor for the January-February time frame.

Moxa Advisory


This advisory describes two vulnerabilities in the Moxa ioLogik E2200 Ethernet Micro RTU controllers. Like Tuesday’s Rockwell advisory these vulnerabilities were reported by Aditya Sood via last summer’s DefCon. Moxa has issued a firmware update and an associated update for their Active OPC Server software that mitigates the vulnerability. There is no indication that Sood has been given the opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Insufficiently protected credential - CVE-2016-2282; and
• Inadequate encryption strength - CVE-2016-2283

ICS-CERT reports that a relatively low skilled attacker could use existing public exploits to remotely exploit these vulnerabilities to gain access to settings and data on the devices.

It is interesting to note that Moxa reports in their release notes that the new version of the OPC Server software will continue to support Windows 2003 and Windows XP systems. Both of these are long out of support at Microsoft and their continued use potentially puts operations at risk for any number of vulnerabilities.


ICS-CERT Monitor


The 2016 January-February Monitor was published this afternoon and I was impressed with the increased level of interesting and usable information. I am definitely recommending that people download and read this issue; not something that I have done in a while.

I expected the opening incident investigation report to touch on the Ukraine power outage and I was wrong. Instead they described a visit to a combined water and electric power utility and actually discussed some control system issues. Nice note that they found a wireless router in one network that operators incorrectly thought was disconnected and an unknown cellular modem (vendor installed) in the other.

There were two things reported in this article that deserved a little more attention; a brief report that ‘low-level malware' was spotted on one network, and the initial comment that the utility was planning on merging their two operations networks. A little discussion could have turned both of these observations into important teaching points.

There was a good overview article on incident response and a description of the changes that went into the newly released CSET v7.1. There was also a favorable write up on the ICS-CERT attendance at Digital Bonds S4x16 conference. The ICSJWG Spring Conference in May also got a plug.

They also provided links to eight updated ICS-CERT fact sheets. I would like to suggest that ICS-CERT date these fact sheets so they can be readily differentiated from the predecessors and any follow-on updates. Those fact sheets were:

Training; and


All in all, I think this was a very well done issue; certainly much more informative that the last couple of issues have been. PLEASE keep up this caliber of reporting.

Wednesday, January 13, 2016

ICS-CERT Publishes Nov-Dec Monitor

This afternoon the DHS ICS-CERT published the latest version of their periodic report on activities under taken by ICS-CERT. Long-time readers will recall that I have become increasingly dismissive of this publication over the years. Unfortunately, I have to continue that trend.

As usual this issue starts off with a ‘report’ on an actual incident that was investigated by ICS-CERT. The details are even more sketchy than normal with no positive indication that a control system was actually involved. I understand that ICS-CERT is restricted in what information that it can share in a public environment, but all were told here is that the Assessment team noted indications of malware and the Incident Response team was called in. They confirmed the infection and provided information to allow the clean-up process to begin. Sorry, but we get more useful information from CSI Cyber®.

There is a nice fluff piece on vulnerability coordination in the medical device space. It contains a nice description of the coordination process but it is a feel good article that weakly makes the case for vulnerability disclosures. I hope ICS-CERT does a better job at next week’s FDA Conference.

We have the typical year end summary of ICS-CERT incidents where ICS-CERT continues to conflate ICS incidents and IT incidents at facilities with ICS. The section in this issue does make one very cogent point:

“While sophisticated intrusions against asset owners persist, in FY 2015, ICS-CERT responded to a significant number of incidents enabled by insufficiently architected networks, such as ICS networks being directly connected to the Internet or to corporate networks, where spear phishing can enable access. It is uncertain if this was a change in targeting by adversaries, if these systems merely represented targets of opportunity, or if there is some other explanation. Regardless of cause, this reinforces the need for asset owners/operators to focus on security fundamentals such as those outlined in our DHS/FBI/NSA joint publication ‘Seven Steps to Effectively Defend Industrial Control Systems’ and ICS-CERT’s ‘Recommended Practice: Improving Industrial Control Systems Cybersecurity with Defense-In-Depth Strategies.’”

The FY 2015 highlights section of the Monitor does provide some interesting factoids about ICS-CERT and industrial control system security. An important milestone mentioned here is the elevation of the ICS-CERT to a continuous presence on the National Cybersecurity and Communications Integration Center (NCCIC) floor. This does mark an important increase in the perceived level of importance of control system security.

