Today the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published yet another advisory about a vulnerability in a SCADA Human Machine Interface system, this time from a vendor in China, Sunway. The heap-based buffer overflow vulnerability affects two Sunway systems, the ForceControl and pNetPower applications.
There are no published exploits for the vulnerabilities and ICS-CERT estimates that it would take an attacker with an intermediate skill level to exploit them. Sunway has published separate patches for each system.
The interesting thing about this particular set of vulnerabilities is that the security researcher who reported them is Dillon Beresford of recent Siemens vulnerability fame. Obviously Dillon is no one-hit-wonder.
ICS-Monthly Monitor Published
ICS-CERT also published the second issue of their Monthly Monitor today. There is a very interesting description of the vulnerability disclosure procedures used by ICS-CERT; an appropriate topic given recent complaints about their apparent inaction on Dillon’s Siemens disclosure.
The interesting bit of disclosure here that was new to me was that, in the coordinated disclosure process, ICS-CERT publishes a limited edition advisory to be released the day that the vendor publishes the patch/mitigation-strategy. This is published, according to the Monitor, on a ‘secure portal library’, “which is available only to a limited vetted membership— primarily CIKR asset owners, federal, state, local, and tribal agencies”. No word on how one gains membership in this elite group.
As a blogger/reporter on chemical security issues I would not expect to be invited/allowed to join such a group. Even if I could, I don’t think that I would accept because of the undoubted limitations on disclosure that would accompany such membership.
I would suspect that any cyber security manager at a high-risk chemical facility, or any facility on the Critical Infrastructure Key Resources (CIKR) list should be interested in joining this group. I’m not sure how you would go about requesting membership, but I suspect that an email to ICS-CERT@dhs.gov would be a good place to start asking the questions.
Thursday, June 16, 2011
PHMSA Pipeline Control Room Management Final Rule
Today the Pipeline and Hazardous Material Safety Administration published their final rule on pipeline control room management in the Federal Register (76 FR 35130-35136). As I noted in a blog post this weekend, this rule changes the effective dates of the previous rule on this topic published on December 9th, 2009 (74 FR 63301) and corrected on February 3rd, 2010 (75 FR 5536).
Revised Effective Dates
The following new dates apply:
October 1st, 2011 (Establish procedures by August 1st, implement October 1st):
I noted in my earlier blog that, based on the OMB web site data, there was some confusion about if this would be an NPRM or a direct final rule. Well, it turns out that there was even more reason for the confusion. The OMB’s regulatory agenda web page noted that the NPRM for this rule had been scheduled for December 2010, but had not yet been published. According to the preamble to this rule the NPRM had actually been published on September 17th, 2010 (75 FR 56972). So, there is no ‘direct final rule’ involved here.
Revised Effective Dates
The following new dates apply:
October 1st, 2011 (Establish procedures by August 1st, implement October 1st):
• §192.631(b) Roles and responsibilitiesAugust 1, 2012:
• §192.631(c)(5) Shift change
• §192.631(d)((2)-(3) Fatigue mitigation education and training
• §192.631(f) Change management
• §192.631(g) Operating experience
• §192.631 (c)(1)-(4) Adequate informationRule Status Confusion
• §192.631 (d)(1) Shift length
• §192.631 (d)(4) Maximum hours-of-service
• §192.631 (e) Alarm management
I noted in my earlier blog that, based on the OMB web site data, there was some confusion about if this would be an NPRM or a direct final rule. Well, it turns out that there was even more reason for the confusion. The OMB’s regulatory agenda web page noted that the NPRM for this rule had been scheduled for December 2010, but had not yet been published. According to the preamble to this rule the NPRM had actually been published on September 17th, 2010 (75 FR 56972). So, there is no ‘direct final rule’ involved here.
TSA Publishes Pipeline Security ICR Renewal Notice
Today the Transportation Security Administration (TSA) published a 60-day notice in the Federal Register (76 FR 35229-35230) of their intention to request OMB approval for the renewal and expansion of their information collection request (ICR) for continued authority to collect ‘critical facility’ information on the top 100 ‘most critical’ pipelines.
That ‘top 100’ description is a misnomer. It comes from the requirement in the Implementing the Recommendations of the 9/11 Commission Act of 2007 {§1557(b)} for TSA to “develop and implement a plan for inspecting critical facilities of the 100 most critical pipeline systems”. What TSA has actually done is to identify the top 125 critical pipeline systems and have them identify their ‘critical facilities’. This has resulted in about 600 facilities that TSA is including in their pipeline inspection program.
According to the discussion in this notice, TSA expects to conduct follow-up visits to up to 125 critical pipeline facilities per year after reviewing the updated information collected under this ICR renewal. During these visits TSA will collect additional information under this ICR using the Critical Facility Security Review form. This new form will be different than the Corporate Security Review (which will remain in use) that is described in the current ICR in that it looks at facility specific information rather than corporate policy data.
