Tuesday, December 15, 2015

ICS-CERT Updates Advantech Advisory and Publishes New Advisory

The afternoon the DHS ICS-CERT updated the Advantech advisory that they published last week. Additionally a new advisory was published for vulnerabilities in an Adcon telemetry gateway.

Advantech Update

This update corrects the name of the researcher who reported the vulnerability in an uncoordinated disclosure. The researcher is now being reported as HD Moore. The confusion apparently arose because Tod Beardsley authored the blog post that publicly disclosed the vulnerability, but even that post credited HD Moore with the discovery.

Adcon Advisory

This advisory describes multiple vulnerabilities in the Adcon Telemetry A840 Telemetry Gateway Base Station. The vulnerabilities were reported by Aditya K. Sood. Adcon has contacted all known customers to offer an upgrade to a more secure and stable version. There is no indication that Sood has verified that the newer version is free of the indicated vulnerabilities.

The vulnerabilities are:

• Hard-coded credentials - CVE-2015-7930;
• Improper authentication - CVE-2015-7931;
• Clear text transmission of sensitive information - CVE-2015-7932; and
• Information exposure - CVE-2015-7934

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to gain administrative access to the target.

The reason for the unusual mitigation measure is that Adcon describes the affected device as obsolete and no longer supports the device.

HR 4240 Introduce – TSDB Report

Last week Rep. Jackson-Lee (D,TX) introduced HR 4240, the No Fly for Foreign Fighters Act. The bill would require the GAO to conduct a study of the FBI’s Terrorist Screening Database (TSDB)

Report to Congress

The bill requires the GAO to report to Congress within 180 days of passage of the bill. The report would address how well the FBI had corrected previously identified problems with the TSDB. It would also address how {§2(b)}:

• Information is being integrated into the TSDB from all relevant sources across the government in a timely manner;
• Agencies are able to comply with increased demands for information to improve the TSDB;
• The TSDB, and relevant subsets of the TSDB, are accessible to agencies, authorities, and other entities, as appropriate; and
• The TSDB is capable of enabling users to identify known or suspected terrorists in the most timely and comprehensive manner possible.

Moving Forward

Ms. Jackson-Lee is the Ranking Member of the Crime, Terrorism and Homeland Security Subcommittee of the House Judiciary Committee, the Committee to which this bill was referred for consideration. The two cosponsors of the bill {Rep. Conyers (D,MI), and Rep. Ratcliffe (R,TX)} are also members of that Committee with Conyers being the Ranking Member. This means that there is probably enough political pull to have the measure considered in Committee.

Since this bill only requires a report to Congress and not any real action or expenditure of funds, there is unlikely to be any major opposition to this bill. And considering the increasing interest in the potential for terrorist attacks in this country, there is every incentive to ensure that the TSDB is an effective tool to help prevent such attacks.

Commentary

This bill does not require the report to address what is probably the biggest drawback to the TSDB; the fact that this is essentially a name based database. Since names are not unique identifiers of people and most people use a number of variations of their own names in day to day life, there exists a very real (and demonstrated) problem of misidentifying people as having possible terrorist ties when what they have is a similar name to someone that has possible terrorist ties.

While this is an inconvenience (perhaps substantial inconvenience) to someone that is prohibited from boarding an aircraft it can mean a loss of livelihood if the misidentified person is denied a Transportation Workers Identification Credential (TWIC) or flagged during a CFATS personnel surety program check.


Since people are not filling out applications to be placed on the TSDB and providing finger prints and background information in the process it is inevitable and probably unavoidable that misidentification will take place. What needs to be understood by policy makers (who may want to expand the use of the TSDB into constitutionally protected areas like weapon sales) is the prevalence of these ‘false positives’, what is being done to reduce them, and what redress measures are available when they do occur. All of this should be included in this report if Congress is to derive any legislative benefit from the report.

Sunday, December 13, 2015

HR 4206 Introduced – Grid Modernization

On Wednesday Rep. Sarbanes (D,MD) introduced HR 4206, the 21st Century Power Grid Act. The bill would require the Secretary of Energy to establish a financial assistance program for projects to modernize the electric production, transmission and distribution system to continue to provide safe, secure, reliable, and affordable power. The bill does not include any authorization for funding.

Eligible Projects

The projects would be required to {§2(b)(1)}:

• Improve the performance and efficiency of the future electric grid;
• Provide new options for customer-owned resources; and
• Demonstrate secure integration and management of energy resources as well as secure integration and interoperability of communications and information technologies.

The projects would be required to include at least one of the following{§2(b)(3)(B)}:

• An investor-owned electric utility;
• A publicly owned utility;
• A technology provider;
• A rural electric cooperative;
• A regional transmission organization; or
• An independent system operator.

Each project would be required to include a Cybersecurity Plan {§2(c)} and a Privacy Risk Analysis {§2(d)}.

Moving Forward

Sarbanes and his two co-sponsors {Rep. Ellmers (R,NC) and Rep. McNerny (D,CA)} are on the Energy and Power Subcommittee of the House Energy and Commerce Committee, one of the two Committees to which this bill was referred for consideration. This means that there is a chance that this bill could make it before the Committee next year.

Since there is no new money authorized for this program and no new requirements are being placed upon industry, there is unlikely to be any significant opposition to this bill.

Commentary

As I have mentioned a number of times with a variety of different bills, it is interesting to continue to see generic cybersecurity language in this bill. It would be helpful, however, if Congress provided a little bit more guidance in what they are going to consider to be a ‘cybersecurity plan’ about which they expect the Secretary to provide guidance.

