Friday, August 13, 2010

Thoughts on Chlorine Dispersion

Earlier this week I reported on a study that TSA will be conducting on the dispersion of chlorine gas from a catastrophic release from a chlorine railcar. TSA is concerned that there is an apparent mismatch between the chlorine dispersion model that is being used to evaluate the risk of a terrorist attack on such railcars and the actual dispersion seen in the two relatively recent chlorine accidents involving such railcars. This week I’ve been thinking about some things that might affect the dispersion that the studies need to take into account.

Weather Affects 

During my time in the military I spent a great deal of time working in 4.2” Mortar Platoons, most of it working in the Fire Direction Center (FDC); I had a special aptitude for doing the calculations necessary for sending mortar rounds to their desired point of impact.

One of the things that I spent some time learning and practicing was the calculations necessary to establish and maintain smoke screens with white phosphorous munitions. A major consideration that had to be taken into account in the attempt to maintain a thick, opaque smoke cloud was the weather in the target area. Not only did we have to take into account the wind speed and direction, but we also had consider the atmospheric temperature gradient; how the temperature varied as a factor of the distance above the ground.

One of the most favorable gradients was where there was a layer of warm air above a layer of cooler air; an inversion situation. This kept the smoke cloud close to the ground and provided for the slowest dispersion of the cloud. In doing their analysis of the accidents in South Carolina and Texas, TSA investigators need to take a hard look at how the local weather affected the dispersion of the chlorine gas cloud. They should also look at the possibility of the low temperature of the gas cloud creating a micro-inversion layer that helped to hold the cold chlorine gas close to the ground and impeding its dispersion.

Chlorine Reactivity

Another thing that needs to be considered in this study is the reactivity of the chlorine molecule. Chlorine is very reactive and chemically combines with a wide variety of both organic and inorganic chemicals; this is what makes chlorine so toxic. The calculations that go into the standard chlorine dispersion model shown in the Chlorine Institute’s Pamphlet 74 assume that the entire amount of chlorine released continues to expand throughout the dispersion pattern.

In reality, as the cloud disperses, the amount of chlorine available to be in the cloud decreases as the chlorine is consumed in a wide variety of chemical reactions. The amount that can be consumed is going to vary based on a wide variety of factors. They include the types of material available for reactions, the amount of water (both as liquid and vapor) available in the area (water acts as a solvent necessary for many of the reactions), and even the temperature (higher temperatures would be expected to increase reactivity) at the site.

Practical Effect 

I am certainly not claiming that the above described effects explain the anomalies apparently seen in the South Carolina and Texas incidents; they are just some of the things that the investigators need to examine. If the studies show no underlying problem with the current model and can explain the anomalies as being based upon situational variables, what will be the practical effect of the study?

First we need to understand that models like those presented in Pamphlet 74 are not intended to be absolute predictions of what will happen with a particular gas cloud. There are too many simplifying assumptions being made in the model design to make that a practical outcome. If the TSA studies show that the apparent anomalies can be explained by readily identifiable mitigating factors, that would not reduce the usefulness of the present model.

Emergency response planners can still use the model for planning for a generic catastrophic rail car release. This can guide initial evacuation decisions while the additional information needed to analyze the mitigating factors can be gathered at an accident scene. For railcar incidents at fixed facilities the situation becomes more complex. For initial planning prioritization decisions, the present model can still serve as a method for determining the population at risk of potential adverse effects from a catastrophic release.

Facilities with the largest at-risk populations should receive a measure of resource prioritization when allocating those resources for developing emergency response plans. Once work is begun on developing an ERP for a particular facility, then clearly defined mitigating factors can be investigated and quantified at that site. Physical layout of the facility and its surroundings could then be plugged into a more advanced model to map boundaries for initial evacuation planning and establishment of emergency notification systems.

Site modifications could be investigated that could have additional release mitigation effects. Additional modeling could be done for weather mitigation effects. Models could be run with a variety of weather conditions examined based on typical weather for the site. The results of these runs could be included as appendices to the ERP. This would allow an incident commander to make a more effective initial deployment of emergency responders. The information produced in these multiple weather runs would also allow everyone to understand what weather changes to be on the look-out for during an actual incident. Responses to those weather changes could be incorporated in the ERP.

