Showing posts with label Physical Security. Show all posts
Showing posts with label Physical Security. Show all posts

Sunday, February 1, 2015

Committee Hearings – Week of 2-1-15

The number of hearings being conducted this week is on the increase, especially on the Senate side of the building. There are three hearings that may be of specific interest to the readers of this blog; one physical security and one cybersecurity.

Facility Access

The Transportation Security  Subcommittee of the House Homeland Security Committee will be holding a hearing on Tuesday on “A Review of Access Control Measures at Our Nation’s Airports.” The current witness list includes:

Mr. Mark Hatfield  - TSA, DHS
Mr. Gary D. Perdue - FBI
Ms. Sharon Pinkerton – Airlines for America
Mr. Miguel Southwell – Hartsfield-Jackson Atlanta International Airport

Airports share a common problem with large chemical facilities, how to control access through multiple gates in a very long perimeter. There will not be a lot of specifics about security measures discussed here, but the questioning may give some insight on how the new Congress will be looking at security issues.

Cybersecurity Issues

The Senate Commerce, Science and Transportation Committee will be holding two hearings this week on cybersecurity issues. The first hearing will be on Wednesday and it will look at “Building a More Secure Cyber Future: Examining Private Sector Experience with the NIST Framework”. The second hearing will be on Thursday on “Getting it Right on Data Breach and Notification Legislation in the 114th Congress”. There are no witness lists currently published for either hearing.

It will be interesting to see how the conflict between the Commerce Committee and the Senate Homeland Security and Governmental Affairs Committee will play out in the Republican controlled Senate. One of the problems in the last couple of sessions in the Senate that lead to very little actual action on cybersecurity issues was the differing outlooks of the two committees.

Neither of these hearings will specifically address control system issues. The big picture in Congress (for the immediate future at least) will be focused on IT issues and specifically those dealing with the compromise of personal information. Any legislative proposals will reflect that focus, though there may be minor, after-thought language expanding coverage to control systems. This may cause more problems than it solves for the control system security community, we will just have to wait and see.

On the Floor

As I mentioned in two earlier posts today, there are two bills coming to the floor of the House that may be of specific interest to readers of this blog: HR 361 and HR 623. Both will be considered on Monday under the suspension of the rules provisions. This means that the House leadership expects these bills to gain enough bipartisan support to sustain a 60% vote required for passage under these rules. I expect that the votes will be much closer to 90% in favor of these two bills.


The Senate is beginning to look at HR 240, the FY 2015 DHS spending bill that passed in the House last month. There will be a first cloture vote on Monday that could lead to the actual debate on the bill. Watching the recent action on S1, the Keystone pipeline bill, I expect that we will see vigorous debate with a number of amendments offered and voted upon. There is a February 27th deadline to get a bill to the President and we may see a short term continuing resolution while the Senate works on amending HR 240 and the two houses of Congress work out their differences on that bill.

Monday, December 8, 2014

If Sony Had Been a Chemical Plant

The infosec world is still buzzing about the recent hack of Sony and how completely their information systems were owned by the attacker. Researchers will be pouring over this attack for a while trying to figure out how it all happened and what could have been done to prevent it.

The Hack

The Sony hackers took, among other things, valuable intellectual property (high quality digital copies of yet to be released films), thousands of internal documents (one source said 1 terabytes worth), and system access information to include log-in credentials and passwords. The attack was so thorough that Sony was forced to shut down all computer systems for days while they went through and inspected/cleaned every machine.

The TWITERVERSE is all agog, of course about #SonyHack. I’ve made my own small contribution (sans hashtag, of course). The one tweet of mine that I would like to look at in more detail came on Saturday:

I guess we should be glad that Sony didn't make dangerous chemicals or supply something really important....”

XYZ Chemical Company

So what would have been different if it had been XYZ Chemical Company that had attracted the ire of the GOP attackers? Other than differences in what IP was stolen, probably not much in the immediate results of the attack. The longer term results could have been much more serious to communities around XYZ plants and possibly to the nation.

Intellectual property theft? Well, formulations come to mind first. The wholesale release of formulations would give every competitor here and around the world a leg up in understanding how XYZ makes their products. Even for fully mature product lines, the little tweaks to the formulation a company makes can make a major difference in pricing and performance. This could make for a serious change in competitive status.

The public publishing of the formulations could have other consequences as well. There are a number of chemicals being used in the chemical industry that have raised concerns among environmental activists. If a formulation list included such chemicals the company could come under additional scrutiny from these activists, potentially leading to image issues. Worse yet, if any of the chemicals being used were on the lists of chemicals offensive to various environmental wacko fringe groups, the facility could become a target for varying degrees of physical attacks.

Control System Insecurity

From a security perspective the IP that is of more concern, however, would be process flow diagrams and control system working documents. Those pieces of information would make it much easier for an attacker that has gained access to the control system to figure out how to manipulate the controls in that system in a manner that could disrupt the facility in the worst possible way.

Since most corporate types use a single set of login credentials across the entire spectrum of company computer systems, it is very likely that even if the control systems were not directly breached in the attack, there would be useable log-in credentials for the control systems to be culled from the corporate log-ins. Once an attacker can gain legitimate access to a control system, the various ‘insecure-by-design’ problems become very large vulnerabilities.

If the control system had been directly breached as well the problems become much worse. The shut down and start-up of a chemical control system, particularly with continuous chemical processes like refineries, is not something that is done lightly or quickly. And searching control systems for logic bombs, back-doors, and forms of re-programing is a much more time consuming task than for an IT system of comparable size. The larger the number of PLCs involved the more difficult the task becomes.

