Friday, September 17, 2010

ICS-CERT Alert – BACnet OPC Client

Today the DHS ICS-CERT updated the Control System Security Program web page with a link to their alert about a buffer overflow vulnerability on the SCADA Engine BACnet OPC Client Buffer.

SCADA Engine is a Building Automation Software development company. Their version of the BACnet OPC Client allows for the connection of an OPC compliant workstation, through the OPC Server to the BACnet network. That network controls building services including:

● Heating, Cooling and Ventilation.
● Chillers, Boilers .
● Air Handling Units.
● Security, Lighting.
● Miscellaneous equipment.
According to the Alert the buffer overflow vulnerability “can be exploited to create a stack-based buffer overflow when a user opens a specially crafted file (e.g., *.csv file)”. The BACnet OPC Client uses a *.csv file for storing the OPC Tag database. So it is not unusual for system users to see *.csv files.

This vulnerability could potentially be exploited to allow an attacker to exercise control over the system by “arbitrary code execution”. This could allow alarms to be turned on or off, manipulate ventilation controls, and control networked building security devices.

According to the Alert there is not currently a patch or workaround available for this vulnerability. The current best defense is for system owners and operators to take extreme caution when opening unexpected or untrusted *.csv files. The ICS-CERT is in the process of contacting the vendor and will provide updates as appropriate.

S 3454 and Cybersecurity

At the end of last month I discussed the possibility of Congress attaching cybersecurity language to the DOD budget bill. I thought of that today when I noted that yesterday the Senate started work on passing S 3454, the FY 2011 DOD authorization bill. This isn’t the same legislation I addressed in that earlier blog, but it is a large bill that is likely to pass and subject to having lots of pet projects attached to it. So I checked to see what cybersecurity provisions were included. Sure enough, there are a couple of obscure provisions that might be of peripheral interest to the industrial control system community.

Pilot Projects on Cyber Security

Section 215 requires the Secretary of Defense to support or conduct four specific cybersecurity pilot projects. As with most of the cybersecurity programs being discussed in the Federal Government these deal mainly with IT systems not control systems and are focused mainly on government systems.

One of the mandated pilots, however, is focused on non-government systems in the ‘defense industrial base’. Under §215(b)(3) the Secretary of Defense would be required to “assess the feasibility [sic] and advisability of utilizing managed security services to improve the cybersecurity capabilities of elements of the defense industrial base”. Nothing in the language describing this system identifies control systems nor does it limit it to IT systems. This pilot would be done in coordination with DHS.

Another of the pilots, described in §215(b)(4), would look at encouraging the private sector to develop cybersecurity tools “to permit the Department of Defense to address threats, problems, vulnerabilities, or opportunities in cybersecurity”. The pilot would focus on the “identification and procurement of cybersecurity capabilities applicable to both Government and private-sector needs”.

Annual Progress Report

Starting March 15, 2011, the Secretary would be required {by §935(a)} to submit an annual report to Congress “on the progress of the Department of Defense in defending the Department and the defense industrial base [emphasis added] from cyber events (such as attacks, intrusions, and theft)”. Again this doesn’t specifically include industrial control systems, but it doesn’t limit the report to IT systems either.

With the recent discussion on the possibility of the Stuxnet worm being developed to ‘attack’ Iranian nuclear production facilities via their Siemens control system, I think it is reasonable to assume that anyone looking at preventing cyber attacks on the defense industrial base will certainly want to consider control system attacks.

Moving Forward

Next Tuesday, the Senate will vote on closing debate on this bill. If there are 61 votes (possible) in favor of that cloture motion then the Senate will begin their debate Tuesday afternoon and a vote on the bill could come this week. There are other issues in this bill that could prolong the debate, but nothing that is likely to affect these provisions.

Stuxnet Mitigation Update 09-16-10

Yesterday the team at DHS-CERT updated their Control Systems Security Program web page. They included a link to an updated advisory on mitigation measures for the Stuxnet malware. The new information on Stuxnet provides information on the five Microsoft vulnerabilities that were exploited by Stuxnet; four of which were 0-day vulnerabilities.