There is another mention in the highlights section that deserves some discussion here. That is the apparent release of version 7.0 of the Cyber Security Evaluation Tool (CSET). Unfortunately, there is no information about the differences between v7.0 and earlier versions and there is no indication on the ICS-CERT web site that the CSET has changed since May of 2014. This is a shame because this has been a valuable tool that can be used either in the stand-alone mode by a facility team or in conjunction with an assistance team from ICS-CERT. I really wish that ICS-CERT would do a better job publicizing the CSET.

In the final analysis, this is a short document that costs nothing but the very short download time. We are going to be hearing about the misleading incident stats for the next 9 months so you might as well read the document.

Monday, November 16, 2015

ICS-CERT Publishes Sept-Oct 2015 Monitor

This afternoon the DHS ICS-CERT published the latest version of the ICS-CERT Monitor. I have been a pretty harsh critic of recent issues of this publication, but, with this issue, I am returning to recommending that ICS-CERT owners read and circulate the document.

I was disappointed with the initial article on information sharing, particularly since it was started with a report of a potential control system compromise on a system that wasn’t compromised. I understand that this is probably a not-unusual occurrence, but it would have made a stronger case for incident reporting if the lead-in story was about a compromised system that was caught before the compromise was exploited. Having said that, a very good point was made in the article about the importance of system logging.

The two lengthy articles in this issue were both well done. The discussion about trends in malware will probably be a little basic for security savvy IT or operations administrators, but it would be a good article to share with plant management. It is a nice overview of malware history leading into potential problems with IIOT.

The second article should, on the other hand, be required reading for everyone in the cyber enterprise, not just industrial control systems. The problem of the disposal of inadequately scrubbed computers spans IT, ICS and personal computing. And it gives nice props to Wighman, Sistrunk and Toecker who worked on the problem with ICS-CERT.

There are a number of short articles that may be of interest to those of us keeping up with things going on in the ICS world. They include:

• ICS-CERT at DEF CON and Black Hat;
• Section 508 and Accessibility;
• ICS-CERT Virtual Learning Portal Upgrade;
• Industrial Control Systems Joint Working Group Meetings;


Again, this issue is much improved over those that were produced recently. I really want to encourage ICS-CERT to keep up the quality and applicability of the information presented in the Monitor. If they do, this will be another valuable tool for that organization to share information with the control system security community.

Friday, September 4, 2015

ICS-CERT Publishes Latest Monitor

This afternoon the DHS ICS-CERT published the latest version of the ICS-Monitor covering July and August 2015. As we have come to expect it reports on an incident at a facility that does not involve control systems, reports a new version of CSET, and includes one technical article of interest; this one on system logging. There are also brief articles on international coordination on various control system security issues, intra-governmental coordination for medical device security and the upcoming ICSJWG Fall Meeting. Fortunately it still costs nothing but the brief download time.

Tuesday, July 7, 2015

ICS-CERT Publishes Monitor

This afternoon the DHS ICS-CERT published the latest version of the ICS Monitor covering activities in May and June of this year. While this issue contains a lot of the standard full-color glossy self-advertisement that we have come to expect from this periodic report there are three interesting articles that are well worth reading.

Incident Investigation

This has become a standard feature in the Monitor; a sanitized report on an on-site investigation carried out by ICS-CERT in the period covered. There are no real details about the incident other than the owner expected possible ‘APT activity’ on their control system network.

The real value of the article is that it points out that the facility did just about nothing to protect its control system. For example, it was not able to enumerate all of the devices on the network. It had no network logs to use for a forensic investigation. Finally, there was not even a good delineation of who was responsible for the various sectors of the network. If there is a need to baseline bad performance this article describes just such an installation.

Situational Awareness

The other two articles of note are found in this section of the Monitor. The first deals with internet connections and the other with using YARA for malware detection.

The first one starts off with the title “If You’re Connected, You’re Likely Infected” and then goes on to discuss the following basic techniques to protect your control system network:

∙ Isolate your ICS network from the internet;
∙ Limit and secure the use of remote access to your control system environment;
∙ Assign a manager responsible for cybersecurity; and
∙ Implement best practices for cybersecurity.

No real new information here, though I am a little surprised (and pleased) to see the brief section on management responsibility.

