Showing posts with label Monthly Monitor. Show all posts
Showing posts with label Monthly Monitor. Show all posts

Friday, October 12, 2012

ICS-CERT Publishes Monthly Monitor


Yesterday the DHS ICS-CERT published the latest version of their Monthly Monitor covering ICS security operations in August. This issue includes a discussion of Shamoon, updated Smart Grid information and many of the repeated features that readers have come to expect.

Delayed News


I have been a strong supporter of the Monthly Monitor from the time that it was first issued, but it seems to me that it is becoming increasingly ineffectual. Part of this is due to the delay in the information presentation. Yesterday was the 11th day of the October and we are just now receiving the September issue. Since there is no breaking news included in this publication, that delay is troubling.

To make matters worse the information in this issue is really from August. The only timely information comes on the ‘Upcoming Events’ page that lists cybersecurity events for October, November and December. Given the fast moving pace of control system security information this delay in presenting information is becoming increasingly irritating and is fast making this publication irrelevant.

Too Vague


This problem is compounded by broad generalities that the editors are forced to speak in when describing ICS-CERT actions in the field. For example in regards to the five on-site assessments that ICS-CERT conducted during August, the editors describe the findings this way:

“General findings included interconnectivity to external networks that require defense-in-depth strategies to protect them from cyber attacks.”

I understand that specifics cannot be made available because of confidentiality agreements and such, but it would be nice to see some sort of characterization of the kinds of interconnectivity (deliberately established, inadvertently established by owner actions, or connections established by programming/documentation errors made by the vendor for example) or even a listing of what types of networks the control systems were connected to (enterprise, security, internet, etc).

Without these types of more detailed information, this ‘ICS-CERT Risk Evaluations’ report is little more than a ‘see what we did’ exercise and 5 on-site assessments in a month just doesn’t sound that impressive. Now if we had been told that a typical assessment took three days on-site and three to four ICS-CERT personnel took part in the average visit, I would be much more impressed.

BTW: They missed the boat on this short report by not informing us of how facility owners could request having ICS-CERT conducting this type of risk evaluation at their site.

Coordinated Disclosures


I am happy to see that the editors continue to plug away at getting security researchers to coordinate the disclosure of their vulnerability discoveries. List the names of researchers working with ICS-CERT on such matters certainly gives these folks some of the name recognition that should come with this type of work.

What is unstated, but even more impressive is the increase in the number of researchers so listed. The January 2012 issue listed 19 researchers and this issue lists 29. This is almost certainly a good thing for the industry (though I’m not sure that the vendors would necessarily agree), but it certainly is an important measure of how the interest in ICS security matters is expanding in the ‘research community’; too bad there isn’t a similar measure of the black-hat community interest.

 

BTW: No mention on ICS-CERT website yet about latest Gleg release that I mentioned Wednesday.

Thursday, August 2, 2012

ICS-CERT Has Been Busy


With the Senate debating a cybersecurity bill that actually includes control system coverage, the folks at ICS-CERT have been hard at work trying to keep the control system community up to date on just how vulnerable our systems are. This week they have published, so far, three alerts, four advisories and their Monthly Monitor.

Alerts



The DEFCON 20 conference last week was the source of the disclosure for two of the alerts, both reported by Dr. Wesley McGrew of Mississippi State University. Both deal with credential type issues and neither are remotely executable. The only thing of real  interest here (other than to owners of the affected systems) is that these are the only vulnerabilities to be reported at DEFCON 20 that ICS-CERT has been concerned about.

The third alert comes from an uncoordinated disclosure from Luigi. It’s a directory traversal vulnerability. It is remotely exploitable and Luigi has, as always, published proof of concept code on his web site. As expected, ICS-CERT did not include a link to Luigi’s disclosure, but I will. According to Luigi’s web site this disclosure was made back in June, hardly a timely notification by ICS-CERT.

It turns out that Luigi is also a composer. If you like techno type instrumentals, check out some of his tracks. 

Advisories



Siemens has self-reported vulnerabilities in two separate systems; it seems that they have gotten on the identifying-correcting-reporting bandwagon. Two versions of  SIMATIC S7-400 CPU have DOS vulnerabilities. Siemens has provided a firmware update for the V6.03 CPU but not the V5 as it has reached end-of-life and has been discontinued. Of course everyone has replaced the older version so it isn’t really a problem (SARCASM alert).

The second Siemens advisory deals with a default password in their Synco OZW Web Server device used for building automation systems. This would allow access to the building automation network which may (not mentioned in the ICS-CERT Advisory) include security systems. A firmware update is available, but changing the default passwords is a simpler option.

