Friday, May 20, 2016

Bills Introduced – 05-19-16

Yesterday with the House and Senate preparing to leave for the weekend, there were 36 bills introduced. Only one of those may be of specific interest to readers of this blog:

S 2956 S.2956 - An original bill making appropriations for Agriculture, Rural Development, Food and Drug Administration, and Related Agencies programs for the fiscal year ending September 30, 2017, and for other purposes. Sen. Moran, Jerry [R-KS]


I do not normally cover this spending bill in this blog, but there is an outside (pretty damn remote) chance that there might be cybersecurity provisions in the FDA portion of the bill.

Thursday, May 19, 2016

HR 5222 Introduced – Iran Cyber-Sanctions

Last week Rep. Ratcliffe (R,TX) introduced HR 5222, the Iran Cyber Sanctions Act of 2016. The bill would require reports from the President to Congress on conducted on the United States at the behest of the government of Iran. The bill is similar to S 2756 that was introduced in the Senate last month.

Differences between House and Senate Versions


While both bills would require presidential reports on Iranian cyber-attacks on the United States, there are some significant differences. The first, and probably least significant, is that the Senate bill requires the first report within 180 days of enactment of the bill where this bill requires the first report in 90 days.

The most significant difference is also found in Section 2(a)(1) of the respective bills. Both bills require the reports on “significant activities undermining cybersecurity”. The Senate bill requires reports on activities conducted by “Iranian persons” while the House bill targets “by persons on behalf of or at the direction of the Government of Iran”.

Another difference is found in §2(b). The paragraph requires the President to add persons identified in the periodic reports required in this bill to the “designated nationals and blocked persons list maintained by the Office of Foreign Assets Control [OFAC] of the Department of the Treasury” {§2(b)(1)}. The Senate version of the bill also requires listing of “any Iranian person” under indictment for “significant activities undermining cybersecurity against the Government of the United States or any United States person” {§2(b)(1)(B)}. The House version of the bill only addresses “any person”.

The House version of the bill adds a new §2(c). It requires the President to take property blocking actions under EO 13694 for anyone identified in §2(b).

The final area where there are significant differences between the two bills is in the definitions paragraph {§2(d) in the Senate bill; §2(e) in the House bill}. The House bill does not contain a definition of ‘Iranian person’ since that term is not used in the House bill. Additionally the House bill adds another sub-paragraph to the definition of ‘Unites States person’: “any government (Federal, State, or local) entity” {§2(e)(3)(C)}.

Moving Forward


Ratcliffe is not a member of either the House Foreign Affairs or Judiciary Committees; the two committees to which the bill was referred for consideration. This means that it would be extremely difficult for him to influence either committee to consider the bill. The more likely way that this bill could get considered would be to add it as an amendment to an appropriations or authorization bill.

I do not see anything in the bill that would raise any significant opposition to the bill if it were to be considered on the floor of either the House or Senate.

Commentary


The differences between the two versions of the bill would mean that the House bill would not require (but would allow) the President to include in his listings purely criminal attacks on US businesses that originate in Iran. It would seem to me that limiting these requirements to politically motivated attacks would be a more reasonable application of US sanctions.

I am still concerned that the bill continues to ignore control system security, particularly with the recent conversations about vulnerabilities in the National Grid and press reports of Iranian attacks on physical infrastructure. This concern could be rectified by adding a sub-paragraph §2(e)(2)(A)(ii); “interfere with the operation of an industrial control system at any critical infrastructure facility;”.


If Ratcliffe really wants to see this bill become law, rather than just establish his anti-Iranian credentials, he really needs to work at getting co-sponsors to this bill that serve on either the Foreign Affairs or Judiciary (or both) Committees; the higher ranking the better. That way he would have a champion that could apply the appropriate legislative pressures to have the bill considered in Committee.

ICS-CERT Publishes Two Advisories

This afternoon the DHS ICS-CERT published two new industrial control system advisories for products from Siemens and Resource Data Management.