This new form, and the intended follow-up data on implementing recommended security measures, have resulted in a change in the burden hours associated with the renewal of this ICR. TSA expects pipeline operators to spend 4 hours providing updated critical facility information. The new Critical Facility Security Review will take 4 hours at each facility and TSA expects facilities to spend five hours responding to TSA follow-up requests about the status of their security recommendations implementation. This results in an expected industry burden of 2,730 hours in the first year and 1,080 hours in each of the following years.
Public comments on this notice are solicited by TSA. Comments may be submitted by email to TSAPRA@dhs.gov. (TSA does not appear to be using the Federal eRulemaking Portal for these comments). Comments must be submitted by August 15, 2011.
That ‘top 100’ description is a misnomer. It comes from the requirement in the Implementing the Recommendations of the 9/11 Commission Act of 2007 {§1557(b)} for TSA to “develop and implement a plan for inspecting critical facilities of the 100 most critical pipeline systems”. What TSA has actually done is to identify the top 125 critical pipeline systems and have them identify their ‘critical facilities’. This has resulted in about 600 facilities that TSA is including in their pipeline inspection program.
According to the discussion in this notice, TSA expects to conduct follow-up visits to up to 125 critical pipeline facilities per year after reviewing the updated information collected under this ICR renewal. During these visits TSA will collect additional information under this ICR using the Critical Facility Security Review form. This new form will be different than the Corporate Security Review (which will remain in use) that is described in the current ICR in that it looks at facility specific information rather than corporate policy data.
This new form, and the intended follow-up data on implementing recommended security measures, have resulted in a change in the burden hours associated with the renewal of this ICR. TSA expects pipeline operators to spend 4 hours providing updated critical facility information. The new Critical Facility Security Review will take 4 hours at each facility and TSA expects facilities to spend five hours responding to TSA follow-up requests about the status of their security recommendations implementation. This results in an expected industry burden of 2,730 hours in the first year and 1,080 hours in each of the following years.
Public comments on this notice are solicited by TSA. Comments may be submitted by email to TSAPRA@dhs.gov. (TSA does not appear to be using the Federal eRulemaking Portal for these comments). Comments must be submitted by August 15, 2011.
Wednesday, June 15, 2011
S 1152 Introduced – Cybersecurity R&D
Last week Sen. Menendez (D, NJ) introduced S 1152, the Cybersecurity Enhancement Act of 2011. This is a companion bill to HR 2096 that I discussed in an earlier blog. This means that it identical to HR 2096 and theoretically allows for simultaneous consideration of the bill in both the Senate and the House, allowing for earlier passage of one of the two bills.
NOTE: The delay in this post is due to the fact that the GPO just published a copy of S 1152 today.
Reader Comment – NIST ICS Security Guide
A reader of this blog, Ragnar Schierholz, added a comment to my recent post about the publication of the NIST ICS Security Guide. He noted, as have some bloggers, that the recently published version of the Guide is little different from the draft of the document that was published about three years ago. He then asked if I had noted the very close similarity in the two versions.
I’m sorry Ragnar, I didn’t. The reason is that I never saw the draft document. Three years ago my understanding of ICS security issues was much narrower than it is today. Like much of the user community, I was essentially unaware of the multitude of cybersecurity issues that we recognize as being important today. Three years ago readers of this blog would have read about physical security measures for control rooms and vague suggestions that complete isolation of control systems was ‘becoming difficult’.
My appreciation for the complexities of control system security issues has changed over time and this has led to increased coverage of those issues in this blog. Hopefully, this has helped to increase awareness in the user community on these issues.
As a number of bloggers have noted, if the user community does not demand increased security in their systems, vendors will likely remain reactive to security vulnerabilities rather than proactively designing more secure systems (I almost wrote ‘secure systems’ there, a misnomer if ever there was one). That demand can only be made if there is an increased understanding of the problem.
So, while the newly released security guide may be little changed from the draft, it is a new document to many of us in the chemical security community. That makes it a valuable addition to any chemical security library.
On a personal note, questions like this one posed by Ragnar make me wonder what security issue I’m overlooking today due to the limits of my knowledge. Hopefully my readers are standing by to help identify those issues for me.
I’m sorry Ragnar, I didn’t. The reason is that I never saw the draft document. Three years ago my understanding of ICS security issues was much narrower than it is today. Like much of the user community, I was essentially unaware of the multitude of cybersecurity issues that we recognize as being important today. Three years ago readers of this blog would have read about physical security measures for control rooms and vague suggestions that complete isolation of control systems was ‘becoming difficult’.
My appreciation for the complexities of control system security issues has changed over time and this has led to increased coverage of those issues in this blog. Hopefully, this has helped to increase awareness in the user community on these issues.
