Showing posts with label Intelligence. Show all posts
Showing posts with label Intelligence. Show all posts

Wednesday, September 9, 2015

Cyber Threat Hearing Witness List Published

This morning the House Intelligence Committee published the witness list for the hearing on global cyber threats that I briefly described yesterday. The scheduled witnesses are:

John O. Brennan, Director CIA;
James R. Clapper, Director of National Intelligence;
James Comey, Director FBI;
Michael S. Rogers, Director NSA; and
Vincent Stewart, Director DIA

These are the heads of the intelligence community reporting, in public, to their congressional overseers. This hearing is almost certainly going to be more about cybersecurity intelligence policy than any details about the cyber threats that the US faces. The questioning could get interesting.


The hearing will be at 10:00 EDT on Thursday. There is nothing on the Committee web site about this hearing being web cast. It is currently scheduled to be broadcast on CSPAN3.

Sunday, August 11, 2013

Cyber-Threat Intelligence – Miscellaneous Info

Cleaning up my computer files this morning I ran across an article I saved a week ago from Net-Security.org and a related article from FederalNewsRadio.com about a new cyber-threat reporting and information sharing program initiated by the FBI called iGuardian. Currently the program is being run by through the InfraGard program and is only available to members of that program. The interesting thing about this program is that it is apparently a two-way program where information from incident reports is shared back to member organizations after being appropriately sanitized.

Towards the end of the FNR article there is a reference to a research paper on cyber threat intelligence sponsored by the Director of National Intelligence and prepared by the Software Engineering Institute (SEI, a Carnegie Mellon organization) on the ‘State of the Practice of Cyber Intelligence’. An SEI blog post on the topic provides some interesting reading. It identifies three peculiar initial findings that represent some challenges for the practice of cyber intelligence:

• A lack of consistent training for the strategic analysis role;
• Reliance on traditional intelligence methodologies; and
• Data gluttony.


As someone who has worked on the periphery of military intelligence on a couple of occasions during my Army career I don’t see that these challenges represent anything new or unique to the cybersecurity realm. I have glanced at their interim report and look forward to having a chance to read it in detail.

Thursday, March 21, 2013

Appropriations Cybersecurity Hearing


Yesterday the Homeland Security Subcommittee of the House Appropriations Committee held an oversight hearing looking at ‘Cybersecurity and Critical Infrastructure’. The hearing was closed to the public because intelligence information was going to be discussed at the Top Secret/SCI level. We do, however, have access to the opening statement from Under Secretary Beers.

CFATS Mentioned

Beers testified on the broadest application of the title of the hearing and took some time to address the CFATS program. He took some time to update the Subcommittee on the improvements made to the CFATS program. This is not unreasonable since the Subcommittee wanted to reduce the CFATS funding by half last year because, at least in part, of the problems the program was having with their site security plan authorization program.

Beers provided an interesting tidbit of information yesterday that was overlooked in the CFATS hearing last week. According to yesterday’s written testimony noted that as of March 5th, “397 ASPs [Alternative Security Plan] have been submitted in lieu of SSPs” (pg 6). These were almost certainly submitted using the American Chemistry Council’s (ACC) ASP format. He made these comments about the importance of the development of ASPs:

“Additionally, DHS has been in discussion with other industry stakeholders, including the Agricultural Retailers Association and the Society of Chemical Manufacturers Affiliates, about developing templates specific to their members. DHS has also been engaging industry partners on the development of “corporate” ASPs. For industry partners that own several regulated facilities, the corporation can develop a single ASP template, which can be easily leveraged by all of its facilities. ASPs submitted by facilities using an industry-developed or proprietary template would be reviewed under the same standards that ICSD currently reviews SSPs. The potential for these ASPs to serve as a force multiplier is tremendous as DHS continues to authorize and approve SSPs and ASPs.”

