Friday, March 16, 2018

Bills Introduced – 03-15-18


Yesterday with both the House and Senate preparing to leave for the weekend, there were 45 bills introduced. Of these on may be of specific interest to readers of this blog:

HR 5300 To provide agencies with discretion in securing information technology and information systems. Rep. Palmer, Gary J. [R-AL-6]

Okay, this clearly seems to be an IT security bill, and it probably does not include any OT provisions, and appears to be limited to government computer systems; so why am I including it here? The phrase ‘discretion in securing’ raises all sort of red flags that bear further investigation. This probably will not show up here again, but who knows what silliness congresscritters can come up with.

BTW: If you ever doubted the potential for congressional knee-jerk response, there were companion bills (HR 5315 and S 2556) introduced in the House and Senate yesterday to establish federal regulations prohibiting putting a live animal in an overhead bin on an aircraft (incident news story here).

Wednesday, March 14, 2018

ISCD Updates CFATS Monthly Update Page – 03-13-18


Yesterday the DHS Infrastructure Security Compliance Division (ISCD) updated their Chemical Facility Anti-Terrorism Standards (CFATS) Monthly Update page reflecting the changes in the implementation of the CFATS program that apparently took place last month (there is no effective date given for the data). The numbers continue to show progress in the implementation and compliance verification efforts of ISCD.

ISCD Activities


The table below shows the reported numbers for the key activities undertaken by ISCD in support of the implementation of the CFATS program.

CFATS Activities
Jan-18
Feb-18
Authorization Inspections to Date
3225
3352
Authorization Inspections Month
97
133
Compliances Inspections to Date
3176
3249
Compliances Inspections Month
63
79
Compliance Assistance Visits to Date
3873
4007
Compliance Assistance Visits Month
122
172

We continue to see an increase in the number of Authorization Inspections being conducted as more of the newly added facilities from the CSAT 2.0 process move through the Site Security Plan submission process. This number should level off and then decline in the coming months as more facilities move into the program compliance stage.

Facility Status


The table below shows the status of the facilities currently covered by the CFATS program. Note: there were two typographical errors on the web page table; the ‘authorized number’ was shown as ‘6665’ and the ‘total’ was shown as ‘4007’.

CFATS Facility Status
Jan-18
Feb-18
Tiered
576
474
Authorized
600
665
Approved
2339
2345
Total
3515
3485

The numbers for tiered facilities continues to go down as these newly tiered facilities move through the CFATS implementation process. The numbers for authorized facilities reflect the movement of facilities through the site security plan implementation process.

The total number of covered facilities shows an apparently increasing number of facilities leaving the CFATS program. I would assume, however, that the earlier months increases in the total numbers, reflecting the new facilities being added by the CSAT 2.0 implementation, masked a substantial number of facilities leaving the program. Facilities have substantial financial incentives to exit the program and there are a number of legitimate methods of risk reduction/elimination that facilities can employ that would allow them to exit the program.

Commentary


ISCD does not include, what is to my mind, a very important statistic in their monthly report; the results of the compliance inspections that have been conducted by the Chemical Security Inspectors. I expect that we will be seeing a new report from either the Congressional Research Office or the Government Services Agency as part of the Congressional review of the program leading to a reauthorization decision later this year. That report should cover the compliance inspection results data.

ICS-CERT Publishes 5 Advisories


Yesterday the DHS ICS-CERT published a medical device security advisory for products from GE. They also published four control system security advisories for products from OSIsoft (3) and Omron. The GE advisory was originally published on the secure HSIN ICS-CERT library on February 6, 2018.

GE Advisory


This advisory describes an improper authentication vulnerability in a number of GE healthcare products. The vulnerability was reported by Scott Erven. GE has produced updates for all but three of the products that mitigate the vulnerability. There is no indication that Erven has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to bypass authentication and gain access to the affected devices.

Interestingly, these vulnerabilities were reported to ICS-CERT in 2015 and advisories were subsequently issued (SB 15-222) by US-CERT. Forbes reported on the issue in 2015 and a presentation was made by Erven at Shakacon (see Dale Peterson’s Tweet) about the issues the same year. I cannot understand why a secure posting about the vulnerability was justified or why it took almost three years to fix the problem. Oh, the FDA has not published anything about these vulnerabilities on the Device Safety page (either for 2015 or 2018). BTW: Rocky and Bullwinkle fans, take a close look at the URL for the 2015 Safety Communications page.

