This afternoon the Senate accepted the Conference Report on
HR 4310 by a roll-call
vote of 81 to 14. The ‘Nays’ were about equally divided between Republicans
and Democrats. The National Defense Authorization Act FY 2013 with its cybersecurity
provisions now goes to the President for signature.
Friday, December 21, 2012
New Private Sector Resources Catalog
I got an email from DHS Assistant Secretary Douglas A. Smith
this morning (actually it was from GovDelivery.com an organization that
provides update notification services for select government web sites) announcing
the publication of the latest version of the DHS Private Sector
Resources Catalog. As I have mentioned on a number of occasions, this web
based document provides a list of publicly available resources available from
DHS concerning the wide variety of programs administered by that Department.
The 91 page .PDF document can be downloaded in whole or
part. Personally, since I don’t have much to do with border enforcement or
immigration issues, I prefer to download just those sections that specifically
address programs of interest to me. Those include:
There is also an appendix that lists key
points of contact within the Department and another that provides a
subject index to the entire publication. Back in May I
noted that the subject index would be more helpful if it included links to
the appropriate section of the Catalog, but that change has not been made.
Because of the re-arrangement of the Departments on-line
presence earlier this year this update is even more valuable than previous
versions. Unfortunately many of the earlier web sites seem to have disappeared
and there are even more programs that require emailing someone at DHS to obtain
the necessary information. I have always found these emails to be answered
relatively promptly, but there is a delay that cannot be avoided. Again, I urge
the Department to put more of the program information documents live on their
web site so that people can get them in a timely manner.
Even with these minor complaints, I really do appreciate DHS
taking the initiative to publish and periodically update this resource. It is a
valuable service to the country.
House Accepts HR 4310 Conference Report
As expected the House voted yesterday along generally
bipartisan lines to agree to the Conference Report on HR 4310, the National
Defense Authorization Act FY 2013. The vote
was 315 to 107 with 30 Republicans and 77 Democrats voting against the
measure.
A unanimous consent agreement was reached in the Senate for
consideration of the Conference Report, probably sometime today. There will be
one hour of debate and a vote on the measure.
As I noted in an earlier
blog post there are a number of cyber related provisions included in the
final version of the bill including requirements for defense contractors to
report cyber-breaches and provisions for secure development requirements for
defense software.
PHMSA Publishes MAOP Reporting Advisory
Today PHMSA published an Advisory Bulletin in the Federal
Register (77 FR 75699-75700)
concerning the requirements for reporting when gas transmission pipelines exceed
their maximum allowable pressure (MAOP). PHMSA cites 49
USC §60139 as the legal basis for this requirement. Citing statute rather
than regulation implies that the PHMSA regulations have not yet caught up with
Congressional action on this matter.
PHMSA notes that legislation signed by President Obama in
January of this year adds the following requirements for pipeline safety
reporting:
“EXCEEDANCES OF MAXIMUM ALLOWABLE
OPERATING PRESSURE.—If there is an exceedance of the maximum allowable
operating pressure with respect to a gas transmission pipeline of an owner or
operator of a pipeline facility that exceeds the build-up allowed for operation
of pressure-limiting or control devices, the owner or operator shall report the
exceedance to the Secretary and appropriate State authorities on or before the
5th day following the date on which the exceedance occurs.” §60139(b)(2)
PHMSA expects to receive the same information on these reports
as required for safety-related condition reports (SRCR) required under 49 CFR §191.25(b).
But PHMSA reminds owner/operators that the reporting exceptions allowed under §191.23(b)
do not apply to this reporting requirement. The report should be titled “Gas Transmission MAOP Exceedance” and contain the
following information:
• The name and principal address of
the operator, date of the report, name, job title, and business telephone
number of the person submitting the report.
• The name, job title, and business
telephone number of the person who determined the condition exists.
• The date the condition was
discovered and the date the condition was first determined to exist.
• The location of the condition,
with reference to the town/city/county and state or offshore site, and as
appropriate, nearest street address, offshore platform, survey station number,
milepost, landmark, and the name of the commodity transported or stored.
• The corrective action taken before
the report was submitted and the planned follow-up or future corrective action,
including the anticipated schedule for starting and concluding such action.
The reports can be filed in the same was as SRCRs {§191.25(a)},
but may also be filed by email (InformationResourcesManager@dot.gov).
PHMSA notes that there is a rulemaking in progress that would allow the email
submission of SRCRs as well.
Thursday, December 20, 2012
ICS Security Legislation
With the first day of the new Congress fast approaching, it
is probably a good idea to start to look at what would make good cybersecurity
legislation for protecting control systems. Let’s first start by looking at an
overview of what the legislation should address. In subsequent posts I’ll try to
address some of the details.
IT vs ICS
The first thing we need to do is to separate the two
different types of cyber systems. Even a cursory look at the debates that scuttled
effective cybersecurity legislation in the 112th Congress shows that
concerns with irrelevancies like personal identity protection and freedom of
speech had as much to do with stopping cybersecurity legislation as did
concerns about regulatory costs. If we separate the ICS security issues from
the IT security issues, many of those irrelevancies will disappear and make a
serious discussion easier to have.
