Tuesday, July 21, 2015

Reader Comment – HR 3039

I received an interesting comment from an anonymous reader yesterday about my post on the introduction of HR 3039; well worth reading in its entirety. In passing a comment was made about the “need to be intentionally vague in order to avoid loopholes and military redtape”. Other than having a minor objection to the use of ‘military’ instead of ‘bureaucratic’ as a modifier of ‘red-tape’, I think Anonymous has an interesting point.

In my post I complained about the lack of definition of ‘malicious cyber-enabled activity’ as that definition was key to deciding what countries would/should be included on the list of State Sponsors of Cyberattacks. Lacking a legal definition the President would be given a great deal of leeway as to which countries should be placed on the list.

Anonymous points out that, given recent events, the bill was probably intended to target China and Iran. In fact a press release from the office of Rep. Brooks (R,AL - the bill’s author) specifically mentions reported attacks by China, Iran and North Korea as examples of recent attacks to which the US has not been able to respond.

Now, I am glad that the bill did not specifically mention those three countries (especially since I have not seen compelling evidence that the DPRK was behind the Sony Hack), but it is clear that Brooks (and a very large number of other people) would expect to see these three countries among the first countries placed upon the list.

If this was simply a sanctions bill I would agree that providing the President with a wide degree of latitude in designating countries for a place on the list is good policy. Placement on such a list could be used as a pretty large stick to encourage governments to take actions against cyber thieves working from within their boundaries and that type of stick should be wielded by the President.

But this bill specifically authorizes military action against countries on the list. Did you miss that? See §3(c)(2)(R); the last item on the list of ‘other actions’ that the President is authorized to take is “Ordering a cyber counterattack”. While this may not be a classic military action, there is no doubt that it will be the military that conducts the attack. Likewise, there is little doubt that the targeted country would consider it a military attack and would likely cry to the UN about an act of war perpetrated by the United States.

Now, I have no doubt that there could be cyberattacks that would justify retaliation in kind, or even an expansion of the retaliation to more readily recognizable military attacks. But to give the President blanket authorization to take retaliatory military attacks against countries that might allow bank scammers to operate with impunity seems to me to be a step too far.

If cyber retaliation is going to remain on the list of tools provided to the President (and I could certainly make a whole list of arguments to support that being included) Congress is going to have to do a better job of limiting where that can be employed without coming back for a specific authorization under Article 1, Section 8, Clause 11 of the Constitution (power to declare war). And that is where a definition of the term ‘malicious cyber-enabled activity’ needs to be included in this bill.

In fact, I think that the definition should be structured in such a way as to describe multiple levels of malicious activity that would be keyed to a specific variety of authorized responses. The ultimate level would include ‘any cyber activity that results in, or could reasonably be expected to result in:

∙ ‘The loss of life,
∙ ‘Interference in the operation of the US military aircraft, vessels or spacecraft; or
∙ ‘Interference in the material operation of any critical infrastructure activity.’

The bill should then go on to specify what sort of ‘counter cyberattack’ would be authorized; “A counter cyberattack is authorized to take immediate action to stop the current attack and prevent future attacks by the source of the original cyberattack”.


Again, legislation should probably be written in broad terms to allow for it to continue to fit changing circumstances. But, there are certain activities that should be constrained by law and the power to initiate an attack (even a cyberattack) on a foreign country should be one of those activities.

Monday, July 20, 2015

Committee Hearings – Week of 7-19-15

This week both the House and Senate will be in Washington, but the hearing schedule looks pretty light as Congress marches on towards its summer break. Only two hearings of potential specific interest to readers of this blog; both in the Senate.

PHMSA Nomination

The Senate Commerce, Science, and Transportation Committee will be holding a nomination hearing on Tuesday to look at Marie Therese Dominguez who has been nominated to be the next Administrator of the DOT’s Pipeline and Hazardous Material Safety Administration.

EMP and Solar Storms

The Senate Homeland Security and Governmental Affairs Committee will be holding a hearing on Tuesday to look at “Protecting the Electric Grid from the Potential Threats of Solar Storms and Electromagnetic Pulse”. The witness list includes:

∙ R. James Woolsey, Foundation for Defense of Democracies
∙ Joseph H. McClelland, Federal Energy Regulatory Commission
∙ Richard L. Garwin, PhD, IBM Thomas J. Watson Research Center
∙ Christopher P. Currie, GAO
∙ Bridgette L. Bourge, National Rural Electric Cooperative Association

ISCD Adds New FAQ to CFATS Knowledge Center

Today the DHS Infrastructure Security Compliance Division (ISCD) published a new Frequently Asked Question (FAQ) on the CFATS Knowledge Center. The question addresses the need to submit a Top Screen for a temporary holding of a DHS chemical of interest (COI). FAQ # 1754 asks:

Does a facility have to report temporary holdings of Chemicals of Interest (COI) at or above the Screening Threshold Quantity (STQ)?

