Saturday, June 9, 2012
ICS-CERT Publishes May Monthly Monitor
Thursday, July 28, 2011
ICS Security Posture
With more and more security vulnerabilities being identified in industrial control system software, it is becoming clear to anyone that is watching that there are significant shortcomings in the industry’s security posture. It is only a matter of time before someone (a terrorist, a disgruntled ex-employee, a criminal organization, or even a foreign power) takes advantage of one or more of these vulnerabilities to attack an industrial control system in the United States with ‘catastrophic consequences’ (I’m sorry; it is just too nice a phrase. I’ll try to come up with another in the near future).
It is also clear that there is no magic bullet that is going to cure the problem overnight. The responsibility for the current situation is the product of too many variables to enumerate and everyone in the business, vendors and users alike, share a fair measure of the blame for getting here.
It is also clear that the politicians have no clue about the extent of the problem and are focused on the (admittedly) larger cyber security issues of the protection of privacy, financial transactions, and intellectual property.
So, the idea of various members of the community getting together to take an organized look at the problem and come up with suggestions for its resolution is a good one. The ICSJWG is probably as good a venue for this as any. It already has a very open structure in place that can accommodate an evolving level of participation. And most of the major players already have links established to this group.
I’m not sure how detailed a proposal can come out of this group (or any group attempting this type of dialogue) because of rules concerning business competition, collusion and market manipulation. But anything that gets a positive dialogue started will be of benefit to the control system community and the country as a whole.
One warning however, the ‘Green’ community has already targeted the Critical Infrastructure Partnership Advisory Council (CIPAC; the actual parent organization for ICSJWG) as an industry lobbying organization with undue influence on DHS. While this is an exaggerated accusation (in my opinion) it is a very real problem that must be dealt with. Unless ICSJWG takes pains to ensure that this discussion is open and inclusive, the political response to the final product will be colored by these types of accusations.
The ICS-CERT announcement invites interested parties to contact them at ics-cert@dhs.gov. They stress that this includes all “ICS vendors, standards bodies, and ICS partners”. With ‘ICS partners’ obviously including owner and operators, I would like to encourage the participation of organizations like SOCMA, ACC and NPRA (to name just a few) that represent many of those owners and operators. And let’s not forget the security researcher (black, white and gray hat) community; they should be participating as well.
Saturday, February 5, 2011
DHS Control System Security Program Page Update
ICSJWG Spring Meeting
The 2011 Spring Meeting will be held on May 2nd thru 5th at the Dallas/Addison Marriott Quorum hotel. According to the meeting web page
“The ICSJWG Conference will consist of panel discussions, presentations, training, and working group meetings on various topics such as emerging technologies, standards development, threat and incident reporting, analysis tools and techniques, roadmap development initiatives, workforce development and certification, vulnerability management, research and development, information sharing, and international coordination.”The page also includes a Call for Papers for this meeting. It provides a non-exclusive list of potential topics, a link to an electronic submission form for sending an abstract for a proposed presentation and a submission deadline of February 18th.
The last day of the Spring Meeting will be the typical ICSJWG all-day training course. For this meeting it will be the Intermediate Industrial Control Systems Cybersecurity training. Prior control system security experience or attendance at the basic-level course is the recommended prerequisite for this class. The training will include:
• The importance of protecting control systems from cyber attacks and why they are susceptibleBoth the Spring Meeting and the all-day training are free. Well, that’s not completely true; no charge for attending, but you do have to pay for travel and accommodations. As I expect that most travel budgets remain tight (I know mine is) I will make my standard recommendation that the organizers of this conference consider providing on-line access to at least some of the presentations. It would certainly expand the potential audience for this valuable information.
• Understanding the risks and potential consequences of attacks
• Understanding common vulnerabilities in industrial control systems
• Discussion of system exposures to attacks, various attack scenarios, and associate mitigation strategies
• Control Systems Security Program products and services that are available to asset owners.
Remote Access for ICS
The DHS Control System Security Program and the Center for the Protection of Critical Infrastructure have produced a new best practices document; Configuring and Managing Remote Access for Industrial Control Systems. In a modern industrial setting there are many legitimate reasons to provide remote access to control systems this lengthy and dense document provide a detailed look at how that access can be provided in a secure manner.
