Monday, September 21, 2015

Subcommittee Amends and Adopts HR 3490

Last week the Cybersecurity, Infrastructure Protection, and Security Technologies Subcommittee of the House Homeland Security Committee amended and favorably recommended to the full Committee HR 3490, the Strengthening State and Local Cyber Crime Fighting Act. The action was taken on a voice vote, suggesting substantial bipartisan support for the bill as I suggested in my earlier post.

The sole amendment added the Federal Law Enforcement Training Center (FLETC) to the list of agencies that the National Computer Forensics Institute is supposed to work with in furthering the goals of effective cyber forensics.

Moving Forward

Again, I expect that this bill will move forward to a full Committee markup fairly quickly. It will not be this week due to the short work week in the House (effectively only two days), but I expect it before the Columbus Day recess.

Commentary


I would still like to see this bill amended to specifically mention a requirement to establish control system forensics capabilities established at the NCFI. While the ICS-CERT certainly significant expertise in this area, they are woefully understaffed and funded to investigate an ever widening number of ‘control’ systems in the internet of things that will be coming under increasing attack as awareness of the vulnerabilities in these systems becomes increasingly understood by the cyber-criminal community. Even critical infrastructure ICS cases are going to start to come under criminal investigation and I don’t believe that criminal forensics is really the purview of ICS-CERT.

Saturday, September 19, 2015

Bills Introduced – 09-18-15

Yesterday only the House was in session so there were only 31 bills introduced. Of those only two may be of specific interest to readers of this blog:

HR 3578 To amend the Homeland Security Act of 2002 to strengthen and make improvements to the Directorate of Science and Technology of the Department of Homeland Security, and for other purposes. Rep. Ratcliffe, John [R-TX-4]

H Con Res 78 Expressing the sense of Congress that the President in consultation with the Department of the Treasury should apply economic sanctions against Chinese businesses and state-owned enterprises that can be linked to cyberattacks against United States entities. Rep. Wilson, Joe [R-SC-2] 

Okay, so I stretched the ‘may be of specific interest’ standards a bit today. Neither of these bills has a high potential for fitting in to my normal blog postings, but they may be covered any way because both could have significant impact on cybersecurity operations even though neither will specifically address control system security.

HR 3578 may increase the importance of cybersecurity in the Directorate’s focus on developing and supporting new homeland security related technology.


This resolution is interesting because instead of focusing on the Chinese government (as has been the target of many Republican congresscritters) it instead asks the President to specifically respond at Chinese businesses. Providing this, let’s face it, Republican backing for the President’s taking action under his recent cyber retaliation EO just might be the final push the President needs to take such action.

DHS Publishes 2015 CSSS Presentations

Earlier this week DHS updated the Chemical Sector Security Summit web site. A number of the presentations that were made at the 2015 CSSS in July now have their slides available on-line.

The on-line slides include:


I have done a quick look review of all of these slide sets and they all contain some valuable information about various aspects of the CFATS Program. Unfortunately, they do not contain the audio portion of the presentation so some of the detailed information provided at the CSSS has been lost. The Department did provide web casts of two presentations this year; the keynote by Amy Pope and David Wulf’s CFATS Update. Hopefully there will be more web casts next year.


Friday, September 18, 2015

Multiple ICS-CERT Advisories on Secure Portal

I have heard rumors that there are two or three ICS-CERT advisories currently on the US-CERT Secure Portal. ICS-CERT typically releases advisories for high impact vulnerabilities on the Secure Portal first to allow critical infrastructure owners a chance to implement appropriate mitigation measures before those vulnerabilities are released to the public.

Readers of this blog will probably be aware that I do not have access to the Secure Portal. It was graciously offered but I turned it down because I did not want to be put in the position of knowing about advisories like this without being able to write about them.


