Sunday, September 16, 2012

Congressional Hearings – Week of 9-17-12


Barring some unforeseen emergency session this should be the last week that Congress is in session until after the November election and it will be a short week, starting on Wednesday. The Senate will take up the continuing resolution on Wednesday and there are currently three hearings scheduled that might be of interest to my readers; a CFATS continuation hearing and two hearings in the Senate that look at the threat picture.

CFATS Hearing


The Homeland Security Subcommittee of the House Appropriations Committee is going to try on Thursday to finish the hearing they started back in July. The witness testimony has already been given we just have the pointed questions from what is essentially already a lame-duck committee. With the FY 2013 spending bill in the hands of the Senate, this Committee has no power over the folks at DHS until the new Congress is seated in January.

The two witnesses that will be grilled Deputy Under Secretary Spaulding and Director Wulf are new enough to NPPD-ISCD that they will be unlikely to be able to effectively explain how the CFATS program got to its current sorry state of affairs. They will only be able to address how they have been able (or not able as the case may be) to fix the current problems. The GAO has already given them substantial cover on that topic in their report on the progress on the 95-point plan.

It will be interesting to see if anyone on the Subcommittee raises questions about the current complaint that has been made to the DHS IG about the personnel issues in the Office of Infrastructure Protection; some of which have to specifically deal with ISCD. If that is addressed, the hearing might get interesting.

The Threat Picture


Two different Senate committees will be looking at the current threat picture from slightly different directions on Thursday. Both hearings are currently scheduled to be open hearings so there is little in the way of juicy intel that we will be hearing. It will be just the broad intel picture painted in bold strokes with no thought given to the upcoming Presidential election. Still security managers and planners need to hear this stuff from time to time to have some idea of what to expect.

The Senate Homeland Security and Governmental Affairs Committee’s hearing will address “Homeland Threats and Agency Responses”. Three witnesses are currently scheduled; Secretary Napolitano, FBI Director Robert Mueller, and National Counter Terrorism Center Director

Matthew Olsen. Given the worldwide response to the anti-Muslim film this week, I would be sure that we will hear some discussion about the potential for violence here in the United States from that reaction, though by Thursday that may have blown over.

The Subcommittee on the Constitution, Civil Rights, and Human Rights of the Senate Judiciary Committee will look at the topic from a slightly different perspective in their hearing on “Hate Crimes and the Threat of Domestic Extremism”. No witnesses have yet been announced, but I would not be surprised to see the same three witnesses since the scheduled times are so far apart.

HJ Res 117


The Senate has a cloture vote scheduled on Wednesday afternoon to allow consideration of HJ Res 117. As always, this ‘purely procedural’ vote will effectively determine the outcome of this version of the Continuing Resolution. If it passes this vote (and I have seen nothing to indicate otherwise, but you can never tell with the Senate) then the FY 2013 spending bill will have been effectively punted to the 113th Congress. If this vote fails, we have a new election year hot potato that will push everything else off the news until it gets resolved.

As long as both parties are convinced that they will control the Congress and the Oval Office next year, this six-month CR makes all sorts of political sense. This election is still way too close to call this early, but at least one of these two are cruising for a fall and it really does, in my opinion, remain unlikely that anyone is going to win the Trifecta. We are almost certainly going to see a replay of the budget battles of the first session of the 112th Congress with slightly different actors.

Saturday, September 15, 2012

ICS-CERT Publishes IOServer Advisory


Yesterday the DHS ICS-CERT published an advisory about multiple file management vulnerabilities on the IOServer OPC Server. The vulnerabilities were first reported by Hinge of foofus.net (ICS-CERT did provide a link to the initial vulnerability report – finally).

The Official Word


The three listed vulnerabilities allow low-skilled attacker to remotely download files from the affected system. The vulnerabilities are:

• Insufficient access controls (CWE-219);

• Directory listing (CWE-538); and

• Directory traversal (CWE-22).

According to the Advisory, IOServer has produced a patch that resolves one of the three (Directory traversal) vulnerabilities and this has been verified by Hinge. Hinge (NOT IOServer) recommends using a trailing backslash on the ‘Root Directory’ configuration value to reduce the extent of the remaining vulnerabilities. There is no mention in the Advisory if/when IOServer will be correcting these vulnerabilities.

The Oddities


There are some odd things going on with this advisory. First off, since there was not an earlier alert, one would normally assume that this was a coordinated disclosure, but that is certainly not stated. In actuality, the original public disclosure that ICS-CERT provides the link to is dated August 17th, 2012 and there is nothing on that site that would imply a coordinated disclosure. Big question here is if it was a coordinated disclosure why did it take ICS-CERT almost a month to report this serious vulnerability (more on that later). If it wasn’t coordinated why wasn’t an alert issued a month ago?