The third article worth reading is titled: “Using YARA for Malware Detection”. This nearly full page article provides a pretty readable guide to how to use the YARA tool. It almost certainly is not quite detailed enough to actually allow someone to use the tool (it is only a page long and fairly generic), but it should be enough to allow a manager to nod his head in the proper places when the control system engineer gives the 30 second version as an explanation for what he is trying to do.

Lies, Damn Lies and Statistics

Okay, a catchy title, but the first two are not apparently appropriate to this update on ICS-CERT incident statistics. As is usual it is not clear from the article just how many of the 108 enumerated “cyber incidents impacting critical infrastructure in the United States” in the first half of FY 2015 (so a full quarter behind) actually involve industrial control systems. Critical Manufacturing is now the hardest hit sector (20.2%) since the Energy Sector has been broken out into its constituent parts (Electric 13%, Petroleum 8%, Natural Gas 4%, and Miscellaneous 3% - Total 28%).

The interesting set of statistics here is found in the chart on incident reporting. Only 27% of the incidents were reported by asset owners while ‘federal partners’ accounted for 45%. Researchers even accounted for 17%. It is not clear if this is just a case of asset owners not knowing about ICS-CERT, not wanting to report to ICS-CERT, or exactly what.

The final set of statistic is shown in the source of the ‘Attempted Infection Vector’. Fully 19% are listed as ‘scanning’ which most cybersecurity experts do not really count as an attack (and, to be fair, ICS-CERT is not reporting any of these as attacks). The scary part is that the single largest ‘infection vector’ is ‘Unknown’ at 28%. It is hard to share meaningful information about ‘Unknown’.

Recommendation


This is a short read, has some good information, and you cannot beat the price. I would recommend that you go ahead and download a copy. I did.

Friday, February 14, 2014

ICS-CERT Monitor is BACK

The DHS ICS-CERT Monitor is back on-line. As far as I can tell it is the same document that I reviewed earlier. There is still no mention on the ICS-CERT site why this was pulled from the site earlier.


BTW: I have saved a copy of this this time and will post it on LinkedIn.

Thursday, April 4, 2013

ICS-CERT Publishes Monitor


Today the DHS ICS-CERT folks published the latest version of the ICS-CERT Monitor. The latest version continues the change from a monthly publication (it used to be called the ICS-CERT Monthly [emphasis added] Monitor) to a quarterly; a move that was started last year.

Incident Response

The Monitor has three separate articles under the heading ‘incident response’. They include

• Attacker Leverages Public Information to Customize Spear-Phishing Campaign;
• Compromise via “Credential Storage” Vulnerability; and
• Watering Hole Attacks.

The ‘Watering Hole Attacks’ claims that ICS-CERT issued an alert about watering hole attacks exploiting Internet Explorer vulnerabilities. I can’t find any such alert on the ICS-CERT page (or blog about it on my page), so it probably was published on the US-CERT Secure Portal. That would be why most people did not see the report.

Situational Awareness

There are five situational awareness articles in this latest version of the Monitor, They include:

• CSET® 5.0  Released – Updated support to protect critical assets;
• Multiyear assessments reveal common vulnerabilities;
• Protecting credentials from compromised;
• Proper permission Management.

The list of common vulnerabilities provides a consolidated list of vulnerabilities in control systems. Those common vulnerabilities include:

• Permission, privileges and access controls;
• Improper authentications;
• Credentials management;
• Security configuration and maintenance;
• Planning/policy/procedures;
• Network design weaknesses; and
• Audit and accountability;

Two other routine features round out the latest edition; ‘Noteworthy news highlights’ and ‘Coordinated vulnerability disclosure’.

Sequestration

DHS sequestration woes are noted on page 11, the ‘Upcoming events 2013’ section shows that four of the five scheduled events were cancelled because of Sequestration. The cancelled training included:

• Houston Regional Training, March 26-29, 2013 [Opps this had already passed when this document was posted today];
• ICSJWG Introduction to Control Systems Cybersecurity Training;
• Industrial Control Systems Cybersecurity Spring Conference (5-9-13);
• Cybersecurity Training for Industrial Control Systems.

The remaining event, addressing ‘Industrial Control Systems; Cybersecurity, Training’; North American Partners is of limited utility since the link to the training information does not work.
 
/* Use this with templates/template-twocol.html */