Showing posts with label Security Researchers. Show all posts
Showing posts with label Security Researchers. Show all posts

Friday, June 28, 2013

DHS Publishes ICS-CERT Monitor

Yesterday the DHS ICS-CERT published their now quarterly (formerly monthly) Monitor. This issue is important because it describes publicly for the first time the first really documented attacks (unsuccessful) on privately-owned control systems.

Pipeline Control System Attacks

We have been hearing about these pipeline attacks for some time now, but the article in the Monitor provides information about the extent of the attack without providing any sensitive details.

One of the more important pieces of information provided in the article was that the initial report to ICS-CERT of these attacks came from a single owner “about an increase in brute force attempts to access their process control network”. System logs identified 10 IP addresses associated with the attempted access. When those addresses were shared with other operators by ICS-CERT similar attempted attacks were found in additional facility systems logs and more IP addresses were identified. This, again, demonstrates the needs for maintaining and checking system logs.

The article also mentions, for the first time that I have seen, the existence of the ‘Control Systems Center’ on the US-CERT Secure Portal and notes that:

“ICS-CERT periodically releases alerts, advisories, and indicator bulletins via the Control Systems Compartment of the US-CERT Secure Portal that provides critical infrastructure constituents with information intended to be useful for network defense.”

We have seen some of these documents make their way to the ICS-CERT web page, but only after they have been available for a couple of weeks on the Portal. It seems to me that owners and operators of control systems owe it to themselves to ensure that they at least have representatives who can routine access and monitor this site for valuable information.

Outside Contributors

This issue marks the first time that the Monitor has included articles from outside contributors. Kyle Wilhoit from Trend Micro wrote “Your SCADA Devices Are Being Attacked” and Reid Wightman from IOActive wrote “Why Sanitize Excessed Equipment”.  Both short pieces provide valuable information. Inclusion of these outside contributors can only make the Monitor more helpful and maybe bring it back to a mostly monthly publication.

Other Offerings

There is a summary type article about the recent Verizon 2013 data breach report. For those that don’t have time to read the gritty details of that report, this is a good summary. ICS-CERT notes that they were one of the 19 global reporters of incident data that helped Verizon with that report.

There is a belated report on the introduction of CSET 5.0. There is still some good information, particularly about the changes that will probably be included in the next version. The article notes that customer feedback is one of the sources for new ideas that ICS-CERT is using trying to target in future versions. If you have ideas or comments contact the ICS-CERT folks at cset@hq.dhs.gov.


All of the standard features we have come to expect in the Monitor are still here. The list of security researchers that are currently working with ICS-CERT continues to grow. All of these people should be encouraged to continue to publicly disclose (preferable through a coordinated disclosure, IMHO) ICS vulnerabilities that they discover. As a community we need to develop some way to reward them for their efforts so that they don’t have to sell their research to the highest bidder that will probably keep the vulnerabilities quiet.

Wednesday, February 22, 2012

Reader Comment – Terms of Use

Last Saturday Dale Peterson, a long time reader and influential member of the control system security community (owner of DigitalBond.com) posted a response to the terms of use portion of my blog post on the Friday ICS-CERT advisories. In part he wrote:

“At least you, and I, have the courtesy to link to the bulletin when we discuss it. ICS-CERT has not linked once to the Basecamp posts or pages that disclose the vulnerabilities even though they just paraphrase what we identify.”

Dale makes a very valid point. The vulnerability disclosures made by security researchers is intellectual property. Some of that property belongs to people like Dale who makes their living selling cybersecurity services. Dale and others like him in the cybersecurity services industry have worked hard to establish their reputations as knowledgeable service providers. A large part of that effort includes things like his blog, his somewhat annual S4 conference, and projects like Project Basecamp. Failure to properly recognize that effort when using the publicly available fruits of his labor and expertise does him a disservice and negatively impacts on his livelihood. For a government agency like ICS-CERT to do so is particularly aggravating.

Now to be fair ICS-CERT has improved their credit-sharing efforts. Six months ago they were not even identifying the names of researchers unless the disclosures were made in a coordinated manner; Basecamp would not even have been mentioned in the alerts if it had happened six months ago. I commended the folks at ICS-CERT when they made that change and continue to maintain that it was a step in the right direction.

However, in the digital communication age, mentioning a name is not enough; a link to the information when it is provided on the web is the absolute minimum of common courtesy. In the case of ICS-CERT alerts and advisories it is even more than that; it is a valuable service to the control system community that relies on ICS-CERT for information about system vulnerabilities.

The ICS-CERT communications are at best summaries of the information on vulnerabilities and the mitigations. They are designed to be, and serve their most valuable purpose when they are digests of information. If they were detailed discourses on the subject only the most dedicated cybersecurity nerds would read them. They would not be of any real service to the community.

A cybersecurity manager or consultant can easily review these products as they are published and make a quick determination of whether or not they may be applicable to their system. But to decide what action needs to be taken in their facility in order to properly respond to the potential vulnerability these people are going to need access to much more information. The vendor will certainly provide some the necessary details; which is why ICS-CERT provides links to the vendor patches and security documentation when it is available.

But, as we have seen over the last year, the adequacy of the responses of the vendors has been less than adequate in many instances. To have the information necessary to respond to a potential vulnerability a security manager or consultant is going to have to access the vulnerability data actually developed by the security researcher. This is the real reason that ICS-CERT should be including links to the original vulnerability reports in their alerts and advisories.

And remember, most security researchers are making at least a portion of their living from these efforts. If not adequately recognized, independent security researchers might turn to portions of the market place for cybersecurity vulnerability information that would be willing to pay for 0-day exploits. We really don’t need that.

So, I urge ICS-CERT to continue to evolve their researcher disclosure policy by including links to the original information on disclosures. It would be a valuable service to the entire cybersecurity community.
 
/* Use this with templates/template-twocol.html */