This is going to require a legal definition of a control
system. From a legislative point of view we probably need to start out with as
wide a definition as possible using other concerns to narrow down the coverage
of the legislation. This would make it easier to expand coverage as new cyber-threats
become more apparent.
I’ll start with the following definition;
Control System – A computer system
that utilizes a combination of software, processors, memory, sensors and
devices to control the operations of physical processes.
This definition is wide enough to include classic industrial
control systems as well as physical security systems, transportation systems
and medical systems.
Critical Infrastructure
While it could certainly be argued that there are legitimate
reasons that the security of every control system should be protected, the
Federal government does not have the resources to effectively manage the
security of all control systems. At the most basic level the owner of a control
system has the inherent responsibility to protect that system from outside
manipulation. The only time that the Federal government has a real interest in
regulating the security of control systems is when unauthorized changes to a
system would have a significant impact on the larger society. The term most
often used to describe such facilities is ‘critical infrastructure’.
There have been a number of different definitions used over
the years since the 2001 terrorist attacks on New York and Washington to
describe which portions of the infrastructure of the country were so critical
to the security of the homeland that they were worthy of regulation by the
Federal government. All of the legislative definitions have one thing in
common; they are all rather vague and provide authority to a high-level member
of the executive branch, normally the DHS Secretary, to provide a more useful
definition by regulation. The reason is that regulatory process is much more
flexible than the legislative process in adapting to changing conditions.
Notice that I am changing Critical Infrastructure to
Critical Control Systems, but keeping with that tradition we can use the following
definition:
Critical Control System – Any control
system that if disrupted could have a significant impact on the security of the
United States, the economic stability of the country or its major subdivisions,
or the continuing life and/or health of significant portions of the population.
The major difference between this definition and the ones
used by other pieces of legislation is that it substitutes the term ‘control
system’ for ‘facility’. The point of this is that it is not the entire facility
that is being regulated but the control systems within the facility.
Regulations will still have to establish what constitutes ‘significant impact’,
‘economic stability’ and ‘significant portions’.
Regulators
There has been a great deal of discussion about which agency
or organization within the Federal government should be given the responsibility
for regulating cybersecurity. The arguments frequently revolve around who has
the technical expertise to oversee the regulatory process. While the NSA
certainly has more technical expertise in cyber-systems and their security than
just about anyone else in the government, if that level of expertise is
required for this regulatory program then we might as well give up now as there
will not be enough qualified personnel in industry to implement the security
measures.
Besides, NSA has no experience in writing regulations for
industry, establishing regulatory regimes or conducting inspections. None of
that is rocket science but it does require a certain set of skills and
experience that would be in short supply in a technical organization like NSA.
No the organization that has the appropriate level of
technical expertise and regulatory experience is the NPPD organization at DHS.
The ICS-CERT folks reside within that organization to provide the technical
expertise and there is some level of experience with setting up a regulatory agency
within that Directorate.
What to Regulate
I was taught in the Army a very basic principle; the infamous
KISS principle, Keep It Simple Stupid. The control system environment is too
complex and too changeable to apply any other management principle to the
situation. So let’s try to apply that here.
First we need to establish a requirement to fully describe
the critical control system. This would be a simple list of all of the
equipment, communications and software that makes up the system. This would be
used by ICS-CERT to make notifications to system owners when they discover or
are made aware of a vulnerability within a system.
Second there would be a requirement to list all of the
available communications modes on the system and a requirement to establish
some measure of control over access to those communications. As ICS-CERT became
aware of undocumented communications modes they would notify system owners so
that those modes could also be protected.
Third there would be a requirement for a personnel surety
program. There could be different levels of background checks required for
different levels of access to the system with administrator level access
requiring full criminal background checks and vetting against the Terrorist
Screening Database (TSDB).
Finally, owners of critical control systems need to be
required to report any suspected breach of the control system with provisions
made for forensics analysis support by DHS.
Other Bells and Whistles
There are a number of other things that should be covered in this legislation. Things like research programs, as well as training and certification programs. There should be some sort of incentive program for reporting vulnerabilities to ICS-CERT and some sort of vulnerability response requirements for vendors. There should also be some sort of incentive program for vendors to improve the security of existing products and to develop products that are basically more securable.
ICS-CERT Closes-out Two Alerts
Today the folks at DHS ICS-CERT published two advisories for
different systems that were based upon uncoordinated disclosures reported
earlier by ICS-CERT. Actually ICS-CERT only notes that one is based upon an
earlier alert, but records show that both were. The affected systems are from
RuggecCom and Carlo Gavazzi Automation.
