Wednesday, November 17, 2010

New Cyber Security Legislation

This evening Chairman Thomson (D, MS), Chairman of the House Homeland Security Committee sent out a press release on new cyber security legislation introduced today. The press release describes a comprehensive piece of legislation that establishes a DHS Office of Cybersecurity & Communications and a “Cybersecurity Compliance Division to oversee the establishment of performance-based standards responsive to the particular risks to the .gov domain and critical infrastructure networks”.

Interestingly the term ‘information networks’ is not used in this press release or in the accompanying one page summary document. Of course, neither is there any specific mention of control systems either. I suspect that this bill would apply to both, but until I can see a copy of the actual legislation, I won’t know for sure.

I won’t know the bill number until today’s Congressional Record is published tomorrow morning. The bill itself may (if it is very short) or may not (if this is truly a comprehensive bill it will be long) be available tomorrow morning. Watch this space for additional information.

CFATS Knowledge Center Data Set

I think the folks at the CFATS Help Desk (whom I am assuming maintain the CFATS Knowledge Center page) may have slipped one by me. This afternoon on one of my periodic checks of that page I noted a new listing in the ‘Downloads’ section on the lower right hand side of the main page, ‘All FAQs and Articles’. I’m not sure when it was put there, fairly recently I’m sure, but it is a small thing that I could have easily missed.

Anyway, I’ve got lots of memory (its so cheap, I can buy five 8-gig USB sticks for what I paid for my first computer that had 4K of RAM, yes K not gigs) so I downloaded it and I’m glad that I did. It is a .PDF file listing all of the FAQ and articles currently listed on the site; just like advertised. Now this won’t be something that all CFATS users will want to have laying around, but large organizations with multiple CFATS facilities may find this 115 page .PDF file good to have on file.

I do have two suggestions for DHS to improve this product.

● First, there needs to be a date on this document. I would prefer that it be on the header of the first page, but somewhere please. I’m assuming that the document will be updated any time there is a change to the FAQ/Article database. We need a way to keep track of the version. NOTE: I put the date I downloaded it in the file name.

● An index would be really handy. The FAQs and Articles are listed separately in numerical order. So, unless you want us to browse the ‘Word of CFATS’ every time you go looking for information, an index would be nice.
Don’t get me wrong though, info junkies like me greatly appreciate the effort that went into formatting the .PDF file. It’s just another one of those information sharing projects that ISCD has made such an integral part of the CFATS program.

HR 6410 Introduced

Yesterday Congressman Markey (D, MA) introduced HR 6410, the Air Cargo Security Act. It would be easy to say that this bill was a direct response to the recent ‘toner bombs’ incidents in cargo shipments coming from Yemen, but Rep. Markey has been a proponent of aggressive cargo screening for quite some time.

Cargo Screening Standards

This bill would essentially apply the same screening standards for shipments going into cargo planes that are currently being imposed on cargo going on passenger planes within the United States. TSA would have 18 months to have 50% of all such cargo screened and three years to have 100% of all cargo screened. There is no distinction in the bill between domestic or foreign origination of the cargo flights for the purposes of the screening requirements.

Shipping Facility Inspections

The bill would also require TSA to inspect “shipping facilities for shipments of cargo transported in air transportation” {§44922(a)(1)}. The Administrator would have 30 days to establish this inspection program. I don’t see any definition of ‘shipping facility’ in this bill, so this could be a problematic area of concern to many manufacturers that ship via air cargo (including FedEx?) aircraft.

A separate paragraph in the same section of the bill would require TSA to enter into agreements with “civil aviation authorities, or other appropriate officials, of foreign countries” {§44922(a)(2)} to ensure that foreign shipping facilities making cargo shipments to the US would similarly be inspected.

Both of the above requirements would have a 30-day deadline and would require a report to Congress in 210 days. The domestic deadline would apply to the establishment of the inspection program; this would be impossible to comply with because of the need to write the appropriate regulations and put them thru the public comment process. Applying the same deadline to the foreign agreement requirement is even more difficult to comply with since TSA would have to work with such a large number of foreign governments whose time tables cannot be mandated by Congress.

Cargo Handler Training

The bill would also require the Secretary to establish a training and evaluation program for cargo handlers “to ensure that the cargo is properly handled and safeguarded from security breaches” (§4). This provision has reference to foreign cargo handlers (thank goodness) and is given a 180-day deadline. Establishing regulations for such a program might be able to be accomplished within that time frame, but to actually establish a training program (after those regulations define the program requirements) will take some additional time to develop and implement.