Unfortunately, in a hearing that was predominantly supposed to be about cybersecurity, Beers made no comments about that topic in his discussion of the CFATS program. This is especially surprising and disappointing in light of the comments and questions he heard from his congressional questioners at last week’s hearing.

Control System Security

The written testimony provided yesterday has a pretty good discussion of control system security for coming from someone outside of the ICS security community. There was nothing new presented, but the fact that ICS security received this much separate attention was encouraging.

Cybersecurity EO

While the cybersecurity executive order was mentioned early on in the testimony it was probably the least informative aspect of the testimony. We have plenty of catch phrases like “encourage enhanced security and resiliency” and “enhanced information sharing programs”, but there was no substance mentioned.

Beers was obviously proud of the fact that “DHS has already formed a task force to coordinate implementation of PPD-21 and EO 13636” (pg 2), but that is hardly an accomplishment since the Administration had been working on the EO since last summer and early drafts that had been circulated show little difference from what we got last month. But, then again, Beers has always been proud of mediocre performance and missed time limits at NPPD.

Intelligence Information

The meat of the hearing yesterday was going to be the intelligence information that supported the cyber-threat analysis. We are unlikely to hear anything directly about that intel any time soon. I would like to think that DHS had the capability to sanitize the intelligence reports to the extent that they could provide a report to industry of at least the same level of detail as the recent Mandiant report on Chinese involvement in cyber espionage.

I’m not going to hold my breath about that happening any time soon, but if I were a CEO of a chemical company that had multiple high-risk chemical facilities, I would like to hear the following information from DHS in general and ISCD in particular:

• Have any chemical facilities had their computer systems hacked by the Chinese (or Iranians, or North Korean, let’s make it easy a new cyber-intel acronym ‘CINK’)?
• If so, were any control systems breached by CINK hackers?
• Is there any indication that information about control systems was accessed by CINK hackers?
• Is there any indication that there were attempts made by CINK hackers to establish backdoors into corporate or control system networks?
• What indications are available for determining if a corporate network or control system has been hacked by the CINK hackers?

I doubt that we will ever see official public-responses to questions such as these, but hopefully this type of information is being provided to corporate leaders and security personnel. If not, then DHS needs to pack up its tent and steal away quietly into the night in disgrace. If they can’t provide this type of information to critical infrastructure owners then they are about useless and the President’s cybersecurity order is just a pretty piece of paper.

Monday, February 7, 2011

House Homeland Security Committee Hearings

The House Homeland Security Committee will start holding hearings in earnest this week, with three separate hearings scheduled that might be of interest to the chemical security community. They will address: counter-terrorism intelligence, transportation security and chemical facility security.


Intelligence

The only hearing with any real details available currently is the planned full committee hearing to address “Understanding the Homeland Threat Landscape - Considerations for the 112th Congress”. There are two announced witnesses; Sec. Napolitano and Director Leiter, National Counterterrorism Center.

This hearing should provide a good, unclassified overview of the current intelligence landscape. More importantly it should give us the best indication of the relationship between the Department and the new Homeland Security Committee.

The hearing will be held at 10:00 a.m. EST on Wednesday.

Transportation Security

The Subcommittee on Transportation Security will conduct a hearing on “Terrorism and Transportation Security” on Thursday at 10:00 a.m. EST. No witnesses have yet been announced.

Chemical Facility Security

The Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies will conduct a hearing on “Preventing Chemical Terrorism: Building a Foundation of Security At Our Nation’s Chemical Facilities” on Friday at 10:00 a.m. EST. No witnesses have yet been announced.

Since we have not yet seen a chemical security bill introduced, this is probably not going to be a look forward to the permanent authorization of CFATS. I would suspect that ISCD will be accounting for the current state of the CFATS implementation. Since this subcommittee also looks at cyber security issues, it will be interesting to see if there is any mention of control system security issues, like maybe Stuxnet?