RuggedCom Advisory
This
advisory is based upon Key Management Errors originally reported by Justin
W. Clarke of Cylance Inc and the ICS-CERT Alert was published
in August and updated
later that month. According to this Advisory a moderately skilled attacker
could use the publicly available exploit “to establish a secure communication
link with RuggedCom network devices and manipulate settings that would result
in a denial of service condition”. Why that would only allow a ‘DOS condition’
is not made clear.
RuggedCom has developed a number of device specific
mitigations for this vulnerability, ranging from an update for ROS devices, to
a recommendation to update SSL and SSH keys for ROX devices. The situation for
RUGGEDMAX devices appears to be more complicated because there is one solution
for SSH service and a temporary solution for HTTPS access; the last doesn’t
sound encouraging.
Carlo Gavazzi Automation Advisory
This advisory
seems to me to be clearly based upon an alert issued
in October for the Sinapsi eSolar Light Photovoltaic System Monitor. That
alert clearly notes that the Gavazzi EOS box is one of the names under
which the Sinapsi product was sold. This advisory does not mention the earlier
alert and it only addresses two of the vulnerabilities (hard-coded credentials
and SQL injection) addressed in that earlier alert. If the earlier alert does
not in fact apply to the EOS box, ICS-CERT should revise the earlier alert to
reflect that fact.
The advisory notes that a relatively unskilled attacker
could use the publicly available exploit code (another reason to believe the
alert should have been referenced) to remotely gain administrative access and
control of the system (credential vuln) or gain access to information about the
system (SQL vuln). Carlo Gazazzi has developed an updated firmware version to
mitigate these vulnerabilities and has released the new firmware ‘directly to
the devices’. Interestingly that is just what Sinapsi did almost a month
earlier to their devices affected by the same vulnerabilities. As I have
mentioned in the past, I thing that the ability of the manufacturer to release
the firmware updates directly to the devices is a vulnerability in and of
itself, even if it is not misused.
Two questions remain unanswered; what happened to the other
two vulnerabilities mentioned in the original alert (and the Sinapsi advisory) and
when will we see the advisories for the other manufacturers listed in the
original alert?
Wednesday, December 19, 2012
House Passes HR 6672 – Emergency Response
Today the House passed HR
6672, the Pandemic and All-Hazards Preparedness Reauthorization Act of 2012,
by a bipartisan vote (383-16)
that matched the bipartisan sponsorship of the bill. In fact, according to a press
release from Rep. Rogers (R,MI) it was “developed after months of work and
careful deliberation between leaders in the two chambers [House and Senate]”.
Chemical Facility Coverage
Most of the bill is outside of the coverage of this blog as
it deals with public health matters. Updating and reauthorizing programs
associated with the Public Health Service Act. It does, however, have specific
applications to chemical security and safety programs in that it modifies that
Act to expand pandemic response “to advance countermeasures to diagnose,
mitigate, prevent, or treat harm from any biological agent or toxin, chemical,
radiological, or nuclear agent or agents, whether naturally occurring, unintentional,
or deliberate” {§101(a)(2) added (7)(A) to 42
USC 300hh-1}. This could be used to expand the medical response capability
to large scale chemical accidents or terrorist attacks on chemical facilities.
Additionally the bill would help to “identify and prioritize
near-, mid-, and long-term needs with respect to such countermeasures or
products to address a chemical, biological, radiological, and nuclear threat or
threats” {§102(a) added (d)(2)(C) to 42
USC 300hh-10}.
While this bill may be of strategic assistance to emergency
response planners it misses, as do all of these types of bills, the tactical
connection that would allow the measures to become useful at the community
level. As long as there is not a requirement for fixed facilities with large
quantities of toxic inhalation chemicals or other chemicals with acute medical
hazards to report those chemicals to local medical treatment facilities there
will be not be prepared to treat large numbers of casualties from accidental or
deliberate catastrophic releases.
Last Minute Politics
This bill was introduced on Monday by Rogers, et al, and was
brought to the floor today under suspension of the rules before the GPO even
had a copy of the bill printed (the link in the first paragraph goes to a
Committee Print). It is extremely odd that this bill would take so long into
the session to get to the House floor, especially with the backing it has received.
Given the fast action in the House, the bipartisan support,
and the reported fact that House and Senate leaders worked together on putting
this bill together, I expect that this bill will be considered in the Senate
tomorrow and will pass under unanimous consent.
Possible Thorn in Passage
This is kind of a stretch, but for bills to pass by ‘unanimous
consent’ they have to be relatively free of controversy. This bill seems like
it fits the bill until one gets down to page 70 of the Committee print. There
the bill (§304) is amending the Federal Food, Drug, and Cosmetic Act, 21
USC 360bbb-4, by adding paragraph (c) Final Guidance on Development of Animal
Models.
If PETA or other animal rights or anti-vivisection people
were to discover this provision, they might be able to raise enough controversy
to stop the Senate from passing this bill this week or this year. Come to think
of it, that may be why this is coming on so fast and furious when no one is
watching the small things in Congress.
Subscribe to:
Posts (Atom)