Wednesday, April 12, 2017

ICS-CERT Publishes BrickerBot Alert

Today the DHS ICS-CERT published a control system security alert today about a new botnet attack that affects IOT devices. The attack bricks the affected devices, thus the name, BrickerBot. ICS-CERT identifies Radware as the initial source of the report on BrickerBot and provides a link to their BrickerBot report (originally published a week ago).

ICS-CERT provides the following summary of the two BrickerBot versions (BrickerBot 1 affects Ubiquiti devices and BrickerBot 2 affects Android devices):

• BrickerBot.1 targets devices running BusyBox with an exposed SSH command window and an older version of Dropbear SSH server. Most of these devices were also identified as Ubquiti network devices, some of which are access points or bridges with beam directivity.
• BrickerBot.2 targets Linux-based devices which may or may not run BusyBox or use Dropbear SSH server. However, Brickerbot.2 can only access devices which expose a Telnet service protected by default or hard-coded passwords.


ICS-CERT is working to identify affected devices and will work with vendors to see what equipment specific mitigation measures (if any) will be used to mitigate this vulnerability.

Tuesday, April 11, 2017

ICS-CERT Publishes Schneider Advisory

Today the DHS ICS-CERT published a control system security advisory for Schneider Modicon PLCs. The advisory describes two vulnerabilities that were reported by Eran Goldstein of CRITIFENCE. These are not the vulnerabilities that I briefly described on Saturday. Schneider has developed compensating controls to mitigate the vulnerability. There is no indication that Goldstein was provided the opportunity to verify the efficacy of the fix. There are no indications that Schneider intends to produce a more permanent fix to these vulnerabilities.

The two reported vulnerabilities are:

• Authentication Bypass by Capture-Replay - CVE-2017-6034; and
• Violation of Secure Design Principles - CVE-2017-6032

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to capture and replay sensitive commands to PLCs on a network using the Modicon Modbus protocol.


The Schneider security notification also mentions that SCADA/ICS Cyber Threats Research Group contributed to the identification of these vulnerabilities.

Reader Question - Material Modifications

I had an interesting question sent to me by a long time reader of this blog concerning the term ‘material modifications’ as it is used in 6 CFR 27.210(d). That Chemical Facility Anti-Terrorism Standards (CFATS) requirement states that: “If a covered facility makes material modifications to its operations or site, the covered facility must complete and submit a revised Top-Screen to the Department within 60 days of the material modification.” The reader asks if the term ‘material modifications’ is defined in the CFR.

No Definition


The short answer is no. This is one of many definitions missing from the CFATS rule. In this case, I suspect that the reason is that there is no specific definition that would fit the situation. The issue was discussed, however, in the preamble to the interim final rule that established the CFATS program. We can see that discussion in response to a specific public request for a definition of the term:

“Material modifications can include a whole host of changes, and for that reason, the Department cannot provide an exhaustive list of material modifications. In general, though, DHS expects that material modifications would likely include changes at a facility to chemical holdings (including the presence of a new chemical, increased amount of an existing chemical, or the modified use of a given chemical) or to site physical configuration, which may (1) substantially increase the level of consequence should a terrorist attack or incident occur; (2) substantially increase a facility’s vulnerabilities from those identified in the facility’s Security Vulnerability Assessment; (3) substantially effect the information already provided in the facility’s Top-Screen submission; or (4) substantially effect the measures contained in the facility’s Site Security Plan.”

Change in Chemical Holdings


The most obvious change in chemical holdings that would be considered a material modification would be the introduction of a new DHS chemical of interest (COI) found in Appendix A to 6 CFR 27. Even if the new COI were not held at a screening threshold quantity (STQ) the addition could still qualify as a material modification if the addition met one of the four standards listed in the preamble discussion.

An inventory increase in one or more of the existing COI reported on the most recent Top Screen could also be considered a material modification that triggers a new Top Screen submission requirement. How much of an increase would be a trigger the requirement would depend on the chemical in question. A one pound increase in propane (Release – Flammable) would almost certainly not be a trigger while a one pound increase in Chlorosarin (Theft - CW) would almost certainly trigger the requirement. Again, the four standards would provide guidance on how much is significant.

The addition of non-COI chemicals to facility chemical holdings is even more complicated. The addition of a new flammable liquid in sizeable quantities could increase the size of a potential conflagration at a facility holding flammable-release COI. The addition of another potential (but unlisted) precursor to a chemical weapon could make it easier for a terrorist to manufacture that chemical weapon as a result of a successful attack on the facility. Once again, the four standards are what establishes the existence of a material modification.

Facility Configuration


Changes to the physical structure or operation of a CFATS covered facility could certainly be considered a material modification. Which changes would trigger the new Top Screen reporting requirements would depend on the facility and the COI holdings at that facility.

At a facility with holdings of theft-diversion COI anything that increases the traffic through the facility would almost certainly be considered a material modification. This could include construction activities, changes in the number of contractors on site, or even changes in the number of pick-ups and deliveries at the site. Again, the four standards listed in the preamble will determine which changes trigger the reporting requirement.

Decreased Risk


Facilities also need to remember that the material modification requirement is not limited to changes that increase the risk of terrorist attack at the facility. Changes that decrease risk can also trigger the reporting requirement. The folks at the Infrastructure Security Compliance Division (ISCD) are certainly not going to fine a facility for failing to report changes that reduce risk, but ISCD could lower the facility Tier ranking or even remove a facility from CFATS coverage when material modifications produce significant reductions in the risk of terrorist attack.