I would encourage all critical infrastructure facilities with control systems to request access to the US-CERT Secure Portal so that they would have access to advisories like this before they are made public. Instructions on how to apply for access can be found on the bottom of the ICS-CERT main website

HR 8 Introduced – Energy Security

On Wednesday Rep Upton (R,MI) introduced HR 8, the North American Energy Security and Infrastructure Act of 2015. The bill mainly addresses energy supply chain issues, but it does have two provisions dealing with actual security issues. The first is protection of information about bulk electrical system security issues and the second is a new cybersecurity program.

Information Protection

Section 1104 of the bill would add a new section (§215A; Critical Electric Infrastructure Security) to the Federal Power Act (16 USC 824 et seq.). The new section would provide authority for the Secretary of Energy to address a grid security emergency {new §215A(b)} and establish a program for the protection of critical electric infrastructure information. The provisions of this section are essentially those found in HR 2271 which I have previously discussed in detail.

While a CEII program does currently exist, pending regulations on controlled but unclassified information (CUI) from the National Archives and Records administration, treat such programs differently if they are authorized by law.

Cyber Sense Program

Section 1106 requires the Energy Secretary to establish a Cyber Sense Program to identify and promote cyber-secure products intended for use in the bulk-power system. The program would allow voluntary industry participation and would include {§1106(b)}:

• A testing process to identify products and technologies intended for use in the bulk-power system, including products relating to industrial control systems, such as supervisory control and data acquisition systems;
• The establish and maintain cybersecurity vulnerability reporting processes and a related database for products in the Cyber Sense program;
• Regulations regarding vulnerability reporting processes for products tested and identified under the Cyber Sense program; and
• Technical assistance to utilities, product manufacturers, and other electric sector stakeholders to develop solutions to mitigate identified vulnerabilities in products tested and identified under the Cyber Sense program.

This section would also require the Secretary to provide for public notice and comments before establishing or changing the required testing program. Products included in the program would be required to be tested every two years.

The bill does not specifically mandate that the results of the product testing should be considered as Critical Electric Infrastructure Information (CEII). It does, however, require that “any vulnerability reported pursuant to regulations promulgated under subsection (b)(3), the disclosure of which could cause harm to critical electric infrastructure (as defined in section 215A of the Federal Power Act), shall be exempt from disclosure” under the Freedom of Information Act or any similar State and local laws.

Moving Forward
As I noted in my earlier post the assignment of ‘HR 8’ to this bill instead of a sequential bill number indicates that the Republican leadership in the House considers this bill a high political priority. It was considered in a markup hearing yesterday before the House Energy and Commerce Committee, but Committee web page does not yet provide any results of that consideration. I expect, however, that the bill was adopted by voice vote.

Commentary

The new Cyber Sense Program proposed by this bill is the first serious attempt by Congress to deal with the problems associated with industrial control system security. The idea of the Federal government establishing a testing and certification program for ICS components and systems is certainly an innovative approach to control system security.

Since this bill does not provide any funding for the program, it is fairly clear that the authors intend this testing to be done by third-party organizations and that is reinforced by the requirement for the Secretary to “oversee Cyber Sense testing carried out by third parties” {§1106(b)(8)}. The problem becomes that, since the Energy Department is not paying for the testing, that it will most likely be the vendor that pays. This always raises the potential issues of testers being beholden to the people that make the products being tested.

The establishment of regulations for vulnerability reporting for Cyber Sense products is something that was fairly glibly added to this bill. But, taken along with the information sharing restrictions outlined, this is going to be problematic. Except for equipment that is uniquely used by the bulk-power system, trying to regulate how security vulnerability reporting is conducted without intimately involving at least ICS-CERT is going to create more problems than it solves.

A brief example will help explain the problem. A private security researcher discovers a vulnerability in a PLC that is part of the Cyber Sense program, but is also used in a wide variety of other industrial control systems. Normally he would have a choice of coordinating that vulnerability disclosure with the vendor, ICS-CERT (or any one of a number of other coordination agencies) or publicly disclosing the vulnerability. Under the new program, if he instead disclosed it to the Cyber Sense program, then there would be no public disclosure through ICS-CERT or the vendor. In fact, if the new regulations were to declare this disclosure to the Cyber Sense to be CEII information (a logical move), then ICS-CERT would not be able to post it to the US-CERT Secure Portal because people without a CEII need-to-know have access to that system.