Tuesday, February 16, 2010

Sharing Intelligence

There is an interesting article over on USAToday.com about a plan to share classified intelligence information with about 10,000 managers, supervisors and “behavior detection officers” working in airport security with TSA. Unfortunately, only 750 of the 10,000 currently have the requisite Secret clearance necessary to receive the information that could be critical to the performance of their mission. The remaining 9,250 should get their clearances within the next two years, according to the article. To the uninitiated, it would seem really odd that the TSA was just now getting around to getting important intelligence information down to the first line supervisor level. After all, didn’t the 9/11 Commission point out that failure to share information between intelligence agencies? Actually, the 9/11 complaint was that there wasn’t adequate sharing of information between intelligence agencies, not the lack of distribution of intelligence to the operational level. Intelligence Distribution Intelligence agencies, even down to the tactical level, exist to provide commanders (up to and including the President) and other executives with the information necessary to properly plan and execute their mission. Distributing the developed intelligence down through the organization is typically limited to one or two levels of subordinate organizations. Even then it is an abbreviated version of the information given to person to whom the agency reports. A major reason for this is that good operational security (OPSEC) requires that the enemy or adversary should not become aware of what one knows about their capability and intentions. That knowledge could result in changes in the adversary’s operations that might not be detected in time to take appropriate preventive actions. Additionally, intelligence collection agencies tend to want to protect their means and methods of data collection. If the adversary knew what information about their actions was actually being collected, they would be able to take additional countermeasures to prevent that collection in the future. Finally, we must remember that most of the collected intelligence information is never distributed outside of the collecting agency. The reason for that is that the raw data is collected in such large volume that sharing all of the unevaluated data would simply clog the communications channels. Analysts must sort, collate and verify the data before it can become useful information. Necessary Intelligence Distribution There are certain kinds of intelligence information that do require the widest possible dissemination. One important type is the intelligence indicator. When an agency develops information that an adversary typically does something before conducting a particular type of operation, then that action becomes an intelligence indicator of possible future action. The widest possible distribution of information on this operational ‘tell’ is important so that the ‘tell’ is detected and reported at the earliest opportunity. One typical ‘tell’ is information about how an adversary conducts pre-operational intelligence collection. For example, a terrorist needs to collect information on a target before that target is attacked. They need to know about the security measures that they will encounter, where critical portions of their target are located, and how to most effectively attack their intended target. Information about how a particular organization collects this information would provide a good indicator that an attack is potentially being planned. Another type of intelligence information that should require distribution to the operational level is information about new adversary capabilities and how to counter them is useful operational intelligence. For example, information on the Underwear Bombers placement of explosives along with information about how to detect that in a pat down search would aid in the early detection and prevention of this type of attack. One of the frequent problems with distributing this type of intelligence is that it is classified in order to protect the means and methods of collecting the information. This requires that the target operational users must have the appropriate security clearance and must be trained in how to deal with handling and disseminating classified material. It also requires a secure means of communications to transmit the information to the intended user. When the person to whom the information is being sent is a Federal government employee, the problem of security clearances is easier to handle. The appropriate agencies typically have the internal rules and regulations in place to govern the handling of classified information. They also have personnel who are qualified to train new recipients of a security clearance in the proper handling techniques. This is not typically the case in most civilian companies or even State and local governments. Intelligence and CFATS While the largest chemical companies probably have some intelligence collection/analysis capability, the vast majority of high-risk facilities have no internal access to counterterrorism intelligence. The CSAT web site does provide a semi-secure means of communication with the Federal government. There is also a set of common set of security information rules and techniques in place to protect sensitive information (the Chemical-Terrorism Vulnerability Information – CVI – program) already in place. What is needed now is an intelligence collection and analysis organization that is dedicated to providing intelligence necessary to protect high-risk chemical facilities against terrorist attack. Most of the collection effort will probably be aimed at training facilities facility management in the development of counter-surveillance programs for their facility and acting as a clearing house for information collected by such efforts. The remainder of the intelligence collection would consist of preparing ‘tasking requirements’ for other intelligence organizations for specific types of information that might indicate the development of tactics and techniques for attacks on chemical facilities. ISCD has been properly focused on developing the tools for identifying, assessing and initially securing high-risk chemical facilities. They now need to start developing an intelligence tool to help maintain adequate levels of protection at those facilities covered under the CFATS program. That tool would include the development of:
A requirement for developing counter-surveillance plans at each of the 6,000+ covered facilities; A collection plan for the counter-surveillance reports from those facilities; A set of chemical facility counter-terrorism collection requirements for other intelligence organizations; An intelligence analysis unit capable of producing intelligence reports at the CVI level for all covered facilities; and A program that would allow for the distribution of classified intelligence reports to Tier 1 (possibly Tier 2) facilities.
This intelligence collection and analysis capability would certainly require Congressional authorization and funding. Including such authorization in a bill that makes CFATS permanent would have the advantage of allowing for full integration of the intelligence requirements with the security requirements. Unfortunately, it would also add another couple of Congressional committees to the mix of those required to review the legislation before it came to the floor for a vote.