Underplayed Vulnerability?


A quick reading of the Advisory leaves one with the impression that this is not a real big thing. After all it does not allow anyone to take control of the system or allow for the execution of arbitrary code; it just allows unauthorized people to read some files (all right the cognoscenti will go “Oh Sh*” to that). Reading the Hinge disclosure makes this sound much more interesting; describing it this way:

A directory traversal vulnerability exists such that the web server can be tricked to serve up any file on the server [emphasis added], outside of the configured “Root Directory”. On Windows, one common thing to do with an issue like this is to download the backup copy of the SAM, in order to retrieve password hashes and mount an offline attack on them. Any other potentially sensitive file on the server can be accessed this way as well, if the attacker knows the path to it”

The original disclosure goes on to describe the impact this way:

“Unexpected arbitrary access to the file system can lead to the disclosure of sensitive information. Worst case, disclosure of the system’s password hashes can lead to compromise of the passwords [emphasis added], and therefore, of the server.”

If you own the OPC Server, you have control of the ICS. So, is this a major vulnerability or what?

Friday, September 14, 2012

"Innocence of Muslims" and the NTAS


A reader of this blog and an important ICS security researcher, Joel Langill, has asked on TWITTER a number of times over the last 24 hours (the latest here) why DHS hasn’t posted an alert on the National Terrorism Advisory System (NTAS) as a result of the Joint Intelligence Bulletin (I can’t find a link to this oft reported Bulletin) from the FBI and DHS that warns faith-based organizations in the United States and U.S. embassies abroad that “the risk of violence could increase both at home and abroad as the film continues to gain attention.”  I tried last night, unsuccessfully, to explain in 140 characters why such an alert is ‘not appropriate under the NTAS’. Since DHS isn’t going to explain, I thought that I would try again in more detail.

The Old System


To fully understand the NTAS you have to first remember the problems we had with the old color-coded. The old system would describe the current state of alert based upon a vague definition of a threat. It provided no real guidance to the public other than to be vaguely ‘alert’ to unusual or suspicious activity. And it stayed at an ‘elevated’ level for so long that it was effectively ignored.

The NTAS


When DHS brought the new NTAS into operation in April of 2011 Secretary Napolitano assured the public that the new system would only be activated when there was a clear and specific threat to the public or a substantial portion of the public. She also promised that the alert would provide specific information to the public about what actions they should take. Finally, it was made clear that any alerts issued would be for a specific, limited time-frame associated with the specific threat.

The NTAS was immediately questioned just a couple of days after its establishment when no alert was issued after the assassination of Osama Bin Laden. I noted in a blog post at the time:

“Today, and for the last five days, we have been under a new National Terrorism Advisory System that requires that “NTAS Alerts will only be issued when credible information is available.” It is way too soon to have any ‘credible information’ available on an organized threat, and much of the unorganized threat will not be planned well enough for there to be much if any chance for the intelligence community to find any credible information.”

Surprisingly there was relatively little in the way of counter-attacks by al Qaeda after Bin Laden’s death; especially here in the United States. In hind sight DHS was absolutely correct that there wasn’t any need for issuing an NTAS alert. Besides, there was more than enough communications from DHS through the media that notified people of the possibility of terrorist actions and reminding them to report suspicious activity. No alert was justified or necessary.

Consulate Attack in Libya


There are certainly initial indications that the attack on the Consulate in Bengasi, Libya was probably a planned terrorist attack specifically targeting Ambassador Stevens. He was a locally popular figure who presented a good image of the United States to the Libyans. As such he was a threat to the success of radical Islamic forces in the area. It even looks like the demonstration outside of the Consulate may have been planned and fabricated as a cover for the attack.

That there might be similar attacks planned at other consulates in Muslim countries is entirely possible. One would like to think that the State Department is taking appropriate precautions. It is unlikely that such a complex attack, however, could be executed in the United States.

Potential for Homeland Attacks


It is clear from what we have heard of the FBI/DHS Joint Intelligence Bulletin, that neither agency has any actionable intelligence about specific related attacks in the United States. What they have announced is a standard warning that this video trailer is objectionable enough to Muslims that it would not be unexpected for it to be capable of being the final straw in the radicalization of some small number of individuals here in the United States; just as was the death of Bin Laden.

That one or more of these individuals could get excited enough in the short term to execute some sort of impromptu attack on perceived targets is always possible. Even though we are unlikely to catch these types of short term attacks before they occur, neither are they expected to be overly effective. Effective attacks take planning, weapon acquisition and training, and reconnaissance. These are the activities that suspicious activity reporting (SAR) is designed to detect; not public alerts.

