Thursday, December 16, 2010

More Info Coming on Omnibus Budget

One of the web sites that I review nearly every morning is the Daily Digest from the Congressional Record. This is a good summary page of the previous day’s activity in Congress and is usually available first thing in the morning. Yesterday it was not available until well after lunch and I found out why last night. Sen. Inouye (D, HW), the Chairman of the Senate Appropriations Committee is paying the cost of cobbling together this bill outside of normal procedures.

Typically, a bill is introduced, referred to Committee and the Committee favorably reports the bill before it comes to the floor for a vote. In the case of appropriations bills, that report is very important as it adds a much greater level of detail about how the government can spend the money provided by the bill. Since this bill did not go through that process, there is not Committee Report. So Sen. Inouye is being forced to provide the information in the form of ‘explanatory statements’ in the Congressional Record. This is the tool that is typically used to explain the results of a Conference Committee report.

Yesterday, the Congressional Record (for Dec 12th) had over 300 pages of ‘explanatory statements’ for the first three Divisions of the Omnibus Appropriations Act that the Senate will try to substitute for the House version of HR 3082. That 300 page installment did not include the DHS Division (Division F). That should be reported in the Congressional Record that is being delayed today (for yesterday) if they keep to the same 3 Divisions per day schedule.

When they are published, I’ll take a look and see if I can glean any more details about the DHS chemical security spending.

BTW: I’m not a legal scholar or a Senate Rules expert, but I don’t think that the Senate can take up this amendment until all of the ‘explanatory statements’ have been published. At the very least it would make for some interesting subsequent legal arguments about the ‘intent of Congress’.

DHS ICS-CERT Issues Ecava IntegraXor Advisory

Yesterday afternoon the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) issued an advisory about a buffer overflow vulnerability for the Ecava IntegraXor Human-Machine Interface (HMI). The vulnerability was discovered by Jeremy Brown, an independent security researcher and has been addressed by Ecava, who has released a patch to mitigate the vulnerability.

ICS-CERT notes that this stack based buffer overflow could allow an attacker with an intermediate skill level to remotely exploit the vulnerability, allowing the execution of arbitrary code. There is currently no known exploit published for this vulnerability.

ICS-CERT recommends the following mitigation measures after conducting a proper impact analysis and risk assessment:

• Update IntegraXor to the latest version and install the latest patch. For more information, customers can contact Ecava support at support@integraxor.com.
• Minimize network exposure for all control system devices. Critical devices should not directly face the Internet. Control system networks and remote devices should be located behind firewalls, and be isolated from the business network. If remote access is required, secure methods such as Virtual Private Networks (VPNs) should be utilized.

Wednesday, December 15, 2010

DHS ICS-CERT Issues Wonderware InBatch Advisory (Updated)

Some time last night the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) issued an advisory for a buffer-overflow vulnerability reported in the Wonderware InBatch Server and I/A Batch Server industrial control system products. The vulnerability affects all supported versions of these products. Invensys confirms the existence of this vulnerability that was posted on an un-named vulnerability disclosure site by an independent security researcher. According to the advisory Invensys is in the process of developing a patch to mitigate this vulnerability.

ICS-CERT notes that exploit code for this vulnerability has been published and expects that an attacker with a moderate skill level could remotely exploit this vulnerability. The buffer-overflow vulnerability could lead to a denial of service (DOS) or potentially allow an attacker to execute arbitrary code.

ICS-CERT recommends the following mitigation measures:

● “Install the patch when it is released. ICS-CERT will provide an update to this Advisory when a patch is released.
● “Minimize network exposure for all control system devices. Control system devices should not directly face the Internet. 2
● “Control system networks and devices should be located behind firewalls and isolated from the business network. Access to TCP Port 9001 should be restricted. If remote access is required, secure methods such as Virtual Private Networks (VPNs) should be utilized.
As always ICS-CERT provides their standard caveat about applying defensive measures; “ICS-CERT reminds organizations that proper impact analysis and risk assessment should be performed prior to taking defensive measures.”

The advisory notes that Invensys has a Cyber Security Updates site, but does not provide a link to that site. There is no mention that I could find of such a site on their publicly accessible web pages; if it exists it is behind the registered user barrier. [NOTE: I just got an email from CERT SOC, they provided the missing link; http://iom.invensys.com/EN/Pages/IOM_CyberSecurityUpdates.aspx and noted that the Advisory will be corrected tomorrow. 8:49 pm EST]
ICS-CERT will update this advisory when a patch is released.

