Friday, April 15, 2011

Long-haul Truck Drivers from Mexico

Wednesday the Federal Motor Carriers Safety Administration published a notice in the Federal Register about their pilot program to allow ‘Mexico-domiciled’ motor carriers to provide international cargo delivery service throughout the United States. Readers who are also subscribers to the Journal of Hazmat Transportation will have already received notice of a description of that program that I did for that publication. Here I would like to take brief look at some of the chemical security implications of that program.

FMCSA does attempt to address potential security issues dealing with trucks entering the United States from a country that has been described as one of the greatest potential security threats to the United States due to their current civil war with the drug cartels.

Security Screening

First FMCSA is requiring that any carrier and driver in the program undergo a security screening. The notice states that:

“FMCSA would submit information on the applicant motor carriers and their drivers designated for long-haul operations in the pilot program to DHS for security screening.” (76 FR 20811)
FMCSA provides a partial list of findings that might preclude a carrier/driver from participating in the program. It includes:
• Providing false or incomplete information;

• Conviction of any criminal offense or pending criminal charges or outstanding warrants;

• Violation of any customs, immigration or agriculture regulations or laws;

• The carrier or driver is the subject of an ongoing investigation by any Federal, State or local law enforcement agency; or

• The motor carrier or driver is inadmissible to the United States under immigration regulations, including applicants with approved waivers of inadmissibility or parole documentation
The problem that is not addressed is the question about the information that DHS would be able to rely upon to complete this screening. The government corruption in Mexico that is part and parcel of the drug cartel problem should bring into question any information provided by that government to DHS. The fact that the corruption is reportedly expanding across the border to include law enforcement (Federal, State and local) in the United States only emphasizes the extent of the problem.

Even if accurate information were available to DHS there is no way to ensure that the person investigated is the person driving the truck. DHS is still having problems establishing standards in the United States to improve the reliability of information on driver’s licenses. The wide spread fraud and corruption in Mexico make any reliance on a Mexican government identification document and exercise in futility at best. A requirement for some sort of a US-issued, biometrically-based identification (TWIC?) might mitigate this concern.

Hazardous Material Carriage

FMCSA does try to limit any potential security implications by ensuring that “operating authority granted under the pilot program excludes the transportation of placardable quantities of hazardous materials” (76 FR 20811). This would seem to limit the possibility of the use of legitimate chemical cargo as a weapon of mass destruction.

Of course the only way to really tell what is in a tank wagon is to open it up and test the contents. This will not happen at the border, or at traffic stops, or at road-side inspections. The only thing about the load that will be checked is the paperwork. Of course terrorists would not forge paperwork (pardon the sarcasm).

The same thing could be done with a load originating in the United States, but it would be more difficult. In the drug gang controlled portions of Mexico all it would take is the order of a gang functionary for a legitimate tank wagon to be diverted to be loaded with chemicals to turn it into a weapon. In a domestically sourced shipment there would presumably be safeguards put into place to ensure that this does not happen (I know; there are no legal requirements for those safeguard, but DHS continues to promise the formulation of transportation security rules).

Oh well, international relations and politics will almost certainly ensure that these issues will be ignored in the development and implementation of this plan for allowing long-haul truck drivers from Mexico to expand their authorized use of US highways. High-risk chemical-facility security-managers should not assume however that FMCSA rules have some how reduced the potential risk.

NOTE: FMCSA is requesting public comments on this proposed pilot program. Comments need to be submitted by May 13, 2011. Comments may be submitted on the Federal eRulemaking Portal (www.regulations.gov; Docket # FMCSA-2011-0097).

HR 901 Marked Up in Sub-Committee

As noted in yesterday’s blog post, the Subcommittee on Cybersecurity, Infrastructure Protection, and Security Technologies of the House Homeland Security Committee held a mark-up of HR 901, the Chemical Facility Anti-Terrorism Security Authorization Act of 2011, that was sponsored by Chairman Lungren. The Subcommittee made no changes to the bill and voted to favorably recommend the Full Committee.

HR 901 Provisions

HR 901 is the middle ground legislation of the three CFATS extension bills currently under consideration in the House. It goes further than HR 908 in that it takes the current CFATS authorization out of the appropriations bill and re-writes the current authorization as an amendment to the Homeland Security Act of 2002. This would change the primary oversight authority in the House to solely a responsibility of the Homeland Security Committee.

As I mentioned in my initial blog on this bill, that there are some other minor changes in the wording of the authorization language, but nothing that would require any significant changes to the CFATS process. It would authorize continuation of the current CFATS program through September 30th, 2018.