Always Consider Material Modification


Just about any change at a facility could have an effect on the security of the facility. CFATS covered facilities have a legal obligation to take a specific look at any changes in facility structure, operation or chemical holdings. This should be a part of the standard management of change process at the facility. Facility management needs to consider the chance that any changes made to the facility may trigger additional security requirements (and the associated costs) if the changes:

• Substantially increase the level of consequence should a terrorist attack or incident occur;
• Substantially increase a facility’s vulnerabilities from those identified in the facility’s Security Vulnerability Assessment;
• Substantially effect the information already provided in the facility’s Top-Screen submission; or
• Substantially effect the measures contained in the facility’s Site Security Plan.


If there are questions about a pending change the simplest thing to do is to ask DHS if they think that a change would be considered a material modification at the facility. For major (read costly) changes at a facility, the earlier the question is asked the better. Remember, the cost of any necessary security changes should be included in estimating costs for any facility modification.

Monday, April 10, 2017

ICS-CERT Updated MEMS Accelerometer Alert

Today the DHS ICS-CERT updated their control system security alert for physical vulnerabilities in a wide variety of MEMS accelerometers. The original alert was published on March 14th, 2017.

Today’s update provides a link to another manufacturer’s (Analog Devices) alert about the problem with a slightly different look at the vulnerability.


Interestingly, ICS-CERT still does not provide acknowledgement of researchers who discovered the vulnerability nor does it provide a link to their academic paper that describes the vulnerability. Nor does it mention the cute vulnerability name that has been attached to the problem by the researchers; ‘Walnut’. I guess that ICS-CERT is the tough nut to crack.

Bills Introduced – 04-07-17

With just the Senate in session there were 37 bills introduced on Friday. Of those only one may be of specific interest to readers of this blog:

S 904 A bill to amend the Homeland Security Act of 2002 to authorize the National Computer Forensics Institute, and for other purposes. Sen. Grassley, Chuck [R-IA]


This bill is probably a companion bill to HR 1616 which I have not covered since it does not include industrial control system inclusive language. That will probably be the fate of this bill as well.

Sunday, April 9, 2017

DHS Publishes Another CFATS ICR Revision

The DHS National Protection and Programs Directorate (NPPD) published another information collection (ICR) revision notice in Monday’s (available on-line yesterday) Federal Register (82 FR 17270-17273) supporting the Chemical Facility Anti-Terrorism Standards (CFATS) program. The requested revisions are due, in part, to the recent changes made to the Chemical Security Assessment Tool (CSAT) now known as CSAT 2.0.

The ICR (1670-0014) covers information collected via the following CFATS activities:


The changes reported here are all relatively innocuous and reflect bureaucratic i-dotting and t-crossing more than any shift in policy or procedures. Normally, I would not have mentioned this ICR notice at all (hardly newsworthy), but given the problems that I have identified with another ICR revision notice (from the TSA) I thought that I would mention this ICR notice and hold it out as an example of an agency providing detailed enough information for members of the public and affected community to be able to formulate an effective comment on the substance of the burden estimate provided by the agency.

The earlier TSA proforma ICR notice provided less than the minimum necessary information and left me with a better understanding of the agency’s reputation for blatant disregard of public opinion. That TSA notice, and their reply to my comment, clearly explicated to anyone that cared to listen that the TSA does not care how their activities affect those that they are supposed to be supporting.


DHS, and yes even the OMB’s Office of Information and Regulatory Affairs, could be well served by using this NPPD ICR notice as a teaching guide as to how a public ICR notice should be prepared and the earlier TSA notice as a counter-example.

Saturday, April 8, 2017

Public ICS Vulnerability Disclosure – Week of 04-02-17

This week there were three public control system security vulnerability disclosures; two published on the Full Disclosure web site and one on SecurityWeek.com. The affected devices include data loggers, network connection devices and PLCs.

PLCs


On Wednesday Eduard Kovacs published an article about twin vulnerabilities in the Schneider Electric Modicon programmable logic controllers (PLCs) that were reported by Simon Heming, Maik Brüggemann, Hendrik Schwartke, Ralf Spenneberg of OpenSource Security. The reported vulnerabilities were:

• Hardcoded encryption key; and
• Password sent in clear text

Schneider received notification of the vulnerabilities back in December, but some snafu occurred and no action was taken. OpenSource published the vulnerabilities on their web site (here and here) on Tuesday.

NOTE: I tweeted about this vulnerability on Wednesday.

Data Logger


On Thursday Karn Ganeshen announced multiple vulnerabilities in data loggers, meter monitors and electric meters from SenNet. The reported vulnerabilities are:

• No access control on the remote shell;
• Shell services running with excessive privileges;
• OS command injection (with POC); and
• Insecure transport

Ganeshen reported that the vendor has fixed the vulnerabilities and ICS-CERT will be issuing an advisory.

Network Connection Devices


On Thursday Karn Ganeshen announced SNMP vulnerabilities in network communication equipment from Cambium. The reported vulnerabilities are:

• SNMP community strings privileges are not enforced correctly;
• Device configuration backups – access control issues; and

Ganeshen also reports that the Cambium devices are also subject to the following design flaws that magnify the above vulnerabilities:

• It is possible to access full device configuration using SNMP. Device configuration includes usernames, passwords, SSIDs, keys, certificates, syslog config, and other network & wifi specific details.
• It is possible to trigger configuration backups, which can then be retrieved using SNMP.
• It is possible to wipe out and / or make changes to the device configuration remotely.


Ganeshen reports that ICS-CERT was notified on September 12th, 2016 and on April 5th Cambium announced that the vulnerabilities would be fixed in 2nd Quarter 2017.
 
/* Use this with templates/template-twocol.html */