PI Web API Advisory


This advisory describes two vulnerabilities in the OSIsoft Web API. OSIsoft is self-reporting these vulnerabilities. They have provided an update that mitigates the vulnerability.

The two reported vulnerabilities are:

• Permissions, privileges and access controls - CVE-2018-7500; and
Improper neutralization of input during web page generation - CVE-2018-7508

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow escalated privileges and may allow remote code execution.

PI Vision Advisory


This advisory describes two vulnerabilities in the OSIsoft PI Vision. These vulnerabilities are self-reported. OSIsoft has an update available that mitigates the vulnerabilities.

The two reported vulnerabilities are:

• Protection mechanism failure - CVE-2018-7504; and
• Information exposure - CVE-2018-7496

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution and expose information.

NOTE: I reported on these vulnerabilities last month when OSIsoft first published their advisory. The OSIsoft alert notes that there are two separate information exposure vulnerabilities, but OSIsoft does not publish CVE numbers so it is not easy to tell if there is an actual discrepancy here.

PI Data Archive Advisory


This advisory describes three vulnerabilities in the OSIsoft PI Data Archive. These vulnerabilities are being self-reported by OSIsoft. They have an update available that mitigates the vulnerabilities.

The three reported vulnerabilities are:

• Deserialization of untrusted data - CVE-2018-752;
• Incorrect default permissions - CVE-2018-7533; and
• Improper input validation - CVE-2018-7531

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause loss of network access to the device or allow escalated privileges that may result in gaining full control of the PI Data Archive server.

NOTE: I reported on these vulnerabilities last month when OSIsoft first published their advisory.

Omron Advisory


This advisory describes seven vulnerabilities in the Omron CX-Supervisor. The vulnerabilities were reported by rgod via the Zero Day Initiative. Omron has released a new version that mitigates the vulnerability. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

The seven reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-7513;
• Use after free - CVE-2018-7521;
• Access of uninitialized pointer - CVE-2018-7515;
• Double free - CVE-2018-7523;
• Out-of-bounds write - CVE-2018-7517;
• Untrusted pointer dereference - CVE-2018-7525; and
• Heap based buffer overflow - CVE-2018-7519

ICS-CERT reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to allow remote code execution.

CFATS Penalty Documents Published


Yesterday the DHS Infrastructure Security Compliance Division updated their Chemical Facility Anti-Terrorism Standards (CFATS) Knowledge Center with a news item pointing to links to two documents related to CFATS penalty assessments. The “Policy for Assessing a Civil Penalty under the Chemical Facility Anti-Terrorism Standards” and the accompanying fact sheet appear to be the same documents (same policy number and publication dates) that were published on the CFATS web site last year. That web page is still active, but it is not listed on the CFATS landing page.

Tuesday, March 13, 2018

Not a Markup Hearing


Well, it turns out that the Energy Subcommittee hearing on the four DOE emergency response and security bills is not a mark-up hearing after all. Last night the witness list was announced, so it seems as if this will be an information gathering hearing with a possible mark-up at some later date.

Updated Hearing Information


The witness list includes:

Mark Menezes, US Department of Energy;
Scott Aaronson, Edison Electric Institute;
Mark Engels, Dominion Energy;
Kyle Pitsor, National Electrical Manufacturers Association;
Zachary Tudor, Idaho National Laboratory; and
Tristan Vance, Indiana Office of Energy Development

The links provided above are to the witness testimony that will be presented at tomorrow’s hearing. The Sub-Committee staff has also produced a background document for the meeting.

Interesting Info in Testimony


Menezes notes that (pg 1):

“To demonstrate our focus on the aforementioned mission [to protect the Nation’s critical energy infrastructure from physical security events, natural and man-made disasters, and cybersecurity threats], the Secretary announced last month that he is establishing an Office of Cybersecurity, Energy Security, and Emergency Response (CESER). This organizational change will strengthen the Department’s role as the Sector-Specific Agency (SSA) for Energy Sector Cybersecurity, supporting our national security responsibilities.”

Menezes also notes that (pg 6):

“Advancing the ability to improve situational awareness of OT networks is a key focus of DOE’s current activities. The Department is currently in the early stages of taking the lessons learned from CRISP and developing an analogous capability for threat detection on OT networks via the Cybersecurity for the Operational Technology Environment (CYOTE) pilot project. Observing anomalous traffic on networks – and having the ability to store and retrieve network traffic from the recent past – can be the first step in stopping an attack in its early stages.”

