Thursday, May 17, 2018

Registration Opens for CFATS West Regional Meeting


Today the DHS Infrastructure Security Compliance Division (ISCD) opened the registration site for their DHSChemSecurityTalks – West  regional meeting. The meeting will be held at the Ronald V. Dellums Federal Building, in Oakland, CA, on June 27th, 2018. The registration site includes preliminary agenda information. This is a no cost event with no web cast. Registration is required and there is limited seating.

NRC Withdraws Cybersecurity Rulemaking


Yesterday the Nuclear Regulatory Commission (NRC) published a notice in the Federal Register (83 FR 22413-22414) announcing that they were discontinuing their rulemaking activities on “Cyber Security for Byproduct Materials Licensees” (RIN 3150-1756). This rulemaking first appeared in the Unified Agenda during the Obama Administration in the long-term actions section. It was moved to the Active Agenda in the Spring of 2017 and then back to the long-term actions in the most recent agenda.

Background


The Byproduct Materials Cyber Security Working Group was formed in 2013 to look into the potential need for a cybersecurity rulemaking for facilities that stored Category 1 or Category 2 quantities of radioactive material (does not include the radioactive material contained in any fuel assembly, subassembly, fuel rod, or fuel pellet; see 10 CFR 37.5).

The working group identified four sets of digital assets that the NRC should evaluate with respect to cyber threat protection:

• Digital/microprocessor-based systems and devices that support the physical security of the licensee's facilities. These include access control systems, physical intrusion detection and alarm systems, video camera monitoring systems, digital video recorders, door alarms, motion sensors, keycard readers, and biometric scanners;

• Equipment and devices with software-based control, operation, and automation features, such as panoramic irradiators and gamma knives;

• Computers and systems used to maintain source inventories, audit data, and records necessary for compliance with security requirements and regulations; and

Digital technology used to support incident response communications and coordination such as digital packet radio systems, digital repeater stations, and digital trunk radio systems.

The most recent, publicly-available document (Update to the U.S. Nuclear Regulatory Commission Cyber Security Roadmap, ML15201A509, 2-28-17) noted that (pg 7):

“The working group plans to complete its evaluation of the [180] questionnaire [sent to all NRC and Agreement State licensees that possess Categories 1 and 2 quantities of radioactive Materials] responses, its consequence analysis, and any follow-up communication with stakeholders in early 2017. As a result, the working group intends to develop recommendations for a path forward by spring/summer 2017.”

Question: Why does the NRC still use antiquated on-line tools to provide access to public documents? Why can I not provide a link to the document listed above? The NRC does not provide links to their documents.

NRC Conclusion


The NRC staff completed its evaluation in October 2017 and concluded that:

“The NRC staff concluded that byproduct materials licensees that possess risk-significant quantities of radioactive material do not rely solely on digital assets to ensure safety or physical protection. Rather, these licensees generally use a combination of measures, such as doors, locks, barriers, human resources, and operational processes, to ensure security, which reflects a defense-in-depth approach to physical protection and safety. As a result, the staff concluded that a compromise of any of the digital assets identified in the January 6, 2016, Commission memorandum would not result in a direct dispersal of risk-significant quantities of radioactive material, or exposure of individuals to radiation, without a concurrent and targeted breach of the physical protection measures in force for these licensees.”

Based upon that recommendation, the NRC is discontinuing rulemaking activity to develop cyber security requirements for byproduct materials licensees possessing risk-significant quantities of radioactive materials.

Commentary


Since I have not seen (and probably never will see for legitimate security reasons) the final NRC staff report, it is hard to draw any hard conclusions about the decision reached by the NRC.

Having said that, I see little in the language in this announcement that provides me with any level of comfort that the Commission took a hard look at anything beyond the immediate security of these materials. There is no language that would indicate that operational security (the security of the devices that manipulate or move the covered materials) has been adequately addressed.

Additionally, since these materials are ideally suited to employment in weapons of mass confusion (radiologically enhanced improvised explosive devices), I am also concerned about the security of information systems that deal with the ordering and shipping of these commercial products. The diverted delivery of legitimate shipments via electronic changes in orders or shipping documents provide a legitimate scenario for terrorists to acquire the material necessary to build a radiological dispersion device (‘dirty bomb’).

Again, the NRC and its staff may very well have looked at these potential vulnerabilities, but there is nothing in this announcement that provides any indication that this is so. Perhaps this is something that Congress out to take a look at.

