Showing posts with label Incident Response. Show all posts
Showing posts with label Incident Response. Show all posts

Thursday, October 28, 2021

Review - HR 5658 Introduced – Cybersecurity Roles

Last week, Rep Bacon (R,NE) introduced HR 5658, the DHS Roles and Responsibilities in Cyber Space Act. The bill would require DHS to prepare “a report on the roles and responsibilities of the Department and its components relating to cyber incident response.” The bill was marked-up in Committee this week and was amended and ordered reported favorably.

Once the Committee Report on the bill is published, this bill is likely to move to the floor of the House under the suspension of the rules process and the bill will almost certainly be approved by a bipartisan majority.

For more details about the report, and the Committee markup of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-5658-introduced - subscription required.

Thursday, April 16, 2015

ICS-CERT Publishes 2014 Year in Review

Today the DHS ICS-CERT published their annual review of ICS-CERT activities for the previous calendar year. It is a nice glossy publication worthy of a Fortune 500 annual report. As with such reports, you have to look real close to see anything beyond PR information.

The ICS-CERT Mission

No annual report would be complete without a mission statement. Unfortunately, ICS-CERT has not yet developed a pithy, single complex sentence statement currently favored by the corporate sector. Instead they have broken their mission out into two functional areas; Operations Functions and Risk-Reduction Functions.

Operations includes incident response, vulnerability coordination, situational awareness, and technical analysis. Risk-Reduction includes cybersecurity assessments, the Cyber Security Evaluation Tool (CSET), training, and the Industrial Control Systems Joint Working Group (ICSJWG). Only two of the eight functions can reasonably be called governmental responsibilities; vulnerability coordination and ICSJWG sponsorship. The other six functions operate in direct competition with many private sector entities.

The situational awareness activities of ICS-CERT receive a lot of attention in this Review. The inherent weakness of many of those activities is highlighted by the classified nature of many of the most important briefing. Because industry has so few operations personnel with security classification, it would be illegal for the C-Level attendees at these briefings from further sharing the information with the people who would most need to know the details to effect and efficient response.

CSET

ICS-CERT takes a great deal of pride in the Cybersecurity Evaluation Tool (CSET). They note in the Review that two new versions (6.0 and 6.1) were released in 2014. Unfortunately, there is nothing on their web site about the new releases with the CSET Fact Sheet still reflecting version 4 information from 2013.

Incident Response

The Review has a nice section on the incident response activities of ICS-CERT. It includes a listing of generic types of incidents that ICS-CERT responded to (pg 6). Two of those deserve special mention.

ICS-CERT reports that of the 245 incident that they responded to some (more than one?) included exploitation of zero-day vulnerabilities in control system devices and software. Interestingly, of the seven alerts issued in 2014 none mention that the vulnerability had been used in a zero-day attack. I would have thought that that would have been important information to be communicated to owners of the devices and software.

The Review also notes that the incidents two which ICS-CERT responded included incidents initiated by watering hole attacks at ‘strategic web sites’. While details are not included in the Review, this almost certainly included the response to the Havex RAT. This is another instance where ICS-CERT was not fully forthcoming with the ICS community; only releasing the names of the affected web sites on the US CERT secure server.

Vulnerability Coordination

This is the area that readers of this blog most often hear about when ICS-CERT is mentioned. The section on vulnerability exposure is very light in the Review. Interestingly there is almost no mention of the outside security researchers that are responsible for finding the vulnerabilities that ICS-CERT coordinates with vendors. Instead the Review almost implies that ICS-CERT is responsible for discovering the vulnerabilities.

For example they describe the five step process that ICS-CERT uses to handle vulnerabilities:

∙ Detection and collection;
∙ Analysis;
∙ Mitigation coordination;
∙ Application of mitigation; and
∙ Disclosure

In most instances ICS-CERT is actually only responsible for steps 3 and 5. More and more frequently even those steps are being handled by some of the vendors leaving ICS-CERT to just re-publish the vulnerability for a larger audience.

Just an Annual Report


I have to admit that this is a good looking brochure. It has lots of staged photographs of people doing cyber looking things and I assume that most of them are members of the ICS-CERT team. But this Review has as much relationship to the actual activities of the ICS-CERT as an Annual Report does to a Fortune 500 company operation. The highlights are all here, but if you really want to understand what is going on you are going to need to do your own research.

Thursday, July 24, 2014

NSTAC Meeting to Look at National Cyber Response

Today DHS published a meeting notice in the Federal Register (79 FR 43058-43059) concerning a public teleconference of the President’s National Security Telecommunications Advisory Committee (NSTAC) on August 13th, 2014. Briefing materials for the meeting will be available on the NSTAC web site on August 1st.

The current agenda includes reviews of the status of two on-going NSTAC studies:

• The needs, benefits, and operational efficacy of a national Information and Communications Technology mobilization capability in the face of a cyber-related event of national significance.
• The cybersecurity implications of the Internet of Things as it relates to national security and emergency preparedness.

Interestingly there is nothing in the mobilization capability scoping document that would seem to indicate that NSTAC is considering anything beyond IT type cyber incidents. While this is a telecommunications advisory committee, this still seems to be extremely short sighted.


Public comments on the above topics are being solicited by NSTAC. People wishing to make live comments on the teleconference need to register in advance. Written comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2014-0032).

Thursday, April 4, 2013

ICS-CERT Publishes Monitor


Today the DHS ICS-CERT folks published the latest version of the ICS-CERT Monitor. The latest version continues the change from a monthly publication (it used to be called the ICS-CERT Monthly [emphasis added] Monitor) to a quarterly; a move that was started last year.

Incident Response

The Monitor has three separate articles under the heading ‘incident response’. They include

• Attacker Leverages Public Information to Customize Spear-Phishing Campaign;
• Compromise via “Credential Storage” Vulnerability; and
• Watering Hole Attacks.

The ‘Watering Hole Attacks’ claims that ICS-CERT issued an alert about watering hole attacks exploiting Internet Explorer vulnerabilities. I can’t find any such alert on the ICS-CERT page (or blog about it on my page), so it probably was published on the US-CERT Secure Portal. That would be why most people did not see the report.

Situational Awareness

There are five situational awareness articles in this latest version of the Monitor, They include:

• CSET® 5.0  Released – Updated support to protect critical assets;
• Multiyear assessments reveal common vulnerabilities;
• Protecting credentials from compromised;
• Proper permission Management.

The list of common vulnerabilities provides a consolidated list of vulnerabilities in control systems. Those common vulnerabilities include:

• Permission, privileges and access controls;
• Improper authentications;
• Credentials management;
• Security configuration and maintenance;
• Planning/policy/procedures;
• Network design weaknesses; and
• Audit and accountability;

Two other routine features round out the latest edition; ‘Noteworthy news highlights’ and ‘Coordinated vulnerability disclosure’.

Sequestration

DHS sequestration woes are noted on page 11, the ‘Upcoming events 2013’ section shows that four of the five scheduled events were cancelled because of Sequestration. The cancelled training included:

• Houston Regional Training, March 26-29, 2013 [Opps this had already passed when this document was posted today];
• ICSJWG Introduction to Control Systems Cybersecurity Training;
• Industrial Control Systems Cybersecurity Spring Conference (5-9-13);
• Cybersecurity Training for Industrial Control Systems.

The remaining event, addressing ‘Industrial Control Systems; Cybersecurity, Training’; North American Partners is of limited utility since the link to the training information does not work.
 
/* Use this with templates/template-twocol.html */