Save the NTAS Alerts for Expected Attacks


The NTAS is designed to notify the public when the intelligence/law enforcement folks have detected an incipient attack and need the public to take specific measures to protect itself against the specific attack. The whole point of the NTAS alert is to be so rare as it captures the public’s attention and causes widespread compliance with the directives of the alert.

If we go back to the old color code standard of initiating active alerts every time that something occurs in the world that will stir up potential radicals, we will always be under alert without being provided specific protective actions. If and when either the Department or the FBI comes up with a specific credible threat of a terrorist attack, we need the NTAS to be an appropriate and watched notification system.

Thursday, September 13, 2012

S 3529 Introduced – Clean Air Act General Duty Clause


Earlier this week Sen. Roberts (R,KS) introduced S 3529, the General Duty Clarification Act of 2012. This is essentially a companion bill to HR 6345; a bill that was introduced by Rep. Pompeo (R,KS). As I noted in that earlier blog post, these bills are intended to make it more difficult for the EPA Administrator from using the General Duty clause of the Clean Air Act to require high-risk chemical facilities to use substitute chemicals or processes as has been suggested by many activists.

A companion bill allows both branches of Congress to work on the same bill at the same time to potentially reduce how long it will take it to complete the consideration process. I called this ‘essentially a companion bill’ because the language in the two bills is not strictly identical. There are two minor, non-substantive wording changes; one in §2(a)(1)(B)(i) (some wording is moved into two new subparagraphs) and the other in §2(b) (a descriptive phrase is moved to the end of the sentence). Neither change should have any impact on the progress of these two bills.

Neither of these bills will receive any consideration before the election. If Romney wins, there will be no need for these bills to be considered; he would never allow his EPA to enforce such an action. If Obama wins there will be an attempt to pass these bills in the lame duck session as his EPA might consider such an attempt in his second term. Or it might not, there is certainly a mixed environmental agenda in the Obama Administration.

The House could certainly pass HR 6345, but the Senate will never see either bill make it to consideration by the Committee on Environment and Public Works, much less than to the floor for a vote. All of that could, of course, change next session depending on the results of the election.

House Passes 6 Month CR


This evening the House passed HJ Res 117, the Continuing Appropriations Resolution, 2013 by a vote of 329 to 91. The vote was split in a unique bipartisan manner; about the same number of Democrats and Republicans voting for the measure and three times as many Republicans than Democrats voting against. It will be interesting to see if this type of voting pattern can be maintained in some of the crucial votes that will take part in the lame duck session.

The Senate will probably take up this bill next week. It looks like there should be enough votes to stop a filibuster if one is tried.

HJ Res 117 to be Considered Today


Last night the House Rules Committee met to formulate the rule for the consideration of HJ Res, 117, the Continuing Appropriations Resolution, 2013. As expected the rule is a closed rule providing for one-hour of debate and no amendments. According to the House Majority Leader’s web site, the CR will be considered today. There should be mixed bipartisan support (some opposition from both parties) for this bill and it should pass without any problem. The Senate would then probably take up the resolution next week, where it is expected to pass as well.

HSSTAC Meeting Announced


Today DHS announced in the Federal Register (77 FR 56662-56663) that the newly reconstituted Homeland Security Science and Technology Advisory Committee (HSSTAC) will be holding its first meeting on September 27th and 28th in Washington, DC. This public meeting will allow the Committee to establish its working priorities and organizational structure.

HSSTAC Purpose


This advisory committee was established to advise the DHS Under Secretary for Science and Technology on areas including:

• Systems engineering;

• Cybersecurity;

• Knowledge management; and

• How best to leverage related technologies funded by other federal agencies and by the private sector.

Agenda


The first day of the meeting will consist of briefings of the new committee by various organizations within the Department. On the second day the Committee will focus on:

• How technology can address homeland security challenges;

• Accelerating innovation through systems analysis; and

• Leveraging industry for impact

Based upon the briefings received, public input and Committee discussions Department officials will provide direction to the HSSTAC on their priorities and the establishment of sub-committees to address identified issues.

Public Participation


The public is invited to participate in these deliberations. Pre-registration to attend the meeting is required and may be accomplished on-line. There will be a public comment period on the second day of the meeting. Comments should be limited to 3 minutes and pre-registration of the intent to make a public comment is required; contact Mary Hanson, HSSTAC Executive Director. Written comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2012-0053).
 
/* Use this with templates/template-twocol.html */