Wednesday, October 14, 2009

ITACG Intel Guide

The Interagency Threat Assessment and Coordination Group has produced an excellent primer on how the intelligence community operates. The ITACG Intelligence Guide for First Responders provides an excellent overview of the who, what, and how of the intelligence process. Written specifically for the first responder community, it provides the front line user of intelligence information with the knowledge necessary to properly understand the information that the intelligence community can, does, and does not provide. Having worked on the front lines of the tactical intelligence community in the military at various times in the production, analysis and use of intelligence information, I have watched with dismay how seriously politicians and the public have misunderstood the intelligence process. This misunderstanding, combined with the theatrical misinformation about the intelligence community in a variety of Hollywood products, has been responsible in large part of the mistrust and misuse of intelligence information. Anyone whose job requires the use or analysis of intelligence information at the tactical level should read this document. It is relatively short, only 114 pages with lots of graphics and white space. It is well written, with clear definitions and concise explanations. I highly recommend this guide to the chemical security community. Federal Intelligence and the Chemical Sector Having said that, I think that the most useful thing about this guide is the fact that it clearly points out one of the most glaring deficiencies in the dissemination of intelligence information; the lack of a clear mechanism to share government produced intelligence with security operatives in the private sector. The guide states in the introduction that it is “designed to assist state, local, tribal law enforcement, firefighting, homeland security, and appropriate private sector personnel [emphasis added] in accessing and understanding Federal counterterrorism, homeland security, and weapons of mass destruction intelligence reporting” (pg 2). Unfortunately in the section on accessing intelligence community products, there is not a single mention of how the private sector can access these products. The one source of Federal intelligence products that could be accessed by the private sector, the Homeland Security Information Network – Intelligence (HSIN-I), is only open by invitation. This means that an individual can only be given specific access by an authorized entity. DHS ISCD needs to set up a program for providing access to this unclassified intelligence portal to designated security personnel at high-risk chemical facilities. That secure link could also provide a mechanism for those facilities to submit raw intelligence reports back to the intelligence community. Along with providing that access, the Department should produce a chemical facility specific intelligence product. This would address the specific security and intelligence concerns of the chemical security community. It would include summaries and analysis of reports submitted by the same community. Those reports would also be useful to police agencies providing response support to their local high-risk chemical facilities. To make such an exchange of intelligence information useful requires the development of rudimentary intelligence capabilities at the facility level. Since intelligence collection and analysis is not taught in chemistry and engineering programs, the intelligence community needs to develop an appropriate training program so that there can be at least one person at each high-risk chemical facility that has a basic understanding of intelligence procedures and products. The ITACG Intelligence Guide is a good first step in providing that education. Every facility security officer should be given this guide and be required to read it. DHS owes it to the chemical security community that this first step is not the last step the government takes to develop a chemical security intelligence community.
 
/* Use this with templates/template-twocol.html */