Engels notes that (pg 3):

“A more expedient [coordinating security activities of DOT and TSA] approach may be to encourage a Memo of Understanding (MOU)between DOE and TSA that outlines roles and responsibilities for dealing with cyber and physical security for the ONG sector. TSA already has an MOU with the DOT’s Pipeline and Hazardous Materials Safety Administration (PHMSA) which has responsibility for pipeline safety. Depending on the type of event, the TSA/DOT MOU has been critical in helping operators understand which Federal entity is the lead agency.”

Engels also notes that (pg 8):

“In 2016, TSA, again working with asset owners, industry associations, and the Department of Homeland Security’s Industrial Control System’s Cyber Emergency Response Team (DHS ICS-CERT), gathered input to update the Guidelines using the National Institute of Standards and Technology’s (NIST) Cyber Security Framework as a model. The updated [Pipeline Security] Guidelines are scheduled for release in the first half of 2018. Industry also provided input to augment the set of cybersecurity questions used in the Corporate Security Reviews (CSR) conducted by TSA.”

Engels also notes that (pgs 12-13):

“INL has undertaken several initiatives to stand up test environments for Industrial Control Systems (ICS). One such initiative was called RENDER (Risk Evaluation Nexus for Digital Age Energy Reliability). RENDER created a three way sharing arrangement involving the lab, the vendor and the asset owner. Previous projects excluded the asset owner from the equation, creating uncertainty associated with remediation of the vulnerabilities identified by INL. With RENDER, the asset owner not only could see what vulnerabilities were discovered, but provide input to the vendor about how critical or not the vulnerability was to the asset owner. This allowed the vendor to prioritize corrections that made the most sense to the asset owners.”

Tudor notes that (pg 4):

“INL developed and completed an initial pilot study of our proprietary Consequence driven, Cyber-informed Engineering (CCE) methodology with Florida Power and Light (FPL) through a Cooperative Research and Development Agreement (CRADA). CCE was developed to address the realization that constantly “chasing” threats and vulnerabilities, rather than getting ahead of these problems, is not sufficient to secure our critical systems. CCE is designed to assist asset owners in understanding the most effective and immediate actions they can take to eliminate the opportunity of the “worst-case” cyber-physical impacts from an attack by the most capable cyber adversaries. CCE leverages an organization’s knowledge and experiences with their systems and processes to “engineer out” the potential for the highest consequence events.”

This could be an interesting hearing.

Monday, March 12, 2018

HR 5175 Introduced – Pipeline Security


Last week Rep. Upton (R,MI) introduced HR 5175, the Pipeline and LNG Facility Cybersecurity Preparedness Act. The bill would require the Secretary of Energy to establish policies and procedures for the physical security and cybersecurity for pipelines and liquefied natural gas facilities.

Requirements


The bill would require the Secretary to {§2}:

• Establish policies and procedures to coordinate Federal agencies, States, and the energy sector to ensure the security, resiliency, and survivability of natural gas pipelines (including natural gas transmission and distribution pipelines), hazardous liquid pipelines, and liquefied natural gas facilities;
• Coordinate response and recovery by Federal agencies, States, and the energy sector, to physical incidents and cyber incidents impacting the energy sector;
• Develop advanced cybersecurity applications and technologies for natural gas pipelines (including natural gas transmission and distribution pipelines), hazardous liquid pipelines, and liquefied natural gas facilities;
• Perform pilot demonstration projects relating to physical security and cybersecurity for natural gas pipelines (including natural gas transmission and distribution pipelines), hazardous liquid pipelines, and liquefied natural gas facilities with representatives of the energy sector;
• Develop workforce development curricula for the energy sector relating to physical security and cybersecurity for natural gas pipelines (including natural gas transmission and distribution pipelines), hazardous liquid pipelines, and liquefied natural gas facilities; and
Provide mechanisms to help the energy sector evaluate, prioritize, and improve physical security and cybersecurity capabilities for natural gas pipelines (including natural gas transmission and distribution pipelines), hazardous liquid pipelines, and liquefied natural gas facilities.

