Saturday, June 9, 2012

ICS-CERT Publishes May Monthly Monitor


Yesterday the folks at ICS-CERT published the latest issue of their Monthly Monitor, a newsletter about all things concerning control systems security. Always an interesting read, this issue:

• Describes a thumb-drive incident;

• Explains complexities of international disclosure coordination;

• Discusses the ‘end of life’ for XP; and

• Recaps the ICSJWG Spring Conference.

As usual it includes their standard features:

• Recent ICS-CERT Product Releases;

• Open Source Situational Awareness;

• Up Coming Events; and

• Coordinated Vulnerability Disclosure.

There is one new feature that I would like to see in this newsletter. We all know that there is sensitive and/or classified cybersecurity information that ICS-CERT and US-CERT share with vetted individuals and organizations via their ‘Secure Portal’. It would be interesting to see an unclassified summary of that information included in the Monthly Monitor. I think this would encourage more organizations to try to get cleared for access to that information and it would give the rest of us unwashed individuals a better understanding of the state of the cybersecurity threat.

Friday, June 8, 2012

House Passes HR 5855 – DHS FY2013 Appropriations Bill


Last night the House passed HR 5855, the Department of Homeland Security Appropriations Act, 2013 in a nearly party-line vote (234-182; 16 Republicans against and 17 Democrats for). I did not see any amendments that directly affected the CFATS program, chemical security, or cybersecurity, though I have not checked each of the many spending changes. There was one amendment that did address the TSA Surface Security Inspection program, but it was defeated in a bi-partisan vote.

TSA Inspector Funding


An amendment was offered by Rep. Turner (R,NY) that would have limited spending of TSA Surface Security Inspectors to $20M. According to Mr. Turner (Congressional Record; H3638):

“My amendment today seeks to limit the inspector program budget to $20 million, which would substantially reduce its size, and allow the saved money to be put forward in other more effective surface programs, such as canine detection units, particularly at bus and rail stations.”

This amendment was defeated on a roll-call vote of 101-314. There were 99 Republicans and 2 Democrats voting in the affirmative.

Critical Infrastructure Designation


The Terry (R,NE) amendment that I discussed briefly yesterday was never actually brought to the floor for consideration.

Spending Changes


There were a large number of spending change amendments offered and many were adopted. Most of them took the form of:

‘On page X, Line Y reduce the dollar amount by $XXXXXX and on page X2, Line Y2 increase the dollar amount by the same amount.’

Any funding increase had to be offset by a corresponding decrease somewhere else, so amenders had to find a program they didn’t like to steal from to improve funding for one of their pet programs. There were, to be sure, a number that just removed money and put it towards deficit reduction.

Tracking down each of these to determine their actual significance is time consuming at best. I’ll just wait for the enrolled version of the bill to be printed by the GPO and check for spending changes of interest there.

PHMSA Announces Pipeline Integrity Management Meeting


Today the Pipeline and Hazardous Material Safety Administration published a notice in the Federal Register (77 FR 34123-34124) that it would be holding a public meeting on Implementing Integrity Management of Gas Distribution Pipelines. The meeting is being jointly sponsored with the National Association of Pipeline Safety Representatives (NASPR). The meeting will be held in Fort Worth, TX on June 27th, 2012.

More detailed information about this DIMP Implementation Workshop (as it is listed on the PHMSA Public Meetings web site) and registration information is available on-line. The registration page seems to indicate that this meeting will be webcast, but there is no mention of that in today’s Federal Register notice. NOTE: I have confirmed with Chris McLaren, US DOT PHMSA PHP-50 that there will be a web cast of this workshop; details will be provided to those who register for the web cast. (6-8-12; 14:00 EDT)

Thursday, June 7, 2012

HR 5855 Begins Floor Debate


Yesterday the House began consideration of HR 5855, the DHS FY2013 appropriations bill under an open rule. A number of amendments were offered, passed/rejected in yesterday’s debate; none directly concerned chemical security or cybersecurity matters.

To date only one amendment has been pre- printed in the Congressional Record (which gives priority to consideration in the floor debate) that deals with cybersecurity issues. Rep. Terry (R,NE) introduced Amendment #1 that would prohibit funds being used “for the designation of critical infrastructure in the banking, telecommunications, or energy sector for cybersecurity purposes”. This would effectively prevent (if adopted) any cybersecurity regulation of critical infrastructure cybersecurity, at least during FY 3013.

The debate will continue today and possibly tomorrow.

ICS-CERT Issues WinCC Advisory


Yesterday DHS ICS-CERT published an advisory for multiple vulnerabilities in the Siemens’ WinCC application. The vulnerabilities were reported in a coordinated disclosure by a number of researchers from Positive Technologies. In a twist that is to be encouraged, Siemens reported an additional related vulnerability that is being covered in this Advisory.

The vulnerabilities disclosed in this Advisory include:

Cross-site scripting, CVE-2012-2595 and CVE-2012-3003;

Xml (xpath) injection, CVE-2012-2596;

Directory traversal, CVE-2012-2597; and

Buffer overflow, CVE-2012-2598.

NOTE: These links may not be active for a couple of days.

The vulnerabilities are all remotely exploitable by a relatively unskilled attacker. Successful exploits could lead to a number of problems, but none are reported to lead directly to execution of arbitrary code.
Siemens has a security advisory addressing the issues and an update that address all but one of the vulnerabilities. The buffer overflow vulnerability is associated with DiagAgent, a utility that is no longer supported. Siemens suggests disabling DiagAgent and replacing it with SIMATIC Diagnostics Tool or SIMATIC Analyser.

Wednesday, June 6, 2012

Homeland Security Committee Amends and Adopts HR 4251 – SMART Port Security Act


At today’s hearing of the House Homeland Security Committee HR 4251, the Securing Maritime Activities through Risk-based Targeting for (SMART) Port Security Act, was amended and adopted by a broadly bipartisan voice vote.

The amendment in the nature of a substitute that I had mentioned in an earlier blog was agreed to in a voice vote. Two additional amendments were adopted by unanimous consent, functionally the same as a unanimous vote.

The first amendment, offered by Rep. Richardson (D,CA), would amend 46 USC §70107(b)(2) to allow Port Security Grants to be used for the replacement of security equipment. This is similar to HR 5802 which she had recently introduced.

The second amendment, offered by Rep. Cravaack (R,MN), would require a report by the DHS Secretary on “unnecessary redundancies or overlaps in Federal transportation security credentialing programs” (§208). The report would also include suggestions for correcting those overlaps and redundancies.

If/when this bill makes it to a floor vote, it will almost certainly pass without the necessity of a rule. Of course it could also get added to another bill, the Coast Guard authorization bill that I discussed earlier, for instance.

DHS Announces CSSS Registration


Today the folks at DHS NPPD Infrastructure Protection got around to posting information about registration for the 2012 Chemical Sector Security Summit on the CSSS web site. This comes a full week after SOCMA provided links to the same information. No new information was provided in the DHS announcement; it had all been covered in the earlier information release.
 
/* Use this with templates/template-twocol.html */