As a number of bloggers have noted, if the user community does not demand increased security in their systems, vendors will likely remain reactive to security vulnerabilities rather than proactively designing more secure systems (I almost wrote ‘secure systems’ there, a misnomer if ever there was one). That demand can only be made if there is an increased understanding of the problem.
So, while the newly released security guide may be little changed from the draft, it is a new document to many of us in the chemical security community. That makes it a valuable addition to any chemical security library.
On a personal note, questions like this one posed by Ragnar make me wonder what security issue I’m overlooking today due to the limits of my knowledge. Hopefully my readers are standing by to help identify those issues for me.
More Personnel Surety Changes to CFATS Knowledge Center
Two sets of changes were made today to the CFATS Knowledge Center web page. Early in the morning a new entry was placed in the ‘Latest News’ section and then later in the day a separate entry was removed from that section.
Addition to Page
The added news item today stated that: “The CFATS Personnel Surety Privacy Impact Assessment is now available.” This was a vague restatement of a note in the Article that I discussed yesterday that stated that the privacy impact assessment could be found at www.dhs.gov. Neither statement was very helpful in telling people where the document could be found.
Actually, all anyone had to do was to look at the ‘Documentation’ section at the bottom left of the page to find a link to “CFATS Personnel Surety Privacy Impact Assessment”. This link was apparently added at the same time as the ‘Latest News’ item. This section of the page has links to just about every conceivable CFATS document published by DHS.
Removed from Page
Sometime later in the day the ‘Latest News’ had the 4-13-11 item removed that had reported the opening of the registration for the Chemical Sector Security Summit. This was an appropriate removal since the registration has been closed since the 20th of May.
The article that supported that news item (Article 1720) remains on the site providing information about the CSSS.
Addition to Page
The added news item today stated that: “The CFATS Personnel Surety Privacy Impact Assessment is now available.” This was a vague restatement of a note in the Article that I discussed yesterday that stated that the privacy impact assessment could be found at www.dhs.gov. Neither statement was very helpful in telling people where the document could be found.
Actually, all anyone had to do was to look at the ‘Documentation’ section at the bottom left of the page to find a link to “CFATS Personnel Surety Privacy Impact Assessment”. This link was apparently added at the same time as the ‘Latest News’ item. This section of the page has links to just about every conceivable CFATS document published by DHS.
Removed from Page
Sometime later in the day the ‘Latest News’ had the 4-13-11 item removed that had reported the opening of the registration for the Chemical Sector Security Summit. This was an appropriate removal since the registration has been closed since the 20th of May.
The article that supported that news item (Article 1720) remains on the site providing information about the CSSS.
Emerging Threats to Rail Security
Yesterday the Senate Committee on Commerce, Science, and Transportation held a full committee hearing on the emerging threats to rail security. I have not had a chance to review the video of the hearing, but a quick review of Administrator Pistole's written testimony and Chairman Rockefeller’s opening remarks continue to show that the main emphasis of the politician’s remains focused on passenger rail and transit operations, not freight rail. The GAO report that formed the written testimony of Mr. Lord does make significant observations about freight rail security matters, though it too concentrates on transit issues.
Training
The GAO report continues to take TSA to task for its failure to implement the training regulation requirements of the Implementing Recommendations of the 9/11 Commission Act of 2007. It does note that TSA reports that they intend to publish a notice of proposed rule making in the fall of this year. The report fails to note that according to the semi-annual Regulatory Agenda reports published every six months or so by DHS, TSA has had intentions of imminently publishing such an NPRM for quite some time.
Information Sharing
The GAO report addresses the multiple information sharing efforts for transit security, but notes that freight rail carriers are not satisfied with the security and intelligence information provided to them. Three of the Class I railroads that GAO interviewed for this report noted that they frequently receive intelligence information from the media before they receive the same information from TSA.
It will be interesting to see if the video of the hearing shows that the politicians on either side of the committee dais addressed these GAO concerns in their discussions during the questioning period of the hearing. I hope to have a chance to review that video this weekend.
Training
The GAO report continues to take TSA to task for its failure to implement the training regulation requirements of the Implementing Recommendations of the 9/11 Commission Act of 2007. It does note that TSA reports that they intend to publish a notice of proposed rule making in the fall of this year. The report fails to note that according to the semi-annual Regulatory Agenda reports published every six months or so by DHS, TSA has had intentions of imminently publishing such an NPRM for quite some time.
Information Sharing
The GAO report addresses the multiple information sharing efforts for transit security, but notes that freight rail carriers are not satisfied with the security and intelligence information provided to them. Three of the Class I railroads that GAO interviewed for this report noted that they frequently receive intelligence information from the media before they receive the same information from TSA.
It will be interesting to see if the video of the hearing shows that the politicians on either side of the committee dais addressed these GAO concerns in their discussions during the questioning period of the hearing. I hope to have a chance to review that video this weekend.
Subscribe to:
Posts (Atom)