Crafters of this bill missed one of the biggest potential incentives for using Cyber Sense components. DHS has the Safety Act program under their Science and Technology Directorate that provides important legal liability protections for providers of Qualified Anti-Terrorism Technologies. This bill should have set up a similar program for Cyber Sense vetted products.

I would like to suggest that instead of making the vulnerability information CEII and limiting the disclosure to just the energy sector, that the bill should have designated ICS-CERT as the agency responsible for coordinating disclosures of vulnerabilities for all Cyber Sense Products. It would then go on to require that ICS-CERT initially release the vulnerability information on the US-CERT Secure Portal and only make full public disclosure in coordination with the Department of Energy organization overseeing the Cyber Sense program. That way non-energy sector organizations using the same equipment would have an opportunity to fix their devices before the public disclosure of the vulnerability.


Now, I really like the idea of an independent agency that does in depth security vulnerability testing of control system components and certifying some level of minimum security for such devices. That would certainly make the purchasing of secure ICS components much easier. But we do need to be careful how that is done to prevent the most egregious unintended consequences.

OMB Approves PHMSA Pipeline NPRM

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the Pipeline and Hazardous Material Safety Administration’s (PHMSA) notice of proposed rulemaking for Safety of On-Shore Liquid Hazardous Pipelines. An advance notice of proposed rulemaking (ANPRM) was published in 2010.

The Unified Agenda notes that:

“This NPRM responds to NTSB recommendations, a GAO recommendation, public safety community input, consideration of research and technology advancements and the review of recent incident and accident reports. Additionally, the Pipeline Safety, Regulatory Certainty, and Job Creation Act of 2011 (P.L. 112-90) [link added], includes several provisions and mandates that are relevant to the 49 CFR particularly section 195.452 [link added].”

There were 24 comments submitted on the ANPRM. They included one from me concerning toxic inhalation hazard pipelines.


In the normal course of events I would expect this proposed rule to be published sometime next week.

Thursday, September 17, 2015

ICS-CERT Publishes Update and New Advisory

This afternoon the DHS ICS-CERT published an update for an advisory from earlier this month for products from SMA Solar Tech and a new advisory for a product from Harmon-Kardon.

SMA Update  

This update makes some important modifications to the Mitigation section of the Advisory. First ICS-CERT changes its characterization of what SMA Solar Tech told owners of this older system. Instead of suggesting that: “It recommends using port forwarding or a VPN to access these devices remotely”; ICS-CERT is now reporting that: “SMA expressly recommends deactivation [emphasis added] of port-forwarding or use of a VPN to access these devices remotely”.

Additionally, ICS-CERT has removed from the advisory its earlier recommendation that “users should remove and replace this system”. In its place they have placed the standard set of protective measures that ICS-CERT has been recommending for some time.

Since I do not have access to the SMA communications with its customers I cannot tell if these changes are due to changes made by SMA or whether it was an initial misreading of those recommendations by ICS-CERT.

NOTE: This advisory is no longer on the main ICS-CERT web page so the casual reviewer would not know that an update had been published. ICS-CERT did announce this update via TWITTER. All control system owner/operators are encouraged to follow @ICS-CERT.

Harmon-Kardon Advisory

This advisory is a follow-up to the DefCon related Alert published in July. It describes an unauthorized remote access vulnerability in the Harmon-Kardon Uconnect telematics infotainment system used in a number of FCA vehicles. The vulnerability was reported by Chris Valasek [then] of IOActive and Dr. Charlie Miller [then] of Twitter. FCA has  distributed a firmware patch as part of the vehicle recall process that mitigates this vulnerability and the two researchers have verified the efficacy of the fix.

ICS-CERT reports that the vulnerability is no longer remotely exploitable due to changes made in the Sprint cellular network. Thus, ICS-CERT reports that an exploit of this vulnerability is difficult because physical access to the system is required.

 
/* Use this with templates/template-twocol.html */