Showing posts with label Internet Connected Devices. Show all posts
Showing posts with label Internet Connected Devices. Show all posts

Friday, May 10, 2019

Bills Introduced – 05-09-19


Yesterday with both the House and Senate in session there were 101 bills introduced. Four of those bills will likely see future coverage on this blog:

HR 2636 To promote the use of smart technologies and systems in communities, and for other purposes. Rep. DelBene, Suzan K. [D-WA-1]

HR 2644 To direct the Secretary of Commerce to conduct a study and submit to Congress a report on the state of the internet-connected devices industry in the United States. Rep. Latta, Robert E. [R-OH-5]

S 1388 A bill to manage supply chain risk through counterintelligence training, and for other purposes. Sen. Peters, Gary C. [D-MI]

S 1398 A bill to promote the use of smart technologies and systems in communities, and for other purposes. Sen. Cantwell, Maria [D-WA]

I will be watching all four bills for cybersecurity language, particularly language pertinent to control system security.

I suspect that HR 2636 and S 1398 are companion bills.

Thursday, November 29, 2018

HR 6032 Passes in House – Internet Connected Devices


Yesterday the House passed HR 6032, the State of Modern Application, Research, and Trends of (SMART) IoT Act, by a voice vote. The ‘debate’ lasted just over 8 minutes and consisted mainly of praising committee leadership for their bipartisan support for crafting this bill.

In my earlier post on this bill I had serious reservations about the definition of ‘internet connected devices’ used instead of trying to define IoT. That concern is further aggrevated by the discussion of the IoT problem found in the House Energy and Commerce Committee report on the bill. In both the sections describing the purpose of the bill and the need for the legislation, the term ‘internet connected devices’ is never used; all references are to the undefined acronym ‘IoT’.

Those discussions in the report clearly (but certainly not concisely) indicate that the Committee is concerned about a wide variety of devices that are connected to the internet but, may communicate over the internet without the specific control of the owner of the data that is being shared or with whom the data is being shared. But that concern is specifically ignored by the inclusion of the requirement in the definition of ‘internet connected devices’ that the physical object connected to the internet would “communicate information at the direction of an individual” {§2(c)(2)(A)}. One of the big problems of so many IoT devices is their capability to communicate information without the direction of the individual owner/operator of the device.

This bill obviously has bipartisan support and more importantly the lack of any significant opposition, so it could be passed in the Senate under their unanimous consent process. If there were a single Senator, however, that objected to this bill, the bill would languish in that body in the limited number of floor hours available for consideration of bills under regular order. I do not expect to see this bill reach the President’s desk.

Thursday, June 14, 2018

HR 6032 Introduced – Internet Connected Devices


Last week Rep. Latta (R,OH) introduced HR 6032, the State of Modern Application, Research, and Trends of (SMART) IoT Act. The bill would require the Commerce Department to conduct a study of the internet-connected devices industry.

Study


Section 2 of the bill requires Commerce to conduct a two-part study. The first is a survey of the internet-connected devices industry and the second is a review of Federal government agencies that have jurisdiction over the industries identified in the first survey.

The bill relies on a very broad definition of ‘internet-connected devices’ which it specifically conflates with the term ‘Internet of Things’. Section 2(c)(2) defines internet-connected devices as a physical object that both:

• Is capable of connecting to the internet, either directly or indirectly through a network, to communicate information at the direction of an individual; and
Has computer processing capabilities for collecting, sending, receiving, or analyzing data.

The inevitable report to Congress is required.

Moving Forward


Latta is the Chair of the Digital Commerce and Consumer Protection Subcommittee of the House Energy and Commerce Committee. He has used his influence there to conduct a markup hearing of this bill yesterday. The bill was adopted without amendment by a voice vote.

This bill is likely to move forward to the full Committee and then the full House without much in the way of opposition. It does not authorize any regulation or expenditure of funds, so there is little here to attract concern.

Commentary


The major problem with this bill is two-fold. First, it uses an overly broad definition which includes practically anything that can connect to the internet. Secondly, it provides no funds for the required study which limits the ability of the Department of Commerce to complete an effective study.

The definition problem is one common with any discussion of IoT. A reasonably good definition of IoT can be found on Wikipedia:

The Internet of Things (IoT) is the network of physical devices, vehicles, home appliances and other items embedded with electronics, software, sensors, actuators, and connectivity which enables these things to connect and exchange data, creating opportunities for more direct integration of the physical world into computer-based systems, resulting in efficiency improvements, economic benefits and reduced human intervention.

Unfortunately, even that definition has problems because its explication of types of ‘physical devices’ included in the definition is incomplete. It does not include, for example, control systems, building environment and access systems, and …. well we could just keep adding things.

This bill (and others, see S 1691 for example), instead of trying to define ‘IoT’ directly, relies on the definition of ‘internet connected devices’. Unfortunately, that forces the inclusion of just about any electronic device, including phones, personal computers, main frames and even super computers. This goes well beyond the IoT problem that Latta is trying to address.