Knee-Jerk Legislation

I understand Rep. Markey’s interest in increasing the security around air cargo shipments, given the recent attempt to send bombs to the United States through this transport mode, but I think that the time-limits given in this bill impose unrealistic standards that would make compliance by DHS impossible. More thoughtful consideration and perhaps some consultation with TSA would have made for a more realistic piece of legislation.

Of course with the limited time left in the 111th Session, perhaps Rep. Markey never intended this to be actually considered or passed. If that is the case, he may be trying to force the air cargo industry into taking pre-emptive security measures to prevent bills like this from becoming law.

DHS Spending Bill

I got an interesting email from an reader yesterday. He asked about the status of the DHS appropriations bill, S 3607. He had noticed that according to the Legislative Status page here on the blog site that the bill had been reported out of committee in the Senate.

S 3607 in Senate

The Senate bill has been on the Senate Legislative Calendar since July 19th. Because of constitutional issues it will stay there until the House passes their bill; the House must initiate all spending bills. Once the House bill is sent to the Senate the language in S 3607 will be substituted for the House language as one of the first amendments considered on the House bill.

Typically we would expect to see a variety of floor amendments offered for the spending bill as it is debated in the Senate. Once it is passed it will go back to the House. If the House agrees to the amended version of the bill, then it goes to the President for signature. Typically the House disagrees with the amendments and the bill goes to Conference where the differences between the two versions will be worked out. The re-amended bill goes back to both the Senate and House for votes.

Since the control of money is an important tool for Congress to control the Executive Branch this can be a complicated and time consuming process. In the normal course of events the Senate could take days to debate an appropriations bill.

House Bill

There has not been any action on appropriations bills in the House since July. Only two Department bills have been introduced, Military/Veterans and Transportation/HUD. The Homeland Security Sub-Committee has passed a draft bill, but it has not been taken up by the full House Appropriations Committee. It won’t be officially introduced until the Committee has passed and ordered the bill to be reported.

As of last night, there are no hearings scheduled in the House Appropriations Committee. The way the House Rules are currently organized, nothing can happen on the Appropriations bill until Chairman Obey calls a Committee Meeting to mark-up the draft bill. There are ten appropriations bills in essentially the same status.

Once reported by the Appropriations Committee the bill would then go to the House Rules Committee for the formation of a rule to regulate the floor debate on the bill. The Resolution coming out of that hearing would provide a list of the allowed amendments that would be debated and voted upon during the floor debate. This process usually takes three days, but it can be greatly abbreviated if the Leadership wants.

The House debate on an appropriations bill would normally take the major part of a day. There would be about a dozen or so amendments that would be debated and voted upon. If the minority party (this year the Republicans) wanted to slow up the debate with procedural issues, the debate could take two or even three days before the final vote on the bill occurred.

December 3rd Deadline

The Federal Government has been without a budget since the start of the Fiscal Year on October 1st. They have been operating under a Continuing Resolution, a stop-gap measure that continues the FY 2010 funding for a short period of time while the Congress works out the budget process. The current Continuing Resolution expires on December 3rd. If nothing is done by that point, the government officially shuts down.

Next week the Congress is scheduled to start their Thanksgiving Recess. This would be expected to start when they adjourn on Friday and typically they wouldn’t come back to work until Tuesday, November 30th. This would leave three days for the process described above to be completed on 12 spending bills. That simply is not going to happen.

Another Continuing Resolution

The Military/Veterans appropriations bill (HR 5822/S 3615) will probably be considered and passed by the Senate and may get through the remainder of the process before the December 3rd deadline. To avoid shutting down the remainder of the government, there will be another house bill that will be converted to the next continuing resolution in the Senate. What will be interesting to see is what date is set for the termination of that resolution.

If the leadership thinks that they will be able to get some of their spending plans approved the continuing resolution will terminate sometime late in December. Given the Christmas holidays a date of the 17th would be a reasonable date though a date of the 30th is possible though it would only add a couple of real legislative days to the process. We would probably see another Omnibus Spending Bill come out of this, though a separate DHS bill could still possible.