The short answer, is yes 6 CFR 27.210(a)(1)(i) requires that a Top Screen be submitted “within 60 calendar days for facilities that come into possession of any of the chemicals listed in appendix A at or above the STQ for any applicable Security Issue”. The response goes on to note that ISCD will work with facilities if they have “if the facility has fluctuating COI or has known future COI holdings”.


The response probably should have included a comment about contacting the CFATS Help Desk {(866) 323-2957} for details on how let ISCD know about the temporary nature of their COI holdings.

Friday, July 17, 2015

HR 3039 Introduced – PROTECT Act

Earlier this week Rep. Brooks (R,AL) introduced HR 3039, the Providing Retaliation Options against Those Engaging in Cyberattacks Targeting the United States (PROTECT) Act. The bill would require the establishment of a ‘State Sponsors of Cyberattacks’ program similar to the ‘State Sponsors of Terrorism’ program.

Section 3 of the bill does two things:

Requires the establishment of a “List of State-Sponsors of Cyberattacks”; and
Provides a list of potential penalties that the President is authorized to impose on nations placed on the List.

List of State-Sponsors of Cyberattacks

Section 3(b) requires the President to submit to Congress a list of countries that have been designated as State-Sponsors of Cyberattacks. There are two reasons that are given for a country being put on the list. The first is a determination that:

“(T)he United States or a United States person has been targeted in a malicious cyber-enabled activity originating from, or directed by a person located, in whole or in substantial part, in a foreign country, and such activity is reasonably likely to result in, or have materially contributed to, a threat to the national security or foreign policy of the United States, or harmed the economic health or financial stability of the United States or a United States person” {§3(b)(2)}.

The second is actually a continuation of the first that specifies particular forms that ‘harmed’ may take. These include {§3(b)(2)}:

Harming or otherwise significantly compromising the provision of services by a computer or network of computers that support the United States or a United States person in a critical infrastructure sector;
Significantly compromising the provision of services by the United States or a United States person in a critical infrastructure sector;
Causing significant disruption to the availability of a computer or network of computers owned or operated by the United States or a United States person;
Causing a significant misappropriation of funds or economic resources, trade secrets, personally identifiable information, or financial information of the United States or a United States person.

Once a country is identified as having met any of the above criteria the President is required to place them on the List State-Sponsors of Cyberattacks.

Penalties

Section 3(c) provides an extensive list of penalties that the President is authorized to apply to countries that are on the List. The first allows the President to impose a duty on “any article or service imported directly or indirectly into the United States that is produced in whole or in part in a country that is included on the list of state-sponsors of cyberattacks” {§3(c)(1)}. It includes 18 other sanctions listed in §3(c)(2) culminating in ordering a trade embargo or ordering a cyber counterattack.

Moving Forward

Brooks is only a member of one of the five committees (Foreign Affairs) that have been assigned to consider this bill. He is a mid-ranking member of the Europe, Eurasia, and Emerging Threats Subcommittee that will probably be assigned initial responsibility within the Foreign Affairs Committee for consideration of this bill. So he may have the political pull to get this bill considered in that Committee.

It is not yet clear if there is enough anger in the Congress over the OPM hack to drive consideration of this bill to the floor. I suspect that if the bill were to make it to the floor, the lack of a requirement to take action against the countries ultimately placed on the list would allow enough members to vote in favor of the bill to obtain passage in the House. I am not sure that the same applies to the Senate.

Commentary

This bill casts a very wide net in what countries could be sanctioned by the President under these provisions. The lack of a definition of “malicious cyber-enabled activity” and that term’s key in defining actions that would place a country on the List means that just about any country could be placed on the list, including any number of friendly allied countries.

More importantly, the United States could certainly be found on a similar list in any country in the world since a very large percentage of the non-state originated ‘malicious cyber-enabled activity’ in the world originates from within our borders. Since the bill does not specify that any of the governments of the countries listed would have to actually be involved in the designated activities we wouldn’t have to worry specifically about the Federal governmental malicious activities that have been exposed by people like Snowden, but those would certainly place us high on the ‘state sponsors’ list of many countries in the world.


A lot of definitions are going to have to be significantly tightened up if the sanction regime that Brooks is trying to implement is to have any significant effect on malicious cyber activity that is becoming endemic across the globe. More importantly, we need to determine if we are going to use these big guns to go after Nigerian bank scams or limit their use to countries that are specifically attacking the United States.