Now, this could result in one of two things. DoC could attempt to complete the survey and report using the definition provided in the bill. But, the lack of specific funding would make that difficult and would result in an incomplete study. Or, it could attempt to divine Latta’s actual intent and limit their study to the ‘smart devices’ (another poorly defined term) that are being increasingly being connected to the internet with securityless (made up word) abandon.

Oh yes; security. That is something else that is curiously missing from specific mention in the bill. Well, not entirely true, in the paragraph on the report to Congress it requires that the report includes “recommendations of the Secretary for growth of the United States economy through the secure [emphasis added] advancement of internet-connected devices” {§2(b)(2)}. Of course, no definition is provided so we could be talking about cybersecurity, supply chain security, or even (a stretch to be sure) physical security.

Okay, one last problem (really, I am stopping here), there is no mention of the bandwidth issue that is associated with these internet-connected devices. And that would include radio frequency bandwidth for both the wireless connections nearly universally used by these devices and the amount of information clogging the information highway.

Friday, June 8, 2018

Bills Introduced – 6-7-18


Yesterday with both the House and Senate in session there were 47 bills introduced. Of those, two may be of specific interest to readers of this blog:

HR 6032 To direct the Secretary of Commerce to conduct a study and submit to Congress a report on the state of the internet-connected devices industry in the United States. Rep. Latta, Robert E. [R-OH-5]

S 3023 An original bill making appropriations for the Departments of Transportation, and Housing and Urban Development, and related agencies for the fiscal year ending September 30, 2019, and for other purposes. Sen. Collins, Susan M. [R-ME]

I will be watching for the outside possibility that HR 6032 will consider specific requirements for either control system devices or cybersecurity in the reporting criteria.

S 3023 would be the Senate version of the THUD appropriations bill. I typically watch that for chemical transportation issues.

Wednesday, August 2, 2017

S 1691 Introduced – Cybersecurity Standards

Yesterday Sen. Warner (D,VA) introduced S 1691, the Internet of Things (IoT) Cybersecurity Improvement Act of 2017 (NOTE: this is a link to an unofficial copy of the bill on Scribd.com provided by Warner’s office). The bill would establish cybersecurity standards for internet connected information systems bought by agencies of the Federal government.

Definitions


Section 2 of the bill establishes ten definitions of terms used in the bill. Seven of those terms are cyber-specific terms:

• Firmware;
• Fixed or hard-coded credential;
• Hardware;
• Internet-connected device;
• Properly authenticated update;
• Security vulnerability; and
• Software

Two of these definitions are of specific importance in establishing the scope of this bill. The first is ‘internet connected device’. This is defined as “a physical object that is capable of connecting to and is in regular connection with the Internet; and has computer processing capabilities that can collect, send, or receive data” {§2(6)}. The second is ‘security vulnerability’. This is defined as “means any attribute of hardware, firmware, software, process, or procedure or combination of 2 or more of these factors that could enable or facilitate the defeat or compromise of the confidentiality, integrity, or availability of an information system or its information or physical devices to which it is connected” {§2(9)}.

Vendor Responsibilities


Section 3(a) of the bill requires the Office of Management and Budget to publish contract guidelines that would establish vendor responsibilities in providing internet connected devices to agencies of the Federal government. Primarily the vendor would be required to provide written certification that each internet connected device {§3(a)(1)(A)(i)}:

• Does not contain, at the time of submitting the proposal, any hardware, software, or firmware component with any known security vulnerabilities or defects;
• Relies on software or firmware components capable of accepting properly authenticated and trusted updates from the vendor;
• Uses only non-deprecated industry-standard protocols and technologies for functions such as communications, encryption and interconnections with other devices or peripherals.

Vendors would also be required to provide agencies subsequent notification “of any known security vulnerabilities or defects subsequently disclosed to the vendor by a security researcher or of which the vendor otherwise becomes aware for the duration of the contract” {§3(a)(1)(B)}. It also requires system support “in a manner that allows for any future security vulnerability or defect in any part of the software or firmware to be patched in order to fix or remove a vulnerability or defect in the software or firmware component in a properly authenticated and secure manner” {§3(a)(1)(C)}. Finally, it would call for repair or replacement of any component that cannot be patched to fix an identified security vulnerability.

On a case-by-case basis, waivers of the above requirements could be requested through the OMB. Justification for the waivers would have to include alternative mitigation measures. NIST would be required to establish standards for alternative mitigation measures. That would include NIST approval of third-party security standards.