Moving Forward


Upton is the Chair of the Energy Subcommittee of the House Energy and Commerce Committee. The bill is scheduled for markup on Wednesday. The bill will probably pass in both the Subcommittee and subsequent full Committee markup with substantial bipartisan support.

The main problem with this bill is that there will likely be substantial opposition from the Chair of the Homeland Security Committee since the Transportation Security Administration (over which Homeland Security has jurisdiction) already has official responsibility for security of pipeline operations. Not that the TSA has done much (nor have they been authorized to do much) about pipeline security beyond publishing security guidelines and conducting courtesy (without enforcement authority) inspections.

There is also likely to be opposition from the Transportation and Infrastructure Committee since that Committee has jurisdiction over the DOT’s Pipeline and Hazardous Material Safety Administration’s oversight of the safe operations of the pipelines covered in this bill. Many of the provisions of this bill directly impact safe operations as well as secure operations.

These intra-party conflicts between committee chairs will probably prevent this bill from reaching the floor of the House.

Commentary


This is another apple pie and motherhood bill that ‘shows’ that Congress is taking pipeline security (specifically including cybersecurity) seriously without allowing the executive branch to issue any regulations that would require industry to comply. It would eventually allow industry to work with DOE in the establishment of the policies and procedures without having to worry about spending a penny more than they thought necessary for protecting their investments.

The other major problem with this bill is that there is no authorization of funds or personnel to carry out these objectives. While it may be possible to establish ‘policies and procedures’ with no additional funding (as long as you have no timetable to meet), the development of ‘advanced cybersecurity applications and technologies’ requires unique expertise and research funding. Anything that is done in this area (and work does need to be done) will come at the expense of other DOE programs.

HR 5174 Introduced – DOE Cybersecurity Responsibilities


Last week Rep. Walberg (R,MI) introduced HR 5174, the Energy Emergency Leadership Act. The bill would generally set the Department responsibilities for energy emergency response and energy cybersecurity.

Responsibilities


The bill amends 42 USC 7133 which identifies the general function of the eight Assistant Secretaries in the Department of Energy. It adds a twelfth activity; energy emergency and energy security functions. These include “responsibilities with respect to infra9
structure, cybersecurity, emerging threats, supply, and emergency planning, coordination, response, and restoration” {§7133(a)(12(A)}. This also encompasses responsibility for providing, upon request, “technical assistance, support, and response capabilities with respect to energy security threats, risks, and incidents" {§7133(a)(12(B)} to State, local, or tribal governments or energy sector entities.

Moving Forward


This bill is currently scheduled for markup on Wednesday. Walberg’s cosponsor {Rep. Rush (D,IL) is the Ranking Member of the Energy Subcommittee to which this bill has been assigned for consideration. This almost certainly means that this bill will receive substantial bipartisan support in Wednesday’s hearing, future Energy and Commerce Committee hearings and probably on the floor of the whole House. There is nothing in this bill that would drive significant opposition.

Commentary


The one thing that is certainly missing from this bill is an effective definition of ‘cybersecurity’. Because of the nature of scope of DOE operations, the definition would clearly need to include operations technology and its attendant control systems. Again, this bill would be a good place to add the definitions that I have previously proposed (here for example). I would add a new paragraph (c):

(c) Definitions- In this chapter (42 USC Chapter 84, Department of Energy) the following definitions apply:

(1) The term ‘information system’ has the meaning given the term in section 3502 of title 44;

(2) The term ‘control system’ means a discrete set of information resources, sensors, communications interfaces and physical devices organized to monitor, control and/or report on physical processes including but not limited to; energy production, transportation, access control, and facility environmental controls;

(3) The term ‘cybersecurity risk’ means:

(A) threats to and vulnerabilities of information, information systems, or control systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of such information, information systems, or control systems, including such related consequences caused by an act of terrorism; and

(B) does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement;

(4) The term ‘incident’ means an occurrence that actually, or imminently jeopardizes, without lawful authority:

(A) the integrity, confidentiality, or availability of information on an information system,

(B) the timely availability of accurate process information, the predictable control of the designed process or the confidentiality of process information, or

(C) an information system or a control system;

This would then require changing the word ‘cybersecurity’ in paragraph 12(A) to ‘cybersecurity risk’. This would ensure that the assigned Assistant Secretary was focused on the risk to information systems and control systems, not the mechanics of system security.

 
/* Use this with templates/template-twocol.html */