Friday, July 20, 2012

OMB Approves Changes to HME ICR


On Thursday the Office of Management and Budget announced that it had approved the extension of the information collection request (ICR) for the TSA’s Security Threat Assessment program supporting the Hazardous Material Endorsement program for the Commercial Driver’s License.

The extension request was initially published in the Federal Register in 2010 (75 FR 52961-52962) to support changes in questions being asked on the questionnaire. That notice estimated that the ICR would annually require 300,000 respondents to spend 975,000 hours providing the requested data at a cost of $27 million. The 30-day notice published in 2011 (76 FR 36560) noted that the same 300,000 respondents would spend 978,000 hours with no cost estimate provided. The approved collection notice published this week approves a collection from 300,905 respondents spending 994,096 hours at a cost of $27.4 million. There is no explanation for the change in data.

The OMB did note that “the supporting statement currently shows estimates from 2009-2011”. This explains why they only approved the current revised ICR until the end of February next year, noting that the “next submission should estimate burden hours and cost for years 2012, 2013, and 2014”.

Interestingly the ICR approval notice notes that the Agency (TSA) received public comments on the ICR. There was no indication in the 30-day ICR notice that there had been any public comments received; which also meant that there was no TSA response to those comments. The whole purpose of the ‘publish and comment’ process is to ensure that there is some form of public input into the regulatory process and that the government agencies take that input into account.

Thursday, July 19, 2012

Vandalism or Terrorism


There is a brief article over at KRQE.com about recent vandalism against a number of gas wells in New Mexico over the last six weeks. It seems that someone has been shooting high-powered rifles at gas well heads and storage tanks. It’s a brief article without much in the way of details other than it appears that local authorities are investigating this as nothing more than vandalism.

It sounds like this may be nothing more than a couple of red-necks looking to see explosions (always fun in the mind of most good-ole boys that I know). The fact that an IED was detonated near (but not at) one of the gas wells does support this idea to some extent. While it remains a possibility that someone is trying to attack these well sites for political ends, the lack of any claim of attack or manifesto for political change makes it unlikely that this is a terrorist attack.

Gas wells have been targets of local eco-terrorists in Canada and TSA has noted threats against pipelines. Anytime that there are attacks against these types of facilities one must consider the possibility that the attacks are terror related. I hope that the local authorities are keeping this in mind as they continue their investigations.

Wednesday, July 18, 2012

Information Sharing


I just had an interesting TWITTER conversation with Chris Jager (@chrisjager) about information sharing in a cybersecurity context. Chris makes the very valid point that ‘sharing information’ is more than a simple single activity of providing a piece of information. It is a complex set of actions that include a number of decision points that can validly interrupt the process. Mandating sharing cannot overcome that shortcoming.

A Potential Example


Look at §704 of the bill that might make it to the Senate floor this month (S 2105). It establishes the information sharing standard from the private sector to the Federal government. It says:

“Notwithstanding any other provision of law, a non-Federal entity may disclose lawfully obtained cybersecurity threat indicators to a cybersecurity exchange.”

That clearly doesn’t mandate information sharing, it allows (‘may disclose’) for that sharing {and §707(e) specifically prohibits such a mandate}. If we make a minor word change (substitute ‘will’ for ‘may’), that would require disclosure. Under that regime let’s look at how many places the information sharing could legitimately break down.

Scenario: A cyber-attack on a small-town water-treatment plant control system causes a chlorine vent valve to fail-open. This is a proof-of-concept attack that an eco-terrorist group is planning on using on a larger water system where the chlorine release would have major consequences. Timely sharing of information on this attack could prevent a larger successful attack.

Information Sharing Breakdown Points:

Investigation concludes that this is a simple mechanical valve failure – no information sharing requirement.

Investigation concludes that it is a control system related issue caused by operator error – no information sharing requirement.

Investigation concludes that it is a control system related issue caused by a programing error – no information sharing requirement.

Investigation concludes that it is a control system issue related to spurious commands from within the network. Management determines that it is due to a disgruntled employee and thus not a cybersecurity threat – no information sharing requirement.

Investigation concludes that it is a control system issue related to spurious commands from outside the network. Management determines that this is due to inappropriate security controls on the part of the vendor and thus does not indicate a wider cybersecurity threat – no information sharing requirement.

Investigation concludes that it is a control system issue related to spurious commands from outside the network. Management determines that, since the control system is clearly not an information system under the definition of the law, there is no information sharing requirement.

Investigation concludes that it is a control system issue related to spurious commands from outside the network. Management determines that this constitutes a cybersecurity threat indicator and makes appropriate notifications two week after the successful attack on the larger chlorine storage facility.