ICS-CERT reports that two of the 0-day vulnerabilities have now been addressed by separate Windows® updates (MS10-046 and MS10-061). Microsoft is reportedly still reviewing the two remaining vulnerabilities and ICS-CERT notes that they “will be releasing updates in future bulletins” (pg 2). The ICS-CERT advisory makes the following Stuxnet mitigation recommendation:

“ICS-CERT recommends that control system owners and operators review system upgrades and consider applying available patches to mitigate the risks for Stuxnet infection. As with all system changes, administrators should consult their control systems vendor prior to making any system changes.”
The Advisory also notes that Siemens is now reporting knowledge of 15 infections, but that “in none of the cases did the infection cause an adverse impact to the automation system”.

Thursday, September 16, 2010

Intelligence and Civil Disobedience

There has always been a fine line that the intelligence community, particularly the domestic intelligence community, has had to draw between civil disobedience, criminal disobedience and terrorist actions. The first is constitutionally protected free speech; the second is a ‘simple’ police response-investigation issue while the third requires extensive intelligence collection-processing and potentially pre-emptive law enforcement actions. Unfortunately the lines between the three are blurred and police agencies frequently error on the pro-active side.

A good example of this problem was seen this week in a controversy in Pittsburg, PA involving the distinction between environmental activists and eco-terrorists. It involves the publication of a recent Pennsylvania Office of Homeland Security Intelligence Bulletin. According to the news article about the controversy many local activists and politicians objected to the listing of public meetings where there might be a “potential public safety hazard”

Civil Disobedience

The bulletin lists a number of public meetings scheduled by local government agencies to discuss gas drilling operations. The meetings were listed in the intelligence documents because they “have been singled out for attendance by anti-Marcellus Shale Formation natural gas drilling activists” (pg 3). Now, simple attendance is protected (and encouraged) free speech; packing the meeting, signage and even periodic interruptions of the meeting fall under protected civil disobedience. Disruption of the meeting or interfering in the operation of the government body at the meeting slips over the line into criminal disobedience and requires police action.

If there has been a notice of intent to disrupt the meetings (not mentioned in the intelligence bulletin, so there probably wasn’t one) then the police would be expected to have sufficient personnel on hand to stop the disruption. If there was a past history of these groups disrupting public meetings (again, not mentioned in this report, so not probably a factor) police would again be expected to be able to respond promptly. Lacking either of those two situations, police forces have no reason to have additional officers on site. But, they still might want to know about the situation in case they are called to handle a disturbance at one of the meetings.

The critical civil liberties question here is not so much about police responding to criminal disobedience (though how they respond is always a potential concern), but how they prepare. If large numbers of police show up in the meeting room before any problems occur, there is a concern about their presence stifling free speech. If they keep files on, or conduct surveillance on, people who are exercising their free speech right, or commit simple civil disobedience because they might escalate to criminal disobedience, there are privacy concerns.

Of course, if political activists escalate to criminal disobedience or terrorist attacks, the public is going to ask why they weren’t stopped before they got to that level. And the public and politicians are going to blame the police or intelligence services for their inefficiency. Everyone in law enforcement or counter-terrorism knows this; this is why they frequently over-react to civil disobedience.

FBI Notes Increasing Activity

The controversy arises here because people have been linking the listing of these meetings with a separate entry five pages later in the intelligence bulletin. This entry is apparently an excerpt from an FBI report on environmental activists targeting the energy industry. It notes (pg 8) that: “To date, the energy industry has encountered little more than vandalism, trespassing and threats by environmental extremists. But this pattern is beginning to morph - transitioning to more criminal, extremist measures”.

The quoted FBI report goes on to note that this may continue to escalate. They base this extrapolation on their “historical understanding that some environmental extremists have progressed from committing low-level crimes against targets to more significant crimes over time in an effort to further the environmental extremism cause”.

There is nothing in this bulletin that links the political meetings with the energy industry being targeted by extremists. According to the article that connection was made in the mind of some local politicians, politicians on both sides of the issue. This jumping to conclusions is common to many politicians and is the reason that the intelligence community does not like sharing their information and assessments with politicians.