Siemens Advisory


This advisory describes twin information disclosure vulnerabilities in the Siemens SPIROTEC Ethernet modules. The vulnerabilities were independently reported by Aleksandr Bersenev from HackerDom team and Pavel Toporkov from Kaspersky Lab. Siemens has produced a firmware update to mitigate the vulnerabilities. There is no indication that either researcher has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to obtain sensitive device information if the attacker has network access to the devices. The Siemens CERT advisory notes that the firmware update only applies to the SPIROTEC Compact versions equipped with the EN 100 Ethernet modules. For other models of the SPIROTEC Compact Siemens recommends protection of the affected networks with standard cybersecurity protections like firewalls, segmentation, and VPN access.

Resource Data Management Advisory


This advisory describes two vulnerabilities in the Resource Data Management Intuitive 650 TDB Controller. The vulnerability was reported by Maxim Rupp. RDM has produced a new version of their TDB Control Editor that is used to program their controllers to mitigate these vulnerabilities. There is no indication that Rupp has been provided an opportunity to verify the efficacy of the fix.

The two vulnerabilities are:

• Privilege escalation - CVE-2016-4505; and
• Cross-site request forgery - CVE-2016-4505


ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to gain elevated access to alter logs and parameters or execute unwanted actions.

House Amends and Passes HR 4909

Late last night the House completed the extensive amendment process on HR 4909, the FY 2017 National Defense Authorization Act and passed the bill by a somewhat bipartisan vote of 277 - 147.

The two remaining amendments of potential interest to readers of this blog were, as predicted adopted by voice votes in en bloc consideration. Rep. Meehan’s (R,PA) National Guard cybersecurity communications amendment was considered as part of block # 8. Rep. Donovan’s (R,NY) TWIC application amendment was considered as part of block #9.

The Senate is likely to take up their own version of the NDAA (S 2943) introduced yesterday and then a conference committee would have to iron out the differences between the two bills.


The President has reported issued a veto threat against HR 4909 over funding provisions in the bill. It remains to be seen if the Senate version contains the same provisions.

OMB Publishes 2016 Spring Unified Agenda – DHS

Yesterday the OMB’s Office of Information and Regulatory Affairs published the Spring 2016 Unified Agenda, a listing of the status of the current regulations being developed by the Federal government. This version of the Unified Agenda is particularly important because it effectively marks the projected end of the Agenda for the Obama Administration. The Fall version of the agenda will essentially be a lame duck agenda.

DHS Agenda


The table below shows which rulemakings that are on the Spring Agenda for the Department of Homeland Security may be of specific interest to readers of this blog.

Prerule Stage
Updates to Protected Critical Infrastructure Information
Proposed Rule Stage
Petitions for Rulemaking, Amendment, or Repeal
Proposed Rule Stage
Chemical Facility Anti-Terrorism Standards (CFATS)
Proposed Rule Stage
Homeland Security Acquisition Regulation: Safeguarding of Sensitive Information
Final Rule Stage
Civil Penalty Inflation Adjustment Act Implementation
Final Rule Stage
Transportation Worker Identification Credential (TWIC); Card Reader Requirements
Final Rule Stage
Revision to Transportation Worker Identification Credential (TWIC) Requirements for Mariners
Final Rule Stage
2013 Liquid Chemical Categorization Updates
Proposed Rule Stage
Security Training for Surface Mode Employees

There is one new item on this list; Civil Penalty Inflation Adjustment Act Implementation (1601-AA80). This lands on the list already in the ‘Final Rule Stage’ because this was a specific requirement from Congress (§701, PL 114-74) so there is no requirement to go through the publish and comment rulemaking process. Congress required that an interim final rule be final on this rulemaking by August 1st of this year.

One item that was on the 2015 Fall Agenda did fall off of this list; Surface Mode Vulnerability Assessment and Security Plans (1652-AA56). This rulemaking has flip-flopped between the Agenda and the Long-Term actions list for a number of years. It is now back on Long-Term Actions (see below)

Long-Term Actions


OIRA also updated their ‘Long-Term Actions’ section of the Unified Agenda. These are regulatory actions that are technically being worked upon, but nobody expects them to be finished for a variety of reasons in the foreseeable future. The items on the DHS list that may be of specific interest to readers of this blog are listed in the table below.