Dr. McGrew (mentioned above) was responsible for the coordinated disclosure of the authentication by-pass vulnerability in the ICONICS  GENESIS32 and BIZVIS Security Configurator. ICONICS is releasing a patch that disables the backdoor security login in some versions (no word on the others) and plans to implement a “more secure encryption algorithm” in the future. There is a publicly available exploit for this vulnerability. HMMM… did Dr. McGrew talk about this at DEFCON as well? Maybe this should have been an alert instead of an advisory.

The Sielco Sistemi advisory closes out two ICS-CERT Alerts for the Winlog SCADA system (one from a Luigi disclosure and another by Michael Messner). Sielco Sistemi has provided a software update that has been verified by Messner (oops, I guess Luigi is on the outs again).

Monthly Monitor


The latest two-month issue of the Monthly Monitor is, as always, a worthwhile read. They provide an interesting update to their previous report on the apparently on-going phishing attacks on pipeline companies. In my opinion the most important part of that discussion is found in the second paragraph on the first page:

“Recent reports and analysis conducted by ICS-CERT indicate that information pertaining to the ICS/SCADA environment, including data that could facilitate remote unauthorized operations, has been exfiltrated as part of this campaign. Despite this, ICS-CERT has not received any reports of unauthorized access into the ICS environment; however, this may be due to limited monitoring and intrusion detection capabilities in the targeted companies control networks. The intent of the attackers remains unknown.”

While this spear phishing campaign appears to be solely directed at pipeline companies, owners of all control systems need to pay attention to this. It is a classroom lesson in how to go about a systematic attack on control systems; infiltrate the system to gain the knowledge necessary to formulate an effective attack on the system. Much the same thing must have been done to prepare the Stuxnet attack.

There is also an interesting snippet about what may be the ‘next’ systemic vulnerability, inadequate keys or certificates in embedded devices. It is apparent that ICS-CERT is concerned about this apparently wide-spread vulnerability. They note that:

“ICS-CERT is currently coordinating with multiple vendors that could be affected by this vulnerability.”

Typically I would expect silence about a vulnerability that is this important until the vendors either have a chance to fix it, or ICS-CERT gives up on their cooperation. Either ICS-CERT is changing their policy (maybe because this is so important) or the level of cooperation that they are receiving leaves much to be desired. We’ll be watching for advisories on this topic and will wonder when people like Luigi start to look for these on their own.

Saturday, June 9, 2012

ICS-CERT Publishes May Monthly Monitor


Yesterday the folks at ICS-CERT published the latest issue of their Monthly Monitor, a newsletter about all things concerning control systems security. Always an interesting read, this issue:

• Describes a thumb-drive incident;

• Explains complexities of international disclosure coordination;

• Discusses the ‘end of life’ for XP; and

• Recaps the ICSJWG Spring Conference.

As usual it includes their standard features:

• Recent ICS-CERT Product Releases;

• Open Source Situational Awareness;

• Up Coming Events; and

• Coordinated Vulnerability Disclosure.

There is one new feature that I would like to see in this newsletter. We all know that there is sensitive and/or classified cybersecurity information that ICS-CERT and US-CERT share with vetted individuals and organizations via their ‘Secure Portal’. It would be interesting to see an unclassified summary of that information included in the Monthly Monitor. I think this would encourage more organizations to try to get cleared for access to that information and it would give the rest of us unwashed individuals a better understanding of the state of the cybersecurity threat.

Sunday, March 4, 2012

February 2012 ICS Monthly Monitor

On Friday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published their February 2012 issue of the Monthly Monitor. This issue includes a brief description of a government facilities incident independently identified by ICS-CERT and a lengthy discussion about network-based intrusion detection systems (NIDS) for control systems.

Incident Description


The incident briefly described on the first page of the monitor deals with a government owned control system of a type frequently overlooked in the general discussion of industrial control systems, an environmental control system for a building. While not directly involved in the production of commercial products they may be used in an important support role in many manufacturing locations (clean rooms for instance).

In this instance ICS-CERT somehow (not discussed in the brief report for obvious reasons) detected the intrusion into the environmental control system of an unidentified state government building. Facility personnel had already detected unauthorized adjustments to the control system and had already reconfigured their system to remove internet access to the controls.

ICS-CERT determined that the access had been made through the Internet interface for the system even though it had been configured to require a password. The report does not note whether the password had been a default password, if it had been compromised or if it had been broken by a bruit-force attack.

