Friday, December 21, 2012

Senate Accepts Conference Report on HR 4310


This afternoon the Senate accepted the Conference Report on HR 4310 by a roll-call vote of 81 to 14. The ‘Nays’ were about equally divided between Republicans and Democrats. The National Defense Authorization Act FY 2013 with its cybersecurity provisions now goes to the President for signature.

New Private Sector Resources Catalog


I got an email from DHS Assistant Secretary Douglas A. Smith this morning (actually it was from GovDelivery.com an organization that provides update notification services for select government web sites) announcing the publication of the latest version of the DHS Private Sector Resources Catalog. As I have mentioned on a number of occasions, this web based document provides a list of publicly available resources available from DHS concerning the wide variety of programs administered by that Department.

The 91 page .PDF document can be downloaded in whole or part. Personally, since I don’t have much to do with border enforcement or immigration issues, I prefer to download just those sections that specifically address programs of interest to me. Those include:




There is also an appendix that lists key points of contact within the Department and another that provides a subject index to the entire publication. Back in May I noted that the subject index would be more helpful if it included links to the appropriate section of the Catalog, but that change has not been made.

Because of the re-arrangement of the Departments on-line presence earlier this year this update is even more valuable than previous versions. Unfortunately many of the earlier web sites seem to have disappeared and there are even more programs that require emailing someone at DHS to obtain the necessary information. I have always found these emails to be answered relatively promptly, but there is a delay that cannot be avoided. Again, I urge the Department to put more of the program information documents live on their web site so that people can get them in a timely manner.

Even with these minor complaints, I really do appreciate DHS taking the initiative to publish and periodically update this resource. It is a valuable service to the country.

House Accepts HR 4310 Conference Report


As expected the House voted yesterday along generally bipartisan lines to agree to the Conference Report on HR 4310, the National Defense Authorization Act FY 2013. The vote was 315 to 107 with 30 Republicans and 77 Democrats voting against the measure.

A unanimous consent agreement was reached in the Senate for consideration of the Conference Report, probably sometime today. There will be one hour of debate and a vote on the measure.

As I noted in an earlier blog post there are a number of cyber related provisions included in the final version of the bill including requirements for defense contractors to report cyber-breaches and provisions for secure development requirements for defense software.

PHMSA Publishes MAOP Reporting Advisory


Today PHMSA published an Advisory Bulletin in the Federal Register (77 FR 75699-75700) concerning the requirements for reporting when gas transmission pipelines exceed their maximum allowable pressure (MAOP). PHMSA cites 49 USC §60139 as the legal basis for this requirement. Citing statute rather than regulation implies that the PHMSA regulations have not yet caught up with Congressional action on this matter.

PHMSA notes that legislation signed by President Obama in January of this year adds the following requirements for pipeline safety reporting:

“EXCEEDANCES OF MAXIMUM ALLOWABLE OPERATING PRESSURE.—If there is an exceedance of the maximum allowable operating pressure with respect to a gas transmission pipeline of an owner or operator of a pipeline facility that exceeds the build-up allowed for operation of pressure-limiting or control devices, the owner or operator shall report the exceedance to the Secretary and appropriate State authorities on or before the 5th day following the date on which the exceedance occurs.” §60139(b)(2)

PHMSA expects to receive the same information on these reports as required for safety-related condition reports (SRCR) required under 49 CFR §191.25(b). But PHMSA reminds owner/operators that the reporting exceptions allowed under §191.23(b) do not apply to this reporting requirement. The report should be titled “Gas Transmission MAOP Exceedance” and contain the following information:

• The name and principal address of the operator, date of the report, name, job title, and business telephone number of the person submitting the report.

• The name, job title, and business telephone number of the person who determined the condition exists.

• The date the condition was discovered and the date the condition was first determined to exist.

• The location of the condition, with reference to the town/city/county and state or offshore site, and as appropriate, nearest street address, offshore platform, survey station number, milepost, landmark, and the name of the commodity transported or stored.

• The corrective action taken before the report was submitted and the planned follow-up or future corrective action, including the anticipated schedule for starting and concluding such action.

The reports can be filed in the same was as SRCRs {§191.25(a)}, but may also be filed by email (InformationResourcesManager@dot.gov). PHMSA notes that there is a rulemaking in progress that would allow the email submission of SRCRs as well.

Thursday, December 20, 2012

ICS Security Legislation


With the first day of the new Congress fast approaching, it is probably a good idea to start to look at what would make good cybersecurity legislation for protecting control systems. Let’s first start by looking at an overview of what the legislation should address. In subsequent posts I’ll try to address some of the details.