Depending on the skills of the initial incident investigators the above information sharing breakdown points could be actual findings for this type of incident. If management has a reason to encourage findings other than a ‘cybersecurity threat indicator’ the above investigation findings could easily be justified by an appropriately dis-motivated employee. And if management has made an active determination not to share information any of the above findings could be the directed results of the incident investigation.

Setting up an Information Sharing Network


Congress has to understand that there is much more to setting up an information sharing network than just establishing one in law. The program must provide incentives for the private sector to participate. The program must also remove disincentives that make it difficult to participate.

‘Incentives’ does not mean that the government must pay for this information; rather it must provide the organization with some other form of benefit. The most obvious example would be that joining the information sharing network ensures that the organization will receive timely cyber-intelligence information that can be used in protecting its networks. There could be a system of rewards for information that leads to the prevention of an attack on another organization.

There are a wide variety of disincentives to sharing information about cyber-incidents. One of the most important is the simple fact of not wanting to look stupid or ineffective. Closely following that are financial disincentives like the fear of losing business, or the fear of fines or other regulatory actions. Requiring the annonymization of information before it is re-shared, even within the government, is an important step in preventing many of these types of disincentives.

Finally, the information sharing process has to be as easy as possible. In many ways the Chemical Security Assessment Tool (CSAT) used by the CFATS regulatory process can be a model for they type systems that could be used for submitting cyber-threat information. This type of on-line tool could be set up for each of the critical sectors for an initial screening and annonymization process. This would allow for people familiar with the types of systems and processes involved in that sector to make the initial analysis of the threat.

Organizations within the sector could register with the information sharing system so that they could receive notifications about specific threats to particular control systems (okay and particular IT systems too) that they use within their organization. More general threat information would be shared throughout the sector. Vendors could also register with these systems, providing specific points of contact for information about particular systems that they sell/support.

Moving Forward


Unfortunately it looks like we have the time necessary to set up a more detailed proposal for an information sharing system as it remains increasingly unlikely that Congress is destined to take any final action on cybersecurity legislation before the November election.

Tuesday, July 17, 2012

Senate Consideration of Cybersecurity Bill


Yesterday theHill.com reported that Sen. Lieberman (I,CT) was saying that the Senate would consider a cybersecurity bill by the end of next week. The article notes that Lieberman was basing this prediction on a promise from Sen. Reid (D,NV). An as of yet not completed compromise version of S 2105 will be the bill to be considered.

The two ideas in the bill that have been holding up consideration have been the requirements for information sharing (privacy protection) and critical infrastructure protection (burdensome regulations of business). As I noted in my initial blog post on this bill, the critical infrastructure protection provisions would not have been particularly effective in regards to their protection of control systems. Further reducing that effectiveness to overcome objections of portions of the business community will make them practically useless in protecting the country from the potential effects of cyber-attacks on critical installations.

If the bill does come to the Senate floor (and Sen. Reid has been making these promises to bring a comprehensive cybersecurity bill to the Senate floor ‘next week’ for two years now) ‘by the end of next week’, it will certainly take some time to get it through the debate process. Let’s assume that it actually passes by July 27th; that would only leave one week for consideration of the bill by the House before the summer recess begins on August 3rd. That is not likely to happen.

Monday, July 16, 2012

Congressional Hearings – Week of 07-16-12


As the time approaches for the House and Senate to take their lengthy summer break (and go into the full re-election mode) there is little time left for taking serious action on much of anything. With this in mind there is only one hearing this week that might be of interest to the cybersecurity community; everyone else can start planning their vacations.

Cybersecurity


The Senate Energy and Natural Resources Committee will hold a hearing on Tuesday looking at “Cyber Security and the Grid”. The witness include representatives from FERC (Director McClelland, Office of Energy Projects), NERC (President Cauley), GAO (Director Wilshusen, Information and Technology), and the Ohio PUC (Chairman Snitchler). It’s just a bit late in the session to be holding this hearing, but it is the Senate.

Cybersecurity on the House Floor


According to the House Majority Leader’s web site the House will consider HR 5856, the Department of Defense Appropriations Act, 2013. As I mentioned in an earlier blog, there is little in the bill specifically mentioning cybersecurity, there will likely be some sort of amendments that will deal with cybersecurity or cyber-warfare issues. Or maybe not; only one amendment has been printed in the Congressional Record since the House Rules Committee hearing on this bill on June 28th.

Sunday, July 15, 2012

ICS-CERT Publishes Tridium Alert


On Friday the DHS ICS-CERT team published an alert about vulnerabilities in the Tridium Niagara AX Framework software. This is an unusual alert for a couple of reasons. First the vulnerabilities were initially disclosed via a coordinated disclosure, second it was outed by the Washington Post, and it isn’t really an ‘industrial’ control system in the way most of us think of a control system.

