John Bennett, author of the Maritime Security Blog, posted
a comment to my earlier
post on the Coast Guard’s meeting on FSO training. He noted that the link I
provided for registering for the meeting (link provided by CG’s meeting notice)
did not work. Fortunately, with his contacts in the CG, he was able to provide
a workable
link. He also noted that the Coast Guard will print a correction notice in
the Federal Register next week. Thanks for passing the word on, John.
Friday, October 12, 2012
Reader Comment – 10-12-12 - ICS-CERT as a Competitor
Dale Peterson of DigitalBond
repute (high repute in my mind, but Dale does have his detractors) left
a comment on today’s
post about the ICS-CERT Monthly Report. As is usual when he comments here,
he has a very interesting point made in few words. He notes (among other
things) that:
“The on-site assessments, like the
training, violate national labs rules. INL is not allowed to compete with
industry, but continues to do so. In fact they are stepping up their
competitive offerings. Maybe it is sour grapes as a competitor, but free and
promoted by DHS are two awfully big competitive advantages.”
My initial knee-jerk reaction is ‘Come on now, there has to
be more business than Dale and his not too numerous competitors can handle.’
After all there are way more ICS systems deployed than all of the researchers
(blackhat and whitehat alike) could ever get to in reasonable amount of time. A
little more thought, however, makes it clear that that is a specious argument at
best; not every ICS owner is going to get his system evaluated for security
problems. The reason is that there have been so few attacks to date (dare
someone to name off six deliberate hacks of an operating control system in the
wild) that most owners still don’t believe (and many with good reason) that
they will ever be the subject of a real attack.
Unfair Competition
Still, even with the limited number of owners actually
caring enough to get their systems evaluated, there should be enough work for
Dale and his for profit compatriots and still leave enough for ICS-CERT to give
away system reviews. But that will still contribute to fixing the continuing
problem of not enough ICS security researchers/fixers. We need lots of competition
to convince young’uns to take the hard courses in school to be able to fill the
need slots in government and private industry to deal with the security of
control systems. There aren’t many that will do that the hard work to just work
for the guvmint. They might be more interested if they made the big money like
Dale and got to travel the world. So let’s keep ICS-CERT from competing with
industry.
On the other hand…
I really do want the folks at ICS-CERT frequently getting
out into the real world and seeing what kinds of screwed up ICS systems are
actually deployed. It isn’t a Siemens/ABB/Schneider world out here. Actually it
isn’t an anything world out here, it’s an everything world; all sorts of bits
and pieces of multigenerational hardware and software cobbled together in a ‘whatever
it takes as long as it doesn’t cost too much’ world. The smaller and older the
operation the more cobbled it is.
Okay, let’s have the ICS-CERT guys start to work with the
other parts of DHS that deal with private sector security issues like CFATS,
MTSA, TSA, whatever. Let’s have them do control system security evaluations for
entities that are regulated under these programs as part of the regulation
process. These agencies don’t have the ICS security expertise to handle this
job in the first place, so they need the help. That’s an inherently
governmental function not one that takes work away from the private sector. And it would give the ICS-CERT people the hands on
experience with the various lash-ups found in the real world. And maybe they
can train the other security inspectors in some basics of control system
security.
BTW: Full Disclosure – I have written some blog posts for
Dale on cybersecurity legislation from time to time.
ICS-CERT Publishes Monthly Monitor
Yesterday the DHS ICS-CERT published the latest version of
their Monthly Monitor covering ICS security operations in August. This issue
includes a discussion of Shamoon, updated Smart Grid information and many of
the repeated features that readers have come to expect.
Delayed News
I have been a strong supporter of the Monthly Monitor from
the time that it was first issued, but it seems to me that it is becoming
increasingly ineffectual. Part of this is due to the delay in the information
presentation. Yesterday was the 11th day of the October and we are
just now receiving the September issue. Since there is no breaking news
included in this publication, that delay is troubling.
To make matters worse the information in this issue is
really from August. The only timely information comes on the ‘Upcoming Events’
page that lists cybersecurity events for October, November and December. Given
the fast moving pace of control system security information this delay in
presenting information is becoming increasingly irritating and is fast making
this publication irrelevant.
Too Vague
This problem is compounded by broad generalities that the
editors are forced to speak in when describing ICS-CERT actions in the field.
For example in regards to the five on-site assessments that ICS-CERT conducted
during August, the editors describe the findings this way:
“General findings included
interconnectivity to external networks that require defense-in-depth strategies
to protect them from cyber attacks.”
I understand that specifics cannot be made available because
of confidentiality agreements and such, but it would be nice to see some sort
of characterization of the kinds of interconnectivity (deliberately
established, inadvertently established by owner actions, or connections
established by programming/documentation errors made by the vendor for example)
or even a listing of what types of networks the control systems were connected
to (enterprise, security, internet, etc).
Without these types of more detailed information, this ‘ICS-CERT
Risk Evaluations’ report is little more than a ‘see what we did’ exercise and 5
on-site assessments in a month just doesn’t sound that impressive. Now if we
had been told that a typical assessment took three days on-site and three to four
ICS-CERT personnel took part in the average visit, I would be much more
impressed.
BTW: They missed the boat on this short report by not
informing us of how facility owners could request having ICS-CERT conducting
this type of risk evaluation at their site.
