Thursday, January 12, 2017

Bills Introduced – 01-11-17

Yesterday with both the House and Senate in session (and the Senate in a late night session) there were 46 bills introduced. Of those three may be of specific interest to readers of this blog:

HR 437 To amend the Homeland Security Act of 2002 to codify authority under existing grant guidance authorizing use of Urban Area Security Initiative and State Homeland Security Grant Program funding for enhancing medical preparedness, medical surge capacity, and mass prophylaxis capabilities. Rep. Bilirakis, Gus M. [R-FL-12]

HR 458 To require the Secretary of Transportation to conduct a study on the economic and environmental risks to the Great Lakes of spills or leaks of oil, and for other purposes. Rep. Trott, David A. [R-MI-11]

S 94 A bill to impose sanctions in response to cyber intrusions by the Government of the Russian Federation and other aggressive activities of the Russian Federation, and for other purposes. Sen. Cardin, Benjamin L. [D-MD]

HR 437 will probably be very similar to HR 361 from the last session. That bill passed in the House early in the 114th Congress, but was never taken up in the Senate. A large number of bills never make it to the floor in the other body. This is simply part of the two-body politics problem of a bicameral legislature. The bill’s author not only has to be able to work for passage in his home body, but also needs to have some influence in the other body to gain floor access for the legislation there. It will be interesting to see if Bilirakis has done anything to achieve success with the bill in the Senate.

It will be interesting to see if HR 458 includes rail-specific language.


S 94 will be of interest here if it includes language that addresses control system security or retaliation language that goes beyond the Russian-election fiasco.

Wednesday, January 11, 2017

Bills Introduced – 01-10-17

Yesterday with both the House and Senate in session there were 73 bills introduced. Of those two may be of specific interest to readers of this blog:

S 79 A bill to provide for the establishment of a pilot program to identify security vulnerabilities of certain entities in the energy sector. Sen. King, Angus S., Jr. [I-ME]

S 88 A bill to ensure appropriate spectrum planning and interagency coordination to support the Internet of Things. Sen. Fischer, Deb [R-NE]

It will be interesting to see if S 79 addresses physical security, cybersecurity, or both.


S 88 looks to be a continuation of efforts by Fischer to promote IOT development. How close this will be to S 2607 from the last session. That bill was reported out of committee but never made it to the floor of the Senate.

ICS-CERT Publishes Two Advisories

On Monday and Tuesday, the DHS ICS-CERT published two advisories. The first is a medical system security advisory for a product from St. Jude Medical. The second is a control system advisory for products from OSIsoft. ICS-CERT also published a call for papers for the Spring 2017 ICSJWG meeting in Minneapolis, Minnesota.

St. Jude Advisory  


This advisory describes a ‘man-in-the-middle’ vulnerability in the St. Jude Medical Merlin@home transmitter. This vulnerability was reported by Med Sec Holdings (apparently the ‘MuddyWaters’ vulnerability?). St. Jude’s has produced a new software version to mitigate the vulnerability. ICS-CERT reports that an undisclosed third-party has verified the efficacy of the fix. The FDA has released a Safety Communication on the vulnerability.

ICS-CERT reports that a highly skilled attacker could remotely exploit this vulnerability to access or influence communications between Merlin.net and transmitter endpoints.

OSIsoft Advisory


This advisory describes an information exposure through server log files vulnerability in the OSIsoft PI Coresight and PI Web API products. OSIsoft reports that a customer (Vint Maggs from Savannah River Nuclear Solutions) identified the vulnerability (not mentioned in ICS-CERT Advisory). OSIsoft has reported workarounds to mitigate the vulnerability while it works on a software update.

ICS-CERT reports that anyone with access to the server file system could exploit this vulnerability. A successful exploit could lead to unauthorized shutdown of the affected PI services as well as potential reuse of domain credentials.

OSIsoft notes that the vulnerability exists only when the system is not installed using the installation defaults.

ICSJWG Spring Meeting


Yesterday ICS-CERT announced via a Tweet® that registration was open and a call for papers had been issued for the Spring 2017 ICSJWG meeting. Unfortunately, the tweet did not provide any links to the information and there is nothing yet listed on the ICS-CERT landing page about the meeting. The meeting web site is up with all of the requisite information.

The meeting will be held on April 11th – 13th, in Minneapolis, MN. Abstracts need to be submitted by February 10th, and advance registration closes April 6th.