Flawed Models If the TSA studies indicate that there are fundamental flaws in the current models, it will be absolutely critical that those models be appropriately modified. Then updated predictions for hazard areas will need to be widely distributed to potentially affected communities, agencies, facilities and transporters. Such information should change emergency planning prioritization.

TSA will need to resist the impulse to place any sort of restriction on the distribution of the new information. This would certainly be a situation where a clear case could be made for wanting potential terrorists to have access to the information. Any information that indicated that the populous at risk would be smaller than the current models predict would make these railcars less productive targets of potential terrorist attack. This would serve to reduce the likelihood of such attacks.

Increased Participation 

TSA is to be commended for pursuing this valuable set of studies. As I mentioned in my earlier blog, I think that the ISCD folks at DHS have a clear interest in the outcome of this study and should be invited to participate. TSA should also consider including participation of people at the EPA responsible for regulating water treatment facilities, as they also have a clear interest in the outcome of the study. DOT representatives from FRA and PHMSA would also be expected to be able to provide valuable information and have an interest in the outcome of this study.

Industry participation should also be considered. Organizations like the Chlorine Institute and the American Association of Railroad both have a well understood interest in this issue. They should be included in the study planning and should be able to provide valuable resources to aid the investigations. Finally, TSA should bite the bullet and consider inviting representatives of advocacy groups that are actively campaigning against the continued transportation of chlorine gas by rail to participate in the study. Not only do these groups have clear interest in the results, but if the models are modified to greatly reduce the expected hazard area for a catastrophic chlorine release, their participation will greatly reduce the public outcry against the results that must be expected.

Wednesday, August 11, 2010

Perimeter Fencing

It has been a while since I’ve actually addressed physical security measures for high-risk chemical facilities, so I guess that it is time to look at some of these important issues. I’ll start with one of my personal favorites, perimeter fencing. I’ll start this discussion off with a true story… True Story The chemical facility that I worked at was in an industrial park with the typical 6ft industrial chain link fence with an 18” barbwire outrigger. When the facility was not operating on weekends there was a single, elderly security guard patrolling the facility and manning the front gate. He actually spent most of his time in the break room in the office building; the air conditioning/heat was better there. I mentioned this to the Plant Manager one day, and he was interested in how I knew this since the gate was locked and could only be operated by the guard from inside the gate shack. I told him that I frequently entered the facility on weekends by climbing the fence since I couldn’t get the guard’s attention. He looked at me and my middle-aged chemist’s body and flatly stated that he didn’t believe me. I took him out to the front gate and showed him how easy it was to climb the fence. He stopped kidding me about the excess weight I carried. Purpose of Fencing The whole point of this story is that fences are not designed to stop determined intruders. Any fence can be breached. Some fences may delay the stealthy intruder who doesn’t want to be detected, but all fences can be breached by someone with just a small amount of training. Over, under, or through, at most a fence will delay someone determined to gain access. Without additional security measures in place a fence simply exists to mark a boundary beyond which it is illegal to precede without permission. Without such a clearly delineated border a casual intruder cannot typically be prosecuted for trespass. A simple fence is designed to keep honest people honest. Barrier Fencing To turn a fence into a barrier that will be a stronger deterrent to intruders requires a detection and response system. The detection portion of the system will be designed to determine when someone tries to breach the fence. The response portion will provide a reaction to the intruder that will impede the intruder from progressing further into the facility. There are a wide variety of detection systems that can be used in conjunction with a fence. Security guards can be stationed around the perimeter or be used to conduct roving patrols. A wide variety of intrusion detection systems (IDS) using any number of different types of sensors can be employed to detect someone approaching and then breaching the fence. Intrusion Response Systems Response systems have a two-fold purpose. First they may be used to investigate an alarm signal to determine if it is actually an intruder or some sort of system transient. The more sensitive an intrusion detection system is the more often they will typically have false alarms. Every alarm must be investigated or the whole purpose of the detection system is violated. Video surveillance systems can be used to perform this investigative function. A system operator would respond to an IDS alert by pointing the appropriate camera at the point of the reported intrusion and determining if someone had actually penetrated the fence line. The use of video systems has the added benefit of providing documentation of the intrusion for use in subsequent prosecution. The second purpose of the response system is to prevent the intruder from further penetration of the facility. This can either be done by intercepting and detaining the intruder so that they can be turned over to law enforcement personnel for subsequent prosecution. The alternative is to provide sufficient incentive for the intruder to stop and leave the facility. Typically security guards are used as the response system. One would expect that a response team (2 or more individuals) would move to the point of the suspected intrusion to determine if a penetration actually occurred. If intruders were detected they would either be chased from the facility or convinced to surrender to the security force. There are other automated systems being developed for the response function. These could include a variety of robotic systems. Other remote controlled or automated systems, up to and potentially including weapons, could conceivably be used. Armed Security Personnel One cannot talk about security response personnel without addressing the issue of whether or not to arm such personnel. Many high-risk chemical facilities are very reluctant to even discuss arming security personnel because of the safety considerations involved in discharging a conventional fire arm around potentially flammable environments. Such safety concerns are of course a legitimate consideration. There are also legal concerns that must be addressed. The other thing that must be taken into account is the possibility of security personnel encountering armed intruders. If there is a significant chance that intruders will be armed, then security personnel need to be armed if for no other reason than to defend themselves. Detailed Considerations This has been just a brief look at some of the general issues that must be considered when looking at the issue of perimeter fencing for high-risk chemical facilities. The details of how to select specific systems for a particular facility require a detailed analysis of the facility situation. Few facilities will have the in-house expertise necessary to determine the optimum system utilization for their particular situation. This is one of the many reasons that facilities will turn to security contractors to set up their systems.