The Notification


Billy Rios and Terrry McCorkle initially reported to ICS-CERT a directory traversal and a weak credential storage vulnerability in the Tridium software. At first there wasn’t any action by Tridium and ICS-CERT considered publishing an alert based upon that lack of action. Then Tridium responded and ICS-CERT withheld the alert. But then the Washington Post published an article (Hey. ICS-CERT published a link to that article in a footnote in the Alert; more about that later.) about the vulnerabilities (a nice detailed and well written article by the way). So ICS-CERT was forced to publish this alert.

The Use of Niagara


The Niagara software is used to control a wide variety of devices in applications that include “energy management, building automation, telecommunications, security automation, machine to machine (M2M), lighting control, maintenance repair operations (MRO), service bureaus and total facilities management” (pg 2). Now these are certainly control applications but not what is usually thought of as ‘industrial control’ (though the only actual ICS attack that ICS-CERT has reported was on a building automation system). On a special note, however, we should probably be really concerned about this vulnerability in ‘security automation’; physical security systems are certainly part of cybersecurity.

Mitigation


Tridium has provided some interesting mitigation measures that can be taken while they are finishing work on a software update that will fix the problem. Those recommendations include:

• Disable the “guest” and “demo” user accounts if enabled.

• Use the “Lock Out” feature to lock out accounts for excessive invalid login attempts.

• Use strong passwords.

• Change default credentials

• Limit user access to the file system following the instructions in the Niagara AX Framework Software Security Alert below

• Ensure that control systems are not directly Internet facing.

Since the whole point of Niagara is the remote control of various devices via the internet the last point is kind of silly. I suppose what Tridium is trying to say is that access to the system should be through a virtual private network (VPN), but that is effectively not much protection when access to VPNs via any number of social networking attacks is so easily available. Hopefully, the patch will provide better security to these systems.

ICS-CERT Acknowledgement


It was very interesting to see ICS-CERT not only acknowledge the identity of the agency that publicly disclosed the vulnerability (an improvement in process that I noted last year) but also the provision of a link to that disclosure. Back in February Dale Peterson and I discussed this in an exchange of comments here on this blog. We both agreed that it is important for ICS-CERT to provide links to disclosures.

This is the first time that a publication of ICS-CERT has included such a link. I would like to think that the comments in this blog helped to influence the provision of that link. Unfortunately, I think that there is a better explanation for this disclosure; compared to the standard security researcher the Washington Post is the 8,000 lb. gorilla in the room; failure to provide the link might attract the wrath (and perhaps legal department) of the WP.

To prove that I am wrong all ICS-CERT has to do is to insure that all future alerts include links to the actual disclosure.

Friday, July 13, 2012

Ammonium Nitrate Fertilizer Hearing Follow-up


Well they held their closed hearing yesterday and, unless someone leaks the information, we will never know what ‘sensitive information’ was presented to the Sub-Committee by DOD and DHS that merited the testimony being presented behind closed doors. I will have to admit that according to what Chairman Lungren (R,CA) said in his opening remarks, it doesn’t sound like there was going to be any testimony about any active or recently foiled IED plot.

This conclusion is supported by the opening comments made by Ranking Member Clarke (D,NY) when she said:

“However, my preference would have been to take the testimony in public, in unclassified formats. I’m sure we could ask all of our witnesses back to give us classified briefings if needed, but, Mr. Chairman, I will not object to your motion to go into executive session.”

The prepared testimony from the witnesses (Woods – ICE, Barbero – DOD, and Johnson – GAO) was rich in administrative details about the counter IED and IED prevention activities being undertaken in Afghanistan. There were no technical details presented, but this Sub-Committee isn’t charged with overseeing that program, so they have no real need for those sensitive technical details.

A couple of interesting points were raised by Lungren in his opening comments. Early in those comments he noted that NPPD declined to send a witness to participate in the hearing. One would presume that the official reason had to do with the fact that, according to the title of the hearing, this was supposed to concentrate on anti-IED operations in Afghanistan and NPPD has not operational experience in that area that would allow them to provide useable information on the topic.

The real reason NPPD declined was alluded to towards the end of Lungren’s remarks when he mentioned the much delayed Ammonium Nitrate Security Program for which we are still waiting to see NPPD publish a final rule). I know from sources in ISCD that the ANPRM and the NPRM had been held up for quite a while in OMB deliberations and I suspect that the same thing is happening now, though the rule hasn’t yet reached the stage where it is officially submitted to OMB for EO 12866 review.

There was no projected date in the Fall 2011 Unified Agenda for the Ammonium Nitrate final rule, but that was because the comment period had just closed in December (well the Fall 2011 Unified Agenda was published in January 2012). We are still waiting to see the Spring 2012 Unified Agenda to be published, maybe that will provide a reasonable date for the publication of the final rule for the Ammonium Nitrate Security Program.
 
/* Use this with templates/template-twocol.html */