House Passes HR 239 – Cybersecurity Research

Yesterday the House passed HR 239, the Support for Rapid Innovation Act of 2017 by a voice vote. The bill was considered under the suspension of the rules process with only 9 minutes of debate. It would require the DHS Science and Technology (S&T) directorate to support the conduct of a variety of cybersecurity research; including research on “technologies to reduce vulnerabilities in industrial control systems” {new 6 USC 321(b)(6)}.

This bill is nearly identical to HR 5388 that was passed in the House last June. It was never taken up in the Senate.

HR 239 shares the same shortcoming of the earlier bill, it specifically {§2(c)} does not include additional funding for the new research requirements. This means that the existing grant monies distributed by S&T for research will be diluted by any amount spent on cybersecurity research.


HR 5388 was introduced so late in the 114th Congress that the failure of the Senate to take up the bill does not signify any specific opposition to the bill. The calendar toward the end of the session was crowded with too many ‘must pass’ pieces of legislation that lower priority bills such as this were easily overlooked. I suspect that HR 239 will be taken up by the Senate under their unanimous consent process sometime in the coming weeks.

OMB Approves PHMSA Oil Volatility ANPRM

On Monday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved for publication an advanced notice of proposed rulemaking (ANPRM) submitted by DOT’s Pipeline and Hazardous Material Safety Administration. PHMSA is considering this rulemaking in response to a petition for rulemaking from the Attorney General of the State of New York.

The ANPRM that will probably be published in the Federal Register in the coming weeks will see information from the public and the regulated community on a variety of questions related to the appropriateness and use of Reid Vapor Pressure (RVP) testing and establishing a maximum RVP standard for shipping crude oil by rail.

The timing of this rulemaking may make for an interesting look at how the Trump Administration will look at the regulatory process for chemical transportation safety. It is generally assumed that the new administration will be very limited in its use of the regulatory process, rather letting ‘market forces’ control how businesses conduct their operations.

This ANPRM is likely to be published before the upcoming inauguration of Donald Trump as President. The public comment period will thus be started under the Obama Administration, but it will be Trump’s DOT Secretary (probably Elaine Cho) who makes the determination of whether to proceed with this rulemaking process or deny the petition for rulemaking.


Those political questions aside, there is still the technical question of the appropriateness of RVP sampling and testing. As I pointed out in an earlier blog post the results of RVP testing can  be extremely variable based upon differences in the sampling regime. If a vapor pressure standard is needed for crude oil shipments (and that is a political question), it would seem to be important that the method used to obtain that information should be the most reliable and replicable method. Hopefully, PHMSA will address this in their request for information in the ANPRM.

Monday, January 9, 2017

Committee Hearings – Week of 1-8-17

This week both the House and Senate will be in Washington, but there will only be a limited number of hearings being held, mainly focusing in the Senate on confirmation hearings. Two of those this week may be of specific interest to readers of this blog; confirmation hearings of DHS and DOT Secretaries.

DHS Secretary


On Tuesday, the Senate Homeland Security and Governmental Affairs Committee will be holding a hearing on the confirmation of General John F. Kelly, USMC (Ret.) to be the Secretary of the Department of Homeland Security. I suspect that we will be hearing some talk about cybersecurity matters, but it will be short on details.

DOT Secretary



On Wednesday, the Senate Commerce, Science and Transportation Committee will be holding a hearing on the confirmation of Elaine Chao to be the Secretary of the Department of Transportation. I suspect that there will be some mention of vehicle automation and chemical transportation safety issues, but again no details.

Thursday, January 5, 2017

ICS-CERT Published Two Rockwell Advisories

Today the DHS ICS-CERT published two control system security advisories for products from Rockwell Automation. Both advisories were previously published on the NCCIC Portal library (formerly US-CERT Secure Portal) to provide critical infrastructure owners time to implement mitigation measures before the vulnerabilities were publicly reported.

MicroLogix Advisory


This advisory describes two vulnerabilities in the Rockwell Allen-Bradley MicroLogix 1100 and 1400 programmable logic controller (PLC) systems. The vulnerabilities were reported by Alexey Osipov and Ilya Karpov of Positive Technologies. Rockwell has developed new firmware versions to mitigate the vulnerabilities. There is no indication that the researchers were provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Clear-text transmission of sensitive information - CVE-2016-9334; and
• Incorrect permission assignment for critical resource - CVE-2016-9338;

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to gain unauthorized access to affected devices, as well as impact the availability of affected devices.

Logix Advisory


This advisory describes a buffer overflow vulnerability in the Rockwell Automation Logix5000 Programmable Automation Controller product line. The vulnerability is apparently self-reported. Rockwell has developed new firmware versions to mitigate the vulnerability.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to cause a denial of service at a controller or execute code on a target controller.
 
/* Use this with templates/template-twocol.html */