Showing posts with label Security Systems. Show all posts
Showing posts with label Security Systems. Show all posts

Sunday, November 4, 2012

Tidbits Heard at SCADA Meeting


One of the things that I have been missing by being unable to attend meetings and conferences is the side conversations that take place during the breaks in the meetings. I heard lots of interesting stuff at the meeting Thursday and I thought that I would mention a couple of them here.

Password Phishing Attacks


I was talking with a nice lady from the Coast Guard (I’m terrible about names and we both thought that she had given me her card, but I don’t have it) and the conversation turned to the DHS HSIN (Homeland Security Information Network) and Homeport. Both are semi-secure communications network that require some level of vetting and password access. I asked about the password change frequency and she told me it was 90-days, so this seems to be some sort of DHS (at least) standard.

I then asked her if the CG sent out emails reminding people about changing their password and they do. I didn’t get to ask any more follow-up questions, but it got me to thinking. Readers will remember that I have taken ISCD to task (most recently) for the emails they send out for updating the passwords for access to CSAT. These emails contain a link to CSAT where the password can be updated. I suspect that the Coast Guard and the folks running HSIN do the same thing.

This practice leaves a large part of the security community open to phishing attacks. A savvy attacker could send out an email like this and get system logon information by having the link go to a site they controlled. It’s not that difficult to set up an official looking site, or even a duplicate of the official site, that would allow for the collection of sign-on information; and even transmit the information to the official site so the password change would take effect.

It seems that DHS as an organization needs to re-think its password policy. I’m not sure how justifiable a 90-day reset requirement is, but the emails going out to remind people to reset their passwords should not include a link to the site where that takes place. I know, it sounds real customer oriented, but it just sets people up for failure.

A final word on this topic (well in this post anyway, I’m afraid I will return to it again at some future time). If you receive an email from a DHS agency about updating one of your passwords with them, DO NOT click on any links in the email to do so. Use your own list of links to get to the site.

Shamoon Attack Vector


You’ll pardon me if I don’t mention where this last tidbit came from. There were a couple of side conversations that went on about the control system implications of the recent big name attacks, including Shamoon. No one had any news about any direct attacks on control systems by these programs, but a number of people were concerned about the possibility of control system information being harvested by these attacks; nothing new there. One of these conversations, however, did provoke a comment about an idea floating around the counter-intel community that the Shamoon attack on Aramco was initiated via a thumb drive (no duh) inserted into a security system computer by a Palestinian security guard.

Palestinians perform a large number of low-level jobs in Southwest Asia including front line security officers. Okay, I know that security guards are an important part of the overall security plan and shouldn’t be considered low-level employees, but they certainly are so considered by most people; just look at their pay scales. It wouldn’t be hard for any national intelligence agency, terrorist group, organized crime syndicate, or even an oil-industry competitor to find and turn one of these security guards into a thumb-drive agent.

I’ll bet that every guard-house at active security gates have a computer or security terminal inside. I would bet that they don’t receive anywhere near the attention that computers do in the secure areas of the facility. But they are networked to the security office which is, almost certainly, linked to the enterprise system. This would be a nice attack surface.

And, if you were planning an attack, cyber or physical, wouldn’t it be nice to have a look at the security system controls before you started the attack? Quis custodiet ipsos custodes? Hopefully, not the attacker.

Saturday, August 25, 2012

Coast Guard Announces NMSAC Meeting Agenda


The Coast Guard is publishing in Monday’s Federal Register (available online today) a notice (77 FR 51817-51818) announcing the upcoming two-day meeting of the National Maritime Security Advisory Committee on September 11th and 12th in Washington, D.C.. This meeting will cover chemical security and cybersecurity topics along with the typical maritime topics.

Topics of specific interest to the chemical and cybersecurity communities include:






Cybersecurity


The information provided on the cybersecurity topic of the agenda is more than a little vague. It states that:

“The Committee will discuss the parameters of a new tasking from the Coast Guard to provide guidance/recommendations on cyber-security initiatives within the maritime sector.” (77 FR 51817)

This wording would seem to indicate that there is a potential to include control system security issues in the discussion as there are a wide variety of water-side and shore-side control systems used in the ‘maritime sector’. It would be particularly interesting to see if the discussion included the cyber-security of various security systems.

Information Sharing


The Coast Guard probably has a better history of information sharing about security matters than any other organization in DHS. This makes it particularly interesting to see how the NMSAC uses the community feedback that it has obtained to suggest further improvements in that information sharing process.

Integration of Security Plans and Systems


Section 822 of the Coast Guard Authorization Act of 2010 required that the owner/operator of an MTSA covered facility (Congress did not include ‘vessels’ in this requirement) to “integrate, to the maximum extent practical, any security system for the facility with compatible systems operated or maintained by the appropriate State, law enforcement agencies, and the Coast Guard” {46 USC §70102(c)(2)}.The Coast Guard is asking the NMSAC to help develop guidance for implementing this rather vague requirement.