IT vs ICS


The first thing we need to do is to separate the two different types of cyber systems. Even a cursory look at the debates that scuttled effective cybersecurity legislation in the 112th Congress shows that concerns with irrelevancies like personal identity protection and freedom of speech had as much to do with stopping cybersecurity legislation as did concerns about regulatory costs. If we separate the ICS security issues from the IT security issues, many of those irrelevancies will disappear and make a serious discussion easier to have.

This is going to require a legal definition of a control system. From a legislative point of view we probably need to start out with as wide a definition as possible using other concerns to narrow down the coverage of the legislation. This would make it easier to expand coverage as new cyber-threats become more apparent.

I’ll start with the following definition;

Control System – A computer system that utilizes a combination of software, processors, memory, sensors and devices to control the operations of physical processes.

This definition is wide enough to include classic industrial control systems as well as physical security systems, transportation systems and medical systems.

Critical Infrastructure


While it could certainly be argued that there are legitimate reasons that the security of every control system should be protected, the Federal government does not have the resources to effectively manage the security of all control systems. At the most basic level the owner of a control system has the inherent responsibility to protect that system from outside manipulation. The only time that the Federal government has a real interest in regulating the security of control systems is when unauthorized changes to a system would have a significant impact on the larger society. The term most often used to describe such facilities is ‘critical infrastructure’.

There have been a number of different definitions used over the years since the 2001 terrorist attacks on New York and Washington to describe which portions of the infrastructure of the country were so critical to the security of the homeland that they were worthy of regulation by the Federal government. All of the legislative definitions have one thing in common; they are all rather vague and provide authority to a high-level member of the executive branch, normally the DHS Secretary, to provide a more useful definition by regulation. The reason is that regulatory process is much more flexible than the legislative process in adapting to changing conditions.

Notice that I am changing Critical Infrastructure to Critical Control Systems, but keeping with that tradition we can use the following definition:

Critical Control System – Any control system that if disrupted could have a significant impact on the security of the United States, the economic stability of the country or its major subdivisions, or the continuing life and/or health of significant portions of the population.

The major difference between this definition and the ones used by other pieces of legislation is that it substitutes the term ‘control system’ for ‘facility’. The point of this is that it is not the entire facility that is being regulated but the control systems within the facility. Regulations will still have to establish what constitutes ‘significant impact’, ‘economic stability’ and ‘significant portions’.

Regulators


There has been a great deal of discussion about which agency or organization within the Federal government should be given the responsibility for regulating cybersecurity. The arguments frequently revolve around who has the technical expertise to oversee the regulatory process. While the NSA certainly has more technical expertise in cyber-systems and their security than just about anyone else in the government, if that level of expertise is required for this regulatory program then we might as well give up now as there will not be enough qualified personnel in industry to implement the security measures.

Besides, NSA has no experience in writing regulations for industry, establishing regulatory regimes or conducting inspections. None of that is rocket science but it does require a certain set of skills and experience that would be in short supply in a technical organization like NSA.

No the organization that has the appropriate level of technical expertise and regulatory experience is the NPPD organization at DHS. The ICS-CERT folks reside within that organization to provide the technical expertise and there is some level of experience with setting up a regulatory agency within that Directorate.

What to Regulate


I was taught in the Army a very basic principle; the infamous KISS principle, Keep It Simple Stupid. The control system environment is too complex and too changeable to apply any other management principle to the situation. So let’s try to apply that here.

First we need to establish a requirement to fully describe the critical control system. This would be a simple list of all of the equipment, communications and software that makes up the system. This would be used by ICS-CERT to make notifications to system owners when they discover or are made aware of a vulnerability within a system.

Second there would be a requirement to list all of the available communications modes on the system and a requirement to establish some measure of control over access to those communications. As ICS-CERT became aware of undocumented communications modes they would notify system owners so that those modes could also be protected.

Third there would be a requirement for a personnel surety program. There could be different levels of background checks required for different levels of access to the system with administrator level access requiring full criminal background checks and vetting against the Terrorist Screening Database (TSDB).

Finally, owners of critical control systems need to be required to report any suspected breach of the control system with provisions made for forensics analysis support by DHS.

Other Bells and Whistles


There are a number of other things that should be covered in this legislation. Things like research programs, as well as training and certification programs. There should be some sort of incentive program for reporting vulnerabilities to ICS-CERT and some sort of vulnerability response requirements for vendors. There should also be some sort of incentive program for vendors to improve the security of existing products and to develop products that are basically more securable.

ICS-CERT Closes-out Two Alerts


Today the folks at DHS ICS-CERT published two advisories for different systems that were based upon uncoordinated disclosures reported earlier by ICS-CERT. Actually ICS-CERT only notes that one is based upon an earlier alert, but records show that both were. The affected systems are from RuggecCom and Carlo Gavazzi Automation.