Physical Insecurity

One set of computer data files that no one wants to see released are physical security plan files. Password and log-in credentials can be changed fairly easily, but making significant changes to a site security plan are very expensive and time consuming. The public availability of site security plans would make the facility much more susceptible to physical attack or theft of chemicals.

While there are some people that claim that the Sony attackers had at least some physical access to the corporate computer system that would not necessarily mean that that access included detailed information about the site security plan. Most folks entering a facility are aware of only a small part of the over-all security plan for the facility.

For many chemical manufacturing facilities a major source of security concerns can be found in the computer systems of the order handling folks. The timing and sourcing of inbound and outbound chemical shipments makes them that much more vulnerable to off-site attack. Those attacks may allow for inbound shipments to be intercepted and converted to a method of attack (VBIED) or simply diverted to some other nefarious or illegal end.

The Big Picture


The major take away from this attack is that this was no longer a hack to deface a web site, steal money or credentials. This was a full scale attack on a company with the intent of seriously harming the company for some as of yet unknown reason. The scope and scale of the attack is unlike anything we have seen in the corporate world. Unfortunately, as with all things cyber, it will undoubtedly set the new gold standard for serious attacks as it give other groups and hackers ideas about what can be accomplished with a successful cyber attack.

Monday, February 17, 2014

Physical Security – Another Perspective

There is an interesting piece on NewYork.CSBLocal.com detailing complaints from Sen, Schumer (D,NY) about the ability of power companies to veto security requirements. I’ll leave the discussion of the politics of electrical system security to the folks that deal with it on a routine basis. I would like to point out a serious flaw in Shumer’s reasoning, a flaw that has been bandied about quite a bit in discussions of this attack on Silicon Valley transformer stations; the assumption that these stations can be protected against a serious physical attack.

The Target

You see these stations scattered all around the country. Some of them are bigger and some are smaller, but they all have a couple of things in common. First off, the purpose of these stations is to transform the very-high voltage cross country transmission lines into the lower voltage used by local transmission networks. The equipment is widely spaced to ensure that there is room to work without worrying about sparks jumping from one set of equipment to another. The big boxes hold huge coils of copper wire surrounded by a cooling fluid, typically an oil of some sort.

If you put a hole in the outer jacket the oil drains out, the transformer overheats and at the very least shuts down. If a shooter is extremely lucky or knowledgeable the bullet will strike and damage the copper coil and cause an immediate shut down.

Another vulnerable area in these stations are the insulators that protect the physical structure of the towers and such from the high voltage transiting the lines. If these are damaged to the point that they allow arcing to the towers or fail to continue to support the transmission lines, you have another immediate shutdown of power transmission.

The slower the shut down the easier it is for the transmission company to re-route the power through other parts of the station or to other stations in a systems with a certain amount of redundancy. The more parts of the system that are taken off-line the more difficult it is to keep the power flowing. It is a testament to the system operator that the loss of 17 transformers at a single transmission station did not take down a large portion of California’s power grid.

Vulnerabilities

It seems as if this attack was executed by multiple shooters putting holes in transformer shells. This does not take snipers unless they are working from really long distances away from the site. Any trained infantryman (or hunter for that matter) can consistently hit a man-sized silhouette at about 300 meters over open sites. A transformer is a much larger target. Put a scope on the rifle and a relatively experienced shooter with a reasonable hunting rifle could engage those targets all day long out to a range of 1000 meters. A trained sniper could nearly double that distance depending on the weapon.

How hard would it be to find a firing position within 1000 meters of a transformer station? Not hard at all at any station that I have seen. Finding a concealed location would be a bit more difficult in most cases, but there really isn’t a need for concealment. These stations are typically unmanned and certainly don’t have an on-site security force to dissuade people from shooting at the facility.

There has been talk of installing a variety of ballistic barriers to protect the transformers at these sites (I suggested Kevlar® curtains on a LinkedIn page a couple of weeks ago) and these would certainly make it harder to take out a transformer (certainly a high-value target in the terms of cost and time-to-replace), but that just would not work to protect the high-voltage insulators. These are harder targets to hit, but bullets are cheap and just a little marksmanship training with a good scoped-hunting rifle would make them easy targets at reasonable ranges.

Even if you were able to harden those insulators and install blast shields, it would not take much more effort to cut a fence and place improvised explosive devices on the transformers. The only way to stop that would be to place a sizeable security team on site and put a real barrier plan into place. Even then, an experienced and determined assault team could get through. Just ask any Iraq or Afghanistan vet how hard it would be to penetrate these facilities. And remember, determined foes managed to execute routine attacks in the Green Zone in Bagdad, one of the most heavily guarded areas in the world.

Security Measures

Some sort of security measures are going to have to be put into place, but they will have to be minimal or the systems will become too costly to operate and the terrorist’s objectives will have been achieved without firing a shot. But it is not going to be possible to put in enough security to stop a determined adversary from shutting down multiple transformer stations. Perfect Security Is NOT Possible.


No the best way to deal with this potential problem is to make these areas non-targets. Make the systems so redundant that taking out one, two or even three of these stations will not be a catastrophic event. Actually, the attack outside of San Jose was one of the best security measures that we could have asked for; the utility was able to continue to supply electricity to its customers even after a significantly successful attack. This means, that as long as the Schumer’s of the world don’t over-react (which is what they do by training and inclination), most terrorist groups will have crossed these off of their target list as there are much easier targets to successfully engage.
 
/* Use this with templates/template-twocol.html */