Water System Lobbying

I ran into an interesting blog post at ISAQQA-WUC.Blogspot.com about efforts of member utilities of the American Water Works Association to oppose passage of legislation that could allow the imposition of changes in disinfectant chemicals on water treatment and waste water treatment facilities.

The AWWA has opposed bills like the House passed version of HR 2868 and the recently introduced S 3598. They are now calling for members to contact their Senators to ask them to support the version of HR 2868 ordered to be reported by the Senate Homeland Security Committee. This very long blog post provides an interesting and detailed discussion of how utilities, which have access to little money for lobbying efforts, can best conduct a campaign to influence their legislators. Anyone intending to conduct a low-cost campaign to influence legislation should review this blog post before they seriously start to plan their own campaign.

Chemical Security Situation 

Of more interest to readers of this blog is the background information on chemical security issues at water treatment facilities. There is a very good summary of the current requirements for security and the types of chemical security responses that many facilities have taken. Careful reading of this section of the blog shows why there really does need to be some sort of water treatment facility language in any comprehensive chemical security language that would extend current CFATS rules.

First the posting explains that current rules require these facilities to conduct a security vulnerability assessment (SVA) and emergency response planning (ERP). There is no standard for the SVA or ERP and there is no real requirement to establish and execute a security plan to protect the vulnerabilities identified. Finally there is no authority for state or federal regulators to review the SVA or ERP or allow them to require correction of deficiencies.

Like various chemical industry organizations the AWWA also likes to brag on the efforts that have been made at member facilities to protect chemicals like chlorine gas. The main difference here is that there is no mandatory security program that member facilities have to adhere to. All of the programs that the AWWA describes here are completely voluntary and this is reflected in the following statement made in the blog post: “Most [emphasis added] have restricted access and enacted other measures to secure critical assets, including chemical supplies.”

One last time I would like to point out that no outside agency has the authority to determine if the ‘restricted access’ and ‘other measures’ provides an adequate degree of security for the facilities that have taken such measures. And no government agency can require the facilities that have not take such measures to do so.

Remove CFATS Exemption 

If the AWWA really wants to preempt efforts in the Senate to require consideration, and a possible mandate to implement, disinfectant substitution they may want to consider finding some Senator to submit a proactive floor amendment to HR 2868 that would remove the current CFATS exemption for water treatment and waste water treatment facilities. If the AWWA were to craft such language to include provisions for denying the Secretary the authority to shut down water facilities and included a grant program for security measures at public treatment facilities, there would be little reason for water facilities to object to CFATS inclusion.

Facilities that have actually addressed security issues would get credit for those efforts in implementing CFATS SSP requirements. Only facilities that have done little to protect the public from the consequences of a potential terrorist attack would expect to have to take extensive actions to get up to CFATS standards.

The benefit to the AWWA and its members would be that they could then point at the CFATS coverage as a reasonable alternative to S 3598 and its included IST measures. While the activists that would like to see chlorine gas removed from all of these facilities would not accept that argument, it is likely that many Senators would accept the increased security provided by CFATS requirements as an adequate first step to protecting the adjacent communities.