Bills Introduced – 07-16-15

There were 54 bills introduced in the House and Senate yesterday as the law makers headed home for the weekend. Of those bills three may be of specific interest to readers of this blog:

HR 3093 To direct the Secretary of Transportation to make certain changes in the implementation of the Compliance, Safety, Accountability program of the Federal Motor Carrier Safety Administration, and for... Rep. Gibbs, Bob [R-OH-7]

HR 3102 To amend the Homeland Security Act of 2002 to reform programs of the Transportation Security Administration, streamline transportation security regulations, and for other purposes. Rep. Katko, John [R-NY-24]

S 1800 An original bill making appropriations for Agriculture, Rural Development, Food and Drug Administration, and Related Agencies programs for the fiscal year ending September 30, 2016, and for other... Sen. Moran, Jerry [R-KS]

I will only be mentioning HR 3093 again if it contains provisions that would specifically affect chemical transportation.

TSA reform typically affects passenger air operations as this is where most (including congresscritters) people interact with TSA. I will only mention HR 3102 if it includes surface transportation changes that effect chemical transportation.


S 1800 (like HR 3049 earlier this week) will only be of interest here if it contains cybersecurity language (in the bill or report) pertaining to FDA devices.

Thursday, July 16, 2015

ICS-CERT Publishes Eaton’s Cooper Advisory

This morning the DHS ICS-CERT published a new advisory for a predictable TCP sequence vulnerability in Eaton’s Cooper Power Systems controls and relays. The vulnerability was initially reported by Dr. Raheem Beyah, David Formby, and San Shin Jung of Georgia Tech. Eaton’s Cooper has produced a patch to mitigate the vulnerability and ICS-CERT reports that the researchers have validated the efficacy of the patch.

ICS-CERT reports that a skilled attacker could remotely exploit this vulnerability to execute a  man-in-the-middle attack.

The Eaton’s Cooper advisory notes that by “ensuring that controls are not accessible from external networks and that appropriate physical security measures are provided at network access points, any risks associated with this vulnerability are greatly minimized”. They also note that the “vulnerability could allow for the potential of spoofing attacks and session hijacking”.

ICS-CERT reports that they had released this advisory to the US-CERT Secure Portal on January 6th. The company advisory was not issued until July 6th after the patches had been made available. The fact that the advisory was issued on the Secure Portal so early in the coordination process indicates how serious this vulnerability can be. And this reinforces the need for system owners to regularly check the Secure Portal for information on critical vulnerabilities.


BTW: The Schneider update is still not listed on the ICS-CERT landing page. I wonder what is going on. The updated advisory is available; it is just not listed.

CSB Meeting Announced for Next Week - Caribbean Petroleum

The Chemical Safety and Hazard Investigation Board (CSB) published a meeting notice in today’s Federal Register (80 FR 42085-42086) for a public meeting to be held in Washington, DC on July 22nd, 2015. The status of several on-going investigations will be discussed, including the final report on the Caribbean Petroleum accident.

Meeting

According to the CSB web site the following topics will be addressed:

Updates on current CSB investigations;
The final report, recommendations, and public comments received on the Caribbean Petroleum incident, a massive fire at an oil storage facility in Puerto Rico in 2009.  The Board may then vote on the Caribbean Petroleum report;
A staff presentation on the calendared recommendation to BP resulting from the CSB’s investigation into the 2005 BP America refinery explosion in Texas City, TX; and
Staff reports on recommendations related to California’s draft Process Safety Management rules and laboratory safety guidelines from the American Chemical Society.

The meeting is open to the public and there is no mention of any requirements for advanced registration. For those not able to attend in person there will be a phone participation option. After the Board completes the agenda items there will be time for public statements limited to 5 minutes or less. Written statements for the record may be submitted at the meeting or provided to Hillary J. Cohen, Communications Manager, hillary.cohen@csb.gov.

Other Issues

People who have been following the CSB will be well aware of numerous personnel issues that have been plaguing the Board for the last couple of years. They are now down to just two active members (a new Chair and another new member have been nominated and are going through the Senate confirmation process). This combined with conflicts between the Board and the CSB staff has undoubtedly affected the performance of the CSB.

Of much more concern have been the allegations of misconduct of some of the past and current Board members. More recently there have been allegations of contract improprieties perpetrated by the self-declared “interim executive and administrative authority”. Exacerbating these issues is the open conflict between the two remaining Board members. NOTE: Thanks to Richard Rosera for pointing me at these last two articles.

The underfunded CSB has a good historical record of investigating serious chemical process and handling accidents, determining root causes of those accidents and turning that information into both specific and broad industry guidelines for improving chemical process safety. The current problems need to be resolved before they have a permanent effect on the Board’s ability to perform its valuable and necessary function.


I am not generally a big fan of congressional investigations, but these problems have reached the point where congressional oversight is probably going to be the only thing that can prevent some of the current calls for the disbanding of the Board to be put into operation.
 
/* Use this with templates/template-twocol.html */