If the leadership doesn’t think that they will be able to get the spending they want through the process (think passage in the Senate), then they could always punt the problem to next year’s Demopublican Congress; putting an end date of some time after January 5th. This may be especially true for Speaker Pelosi. She has complained on a number of occasions about the inability of the Senate to confirm the hard work done in the House. She might calculate that dumping the spending bill problem on the Republican controlled House would improve her chances of regaining the Speakership in two years.

BTW: Any continuing resolution would almost certainly contain specific language extending the authority for the CFATS program that also expires with the current continuing resolution. An extension until October of 2011 would be included in any DHS budget bill.

In any case, the 111th Congress is going to continue to be interesting to watch, right to the bloody end.

Tuesday, November 16, 2010

Vulnerability Disclosure

Andrew Ginter has an interesting posting on his Control System Security Blog (also posted on the Findings From the Field blog) talking about public disclosure policies for discovered cyber vulnerabilities. This is a recurring topic in the cyber security community, but Andrew adds a new dimension to the discussion after looking at the latest discoveries made by Symantec about the Stuxnet worm. Those discoveries seem to point even more firmly towards Stuxnet being a cyber weapon targeted at Iranian nuclear processing capabilities.

Control System Vulnerability Disclosure

Andrew does a very good job of describing the standard debate between security researchers (those who discover vulnerabilities) venders (those who create and must fix vulnerabilities) and system owners (who might get attacked via the vulnerabilities). I’ll summarize briefly here (and the summary is my fault not Andrew’s):

● Researchers – want their discovery released so that they get full and open credit for their prowess in detecting vulnerabilities.
● Venders – want to keep vulnerabilities quiet as they make them look bad and they have to take people away from new product development to fix something that they have already sold.
● Users – want to know about the vulnerabilities, want them fixed, but don’t want anyone telling potential attackers how to get inside their systems.
Weapon System Disclosure

When a cyber weapon (like maybe Stuxnet) is involved, as Andrew points out, the problem becomes even more clouded. First off we, presumably, add a government or two to the mix of players. The first is the target government and the second is the targeting government. Their motivations in the disclosure debate are even more complex.

When a cyber weapon is covert the government wielding the weapons does not even want its existence disclosed as that would decrease the potential effectiveness. They certainly don’t want the detailed mechanisms of the weapons disclosed as this would make it easier to defend against. And they probably don’t want their identity as the weapon wielder disclosed; it could expose them to retaliatory attacks (and not necessarily cyber attacks either).

There are potential reasons that the targeted government would not want it disclosed that they were the target of a cyber attack. The disclosure of an attack almost requires a knee-jerk requirement for a retaliation; the more effective the attack the stronger the required response. If a government does not think that it has the where-with-all to mount an effective response, it might not want the attack exposed. Or it may want to use a period of non-disclosure for planning and mounting an appropriate counter attack. If it didn’t look like they knew they were being attacked, perhaps the attacker would be less diligent in looking for the counter-attack.

The innocent bystanders, in this case other control system owners not involved in either the attack from either side, also have a complex outlook about disclosure. At first it would seem obvious that they would want disclosure about the attack vector/method so that they could consider deploying defenses to defend their system from similar attacks. The argument against disclosure from this view point is a bit more convoluted, but still potentially very real.

Stuxnet is a large and convoluted piece of software. According to most commentors it required a lot of assets and knowledge to put together and deploy. The list of countries with the in-house expertise to construct this cyber weapon is fairly limited, by some estimates no more than a half-dozen countries; most of whom the United States considers friendly to our interests. That keeps us relatively safe against a similar attack, or at least common wisdom would seem to hold that point of view.

The problem is that ‘weapons’ like Stuxnet, once they are understood, are relatively easy to duplicate and modify; the hard work has been done. The key word there is, of course, ‘understood’. So, full disclosure here would almost certainly increase the number of countries (and potentially groups) that could file off the serial numbers and re-direct Stuxnet type weapons at whom ever they desired.

Pandora’s Box is Open

Unfortunately, Andrew’s valuable discussion is about two months too late. The details about Stuxnet that have been released by Langner and Symantec are almost certainly enough to increase the number of Stuxnet capable countries by a factor of at least two. The cyber weapon arms race has almost certainly begun and there is no non-proliferation agreement.

To make matters worse there is already an international arms market in existence for the ‘small arms’ in this weapons race. There is also a growing ‘small arms’ independent research establishment in existence supporting that arms market. Both will almost certainly realize that scaling up their research and weapons development to the industrial scale is not only possible, but certainly profitable.

