Today the DHS Infrastructure Security Compliance Division
(ISCD) opened the registration
site for their DHSChemSecurityTalks
– West regional meeting. The meeting
will be held at the Ronald V. Dellums Federal Building, in Oakland, CA, on June
27th, 2018. The registration site includes preliminary
agenda information. This is a no cost event with no web cast. Registration
is required and there is limited seating.
Thursday, May 17, 2018
NRC Withdraws Cybersecurity Rulemaking
Yesterday the Nuclear Regulatory Commission (NRC) published
a notice in the Federal Register (83 FR
22413-22414) announcing that they were discontinuing their rulemaking
activities on “Cyber Security for Byproduct Materials Licensees” (RIN
3150-1756). This rulemaking first
appeared in the Unified Agenda during the Obama Administration in the
long-term actions section. It was moved to the Active
Agenda in the Spring of 2017 and then back to the long-term actions in the most
recent agenda.
Background
The Byproduct Materials
Cyber Security Working Group was formed in 2013 to look into the potential
need for a cybersecurity rulemaking for facilities that stored Category 1 or
Category 2 quantities of radioactive material (does not include the radioactive
material contained in any fuel assembly, subassembly, fuel rod, or fuel pellet;
see 10
CFR 37.5).
The working group identified four sets of digital assets
that the NRC should evaluate with respect to cyber threat protection:
• Digital/microprocessor-based
systems and devices that support the physical security of the licensee's
facilities. These include access control systems, physical intrusion detection
and alarm systems, video camera monitoring systems, digital video recorders,
door alarms, motion sensors, keycard readers, and biometric scanners;
• Equipment and devices with
software-based control, operation, and automation features, such as panoramic
irradiators and gamma knives;
• Computers and systems used to
maintain source inventories, audit data, and records necessary for compliance
with security requirements and regulations; and
• Digital technology used to support incident
response communications and coordination such as digital packet radio systems,
digital repeater stations, and digital trunk radio systems.
The most recent, publicly-available document (Update to the
U.S. Nuclear Regulatory Commission Cyber Security Roadmap, ML15201A509,
2-28-17) noted that (pg 7):
“The working group plans to
complete its evaluation of the [180] questionnaire [sent to all NRC and
Agreement State licensees that possess Categories 1 and 2 quantities of
radioactive Materials] responses, its consequence analysis, and any follow-up
communication with stakeholders in early 2017. As a result, the working group
intends to develop recommendations for a path forward by spring/summer 2017.”
Question: Why does the NRC still use antiquated on-line
tools to provide access to public documents? Why can I not provide a link to
the document listed above? The NRC does not provide links to their documents.
NRC Conclusion
The NRC staff completed its evaluation in October 2017 and concluded that:
“The NRC staff concluded that
byproduct materials licensees that possess risk-significant quantities of
radioactive material do not rely solely on digital assets to ensure safety or
physical protection. Rather, these licensees generally use a combination of
measures, such as doors, locks, barriers, human resources, and operational
processes, to ensure security, which reflects a defense-in-depth approach to
physical protection and safety. As a result, the staff concluded that a
compromise of any of the digital assets identified in the January 6, 2016,
Commission memorandum would not result in a direct dispersal of
risk-significant quantities of radioactive material, or exposure of individuals
to radiation, without a concurrent and targeted breach of the physical
protection measures in force for these licensees.”
Based upon that recommendation, the NRC is discontinuing
rulemaking activity to develop cyber security requirements for byproduct
materials licensees possessing risk-significant quantities of radioactive
materials.
Commentary
Since I have not seen (and probably never will see for
legitimate security reasons) the final NRC staff report, it is hard to draw any
hard conclusions about the decision reached by the NRC.
Having said that, I see little in the language in this
announcement that provides me with any level of comfort that the Commission
took a hard look at anything beyond the immediate security of these materials.
There is no language that would indicate that operational security (the
security of the devices that manipulate or move the covered materials) has been
adequately addressed.
Additionally, since these materials are ideally suited to
employment in weapons of mass confusion (radiologically enhanced improvised
explosive devices), I am also concerned about the security of information
systems that deal with the ordering and shipping of these commercial products.
The diverted delivery of legitimate shipments via electronic changes in orders
or shipping documents provide a legitimate scenario for terrorists to acquire
the material necessary to build a radiological dispersion device (‘dirty
bomb’).
Again, the NRC and its staff may very well have looked at
these potential vulnerabilities, but there is nothing in this announcement that
provides any indication that this is so. Perhaps this is something that
Congress out to take a look at.
Wednesday, May 16, 2018
Bills Introduced – 05-15-18
Yesterday with both the House and Senate in session there
were 71 bills introduced (a lot of opioid legislation in the House). Of those,
there are three that may be of specific interest to readers of this blog:
HR
5822 To establish a National Office for Cyberspace, and for other purposes.
Rep.