The most interesting thing about this brief report is that ICS-CERT contacted the facility not the other way around. As with the ‘water system hack’ last year it is becoming increasingly evident that the services of ICS-CERT are not adequately known or facilities are reluctant to report incidents to the one government agency most likely to be able to help them deal with a control system intrusion or attack.

Situational Awareness


In the Situational Awareness article there is an informative write up about NIDS and two open source NIDS packages recently upgraded (SNORT) or being upgraded (Suricata) to be useful in detecting control systems intrusions. This information alone in the article makes it well worth reading, but the lengthy article also addresses two other ICS issues of at least equal importance; Project Basecamp and source code exfiltration.

Project Basecamp is certainly not new and it has been addressed by ICS-CERT in advisories and alerts, but this is the first time that ICS-CERT has actually described the Project Basecamp process and discussed its consequences (and yes, it does include the appropriate links to the source material). Nothing really new informationally here, but it is a valuable acknowledgement of the importance of Project Basecamp.

The recent public exposure of the source code for two Symantec products (Norton Anti-virus and PCAnywhere) is addressed in the portion of the article about source code. While these two specific incidents have been addressed in more depth elsewhere, this Monthly Monitor piece addresses the general potential importance of exfiltrating control system source code. While identification of system vulnerabilities is the most obvious problem with gaining access to the source code for any application this ICS-CERT write-up identifies an even scarier potential problem modifying the code to implant backdoors and other vulnerabilities and re-infiltrating the code on the vendor’s site for distribution. Similar problems could occur if doctored counterfeit copies of the system were sold on the black market.

The Situational Awareness article closes with a well-deserved plug for the ICS-CERT CSET Assessment Tool and the on-site assistance that ICS-CERT can provide for using that tool to conduct an in depth assessment of the security of a facility’s control system.

Another Good Monthly Monitor Issue


The other standard features of the Monthly Monitor provide a wealth of valuable ICS-CERT information (list of ICS-CERT alerts and advisories from February) and links to other sources of ICS security information. The plug for coordinated vulnerability disclosure includes even further expanded recognition of researchers who do not fully work ‘within the system’ on vulnerability disclosures by recognizing researchers who do assist in the validation of patches developed in response to their uncoordinated disclosures.

All in all this is another example of the type of open-source information sharing that should be the hallmark of any public-private partnership on ICS security.

Thursday, December 22, 2011

New ICS-CERT Monitor and 2 Advisories

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published the December edition of their Monthly Monitor and two new Advisories for control system vulnerabilities affecting WellinTech’s KingView and 7-Technologies IGSS SCADA systems.

Monthly Monitor


ICS-CERT continues to produce a brief but valuable monthly newsletter that should be widely read in the control system community. The latest issue contains:

• A neat new logo (okay that’s not so important, but it is good graphics design);

• Another overview of the ‘Water System Hack’;

• A good summary of generic malware analysis and mitigation techniques;

• A summary of the ‘latest’ Gleg Agora SCADA release (probably more appropriate here than as an alert)

• A lengthier listing of control system security articles and blog posts (including one by SCADAHacker, a nice response to my comment last month about the lack of bloggers); and

• Their standard listing of Alerts and Advisories and plug for Coordinated Vulnerability Disclosure

WellinTech


This Advisory describes a heap based buffer overflow vulnerability reported by Luigi through ZDI (so it was coordinated) in the WellinTech KingView system. It appears to be a common remotely exploitable vulnerability that allows execution of arbitrary code by an attacker with an intermediate skill level. WellinTech has a patch available. The CVE number provided in the Advisory is not yet active.

Two interesting things here. First ICS-CERT includes a link to the Chinese language instructions for the patch in addition to the English language instructions (multiculturalism at its best). More importantly the Advisory notes that there are no known exploits available. Luigi typically develops and publishes exploit code, though I can’t find a reference to this vulnerability on his web page. Since this is part of the ZDI project I wonder if he provided them with the code and they just haven’t released it.

7-Technologies


7-Technologies seems to be catching it this week. Earlier there was an advisory for their data server and yesterday a new advisory for similar buffer overflow vulnerability discovered by a separate researcher Celil Unuver (SignalSEC LLC). It appears that the same product update will solve both problems. The CVE file on this vulnerability is also not yet active.

Wednesday, November 23, 2011

ICS-CERT Reports on Water Hack and Published Monthly Monitor

Today the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published a bulletin on the cyber security talk of the last week, the report of a water hack of a water control system in Illinois and the latest issue of their Monthly Monitor. Both provide important information on industrial control system security.