We better start building better defenses quick. The offense always has the benefit in the arms race between offense and defense. We better not get too far behind.

112th Congress First Meeting

Amazingly, the first day of the lame duck session for the 111th started out with new bills being introduced, as if they have time to consider most of these. One important piece of legislation that was introduced in the Senate yesterday; Senate Joint Resolution 40, is a joint resolution appointing the day for the convening of the first session of the One Hundred Twelfth Congress.

This resolution would set the day of the first meeting of the 112th Congress as Wednesday, January 5th, with the first regular session for both houses meeting at noon on that day.

The bill was approved by unanimous consent in the Senate and is currently waiting action in the House.

Water Facility Security in the Wiki Bill

One of the things that I did in my draft chemical facility security bill was to include water facilities in the chemical security program. I didn’t do this by modifying the current water facility security rules like Sen. Lautenberg did in S 3598 in the current session or the House did in the version of HR 2868 they passed last year. I just removed the language in the §550 authorizing language that exempted those facilities from coverage under the current CFATS program.

The reason for this is that the current water facility security program focuses mainly on the prevention of contamination of drinking water supplies. This is an important function in its own right and one that is probably better dealt with by water treatment experts. The processes that must be understood to deal with the security of the drinking water supply are significantly different than those processes affecting chemical facility security.

The protection of the chemicals at those facilities that would normally fall under the CFATS mandate (chlorine, anhydrous ammonia, and the like) will require the same types of security protocols, however, where ever they are located. So to me, it makes eminent sense to regulate the security of those chemicals under the CFATS program where ever they are found.

Chemical Security Sanctions

One of the main objections that the water treatment community has had with adding their facilities to the CFATS program is that those regulations give the DHS Secretary the authority to shut down non-complying facilities. Obviously no one expects water facilities to defy DHS, but the thought of the Secretary potentially shutting down a water facility that was fulfilling its water distribution function just does not make sense to the water treatment community.

I dealt with this by specifically exempting them from that sanction in the §550 authorization in §2(a)(4) of my proposed bill. I also realize that there must be provisions for some sort of sanctions against facilities that refuse to comply. I address this by having those sanctions applied through the Administrator of the EPA. Presumably the EPA would have a better understanding of the water treatment facility’s unique situation and would be better able to apply those sanctions.

Conflicts with Water Security Rules

Many water facility operators will undoubtedly be concerned that their coverage under the CFATS program will conflict with their security programs under the water system security programs. This is of course the same concern that many chemical facility operators had when CFATS was going to be applied to them in 2007. Existing security procedures are not invalidated by the CFATS program; they are incorporated in the CFATS process.

It is almost inevitable that additional security procedures will need to be implemented at these water facilities. Even facilities with extensive security measures will have holes in their program. This is a consequence of the fact that there has been no independent risk-based review of the security program. CFATS will certainly provide that.

Need for CFATS Coverage

Why shouldn’t we utilize the Lautenberg model of chemical security? The big problem is that there are no inspectors to insure that chemical security measures are adequate. I don’t understand how anyone expects that there will be adequate security measures put into place if there is no inspection program to ensure compliance, but that is how the water facility security program works.

Part of the reason for that is that the water security program is managed by each State. If the federal government mandated that the States added an inspection program to their current voluntary management of water treatment facilities there would have to be federal funding to support that requirement.

For EPA to have an effective security program that actually ensures that the chemicals used and stored at water facilities are adequately protected from potential terrorist attack they would have to establish an inspection program. To ensure that the inspection force (either federal or State) is adequately prepared to validate security measures, the EPA would have to initiate an inspector training program. If the chemical security program were designed in the way envisioned in S 3598, that training would have to be offered to each State’s inspection force.

Wiki Participation

I think that removing the current exemption of water facilities from CFATS coverage is the most reasonable way of ensuring that the extremely hazardous toxic inhalation hazard chemicals used at many of those facilities are adequately protected. I am also smart enough to know that I don’t have exclusive franchise on chemical security knowledge. Others may have other ideas on how to deal with these issues, and it is inevitable that adding some of those ideas to mine will result in a better legislative product.

That is one of the nice things about this project at WriteTheBillWiki. It allows for a collaborative approach to preparing legislation. Anyone can register with the system and take part in both the discussion surrounding the draft legislation, or even amend the actual language of the bill.

I would certainly like to invite all of my readers to actively participate in this project.
 
/* Use this with templates/template-twocol.html */