Langevin, James R. [D-RI-2]
HR
5823 To prohibit Federal agencies from mandating the deployment of
vulnerabilities in data security technologies. Rep.
Lofgren, Zoe [D-CA-19]
S
2840 A bill to require a strategic plan to improve capabilities of
Department of Defense training ranges and installations. Sen.
Rounds, Mike [R-SD]
Definitions in the two House-bills will determine whether or
not they will be followed here. The NOC bill has the best chance, but the
encryption back door bill could include ICS inclusive definitions.
There is an outside chance that the Senate bill actually
refers to, or includes, ‘cyber ranges’.
Tuesday, May 15, 2018
ICS-CERT Publishes Advantech Advisory and Updates Siemens Advisory
Today the DHS ICS-CERT published a control system security
advisory for products from Advantech. They also updated a previously issued
advisory for products from Siemens.
Advantech Advisory
This advisory
describes eleven vulnerabilities in the Advantech WebAccess products. The
vulnerabilities were reported by Mat Powell and rgod, working with ZDI; Steven
Seeley of Offensive Security, working with ZDI; and Donato Onofri and Simone
Onofri of Business Integration Partners S.p.A. Advantech released a new version
that mitigates the vulnerabilities. There is no indication that any of the
researchers were provided an opportunity to verify the efficacy of the fix.
The eleven reported vulnerabilities are:
• SQL injection - CVE-2018-7501;
• Information exposure through
directory listing - CVE-2018-10590;
• Improper authorization - CVE-2018-7505;
• Path traversal (2) - CVE-2018-7503,
and CVE-2018-10589;
• Stack-based buffer overflow - CVE-2018-7499;
• Heap-based buffer overflow - CVE-2018-8845;
• Untrusted pointer dereference - CVE-2018-7497;
• External control of file name or
path - CVE-2018-7495;
• Origin validation error - CVE-2018-10591;
and
• Improper privilege management - CVE-2018-8841
ICS-CERT reports that a relatively low-skilled attacker
could remotely exploit the vulnerabilitie to disclose sensitive information
from the host and/or target, execute arbitrary code, or delete files.
Siemens Update
This update
provides additional information for an advisory that was originally
published on May 9th, 2017 and updated on
June 15, 2017,on July
25th, 2017, on August
17th, 2017, on October
10th, on November
14th, November
28th, February
27th, 2018 and most recently on May
3rd, 2018. The new information includes links to new versions
for version 4.7 of:
• SINAMICS G130;
• SINAMICS G150;
• SINAMICS S120; and
• SINAMICS S150
The Siemens security advisory provided undated version
information for the same products, but that was not reported in the ICS-CERT
advisory
NOTE: Siemens also reported two other updated advisories (here and here) and
a new advisory (here)
today when they reported this update. Hopefully ICS-CERT will publish their
versions later this week.
Bills Introduced – 05-14-18
Yesterday with just the Senate in session (the House returns
to Washington today) there were three bills introduced. One of those bills may
be of specific interest to readers of this blog:
S 2836
A bill to assist the Department of Homeland Security in preventing emerging
threats from unmanned aircraft and vehicles, and for other purposes. Sen.
Johnson, Ron [R-WI]
It is interesting that the bill will address “unmanned
aircraft and vehicles”;
definitions will be a key point in this bill.
Monday, May 14, 2018
Committee Hearings – Week of 05-13-18
With both the House and Senate in session this week we see
both bodies working on must complete issues; spending and the National Defense
Authorization Act (NDAA). We will also see a markup hearing dealing with our
ICS cybersecurity bill.
Spending Bills
The House Appropriations Committee is fully into the
spending bill markup process. The Full Committee will mark-up the FY 2019
Energy and Water and Agriculture, Rural Development, Food and Drug
Administration, and Related Agencies Appropriations Bill on Wednesday.
Subcommittee mark-ups of possible interest here this week include:
• FY 2019 Interior, Environment,
and Related Agencies Appropriations Bill – Tuesday; and
• FY 2019 Transportation, and
Housing and Urban Development (THUD), and Related Agencies Appropriations Bill –
Wednesday
The Senate Appropriations Committee subcommittees are still
looking at the details of the respective budget requests, so they are a tad bit
behind the House on the bill writing schedule. That is not a significant
problem as the House has to consider spending bills before the Senate can act
on them. The Appropriations Committee will have language ready by the time the
House bills make it to the Senate even if they do not have their own bill
introduced.