This is not a how-to manual, but more of a policy discussion. As is typical for many policy discussion documents this means that the writing can get fairly intense. For example, here is the opening paragraph in the discussion of on ‘password policy’:
“In an ideal deployment, authentication mechanisms should be chosen based on the criticality of the system being accessed and should include not only passwords, but other mechanisms as well (see the section on ‘Two form factor authentication’). When using passwords, a secure remote access system should enforce complex passwords of 8 to 25 characters that are a mixture of upper and lower case letters, numbers and symbols.k In addition, corporate policy should demand that these passwords be changed at a rate that is commensurate with the value of the system being protected and regular audits of the strength of these passwords should be done as part of the organisational [sic] cyber security program. The corporate cyber security policy should dictate that these passwords are never shared and that each user ID is unique across the entire system.”This seems fairly straightforward until you get down to the footnote referred to in the middle of the paragraph. That footnote (k) reminds the reader that:
“This guideline is a recommended best practice for general ICT security and the authors recognise [sic] that the creation and use of a 25-character complex password (although ideal) for day-to-day human machine interface operations may be inappropriate. The recollection and usage of such a password under duress may create circumstances that are unacceptable from a safety perspective.”I think that this is a valuable manual to have and review, but I do have on major complaint about the mechanics of the document. There are a large number of high-density graphics included that make navigation through the 66-page document difficult and time consuming if you are using an older system. I had page load times of almost two minutes using my old Windows 2000 based lap top.
Tuesday, May 25, 2010
ICSJWG Page Update 05-24-10
Workforce Development Control Systems Security Research International Coordination Standards Development Incident Response and Handling Vulnerability Management Emerging Technologies Managing Vendor Relations Law Enforcement and Forensics for ICS Integration of Cryptographic Technologies Security Management Metrics Information Sharing Wireless Integration in ICS environments Lessons learned Securing network perimeters Malware and Vulnerabilities Effective Cybersecurity Programs Coordination of Threat Reporting and Determining AttributionI don’t see a single topic listed here that wouldn’t be a valuable subject for discussion, but I would have liked to see at least one topic that directly addressed government cyber security standards (CIP, CFATS, etc). In fact, it would probably be worth while to have a representative of the various enforcement agencies provide updated information on their programs.
Friday, May 14, 2010
ICSJWG Teleconferences
Today the DHS-CERT Control System Security Program Calendar web page shows a series of teleconferences to be held by various elements of the Industrial Control System Joint Working Group (ICSJWG) over the next two weeks. No real details are available, though I expect that the individuals involved probably understand what is going on. I suspect that it has something to do with the recently announced dates for the 2010 ICSJWG Fall Conference, October 25-28, 2010. The following teleconferences have been announced
ICSJWG Government Coordinating Council Teleconference – 5-20-10
ICSJWG Research and Development Subgroup Teleconference – 5-20-10
ICSJWG Vendor Subgroup Teleconference – 5-24-10
ICSJWG Workforce Development Subgroup Teleconference – 5-25-10
ICSJWG Industrial Control System Roadmap Subgroup Teleconference – 5-27-10
The web site provides an email POC, ICSJWG@dhs.gov, for further information about these teleconferences.
Tuesday, March 2, 2010
ICSJWG Spring Agenda
The DHS CERT’s Industrial Control System Joint Working Group’s (ICSJWG) web page about their spring meeting now provides a link to a draft agenda for that meeting. Since it is prominently labeled draft, I would assume that there are still changes being planned, but it still looks like this meeting will provide a great deal of interesting information. It looks like there will be presentations from just about everybody of consequence in the ICS Cyber Security Community. The topics range from analysis of actual cyber security incidents, to defeating malicious code, to managing patch management. While there is not time to cover every possible topic, it looks like the organizers have done a good job at trying to accomplish just that.
The one topic that is missing that I am disappointed in is that there is no presentation on the implementation of the cyber security requirements for the chemical facility anti-terrorism standards (CFATS). As this program is just now hitting the actual enforcement stage of its implementation, I would have thought that some practical coverage of this program would be important for this group. Maybe it will show up in a later version of the agenda.
Wednesday, January 6, 2010
ICSJWG January 2010 Newsletter
Wednesday, December 23, 2009
CSSP Web Page Update 12-23-09
Monday, August 10, 2009
Control System Security Conference November 2009
“The ICSJWG Conference will consist of panel discussions, presentations, training, and working group meetings on various topics such as emerging technologies, standards development, threat and incident reporting, analysis tools and techniques, roadmap development initiatives, workforce development and certification, vulnerability management, research and development, information sharing, and international coordination.”The Program Committee is still accepting proposal abstracts for presentations or panels. Proposals must be submitted via the electronic form prior to August 17, 2009. According to the Call for Papers: “Marketing or sales presentations aimed at gaining the audience’s interest in services, capabilities, or products will NOT be approved.” Topics will include:
Workforce Development Control Systems Security Research International Coordination Standards Development Incident Handling Vulnerability Management Emerging Technologies Managing Vendor Relations Integration of Cryptographic Technologies Security Management Metrics Wireless Integration in ICS environments Coordination of Threat ReportingThis is being billed as an opportunity for government professionals, control systems vendors and systems integrators, research and development and academic professionals, and owners and operators to interface with cyber security peers and stay abreast with the latest initiatives impacting security for industrial control systems.