RuggedCom Advisory


This advisory is based upon Key Management Errors originally reported by Justin W. Clarke of Cylance Inc and the ICS-CERT Alert was published in August and updated later that month. According to this Advisory a moderately skilled attacker could use the publicly available exploit “to establish a secure communication link with RuggedCom network devices and manipulate settings that would result in a denial of service condition”. Why that would only allow a ‘DOS condition’ is not made clear.

RuggedCom has developed a number of device specific mitigations for this vulnerability, ranging from an update for ROS devices, to a recommendation to update SSL and SSH keys for ROX devices. The situation for RUGGEDMAX devices appears to be more complicated because there is one solution for SSH service and a temporary solution for HTTPS access; the last doesn’t sound encouraging.

Carlo Gavazzi Automation Advisory


This advisory seems to me to be clearly based upon an alert issued in October for the Sinapsi eSolar Light Photovoltaic System Monitor. That alert clearly notes that the Gavazzi EOS box is one of the names under which the Sinapsi product was sold. This advisory does not mention the earlier alert and it only addresses two of the vulnerabilities (hard-coded credentials and SQL injection) addressed in that earlier alert. If the earlier alert does not in fact apply to the EOS box, ICS-CERT should revise the earlier alert to reflect that fact.

The advisory notes that a relatively unskilled attacker could use the publicly available exploit code (another reason to believe the alert should have been referenced) to remotely gain administrative access and control of the system (credential vuln) or gain access to information about the system (SQL vuln). Carlo Gazazzi has developed an updated firmware version to mitigate these vulnerabilities and has released the new firmware ‘directly to the devices’. Interestingly that is just what Sinapsi did almost a month earlier to their devices affected by the same vulnerabilities. As I have mentioned in the past, I thing that the ability of the manufacturer to release the firmware updates directly to the devices is a vulnerability in and of itself, even if it is not misused.

Two questions remain unanswered; what happened to the other two vulnerabilities mentioned in the original alert (and the Sinapsi advisory) and when will we see the advisories for the other manufacturers listed in the original alert?

Wednesday, December 19, 2012

House Passes HR 6672 – Emergency Response


Today the House passed HR 6672, the Pandemic and All-Hazards Preparedness Reauthorization Act of 2012, by a bipartisan vote (383-16) that matched the bipartisan sponsorship of the bill. In fact, according to a press release from Rep. Rogers (R,MI) it was “developed after months of work and careful deliberation between leaders in the two chambers [House and Senate]”.

Chemical Facility Coverage


Most of the bill is outside of the coverage of this blog as it deals with public health matters. Updating and reauthorizing programs associated with the Public Health Service Act. It does, however, have specific applications to chemical security and safety programs in that it modifies that Act to expand pandemic response “to advance countermeasures to diagnose, mitigate, prevent, or treat harm from any biological agent or toxin, chemical, radiological, or nuclear agent or agents, whether naturally occurring, unintentional, or deliberate” {§101(a)(2) added (7)(A) to 42 USC 300hh-1}. This could be used to expand the medical response capability to large scale chemical accidents or terrorist attacks on chemical facilities.

Additionally the bill would help to “identify and prioritize near-, mid-, and long-term needs with respect to such countermeasures or products to address a chemical, biological, radiological, and nuclear threat or threats” {§102(a) added (d)(2)(C) to 42 USC 300hh-10}.

While this bill may be of strategic assistance to emergency response planners it misses, as do all of these types of bills, the tactical connection that would allow the measures to become useful at the community level. As long as there is not a requirement for fixed facilities with large quantities of toxic inhalation chemicals or other chemicals with acute medical hazards to report those chemicals to local medical treatment facilities there will be not be prepared to treat large numbers of casualties from accidental or deliberate catastrophic releases.

Last Minute Politics


This bill was introduced on Monday by Rogers, et al, and was brought to the floor today under suspension of the rules before the GPO even had a copy of the bill printed (the link in the first paragraph goes to a Committee Print). It is extremely odd that this bill would take so long into the session to get to the House floor, especially with the backing it has received.

Given the fast action in the House, the bipartisan support, and the reported fact that House and Senate leaders worked together on putting this bill together, I expect that this bill will be considered in the Senate tomorrow and will pass under unanimous consent.

Possible Thorn in Passage


This is kind of a stretch, but for bills to pass by ‘unanimous consent’ they have to be relatively free of controversy. This bill seems like it fits the bill until one gets down to page 70 of the Committee print. There the bill (§304) is amending the Federal Food, Drug, and Cosmetic Act, 21 USC 360bbb-4, by adding paragraph (c) Final Guidance on Development of Animal Models.

If PETA or other animal rights or anti-vivisection people were to discover this provision, they might be able to raise enough controversy to stop the Senate from passing this bill this week or this year. Come to think of it, that may be why this is coming on so fast and furious when no one is watching the small things in Congress.
 
/* Use this with templates/template-twocol.html */