NDAA
The House Armed Services Committee finished their mark-ups
of HR 5515 last week and ordered the bill reported to the House. I expect to
see an official version of the bill published this week. The House Rules
Committee has announced that it is accepting proposed amendments to the bill
through Thursday morning. This means that it will probably be considered on the
floor of the House next week.
The Senate Armed Services Committee is starting the mark-up
process for their version of the NDAA (not yet introduced) this week with
subcommittee mark-ups. The Subcommittees of potential interest here include:
• Subcommittee on Cybersecurity;
and
• Subcommittee on Emerging Threats
Both will hold their mark-ups on Tuesday. Both will be
closed hearings.
Cybersecurity Mark-Up
On Wednesday the House Homeland Security Committee will be
holding a mark-up hearing to consider nine bills. HR
5733, the DHS Industrial Control Systems Capabilities Enhancement Act of
2018, is one of the bills being considered. No word yet on any possible
amendments.
Sunday, May 13, 2018
HR 5733 Introduced – ICS Cybersecurity
Last week Rep Bacon (R,NE) introduced HR
5733, the DHS Industrial Control Systems Capabilities Enhancement Act of 2018
(Note: the link is to a Committee draft of the bill not the official GPO
version). The bill would amend 6 USC 148 to provide specific requirements for
the National Cybersecurity and Communications Integration Center (NCCIC) to
address industrial control system security issues.
Section 148 Amendments
The bill would make two specific amendments to §148. First it would add
to the list of principles outlined in paragraph (3)(1) the following language: “activities
of the Center address the security of both information technology and operational
technology, including industrial control systems;”.
Second the bill would add a new paragraph (f) that would
require the NCCIC to “maintain capabilities to identify and address threats and
vulnerabilities to products and technologies intended for use in the automated
control of critical infrastructure processes.” This would specifically include requirements
to:
• Lead, in coordination with
relevant sector specific agencies, Federal Government efforts to identify and
mitigate cybersecurity threats to industrial control systems, including
supervisory control and data acquisition systems;
• Maintain cross-sector incident
response capabilities to respond to industrial control system cybersecurity
incidents;
• Provide cybersecurity technical
assistance to industry end-users, product manufacturers, and other industrial
control system stakeholders to identify and mitigate vulnerabilities; and
• Conduct such other efforts and assistance as the
Secretary determines appropriate.
Moving Forward
Bacon and both of his cosponsors {Rep. McCaul (R,TX) and
Rep. Ratcliff (R,TX)} are members of the House Homeland Security Committee to
which this bill was assigned. The bill is currently scheduled to be marked-up
by that Committee on Wednesday. While there are no Democratic sponsors for the
bill, I expect that it will receive bipartisan support in the Committee and on
the floor of the House. It would likely be considered under the suspension of the
rules provisions in the House (limited debate, no floor amendments).
Commentary
While I certainly applaud the addition of control system
language to this bill, the lack of a definition and changes to other
definitions in §148
is likely to cause problems down the road. I would like to offer this
definition for addition to §148(a):
Industrial
Control System - The term ‘control system’ means a discrete set of information
resources, sensors, communications interfaces and physical devices organized to
monitor, control and/or report on physical processes including but not limited
to; manufacturing, transportation, access control, and facility environmental
controls;
Additionally, the following existing definitions need
revision:
Cybersecurity
Risk - The term ‘cybersecurity risk’ means:
(A) threats to and vulnerabilities of information, information systems,
or control systems and any related consequences caused by or resulting from
unauthorized access, use, disclosure, degradation, disruption, modification, or
destruction of such information, information systems, or control systems,
including such related consequences caused by an act of terrorism; and
(B) does not include any action that solely involves a violation of a
consumer term of service or a consumer licensing agreement;
Incident
- The term ‘incident’ means an occurrence that actually, or imminently
jeopardizes, without lawful authority:
(A) the integrity, confidentiality, or availability of information on
an information system,
(B) the timely availability of accurate process information, the
predictable control of the designed process or the confidentiality of process
information, or
(C) an information system or a control system;
I am disappointed that there was no specific mention of cyber
emergency response teams, either US-CERT or ICS-CERT. This bill would have been
a good place to add mention of them in §148(d)(1)(C).
With the addition of industrial control systems to the areas of NCCIC oversight
the mention of ICS-CERT would certainly be appropriate, and that mention could
not be made without also including US-CERT.
Finally, I am astounded that this bill did not modify the ‘functions’
of the NCCIC, as outlined in §148(c).
If the definitions I suggested above were made, at least part of that problem
would be corrected because of the frequent references to ‘cybersecurity risk’
and ‘incidents’. Even so the language of §147(c)(7) would still need to add mention of
industrial control systems to ensure that the NCCIC appropriately addresses the
cybersecurity issues associated with control systems.
Subscribe to:
Posts (Atom)