No Water Hack in Illinois


All of us who have been talking about the report from the Illinois Statewide Terrorism & Intelligence Center (ISTIC) are going to have to do some explaining about our apparent overreaction to a premature report. According to an Information Bulletin issued today by ICS-CERT the fly away team has looked into situation and cannot find any information to support the preliminary conclusion from the ISTIC that a cyber-attack was involved in the pump failure Curran-Gardner Public Water District. The report states that:

• There is no evidence of a cyber-intrusion into the SCADA system of the Curran-Gardner Public Water District in Springfield, Illinois;

• There is no evidence to support claims that any credentials were stolen; and

There was no malicious or unauthorized traffic from Russia or any foreign entities.

It seems that we all reacted to Joe Weiss’ report about the ISTIC report as if it were established fact. While most of us included appropriate weasel words (I prominently included: ‘If this happened’ at the start of my initial tirade) it was apparent that we took the report at face value. This is probably because most of us know that it is just a matter of time that this will happen for real. Unfortunately, we have some egg on our face with people inevitably talking about the boy who cried wolf.

I still believe that ICS-CERT could have nipped a lot of this yelling and screaming in the bud if they had published an alert on the initial ISTIC report (even though they received it six days after the alert was published) much the same way that they do with initial reports of uncoordinated-disclosures of a new soft-ware vulnerabilities. Then the report published today would have been their follow-up and most of us would have commenting on the over reaction of ISTIC.

The bigger problem, in the long run, is that ICS-CERT is so unknown outside of a relatively small circle of control system security experts that a State intelligence agency did not contact them immediately upon receiving  the initial report of a control system incident. This is an issue that DHS needs to address through its network of fusion centers.

November Monthly Monitor


ICS-CERT published the latest issue of their November Monthly Monitor today. This is one of the tools that ICS-CERT uses to communicate with the control system security community. This issue addresses vulnerability disclosure, researcher acknowledgment, Duqu and internet facing control systems.

They have a nice brief piece on the recent discussions about responsible disclosure that ICS-CERT participated in at the recent ICSJWG fall meeting. With their typical class, they gave recognition to Dale Peterson, one of their vocal critics on this topic. One of the results of the discussion was that ICS-CERT has reviewed and modified their policy on providing attribution for uncoordinated disclosures of newly identified vulnerabilities. They will now provide the name of security researchers (unless the researcher requests anonymity) for all vulnerability discoveries, even if the researcher does not participate in the coordinated disclosure program.

There is a nice summary article about Duqu. There is no new information that has not already been published by ICS-CERT. They do provide a summary of the differences between Stuxnet and Duqu, noting that their analysis of the “code and each malware’s characteristics indicates significant differences between Duqu and Stuxnet, lending more fuel to the debate about common authorship”.

There is a short piece on internet facing systems that notes that Eireann Leverett, at Cambridge
 University has discovered “thousands of Internet facing control system devices throughout the world”. ICS-CERT “responded to reports of over 70 instances of Internet facing control system devices, mostly in the water sector” in the month of April alone.

Sunday, August 21, 2011

ICS-CERT Monthly Monitor


Friday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published the latest edition of their ICS security newsletter, the ICS-CERT Monthly Monitor; which this issue covers two months. A number of interesting topics are covered in this issue, including Spear Phishing, Black Hat 2011, the Siemens fiasco and preserving cyber forensics data.

Spear Phishing


A nice article on Spear Phishing notes that ICS-CERT has been responding to an “increasing number of spear phishing attacks”. One would assume that when ICS-CERT got involved it was a successful spear phishing attack where something ‘malicious’ was noted on the attacked network. It is interesting to note in the article (mentioned in passing as it were) that the apparent response to a successful spear phishing attack involves shutting down the corporate email system “until the extent of the problem [is] known and mitigation steps [are] taken”.

Black Hat Briefings


The brief piece on the Black Hat Briefings conference provides a brief bit of information from the conference that I haven’t seen mentioned elsewhere; the description of an airborne hacker tool. The wireless aerial survey platform (WASP) is apparently a remotely piloted vehicle that would fly over an installation trying to detect and intercept Wi-Fi and cell transmissions. With the increased use of wireless communications between control systems components, this could provide another route of access into the control system network. Of course, high-risk chemical facilities should already be concerned about the use of RPVs for surveillance or even attacks, so this is just one more reason to acquire sophisticated anti-aircraft attack capabilities (just a little sarcasm).