Chairman Lungren made it clear in his opening statement that he wants no changes made to the current program. He noted that:

“Although implementation has been slower than Congress wanted, CFATS is working [sic]. It is building a foundation of security in the chemical industry which will protect our citizens and our economy from future terror attacks. Is it a perfect plan? No. Are there gaps? Probably. But our priority should be to extend this working chemical security program and not allow the perfect plan to be the enemy of the good.” (Pages 1-2)
Amendments Offered

Three minor amendments were offered by Democratic members of the Subcommittee. The three amendments addressed issues of facility coverage, process safety, and employee participation in the development of security plans.

Rep. Clarke (D, NY) offered an amendment expanding the coverage of the CFATS program. Her amendment would have continued the current exemption for CFATS coverage only for DOD and DOE owned or operated facilities. In order to avoid further overtaxing the folks at ISCD, the amendment would have required the Secretary to delegate CFATS authority to:

• The Nuclear Regulatory Commission (NRC) for those facilities currently “subject to regulation by the Nuclear Regulatory Commission” {§2101(b)(3)(A)};

• The Commandant of the Coast Guard for facilities currently covered under the Maritime Transportation Security Act (MTSA); and

• The Administrator of the EPA for water treatment and waste water treatment facilities.
Rep. Richardson’s (D, CA) amendment would have required the CFATS regulations to add “requirements for chemical facility process safety reviews” {§2101(a)(3)}. Typically those requirements are covered under less than effective EPA and OSHA regulations. A large number of the CFATS covered facilities do not fall under those regulations for a variety of reasons. The term was not defined, but would have allowed the CFATS regulations to include inherently safer technology provisions as those provisions are really process safety issues.

Rep. Richmond (D, LA) would have required employee participation in “developing, revising, updating, or implementing a chemical facility security vulnerability assessment or site security plan” {§2101(f)}. This has been a priority for Democrats for some time as they maintain that hourly employees understand what actually goes on in the facility better than does management. There would be less management objection to these provisions if they did not mandate union involvement in the process, though Union involvement in work-rule development in support of the security requirements would be difficult to avoid at facilities covered by labor agreements.

All three amendments were voted down on straight party-line votes.

Moving Forward

The bill will next be considered by the full committee. I expect that there will be other amendments offered in the full committee mark-up that will touch on these issues. And they are just a certainly going to fail on party-line votes. It would be interesting, however, to see how an employee participation provision that does not specifically require union representation in the process would fare.

COMMITTEE WEB SITE NOTE: Readers might be surprised that I did not give more advanced notice of this mark-up hearing. It wasn’t because the Committee web site didn’t provide notice; it was because they keep mark-up meeting notices on a separate web page from their hearing notices. Most committees combine those notices on the same page. I’ll watch both Homeland Security Committee pages from now on.

Thursday, April 14, 2011

House and Senate Pass HR 1473

As expected, both the House and Senate passed HR 1473 today. The votes on the main bill were mixed in both Houses with a large number of Democrats voting for the bill and a significant number of Republicans voting against.

The votes on the two modifying resolutions were much more along party lines with both resolutions passing in the House and failing in the Senate. The vote on the Obama healthcare defunding drew three Democrat ‘Yeas’ in the House and the Planned Parenthood defunding measure drew 5 Republican ‘Nays’ in the Senate.

So, with the government over half-way through the fiscal year we now finally have a funding bill in place. We also have a little more permanence in the CFATS authorization, at least for the remainder of the fiscal year; actually until October 4th, 2011.

Senate to Consider HR 1473 Today

According to the Daily Digest for the Congressional Record (pg D 403) the Senate reached a unanimous consent agreement yesterday to consider HR 1473 today as soon as the House notifies them that they have completed action on the bill and its two associated resolutions.

The agreement requires that 60 votes will be necessary for passage. This may be a tough requirement for the bill, but it will be a certain death knell for the two amending resolutions.

The Senate will consider the three items in a different order than will be used in the House. The Senate will consider H. Con. Res 35, then H. Con. Res 36 and then, finally, HR 1473. The House rule called for a vote on HR 1473 with the other two votes to follow only if HR 1473 passes. Apparently there are those in the Senate leadership that were concerned that some members might not vote for HR 1473 if the possibility existed that either (or both) of the two resolutions could also be passed.

That the Senate was able to agree to this consideration format has ensured that a vote will take place if/when the House passes the bill. No one Senator from either extreme will be able to stop the consideration of the bill. It certainly isn’t a guarantee that the bill will pass (I’m betting that it will), but it does insure that a vote will take place.