One would like to think that ‘integrating facility security systems’ would include such things as linking alarm notifications (both intrusion and chemical release) to local law enforcement and emergency response dispatch centers, ensuring that first responders are familiar with local facility procedures, and that emergency response plans are fully coordinated and exercised with local authorities.

Public Participation


As we have come to expect with the NMSAC, there are multiple modes available for public participation in this two-day meeting. First written comments on the topics may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # USCG-2012-0797). People may attend the meeting in person (limited seating available, contact Mr. Ryan Owens, ryan.f.owens@uscg.mil), via teleconference {(866) 810-4853; the pass code to join is 9760138#.}, or webcast (http://connect.hsin.gov/nmsac91112/). There will be a public comment period at the end of each day’s session.

Monday, December 21, 2009

Reader Comment 12-19-09 Security Systems II

A reader, Security Systems, left a short note to a posting about an earlier reader’s comment about security systems. Security Systems wrote: “Security problem is not an easy thing to deal with. But security systems does [sic] make the work much easier these days.”

We’ve Come a Long Way 

I fondly remember my first security patrol (guard duty) in Basic Training at Ft. Ord, CA back in the winter of 1973. I was dressed in fatigues with highly polished boots, equipped with a pistol belt/canteen, a fiberglass helmet liner and a baseball bat for a weapon. My post was to walk the flight line at the local aviation detachment and I had to prove that I had a dime to call the Commander of the Relief in the event of a problem.

The flight line was well lit, but the coastal fog made it nearly impossible to see even the parked helicopters from more than 30 feet away. Today that post would be watched via video cameras backed up with motion detectors, fence alarms and key-padded gates.

Vehicle teams would spot check that post along with a dozen others periodically through the night. The fog would be effectively transparent, and any intruders would have a much more difficult time approaching an aircraft undetected than when I was guarding those birds those many nights ago. 

Security systems have advanced by leaps and bounds over the years. The advent of cheap electronics has made it much easier to design a multi-tiered security system with multiple methods to detect intruders. The large numbers of systems from a seemingly endless supply of providers have made security planning more difficult, though, instead of less.

This increased complexity has given rise to a new industrial specialty, the security system integrator. This is the person that integrates the variety of human and electronic security systems that need to work together to form the seamless security package required for the high-risk facility. If you ignore the complexity of the systems involved, and as a society we have become very adept at ignoring system complexity, then the wide variety of security systems now available to help secure critical facilities does make the job of security easier.

All we have to do is fob off the hard part to those trained and experienced to handle that chore.

Tuesday, December 8, 2009

Reader Comment – 12-07-09 – Security Systems

Yesterday D. Coleman, a security integrator from Atlanta, left a comment on a blog about fences that I wrote last month. It is a lengthy comment that is well worth reading. Some specific points deserve special attention. 

Guard Fatigue 

D. Coleman writes: “Even the very highly motivated, however, have to contend with the numbing of routine that follows from the fact that security problems happen very rarely.” This security fatigue is a very real problem where security personnel are not actively involved in some activity. A gate guard that is frequently processing incoming and outgoing vehicles and personnel can remain relatively alert for extended periods of time. A security operator monitoring a bank of video monitors quickly becomes complacent and loses some attentiveness. Even security personnel on patrol can become mentally numbed to their surroundings if there is no mental stimulation. 

I spent a lot of time on guard duty in my time in the military. I spent time in dress uniform standing at doors to secure communications facilities and time in battle dress on patrol at ammunition facilities. At no time did I spend more than two hours ‘on post’. As a supervisor of guards, I was routinely required to physically check every guard post at least once every two hour shift. The military understands that guards become inattentive over time. 

Security managers need to keep this in mind when they are planning for and supervising a security force. Personnel at stationary posts need to get up and move around periodically; this requires that someone else cover their post during that period. One solution is to have a combination of fixed and roving security posts with personnel rotating between positions. Or a security supervisor can fill in at a fixed post while that operator/guard conducts random physical checks of points within the security perimeter. 

System designers can help assure the attentiveness of personnel monitoring electronic security stations by making periodic changes in the display. This can take the form of having random administrative alerts to which operators must respond; this can also serve as a real time measure of operator responsiveness. 

False Alarms 

D. Coleman makes the important point that: “electronic security can also make a site less secure.” The point being made is that false alarms from an electronic security system can either detract the attention of security personnel from actual security events or they can create such mistrust in alerts that actual security events are ignored. 

An electronic security system probably has to have some level of false alarms. The complete absence of false positive alerts probably indicates that the system sensitivity is set too low and will allow undocumented penetrations. A balance between the two competing concerns will have to be reached by system designers. Coleman makes the point that multiple, overlapping systems can help make this balance easier to achieve by allowing for quick checks of alarms by one system with the output of another system. 

System Design 

These are just some of the problems that security managers have to deal with in developing security systems for high-risk chemical facilities. Security managers are either going to have to be trained security professionals or they are going to have to rely heavily on the work of outside consultants to design and manage security systems. Facility management will have to decide which is the appropriate solution for their facility, but even that decision requires a level of security sophistication that most chemical professionals are ill prepared to make.
 
/* Use this with templates/template-twocol.html */