On Going Problem

Finding the proper balance between protecting the public and property from illegal actions taken in the name of a political cause and protecting the individual’s freedom of speech and freedom of expression is always difficult. If we see the recent increase in home-grown plots toward political violence continue or escalate, finding and maintaining that proper balance will become even more difficult.

Chemical Sector Training and Resources Update 09-15-10

This is just a brief note about a recent change to the DHS Chemical Sector Training and Resources web page. Yesterday DHS added a link to allow readers to select this page as one of the pages that they would be automatically notified of changes to the web page. This is showing up on more and more resource pages on the DHS web site and DHS is to be commended for adding and expanding the use of this tool.

Wednesday, September 15, 2010

CI Learning Series Update 09-14-10

Today DHS updated their Critical Infrastructure Learning Series web page, listing a new webinar that will be presented by both Infrastructure Protection and FEMA. The webinar will address “Partnering for Critical Infrastructure Preparedness”; covering current collaborative initiatives to promote preparedness through partnerships between DHS and critical infrastructure owners and operators.

Jim Caverly (Division Director Partnership and Outreach Division, DHS Office of Infrastructure Protection) and Dan Stoneking (Director of the Private Sector Division, Office of External Affairs, DHS Federal Emergency Management Agency) will provide an overview of various efforts coordinated jointly by FEMA and the Office of Infrastructure Protection including updates on the Private Sector Preparedness Program (PS-Prep), the work of the Preparedness Task Force, the National Level Exercise Program, and the increased focus on coordination with private sector partners at the regional level.

The one-hour webinar will be held on Friday, September 24, 2010 at 1:00 pm EDT. Registration is currently open.

TWIC and CFATS

There is an interesting blog post over on the CFATS 2.0 blog about the use of the Transportation Workers Identification Credential (TWIC) to satisfy the personnel surety requirements for high-risk chemical facilities covered by the Chemical Facility Anti-Terrorism Standards (CFATS). There have been a lot of questions about the use of TWIC for this requirement and it has seemed that the DHS-ISCD folks have tried to discourage this use, but Fasteddie565 certainly seems to layout a clear justification for its use.

CFATS Personnel Security Program

Of course, at this point in time there is no DHS-ISCD approved personnel surety program for CFATS. There is a clear requirement for facilities to establish a program to check the identity of personnel with unaccompanied access to critical assets and restricted areas of their high-risk facility, and that requirement specifies a check of the Terrorist Screening Data Base (TSDB). Currently the only program that provides access to that check is the TWIC program.

According to the presentation on the CFATS Personnel Surety Program made at this year’s Chemical Sector Security Summit (see my earlier blog for more information on that presentation), DHS is still moving forward with rolling out their program for submitting personnel information for the TSDB verification. They expect to have it in place for an initial trial run in October. That trial run is expected to be run at Tier 1 facilities with approved Site Security Plans.

Once that program is up and running it will be interesting to see if DHS tries to make facilities that have used the TWIC solution proposed by Fasteddie565 (and many others) re-submit their data in the new program. I’m not sure that the §550 restrictions on specifying particular security measures would allow that. We will have to see what DHS does when they rollout their program.

TWIC Readers

In the meantime, Fasteddie565 makes an interesting point about the TWIC card. He notes that “it also has the electronics to activate access control measures via the use of accepted TWIC readers”. For facilities wanting to electronic access controls for their critical areas (control rooms, ICS server rooms, etc) the ability to use established TWIC readers (though the Coast Guard has yet to complete their review of the TWIC reader trials) for that access control certainly makes a certain amount of sense. This is particularly true for organizations that also operate MTSA facilities that will require the use of such readers when they are finally approved.

Will this make the use of the TWIC economically sensible, even if DHS ends up requiring facilities to submit the personally identifiable information on personnel in the facility personnel surety program? It may, particularly if the facility can convince suppliers to ensure that their delivery drivers to get TWIC cards; the use of TWIC to verify the identity of these drivers may make screening of incoming deliveries that much easier.

In any case, we will see how DHS deals with the TWIC issue. My bet is that they won’t like it, but they will end up accepting it.
 
/* Use this with templates/template-twocol.html */