Long-Term Actions
Ammonium Nitrate Security Program
Long-Term Actions
Updates to Maritime Security
Long-Term Actions
Amendments to Chemical Testing Requirements
Long-Term Actions
Protection of Sensitive Security Information
Long-Term Actions
Surface Mode Vulnerability Assessment and Security Plans
Long-Term Actions
Standardized Vetting, Adjudication, and Redress Services

Cybersecurity


Once again there are no cybersecurity regulations listed on the DHS Unified Agenda (other than the SAR regulation on contractors protecting sensitive information. DHS may have an apparently ever expanding role in cybersecurity, but there is no apparent intent to establish any sort of regulations on the topic.

Rule-Making Schedule


Many of the items on the list of active rulemakings listed above have projected dates for the next step in the publish-comment process. To call these dates illusory would be generous. The TSA security training rulemaking has been on the agenda for almost a decade now with absolutely no action. Deadlines established by Congress are essentially unenforceable. The rulemakings will appear if and when they appear. Anyone that believes the projections included in the Unified Agenda should contact me; I have some property 40 miles south of Key West for sale, cheap.

Bills Introduced – 05-18-16

With both the House and Senate in session yesterday twelve bills were introduced. Actually at this point there were twelve bills introduced in the Senate. Since the House did not adjourn until almost 1:00 am EDT this morning any bills introduced in the House yesterday were not included in yesterday’s listing on Congress.gov. In any case only one of the twelve bills listed may be of specific interest to readers of this blog:

S 2943 An original bill to authorize appropriations for fiscal year 2017 for military activities of the Department of Defense, for military construction, and for defense activities of the Department of Energy, to prescribe military personnel strengths for such fiscal year, and for other purposes. Sen. McCain, John [R-AZ]

NOTE: Title Corrected for date on 5-20-16 07:48 EDT.

Wednesday, May 18, 2016

ICS-CERT Updates Meteocontrol Advisory

This morning the DHS ICS-CERT published an updated advisory for control system vulnerabilities reported in the Meteocontrol WEB'log. The Advisory was originally published last week and I reported on potential problems with the advisory yesterday. Additionally, the Karn Ganeshen memo to Full Disclosure on this topic is now available.

Revised Advisory


ICS-CERT made changes to two areas of the Advisory. First they added a new paragraph to the ‘Impact’ section of the advisory. That new paragraph reads:

“Successful exploitation of these vulnerabilities can allow silent execution of unauthorized actions on the device such as modifying plant data; modifying modbus/inverter/other devices; configuration parameters; and saving modified configuration and device reboot.”

ICS-CERT also made a number of changes to the vulnerability overview section of the advisory. They changed the title and description of the first two vulnerabilities and added a third new vulnerability.

The ‘Information Exposure’ vulnerability (CVE-2016-2296) was changed to ‘Improper Access Control’ with this new description:

“All application functionality, and configuration pages, including those accessible after administrative login, can be accessed without any authentication.”

The ‘No Authentication’ vulnerability (CVE-2016-2297) was changed to ‘Command Shell Accessible’ with this new description:

“The application has a hidden/obscured access command shell-like feature that allows anyone to run a restricted set of system commands. This shell can be accessed directly without any authentication.”

Finally, ICS-CERT added a Cross-Site Request Forgery vulnerability (CVE-2016-4504).

Full Disclosure Memo


I mentioned yesterday that Karn Ganeshen had reportedly sent a memo to the Full Disclosure list explaining the deficiencies in the original Meteocontrol Advisory. Today that memo has been published on the site. In that memo, Karn has provided sample URLs that would allow access to the information on WEB’log devices without authentication.


I’m not sure if this information rises to the level of ‘exploit code’ since some additional work (I think) would have to be done to get these sample URL’s to work. In any case ICS-CERT continues in this version of the Advisory to report that: “No known public exploits specifically target these vulnerabilities.” Then again, they may not have known about the existence of this Full Disclosure memo when they revised the Advisory.
 
/* Use this with templates/template-twocol.html */