HR 901 Markup Hearing Today?

The Daily Digest of the Congressional Record (pg D411) today notes that the Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies of the House Homeland Security Committee will be holding a mark-up hearing today at 10:00 on HR 901, the Chemical Facility Anti-Terrorism Security Authorization Act of 2011. The Homeland Security Committee web page does not list any hearings today.

New Article on CFATS Knowledge Center

Yesterday the folks at ISCD updated their CFATS Knowledge Center web site, adding a note under the ‘Latest News’ heading and adding an article to the list of frequently asked questions. Both items provided information about the 2011 Chemical Sector Security Summit.

The note under ‘Latest News’ states:

“Registration Open for 2011 Chemical Security Summit, July 6-7, 2011, Hilton Baltimore, Baltimore, Maryland. Go to http://guest.cvent.com/d/rdqt3v for Summit information and registration. Due to space constraints, each organization, company, and agency will be limited to two (2) registrants. There is no registration fee associated with this year’s event. See the article 2011 Chemical Sector Security Summit for additional information.”
The referenced article is Article # 1720 (Sorry, the link I copied yesterday for this article does not work today due to a 'checksum' error). That article provides some of the basic information on the CSSS including links to the registration site, and the CSSS web site. None of this information is new, it can all be found on the CSSS web site and was discussed here on this blog back in late March.

This is the first time that ISCD has included information on the CSSS on the Knowledge Center. Okay, the Knowledge Center was started the week before last year’s CSSS so that doesn’t really mean much. The fact that there was never a FAQ concerning the CSSS is also relatively meaningless as this is an ‘Article’ not a FAQ (same numbering system different format).

I suppose that I shouldn’t complain about an additional source of information about the CSSS, but I do have a couple of problems with the way that this was done. First, since there is already a web site for the CSSS I don’t really think that an article is necessary. The note under the ‘Latest News’ heading was a good idea, but it probably should have just included a link to the CSSS web site instead of the registration site.

Wednesday, April 13, 2011

ICS-CERT Publishes Two New Advisories

Today, the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published two new SCADA advisories in the Wonderware InBatch Client and the Honeywell ScanServer. Both vulnerabilities were discovered by security researchers and have patches that have been developed by the vendor and verified by ICS-CERT.

Wonderware InBatch

This new Wonderware vulnerability is similar to the earlier reported vulnerability in the Inbatch Server in that it is a buffer overflow vulnerability. The difference is that this vulnerability is in the Client ActiveX control and it is not covered by the earlier patch. Additionally, this vulnerability would be more difficult to exploit because it would require a social engineering attack to convince the user to access a malicious host.

No direct link to the patch is provided in this advisory. Invensys recommends that registered users log into the Wonderware Developer Network or contact Wonderware Tech Support. Additional information can be obtained by logging into the Invensys Cyber Security Updates site.

Honeywell ScanServer

The reported Honeywell vulnerability is found in its ScanServer, a component of their Web Toolkit. The toolkit can be included in the Honeywell SymmetrE building control systems product or as a stand alone tool to be used with other software products. According to the ICS-CERT advisory explains:

“When a client system accesses a web page created with the vulnerable version of Honeywell’s Web Toolkit, it will receive an ActiveX component that is vulnerable to exploitation if the client system subsequently visits a malicious website.” (page 1)
The publicly available proof of concept (PoC) code could allow a moderately skilled attacker to create an exploit that would allow remote execution of arbitrary code. Implementing the exploit would require convincing the target to visit a malicious web site.

The advisory provides a detailed discussion of the mitigation measures that include downloading the “the updated version of Web Toolkit ScanServer component build 862.1.10.1”. The remaining mitigation measures will depend on the type system involved.

Spear Phishing

It is interesting that both of these vulnerabilities require the use of social engineering tools. Since the previous report from ICS-CERT was the NCCIC report on spear phishing, it almost seems as if the web site owner knew these advisories were coming. Well, actually they almost certainly did; these advisories have been in the work for some time with ICS-CERT apparently being contacted by the researcher and then working with the vender to verify the vulnerability and the effectiveness of the mitigation.

In fact, I would assume that the reason for the unusual posting of an NCCIC report on the ICS-CERT site was the fact that these two vulnerabilities were quickly approaching publication. I think that it would have been more effective if all three documents were released on the same day and some one at ICS-CERT had published a more reader friendly editorial going into more detail how different social engineering attacks were crafted.
 
/* Use this with templates/template-twocol.html */