I’m not asking for any level of technical detail. That is not the job of the legislative branch and it certainly is not their strong point. What I am asking for is a little political guidance on what such a plan should include. If I were writing this bill I would include requirements to:

• Conduct a risk analysis to determine the worst case failure modes for the system;
• An outline of the devices and systems that could lead to those failures;
• A plan to insure that the devices and systems are designed, installed and maintained in a manner to reduce the likelihood of those failure modes;
• A plan to isolate those devices and systems from potential attack; and
• An identification of the requirements to recover from a successful attack against those failure modes.


Furthermore, the mere publication of a document that is called a cybersecurity plan should not be sufficient. It needs to be reviewed and approved by an appropriate agency within the DOE before any funding is provided.

HR 4187 Introduced – Breach Notification

Last Tuesday Rep. Schakowsky (D,IL) introduced HR 4187, the Secure and Protect Americans’ Data Act. This is a very comprehensive personal data protection and breach reporting act that give the FTC regulatory authority over these matters.

New Regulations

The FTC is required to promulgate regulations pertaining to the requirements for securing ‘personal information’ {§2} and reporting breaches that result in “personal information [that] was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose” {§3(a)(1)}.

The definition of personal information {§5(6)} is quite extensive and includes a wide variety of identification information. Items of particular interest to readers of this blog include:

• Unique biometric or genetic data such as a faceprint, fingerprint, voice print, a retina or iris image, or any other unique physical representations {§5(6)(v)};
• Information that could be used to access an individual’s account, such as user name and password or email address and password {§5(6)(vi)};
• An individual’s first and last name or first initial and last name and any security code, access code, or password, or source code that could be used to generate such codes or passwords {§5(6)(vii)};
• Digitized or other electronic signature {§5(6)(xi)};
• Nonpublic communications or other user-created content such as emails, photographs, or videos {§5(6)(xi)}; and
• Any additional element the Commission defines as personal information {§5(6)(xiv)};

Moving Forward

Ms. Schakowsky is the Ranking Member of the Commerce, Manufacturing and Trade Subcommittee of the House Energy and Commerce Committee, the Committee to which this bill was referred for consideration. While none of the seven co-sponsors are Republicans they do include other influential members of the Committee, including Rep. Pallone (D,NJ) the Ranking Member. There is a chance that this bill could be considered in Committee. If it does get recommended out of Committee then it could move to the floor for consideration, probably under a rule.

Commentary

With all of the big name data breaches that we have seen in the public sector over the last couple of years there have been a number of data breach bills that have been introduced in the 114th Congress and this probably will not be the last. This bill is, however, one of the most comprehensive and wide reaching that I have seen. It does not, for example, contain a minimum information breach size or data base size to be considered by the regulator.

Most breach legislation to date has been more specifically targeted at IT processes and financial information in particular. Looking at the list above of covered personal information that I abstracted from the bill it is quite clear that the staff writing this bill was expanding greatly the types of information included and thus the business that would be potentially covered by the resulting regulations.

Because there is no minimum size for a covered breach, even the loss of a single user name/password combination would technically be covered. This could directly affect attacks on control systems where that information was (or could have been) taken by the attacker. We have seen a large number of vulnerabilities over the last couple of years that specifically put this information at risk.


I don’t currently see Congress taking on this bill due to its extremely comprehensive coverage. That could easily change if we have a series of very public credit card breaches over the holidays or some unusual type of large breach in a previously unaffected sector.

Saturday, December 12, 2015

Bills Introduced – 12-11-15

With just the House in session yesterday (the Senate having left for a long weekend) there were eleven bills introduced. Only one of those bills may be of specific interest to readers of this blog:

HR 4240 To require an independent review of the operation and administration of the Terrorist Screening Database (TSDB) maintained by the Federal Bureau of Investigation and subsets of the TSDB, and for other purposes. Rep. Jackson Lee, Sheila [D-TX-18]


Since the TSDB is an integral part of the TWIC process and the soon (maybe) CFATS personnel surety process this bill will almost certainly be of interest, at least in the long run, to readers of this blog. Of course, the reason Ms Jackson-Lee is offering this now (though her concern is certainly not new) is that well known problems with the TSDB have been used by Republicans as a reason to not use that database as part of the gun permitting process.

Friday, December 11, 2015

House Passes Short Term CR

Earlier this afternoon the House agreed to the Senate amendment to HR 2250, the short term continuing resolution that continues the current rate of federal spending until December 16th. There was less than seven minutes of debate and the measure was agreed to by a voice vote. The bill will probably be signed by the President this afternoon.


It looks like we are going to have to wait until at least Monday before we will have a chance to see the Omnibus spending bill that is still being negotiated behind closed doors.

House Passes Three Homeland Security Bills

Yesterday the House passed three homeland security related bills under suspension of the rules; all with no significant opposition and little debate.

The three bills were:

HR 3875, Department of Homeland Security CBRNE Defense Act of 2015 – Voice vote
HR 3578, DHS Science and Technology Reform and Improvement Act of 2015 – 416 - 0 
HR 3869, State and Local Cyber Protection Act of 2015 – Voice vote


I do not think that these bills will be considered by the Senate before the year-end recess, but they will likely be taken up under the unanimous consent process early next year.
 
/* Use this with templates/template-twocol.html */