Tuesday, August 10, 2010

National Dialogue on Preparedness

I got an interesting email the other day from DHS Asst. Sec Juliette Kayyem (I am on the most interesting mailing lists…) about the Department’s new National Dialogue on Preparedness. This is yet another of the DHS attempt to engage the public in identifying solutions to homeland security issues; this one is supporting the efforts of the DHS Local, State, Tribal, and Federal Preparedness Task Force. Outside of the QHSR effort, we have yet to see anything other than allowing citizens to vent to come out these programs. Well, maybe this one will be different. As readers of this blog might expect I have already put my two-cents worth in on this Dialogue. I added my thoughts on “Counter-Terrorism Emergency Response Plan – CFATS”. It was idea #45 in submission and #42 on the site (meaning I suppose that they took off three ‘inappropriate’ ideas). The ideas can be submitted in seven different categories. Those categories are:

· General Preparedness · Preparedness Capabilities and Assessments · Preparedness Policy and Guidance · Preparedness Grant Programs and Incentives · Individual/Community Preparedness · Private Sector Preparedness · Nongovernmental and Volunteer Organization Preparedness

Provisions are made for voting on ideas; +1 for ‘agree, -1 for ‘disagree’. Votes are automatically tallied to allow for ranking ideas on their levels of acceptance or popularity. There is also a means to append comments to the various ideas. Idea submission, voting and commenting all require registration. Apparently, if you were registered on one of the other DHS Dialogues, the registration does not carry over to this one. If you have a cute nome de guerre that you had previously registered, you might want to act fast to keep it for this dialogue.

I will watch this Dialogue to see if anything interesting comes of it. While I don’t expect DHS to put much effort into using the results of this citizen participation, I will recommend that people take the time and effort to put out their two cents worth. At least that way when you complain about the governments lack of action you can point out that you made your effort.

Monday, August 9, 2010

TSA and Chlorine Dispersion Modeling

This weekend I ran into an interesting article over at GSNMagazine.com. It briefly describes some concerns that the Transportation Safety Administration (TSA) has with the current scientific model used to describe the dispersion of chlorine gas from a catastrophic release from a chlorine railcar. It seems that the chlorine cloud from the two most recent catastrophic releases of chlorine from rail cars did not come anywhere near following the dispersion model for the release. TSA is initiating a two phase study of chlorine gas dispersion to clarify these discrepancies.

Chlorine Gas Dispersion Model 

I had a rather detailed discussion (for a blog) of the current chlorine gas dispersion model in a blog post back in March of this year. I discussed the model description in the Chlorine Institute’s Pamphlet 74 that is the currently accepted standard description of the chlorine gas release from a large hole in a chlorine railcar. I summarized that model in a single paragraph this way:
“Now, having exposed the hype, it must be clearly understood that there will be a significant area under the exposure curve where people will die if they are not adequately protected against exposure. There is an even larger area where there will be serious medical consequences from exposure to the peak concentration levels as the toxic cloud passes through the area. Looking at the charts on pages 24 and 25 of Pamphlet 74 it looks like anyone inadequately protected in the cloud for up to a couple of miles away from the catastrophic release from a full railcar is at serious risk of being killed by the cloud. Inadequate protection in the cloud at distances of up to 15 miles from the release could have very serious medical consequences.”
A TSA document prepared as part of their solicitation for commercial services for the first part of this study describes the reality of the results in 2004 and 2005 this way:
“However, evidence available to TSA suggests that this may not have happened in the Graniteville and Macdona chlorine releases. Unexpectedly, the released material appears to have had most of its impact in the area close to the release point with little downwind effects.”
TSA Modeling Study TSA is the agency responsible for assessing and regulating the security of chlorine gas in transit; protecting against a terrorist attack, if you will. As such they need to have a clear understanding of the potential consequences of such a terrorist attack. Thus TSA is preparing to conduct a two-part study of the situation. The first part will be a detailed review of the two accidents where there was a catastrophic release of chlorine. TSA expects to hold a seminar type meeting to evaluate what happened at those two incidents. That seminar is currently being tentatively scheduled for January, 2011.

A contractor, yet to be selected, will be responsible for collecting the information and putting it into a presentation format for this seminar. The second phase will be a physical study conducted with the US Army Edgewood Chemical and Biological Center (ECBC). I have not yet seen any details about that portion of the study. It will be interesting to see what comes of these studies and how much TSA actually intends to share with the potentially affected public. The ISCD folks might want to join TSA in this study because it would also be expected to pertain to protecting high-risk chemical facilities that produce, store, or use large quantities of chlorine gas. The Chlorine Institute might also have an interest in this study.