Chemical Security in Senate Appropriations

Well I had a chance to review the DHS portion (pages 644 thru 747) of the Omnibus Appropriations Act published yesterday by the Senate Appropriations Committee along with a published summary of the DHS portion of that bill. There are significant differences between this bill and S 3607 that was reported this summer by the Senate Appropriations Committee and with the HR 3082 version passed in the House last week.

CFATS Extension

As expected the CFATS authorization is extended in this proposed legislative amendment. The extension is found in §545 (pg 726) though there is a minor technical error in that section. As published it reads:

“Section 550(b) of the Department of Homeland Security Appropriations Act, 2007 (Public Law 109–295; 6 U.S.C. 121 note) is amended by striking ‘on October 4, 2010’ and inserting ‘on October 4, 2011’.”
The minor error is the fact that §550 has been amended twice by continuing resolutions this year and the current expiration date is December 18, 2010. This is the type of error you expect to see in a 1924 page bill that was cobbled together from twelve separate draft bills and then modified to meet current political conditions. Small stuff slips through the cracks.

CFATS Money

The overall funding for DHS is $43.548 billion, a decrease from President Obama’s ($43.890 billion) budget request but an increase over FY 2010 ($42.665 billion) according to Committee DHS summary. Of this the infrastructure protection and information security programs and activities (which includes the Infrastructure Security Compliance Division) would receive $874,923,000 [vs $878,316,000 in HR 3082 passed in the House and $989,342,000 in S 3607].

That is as close as the actual budget language gets to the CFATS program. It is just too small a program to be actually listed in the document. The DHS summary document does note that the above amount would include “$105 million, as requested, to support the coordination and management of regulating high-risk chemical facilities” (pg 3).

Other Programs of Interest

The surface transportation security program at TSA would receive $137,558,000 (pg 662). This would include the folks that deal with the freight rail security program, though I would suspect that the bulk of that money will go to passenger rail and public transport security measures. It specifically includes, according to the summary, money for the “100 new inspectors and 15 Visible Intermodal Protective Response -- “VIPR” -- Teams added in FY 2010” (pg 3).

There will be “$386 million for cyber security, $7 million above the President’s request” (pg 4). The bulk of that money will go to IT programs, but I think that we can assume that ICS-CERT will continue to get its funding; whether there will be an increase in that funding remains to be seen.

The Coast Guard will receive “$8.92 billion (excluding mandatory retirement funding), $142 million above FY 2010 and $200 million above the request” (pg 2). The MTSA program and various hazmat security programs are too small to be mentioned.

The Way Forward

HR 3082 will not come up in the Senate until sometime after the tax cut bill vote is completed (probably today?). It is not clear that there are enough votes to bring this amendment to an actual vote. Many Republicans want to see a short term continuing resolution (45 days) to allow the new Congress to set the spending priorities for the bulk of FY 2011. There may be enough Republican votes from the members of the Senate Appropriations Committee to close debate.

Of course if this amendment is passed in the Senate, then HR 3082 will have to go back to the House. It would probably be approved there; the Democrats can always point to their attempt to reduce spending and the Republican objections effectively don’t count. Of course, if there is any delay or hold up in the process, there will need to be another very short term continuing resolution; the current CR expires Saturday.

Tuesday, December 14, 2010

FY 2011 Omnibus Appropriations Act

The Senate Appropriations Committee now has a copy of the FY 2011 Omnibus Appropriations Act available on its web site. It is a .PDF file and is very large (1900+ pages). This will be offered as ‘an amendment in the nature of a substitute’ for HR 3082 when that bill comes before the Senate. I’ll be looking at the DHS stuff and report back when I have more info.

Anhydrous Ammonia Video

There is a very brief article over on EmergencyMgmt.com pointing their readers to a police dash-cam video of an Illinios State Trouper responding to an auto accident that, unknown to him, includes a fertilizer application trailer leaking anhydrous ammonia. The video should be one that is required viewing for all first responders.

I’m sure that the training that the Trooper received included recognizing DOT hazard placards. I am also pretty sure that he had received specific training on the hazards of anhydrous ammonia, Illinois has tough rules about the security of anhydrous ammonia storage because of the number of thefts of the material by meth manufacturers. Responding to leaks associated with those thefts must be common enough in the State for there to be specific hazard training to be conducted as a matter of course.

Unfortunately the trooper commits a common hazmat response error. He forgets his training when he sees the injured body lying on the road. Ignoring the ‘cloud of smoke’, the markings on the trailer and the strong pungent odor of ammonia he races, first aid kit in hand, to the injured person’s side. He is overcome by the fumes so quickly he cannot even radio for assistance. He passed-out on top of the person he was attempting to aid.