Security Vulnerability Research


Section 3(b) would require the DHS National Protection and Programs Directorate (NPPD) to establish guidelines for “for each agency with respect to any Internet-connected device in use by the United States Government regarding cybersecurity coordinated disclosure requirements that shall be required of contractors” {§3(b)(1)} providing internet connected devices. The guidelines would address {§3(b)(2)}:

• Policies and procedures for conducting research on the cybersecurity of an Internet-connected device, which shall be based, in part, on ISO 29147; and
•Require that research on the cybersecurity of an Internet-connected device provided by a contractor to the United States Government shall be conducted on the same class, model, or type of the device provided to the United States Government and not on the actual device provided to the United States Government.

Section 3(c) of the bill would amend two statutes related to computer crimes to provide some protection to security researchers. First the bill would amend 18 USC 1030 to provide an exception to that section for security researchers conducting vulnerability research in accordance with standards established under §3(b)(2) on “an Internet-connected device of the class, model, or type provided by a contractor” {new §1030(k)(1)} to the US government. Second the bill would amend 17 USC 1203 providing a similar exception to the copywrite restrictions in that section.

To make these exceptions usable to security researchers not associated with the contractors providing the devices, the OMB would be required to maintain a publicly accessible database of “devices and the respective manufacturers of such devices for which limitations of liability exist under this Act” {§3(c)(3)}. A similar database would be maintained listing of devices for which notification has been received by the federal government that security support has lapsed on those devices.

Moving Forward


Warner is not a member of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. One of his three cosponsors {Sen. Daines (R,MT)} is, however, a member of that Committee so it is possible that the bill could be considered in Committee.

This would be a fairly large change in congressional action on cybersecurity, so it is likely to take some time for this bill to move forward. There would be some push-back from industry on the requirements of the bill (see my discussion below), but nothing that should prevent the bill from passing if considered. I suspect that there will be significant changes to the bill made in Committee before it has a chance to move forward.

Commentary


The title of the bill is a serious misnomer. There is no mention of IoT in the bill and the requirements are certainly not limited to devices that are normally included in the term ‘internet of things’. Almost any electronic device capable of internet connection (certainly including lap top computers, office computers, servers, and even cell phones) would be included in the definition of ‘internet connected device’.

Whether or not the definition specifically applies to industrial control systems used by federal agencies is slightly less clear. They can certainly be ‘internet connected devices’, but arguments could be made that ICS devices are not included since they are not ‘information systems’ as that term is used in the definition of security vulnerability. I do not think that anyone on Warner’s staff had a firm idea either way when they wrote this bill.

The biggest problem with this bill (from the view point of contractors) are the provisions of §3(a)(1)(A)(i) that prohibit the supplying of devices with known security vulnerabilities. Typically, computers and other electronic devices are shipped with a basic version of the software. Security updates that are developed between the date that version was installed and the contract date are then provided to the customer once the system is set up. This provision would require the contractor to open the box, apply the interim updates, and then deliver the computer. The additional time and personnel required to complete these tasks could increase the costs of the system.

Another problem is that a contractor may not be (I suspect frequently is not) the manufacturer/vendor of the device. They thus they may not know all of the security vulnerabilities known to the manufacturer. The wording of the bill does not include a qualifying ‘known to the contractor’ provision, setting the contractor up for a variety of potential problems if the contractor does not have a very close relationship with the manufacturer/vendor. This problem is made even more vexing by the use of third-party software and libraries(see for example my post here) by the manufacturer/vendor; they may not even be aware of all of the ‘known security vulnerabilities’. In some circumstances the manufacturer/vendor may not be willing to share ‘all of the known vulnerabilities’ with the contractor.

I understand the need for the first database (the listing of device types). Since researchers can only get credit for coordinated disclosure research when they conduct their research “on the same class, model, or type of the device provided to the” government, the independent researcher needs to know which devices should be used for their research. The reason for the second database (listing of devices for which security support has expired) is much less clear. I’m not sure that the crafters of the bill realize that the information in the database combined with the use of a search engine like Shodan, could provide attackers with a very interesting list of potentially vulnerable government devices.

I am rather surprised that the crafters of the bill did not provide some additional instructions about these databases. First, given congressional concern with privacy, I would have expected to see a prohibition about including personally identifiable information in the database. More importantly, I would have liked to have seen it specified that the database would not include the agency or office to which the device belonged in the device listing.

I will be surprised to see this bill actually pass in this Congress. There has been a reluctance to establish any firm cybersecurity rules legislatively. Part of that is (I hope) a realization that there is a basic lack of the necessary technological background in Congress (or its staffs) to write effective legislation about cybersecurity matters.

Having said that, I think that this legislation (with some minor fine tuning) may actually be an interesting alternative to cybersecurity mandates upon the general population. While it does not directly affect most businesses (very few actually sell to the federal government) it should have a bootstrap effect as devices meeting the government standards would also be sold to the private sector. Additionally, business wishing to ensure the cybersecurity of their own devices would have model contract language available as well as a stable of contractors available that were used to abiding by that language.


This is almost certainly not the most effective way to get to a society with an adequate basic level of cybersecurity proficiency, but it is probably the most politically expedient.
 
/* Use this with templates/template-twocol.html */