Coordinated Disclosures
I am happy to see that the editors continue to plug away at
getting security researchers to coordinate the disclosure of their
vulnerability discoveries. List the names of researchers working with ICS-CERT
on such matters certainly gives these folks some of the name recognition that
should come with this type of work.
What is unstated, but even more impressive is the increase
in the number of researchers so listed. The January 2012 issue listed 19
researchers and this issue lists 29. This is almost certainly a good thing for
the industry (though I’m not sure that the vendors would necessarily agree),
but it certainly is an important measure of how the interest in ICS security
matters is expanding in the ‘research community’; too bad there isn’t a similar
measure of the black-hat community interest.
BTW: No mention on ICS-CERT website yet about latest Gleg
release that I
mentioned Wednesday.
Thursday, October 11, 2012
No Personnel Surety Notice
Last
month I reported that Under Secretary Rand Beers told the Energy and the Economy Subcommittee of the House Energy
and Commerce Committee that the 60-day information collection request (ICR)
notice for the new CFATS personnel surety program would be published in the
Federal Register in 30 days. Well, today
is 30-days and there is no such notice in the Federal Register and there is no
indication that one will be published tomorrow.
This is just another incidence of Beers promising more than
his organization can produce. But then again, no one seriously expected
anything different.
PHMSA Pipeline Data Collection Meeting
The DOT Pipeline and Hazardous Material Safety Administration
(PHMSA) published a notice in today’s Federal Register (77 FR
61825-61826) announcing a 2-day public meeting conducted jointly with the National
Association of Pipeline Safety Representatives (NAPSR) on October 29th
and 30th, 2012 in Washington, D.C. The purpose of the meeting is to
discuss how pipeline data is currently used by stakeholders and identify
potential improvements in pipeline safety performance measures.
The objectives of the meeting are (77 FR 61826):
• Determine how stakeholders,
including PHMSA, industry, and the public use the data.
• Determine how industry and PHMSA
currently measure performance, how performance measures could be improved, and
what additional data is needed to do so.
• Determine the best method(s) for
collecting, analyzing, and ensuring transparency of additional data needed to
improve performance measures.
• Summarize the data PHMSA
currently collects, who we collect it from, and why we collect it.
• Discuss data quality improvement
including past efforts and future opportunities
Presentations at the meeting will be made by PHMSA, the
NTSB, NAPSR, the Pipeline Safety Trust and representatives of the pipeline
industry. The agenda
includes:
• PHMSA’s Data Vision
• Meaningful Performance Metrics –
Their Role and Value in Pipeline Safety
• Pipeline Safety Regulators Use of
Data
• Industry Use of Data
• Public Use of Data
• Pipeline Safety Regulator
Perspective on Improving Performance Measures
• Industry Perspective on Improving
Performance Measures
• How additional data best
collected, analyzed, and transparency ensured
The meeting web
page provides a link to an on-line registration site. There will be a web
cast of the meeting and connection details will be provided to registrants
indicating that they will attend ‘virtually’. There is nothing in this notice
that indicates that PHMSA is soliciting public comments on the topics being
addressed at the meeting.
CG Facility Security Officer Training Meeting
Today the Coast Guard published a notice in the Federal
Register (77 FR 61771-61772)
announcing a public meeting to obtain input on a draft model FSO training
course and other elements of the FSO training program. This training program
development was mandated by §821 the Coast Guard Authorization Act of 2010 (46
USC §70125).
The meeting will be held on November 9th, 2012 in
Washington, D.C. Seating is limited so advanced registration is required; register
on-line. As we have come to expect from the Coast Guard (again special
kudos) the meeting will be streamed live
on-line.
Copies of the draft model FSO training course will be
available on the Federal eRulemaking Portal (www.Regulations.gov; Docket # USCG-2012-0908)
and on the CG Homeport web site two
weeks before the scheduled meeting. The meeting will address the following topics
about the training program (77 FR 61772):
• Draft model FSO training course;
• Computer-based training and
distance learning;
• Provisional FSO certification;
• FSO continuing education;
• FSO refresher course;
• Interim policy to provide
curriculum guidelines for potential FSO training course providers.
Public comments will be solicited at the meeting and written
comments may be submitted to the docket on the Federal eRulemaking Portal
through November 23rd, 2012.
Wednesday, October 10, 2012
ICS-CERT Publishes Sinapsi Alert
This afternoon the DHS ICS-CERT published
an alert on an uncoordinated disclosure of multiple vulnerabilities in the Sinapsi
eSolar Light Photovoltaic System Monitor. The disclosure was made by Roberto
Paleari and Ivan Speziale, who
described the vulnerable system as being
the Schneider Electric Ezylog photovoltaic SCADA management server.
ICS-CERT notes that the Italian company produces the system that is used by
multiple vendors including Schneider Electric.
The multiple vulnerabilities reported were:
• Hard-coded Credentials
• SQL Injection
• Command Execution
• Broken Session
Enforcement
Tomorrow’s ICS-CERT Alerts?
Joel Langill reports
on his SCADAHacker Blog that Gleg has released SCADA+ Exploit Pack V 1.18 that
includes 0-day exploits for three separate SCADA systems; Elipse E3, Carel
PlantVisor, and QNX FTPD. Joel has a brief synopsis of the vulnerabilities. I
would expect for ICS-CERT to address these vulnerabilities tomorrow. I suspect
that these may be advisories instead of alerts; there were some TWEETS® sometime
last month about Gleg related releases on the secure US CERT server.
Subscribe to:
Posts (Atom)