The fire truck and ambulance crews approaching from the opposite direction were either better informed about the accident, or just more experienced and wary. They did not approach to execute the rescue until they had donned their breathing apparatus and had set a hose to knock down the toxic cloud. When they carried the Trooper away from where he had fallen he was still breathing.

This was a relatively small and nearly-benign hazmat incident. The leak is apparently small with a decent breeze blowing through the area. This is an ideal situation to keep the concentration of the ammonia cloud relatively low, below deadly levels. If the leak had been faster or the wind slower the cloud would have been much more toxic and the Trooper probably would not have even made it to the other victim’s side.

If this had been a tank truck or railcar of anhydrous ammonia instead of a fertilizer application trailer, the cloud would have affected a much larger area. If the accident had taken place in a town or a city, the potentially affected population would have been larger and significantly less well trained.

This is why emergency response personnel have to be trained and retrained, practiced and rehearsed, made to repeat the response until it becomes as automatic as that seen in the fire truck crew in this video. They need to know what hazardous materials they could routinely encounter in their area, either from transportation trailers or from fixed sites. Local companies that make, use, or transport these materials, particularly TIH chemicals need to ensure that their local responders are appropriately trained and equipped to deal with these incidents.

If you disagree, watch the video again.

S 4021 Introduced - Silly Cyber Security

Last week Sen. Cardin (D, MD) introduced a new piece of cyber security legislation, S 4021, (Corrected bill number 5:59 pm EST) the Internet and Cybersecurity Safety Standards Act. Since its introduction there have been a number of references in the press to this bill establishing ‘cybersecurity standards’. With the actual bill being published on the GPO website today, we can finally see that the press hype has been overblown as usual. All this bill does is require DHS to conduct yet another silly cybersecurity study.

WARNING: Dripping sarcasm alert...

Another DHS Study Required

This bill does not specifically address control system security issues, or even information system security issues. It is much more expansive than that. It proposes to address the prevention of “terrorists, criminals, spies, and other malicious actors from compromising, disrupting, damaging, or destroying computer networks, critical infrastructure, and key resources” {§4(a)}.

Actually it doesn’t even do that. What it does is to require the Secretary of DHS to take a year to “conduct an analysis to determine the costs and benefits of requiring providers to develop and enforce minimum Internet and cybersecurity safety standards for users of computers” to effect that prevention. Yes, it wants DHS to study the effectiveness of putting the onus for cybersecurity on the “users of computers”.

The scope of the study will be appropriately broad, requiring the Secretary to “consider all relevant factors, including the effect that the development and enforcement of minimum Internet and cybersecurity safety standards may have on homeland security, the global economy, innovation, individual liberty, and privacy” {§4(b)}. Let's not forget the sanctity of the flag, the protection of motherhood and the promotion of apple pie.

Of course, before the Secretary can conduct such an analysis, she is required to “consult with relevant stakeholders in the Government and the private sector, including the academic community, groups, or other institutions, that have scientific and technical expertise related to standards for computer networks, critical infrastructure, or key resources” {§5} How the Secretary is going to consult with such a disparate group of experts, and conduct the cost benefit analysis, has been left, appropriately, to the discretion of the Secretary.

Standards? We Don’t Need No Stinkin’ Standards

Of course the legislation completely ignores two essential prerequisites for a ‘cost-benefit’ analysis of this sort. First there would have to be a set of standards that could be evaluated for their effectiveness and second there would have to be an enforcement mechanism that could likewise be evaluated. Neither of these is addressed in this legislation.

Oh yes, I forgot to mention the most ludicrous part of this proposed bill. Back in Section 3, Sen. Cardin lists the Congressional Findings that provide the reasoning underlying the need for this legislation. The first predicate finding of this legislation concludes that “computers pose a risk to computer networks, critical infrastructure, and key resources in the United States”{§3(1)}. Yep, computers are the threat; not compromised computers, not inadequately secured computers, just ‘computers’. Burn em all and we'll have cyber security, you betcha.

Fortunately, this bill was introduced too late in the session to cause any significant embarrassment to the Chairman of the Senate Committee on Commerce, Science, and Transportation to whom it was referred for consideration. The bill, without any consideration, will die when the Senate adjourns sin die later this month. Hopefully, it will be buried in an unmarked grave with an oaken stake through its heart, so that it can never be resurrected.
 
/* Use this with templates/template-twocol.html */