Reader Comment 08-07-10 Influence

Fred Millar, a long time reader and well known acitivist, took objection to some of my comments on the political aspects of the most recent PIRG Report on chemical security issues. As always, Fred’s comments are worth reading in their entirety. The tone of Fred’s comments reflect his commitment to the causes that he supports, but are also indicative of the reasons that once again there will almost certainly be no comprehensive update of the CFATS authorization this year. Both sides of this debate have vociferously ignored the legitimate interests of the people on the other side of the ‘discussion’. This failure to engage in a real dialogue (again on both sides of the issue) makes it impossible to reach a reasonable compromise that both sides can live with. In the current situation, since the current authorization is certainly flawed and inadequate, the failure to engage in dialogue benefits the corporate interests that do not want to see that authorization expanded. Now PLEASE don’t think that I am blaming Fred for the current impasse. There are two sides to this lack of discussion and both sides bear a full share of the blame for making it next to impossible to engage in a constructive dialogue. Name calling, vilifying the opposition and exaggerating the goals of the other side do nothing to move a political dialogue forward. Legitimate Interests Chemical companies have a legitimate interest in influencing any legislation that will have an impact on their operations; influencing not dictating. Their management has a legal obligation to their owners (that includes a large number of their employees and members of the public who own stock through 401K plans and other investment vehicles) to ensure that the companies operate at a profit within the constraints of the current legal system. Corporations cannot vote, so they must effect their legitimate influence through legal campaign contributions and legal lobbying efforts. The activists of the ‘blue-green coalition’ have legitimate concerns about the safety of hazardous chemicals in commerce. They have seen too many examples of inept and/or shortcut safety and security practices that have resulted in releases of too many of these chemicals harming the public in both the short term and long term. They have seen too long a history of too many chemical facilities ignoring safety concerns to the detriment of their customers and local communities. As a result they feel that they cannot trust current chemical facility management to do the right thing when it comes to safety and security. These organizations cannot vote either; they effect their influence on the political process through publicizing their points of view and organizing individuals in political activism campaigns to influence legislators. Finally, safety and risk are not absolute values. There is no such thing as zero risk or absolute safety. There is a continuum of values that only tangentially approaches zero. Moving any product or process lower on the risk/safety scale requires the expenditure of energy and money. Incremental changes in risk or safety require higher and higher expenditures as one gets closer to zero. What is an acceptable risk or acceptable safety or a reasonable expenditure to achieve increased safety/risk can only be determined through a full frank discussion in the political process. Political Discussion We need to stop yelling at each other and start talking with each other. Otherwise nothing substantive is going to be accomplished. We will remain at the inadequate status quo until some terrorist organization finally realizes what a juicy target these enterprises actually are and figures out a way to exploit the weaknesses in security that remain because of our political failure to address the problems. The consequences for the public and the corporations will be unbearable.

Reader Comment 08-06-10 VxWorks Exploit

Last Friday an Anonymous reader took objection to a statement I made in my blog posting that updated people on Stuxnet and identifying a newly identified SCADA vulnerability. Anonymous objected to my comment that:
“These vulnerabilities were discovered by a security researcher and the details of the exploit have not yet been made public. No exploits in live systems ‘in the wild’ have yet been seen.”
Anonymous then pointed us at a blog posting on Metasploit.com addressing the same VxWorks vulnerability. That posting by HDM describes how the author discovered the vulnerability and enough details about the vulnerability that even a reader with my level of expertise (very low) in software engineering can see that this is a vulnerability that a large truck load of problems could be driven through. My apologies to HDM for slighting him in my comment, but I had not read his blog when I wrote my post. I based my comments on the report on this vulnerability provided by ICS-CERT. That report explained:
“Proof-of-concept code is expected to be made public by the researcher. However, at the time of this writing, no known exploits exist in the field specifically targeting these vulnerabilities.”
There is a material difference between “[p]roof-of-concept code” and “details of the exploit” that is very clear when you read the HDM blog post. HDM certainly provided enough details about the vulnerability to allow Carnegie Mellon CERT to coordinate with 100 vendors before the public announcement of the vulnerability was made.
 
/* Use this with templates/template-twocol.html */