Siemens


The brief piece on the Siemens issues provides essentially a summary of their summarizing advisory that I have previously addressed. I would like to suggest that an alternative analysis of the ICS-CERT approach to the Siemens issues can be found at Ralph Langner’s recent blog posting on the issue. Anyone who has read Ralph’s stuff on Stuxnet will not be surprised that he has been less than enamored with the response of ICS-CERT on much of anything to do with Siemens.

Cyber Forensics


There is a relatively lengthy piece on cyber forensics and the importance of planning for how to respond to a cyber incident. Most facilities will be focusing on getting their systems back into the normal functional mode when something goes wrong with their system (either from an attack, human error, or just a glitch piece of equipment/software). Cyber forensics is used to determine why and how a problem occurred and is important in figuring out how to limit the current problem and prevent it from happening again. This piece is well worth the read and further exploration. Some of the techniques suggested for preserving forensics data would normally fly in the face of standard procedures for quickly restoring functionality, but with more cyber-attacks occurring, facilities really need to consider these techniques as a method of discovering the true extent of what happened.

Other Information


There is also a nice text box describing the wonders and benefits of ‘coordinated vulnerability disclosure’. ICS-CERT has a vested interest in the CVD process, so they can be expected to support it. It seems to me that when the process works (ie: the vendor responds promptly and puts forth a reasonable effort to fix the problem) this system provides the most effective method for identifying and responding to vulnerabilities. When there is no response, or an inadequate response, then alternate methods of communication need to be used.

Finally, the Monitor closes with two pages of ‘Open Source Situational Awareness Highlights’; a listing or articles and blog posts of significance to the control system security community. While certainly not an exhaustive bibliography, it certainly provides a pretty good reading list. I was impressed that there are a couple of blog posts included in their list (none of mine, alas). I would have been more impressed if they had included a listing of some posts by people like Ralph Langner or Dale Peterson that questioned the various responses of ICS-CERT to cyber security issues, but that would be expecting a bit more objectivity than is probably reasonable.

In short, this is a fairly impressive newsletter by a government agency that is small but important cornerstone of the Federal response to cyber security issues in industrial control systems. Everyone in the ICS security community should read it.

Thursday, April 7, 2011

New ICS-CERT Publications

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published links to two new ICS advisories and a new monthly newsletter. One advisory provides further updated information on the Siemens FactoryLink vulnerabilities reported last month by Luigi. The second advisory provides more information on the recently released Agora SCADA+ Exploit Pack.

ICS-CERT Monthly Monitor

It looks like ICS-CERT is trying to establish a monthly newsletter to provide the control system community to keep up to date on what’s going on in the security arena. The April edition of the Monthly Monitor provides an interesting summary of events that have been going on over the last few months including a list of released alerts and advisories.

There is an interesting summary of some investigations that the teams have undertaken at some water treatment facilities (the summaries have been combined and scrubbed to remove any juicy (revealing) details. The ‘lessons learned’ section doesn’t provide any real new information, but it does emphasize some important control system security issues.

If ICS-CERT keeps up this level of quality on these monthly newsletters, they will become an important part of the ICS security literature that should be reviewed by everyone working with and/or managing control system security. I would like to suggest that DHS consider establishing a subscription based email distribution of these newsletters. It would be well worth the effort.

FactoryLink Advisory Update

The updated advisory on the Siemens FactoryLink vulnerability provides confirmation by ICS-CERT that the patch provided by Siemens does adequately correct the previously identified vulnerabilities.

Agora SCADA+ Exploit Pack

The advisory on the Gleg Agora SCADA+ Exploit Pack for the Canvas system is an interesting summary on this package of adaptations of a large number of industrial control system vulnerabilities and exploits for use in penetration testing. There has been some discussion about this package in a number of control system security blogs. The new information here is a summary of the known vulnerabilities that ICS-CERT believes to be included in the latest update of SCADA+.

The advisory also notes that it appears that there may be five previously unidentified (0-Day) vulnerabilities include. Apparently there are not enough technical details about these vulnerabilities provided to ICS-CERT to allow them to completely verify their status.

ICS-CERT is careful to explain that this is a preliminary report, noting:

“Please note that at this time, the information contained in this report is not conclusive, nor is it comprehensive. This report represents a cursory and credible snapshot of the vulnerabilities that are likely contained in the pack, based on the analysis conducted by ICS-CERT.”
 
/* Use this with templates/template-twocol.html */