Friday, October 12, 2012

Reader Comment – 10-12-12 – CG Meeting POC Change


John Bennett, author of the Maritime Security Blog, posted a comment to my earlier post on the Coast Guard’s meeting on FSO training. He noted that the link I provided for registering for the meeting (link provided by CG’s meeting notice) did not work. Fortunately, with his contacts in the CG, he was able to provide a workable link. He also noted that the Coast Guard will print a correction notice in the Federal Register next week. Thanks for passing the word on, John.

Reader Comment – 10-12-12 - ICS-CERT as a Competitor


Dale Peterson of DigitalBond repute (high repute in my mind, but Dale does have his detractors) left a comment on today’s post about the ICS-CERT Monthly Report. As is usual when he comments here, he has a very interesting point made in few words. He notes (among other things) that:

“The on-site assessments, like the training, violate national labs rules. INL is not allowed to compete with industry, but continues to do so. In fact they are stepping up their competitive offerings. Maybe it is sour grapes as a competitor, but free and promoted by DHS are two awfully big competitive advantages.”

My initial knee-jerk reaction is ‘Come on now, there has to be more business than Dale and his not too numerous competitors can handle.’ After all there are way more ICS systems deployed than all of the researchers (blackhat and whitehat alike) could ever get to in reasonable amount of time. A little more thought, however, makes it clear that that is a specious argument at best; not every ICS owner is going to get his system evaluated for security problems. The reason is that there have been so few attacks to date (dare someone to name off six deliberate hacks of an operating control system in the wild) that most owners still don’t believe (and many with good reason) that they will ever be the subject of a real attack.

Unfair Competition


Still, even with the limited number of owners actually caring enough to get their systems evaluated, there should be enough work for Dale and his for profit compatriots and still leave enough for ICS-CERT to give away system reviews. But that will still contribute to fixing the continuing problem of not enough ICS security researchers/fixers. We need lots of competition to convince young’uns to take the hard courses in school to be able to fill the need slots in government and private industry to deal with the security of control systems. There aren’t many that will do that the hard work to just work for the guvmint. They might be more interested if they made the big money like Dale and got to travel the world. So let’s keep ICS-CERT from competing with industry.

On the other hand…


I really do want the folks at ICS-CERT frequently getting out into the real world and seeing what kinds of screwed up ICS systems are actually deployed. It isn’t a Siemens/ABB/Schneider world out here. Actually it isn’t an anything world out here, it’s an everything world; all sorts of bits and pieces of multigenerational hardware and software cobbled together in a ‘whatever it takes as long as it doesn’t cost too much’ world. The smaller and older the operation the more cobbled it is.

Okay, let’s have the ICS-CERT guys start to work with the other parts of DHS that deal with private sector security issues like CFATS, MTSA, TSA, whatever. Let’s have them do control system security evaluations for entities that are regulated under these programs as part of the regulation process. These agencies don’t have the ICS security expertise to handle this job in the first place, so they need the help. That’s an inherently governmental function not one that takes work away from the private sector. And it would give the ICS-CERT people the hands on experience with the various lash-ups found in the real world. And maybe they can train the other security inspectors in some basics of control system security.

BTW: Full Disclosure – I have written some blog posts for Dale on cybersecurity legislation from time to time.

ICS-CERT Publishes Monthly Monitor


Yesterday the DHS ICS-CERT published the latest version of their Monthly Monitor covering ICS security operations in August. This issue includes a discussion of Shamoon, updated Smart Grid information and many of the repeated features that readers have come to expect.

Delayed News


I have been a strong supporter of the Monthly Monitor from the time that it was first issued, but it seems to me that it is becoming increasingly ineffectual. Part of this is due to the delay in the information presentation. Yesterday was the 11th day of the October and we are just now receiving the September issue. Since there is no breaking news included in this publication, that delay is troubling.

To make matters worse the information in this issue is really from August. The only timely information comes on the ‘Upcoming Events’ page that lists cybersecurity events for October, November and December. Given the fast moving pace of control system security information this delay in presenting information is becoming increasingly irritating and is fast making this publication irrelevant.

Too Vague


This problem is compounded by broad generalities that the editors are forced to speak in when describing ICS-CERT actions in the field. For example in regards to the five on-site assessments that ICS-CERT conducted during August, the editors describe the findings this way:

“General findings included interconnectivity to external networks that require defense-in-depth strategies to protect them from cyber attacks.”

I understand that specifics cannot be made available because of confidentiality agreements and such, but it would be nice to see some sort of characterization of the kinds of interconnectivity (deliberately established, inadvertently established by owner actions, or connections established by programming/documentation errors made by the vendor for example) or even a listing of what types of networks the control systems were connected to (enterprise, security, internet, etc).

Without these types of more detailed information, this ‘ICS-CERT Risk Evaluations’ report is little more than a ‘see what we did’ exercise and 5 on-site assessments in a month just doesn’t sound that impressive. Now if we had been told that a typical assessment took three days on-site and three to four ICS-CERT personnel took part in the average visit, I would be much more impressed.

BTW: They missed the boat on this short report by not informing us of how facility owners could request having ICS-CERT conducting this type of risk evaluation at their site.

Coordinated Disclosures


I am happy to see that the editors continue to plug away at getting security researchers to coordinate the disclosure of their vulnerability discoveries. List the names of researchers working with ICS-CERT on such matters certainly gives these folks some of the name recognition that should come with this type of work.

What is unstated, but even more impressive is the increase in the number of researchers so listed. The January 2012 issue listed 19 researchers and this issue lists 29. This is almost certainly a good thing for the industry (though I’m not sure that the vendors would necessarily agree), but it certainly is an important measure of how the interest in ICS security matters is expanding in the ‘research community’; too bad there isn’t a similar measure of the black-hat community interest.

 

BTW: No mention on ICS-CERT website yet about latest Gleg release that I mentioned Wednesday.

Thursday, October 11, 2012

No Personnel Surety Notice


Last month I reported that Under Secretary Rand Beers told the Energy and  the Economy Subcommittee of the House Energy and Commerce Committee that the 60-day information collection request (ICR) notice for the new CFATS personnel surety program would be published in the Federal Register in 30 days.  Well, today is 30-days and there is no such notice in the Federal Register and there is no indication that one will be published tomorrow.

This is just another incidence of Beers promising more than his organization can produce. But then again, no one seriously expected anything different.

PHMSA Pipeline Data Collection Meeting


The DOT Pipeline and Hazardous Material Safety Administration (PHMSA) published a notice in today’s Federal Register (77 FR 61825-61826) announcing a 2-day public meeting conducted jointly with the National Association of Pipeline Safety Representatives (NAPSR) on October 29th and 30th, 2012 in Washington, D.C. The purpose of the meeting is to discuss how pipeline data is currently used by stakeholders and identify potential improvements in pipeline safety performance measures.

The objectives of the meeting are (77 FR 61826):

• Determine how stakeholders, including PHMSA, industry, and the public use the data.

• Determine how industry and PHMSA currently measure performance, how performance measures could be improved, and what additional data is needed to do so.

• Determine the best method(s) for collecting, analyzing, and ensuring transparency of additional data needed to improve performance measures.

• Summarize the data PHMSA currently collects, who we collect it from, and why we collect it.

• Discuss data quality improvement including past efforts and future opportunities

Presentations at the meeting will be made by PHMSA, the NTSB, NAPSR, the Pipeline Safety Trust and representatives of the pipeline industry. The agenda includes:

• PHMSA’s Data Vision

• Meaningful Performance Metrics – Their Role and Value in Pipeline Safety

• Pipeline Safety Regulators Use of Data

• Industry Use of Data

• Public Use of Data

• Pipeline Safety Regulator Perspective on Improving Performance Measures

• Industry Perspective on Improving Performance Measures

• How additional data best collected, analyzed, and transparency ensured

The meeting web page provides a link to an on-line registration site. There will be a web cast of the meeting and connection details will be provided to registrants indicating that they will attend ‘virtually’. There is nothing in this notice that indicates that PHMSA is soliciting public comments on the topics being addressed at the meeting.

CG Facility Security Officer Training Meeting


Today the Coast Guard published a notice in the Federal Register (77 FR 61771-61772) announcing a public meeting to obtain input on a draft model FSO training course and other elements of the FSO training program. This training program development was mandated by §821 the Coast Guard Authorization Act of 2010 (46 USC §70125).

The meeting will be held on November 9th, 2012 in Washington, D.C. Seating is limited so advanced registration is required; register on-line. As we have come to expect from the Coast Guard (again special kudos) the meeting will be streamed live on-line.

Copies of the draft model FSO training course will be available on the Federal eRulemaking Portal (www.Regulations.gov; Docket # USCG-2012-0908) and on the CG Homeport web site two weeks before the scheduled meeting. The meeting will address the following topics about the training program (77 FR 61772):

• Draft model FSO training course;

• Computer-based training and distance learning;

• Provisional FSO certification;

• FSO continuing education;

• FSO refresher course;

• Interim policy to provide curriculum guidelines for potential FSO training course providers.

Public comments will be solicited at the meeting and written comments may be submitted to the docket on the Federal eRulemaking Portal through November 23rd, 2012.

Wednesday, October 10, 2012

ICS-CERT Publishes Sinapsi Alert


This afternoon the DHS ICS-CERT published an alert on an uncoordinated disclosure of multiple vulnerabilities in the Sinapsi eSolar Light Photovoltaic System Monitor. The disclosure was made by Roberto Paleari and Ivan Speziale, who described the vulnerable system as being  the Schneider Electric Ezylog photovoltaic SCADA management server. ICS-CERT notes that the Italian company produces the system that is used by multiple vendors including Schneider Electric.

The multiple vulnerabilities reported were:

• Hard-coded Credentials

• SQL Injection

• Command Execution

• Broken Session Enforcement

Tomorrow’s ICS-CERT Alerts?


Joel Langill reports on his SCADAHacker Blog that Gleg has released SCADA+ Exploit Pack V 1.18 that includes 0-day exploits for three separate SCADA systems; Elipse E3, Carel PlantVisor, and QNX FTPD. Joel has a brief synopsis of the vulnerabilities. I would expect for ICS-CERT to address these vulnerabilities tomorrow. I suspect that these may be advisories instead of alerts; there were some TWEETS® sometime last month about Gleg related releases on the secure US CERT server.
 
/* Use this with templates/template-twocol.html */