Wednesday, May 16, 2018

Bills Introduced – 05-15-18


Yesterday with both the House and Senate in session there were 71 bills introduced (a lot of opioid legislation in the House). Of those, there are three that may be of specific interest to readers of this blog:

HR 5822 To establish a National Office for Cyberspace, and for other purposes. Rep. Langevin, James R. [D-RI-2]

HR 5823 To prohibit Federal agencies from mandating the deployment of vulnerabilities in data security technologies. Rep. Lofgren, Zoe [D-CA-19]

S 2840 A bill to require a strategic plan to improve capabilities of Department of Defense training ranges and installations. Sen. Rounds, Mike [R-SD]

Definitions in the two House-bills will determine whether or not they will be followed here. The NOC bill has the best chance, but the encryption back door bill could include ICS inclusive definitions.

There is an outside chance that the Senate bill actually refers to, or includes, ‘cyber ranges’.


Tuesday, May 15, 2018

ICS-CERT Publishes Advantech Advisory and Updates Siemens Advisory


Today the DHS ICS-CERT published a control system security advisory for products from Advantech. They also updated a previously issued advisory for products from Siemens.

Advantech Advisory


This advisory describes eleven vulnerabilities in the Advantech WebAccess products. The vulnerabilities were reported by Mat Powell and rgod, working with ZDI; Steven Seeley of Offensive Security, working with ZDI; and Donato Onofri and Simone Onofri of Business Integration Partners S.p.A. Advantech released a new version that mitigates the vulnerabilities. There is no indication that any of the researchers were provided an opportunity to verify the efficacy of the fix.

The eleven reported vulnerabilities are:

• SQL injection - CVE-2018-7501;
• Information exposure through directory listing - CVE-2018-10590;
• Improper authorization - CVE-2018-7505;
• Path traversal (2) - CVE-2018-7503, and CVE-2018-10589;
• Stack-based buffer overflow - CVE-2018-7499;
• Heap-based buffer overflow - CVE-2018-8845;
• Untrusted pointer dereference - CVE-2018-7497;
• External control of file name or path - CVE-2018-7495;
• Origin validation error - CVE-2018-10591; and
Improper privilege management - CVE-2018-8841

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilitie to disclose sensitive information from the host and/or target, execute arbitrary code, or delete files.

Siemens Update


This update provides additional information for an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017,on July 25th, 2017, on August 17th, 2017, on October 10th, on November 14th, November 28th, February 27th, 2018 and most recently on May 3rd, 2018. The new information includes links to new versions for version 4.7 of:

• SINAMICS G130;
• SINAMICS G150;
• SINAMICS S120; and
• SINAMICS S150

The Siemens security advisory provided undated version information for the same products, but that was not reported in the ICS-CERT advisory

NOTE: Siemens also reported two other updated advisories (here and here) and a new advisory (here) today when they reported this update. Hopefully ICS-CERT will publish their versions later this week.

Bills Introduced – 05-14-18


Yesterday with just the Senate in session (the House returns to Washington today) there were three bills introduced. One of those bills may be of specific interest to readers of this blog:

S 2836 A bill to assist the Department of Homeland Security in preventing emerging threats from unmanned aircraft and vehicles, and for other purposes. Sen. Johnson, Ron [R-WI]

It is interesting that the bill will address “unmanned aircraft and vehicles”; definitions will be a key point in this bill.

Monday, May 14, 2018

Committee Hearings – Week of 05-13-18


With both the House and Senate in session this week we see both bodies working on must complete issues; spending and the National Defense Authorization Act (NDAA). We will also see a markup hearing dealing with our ICS cybersecurity bill.

Spending Bills


The House Appropriations Committee is fully into the spending bill markup process. The Full Committee will mark-up the FY 2019 Energy and Water and Agriculture, Rural Development, Food and Drug Administration, and Related Agencies Appropriations Bill on Wednesday. Subcommittee mark-ups of possible interest here this week include:

• FY 2019 Interior, Environment, and Related Agencies Appropriations Bill – Tuesday; and
• FY 2019 Transportation, and Housing and Urban Development (THUD), and Related Agencies Appropriations Bill – Wednesday

The Senate Appropriations Committee subcommittees are still looking at the details of the respective budget requests, so they are a tad bit behind the House on the bill writing schedule. That is not a significant problem as the House has to consider spending bills before the Senate can act on them. The Appropriations Committee will have language ready by the time the House bills make it to the Senate even if they do not have their own bill introduced.

NDAA


The House Armed Services Committee finished their mark-ups of HR 5515 last week and ordered the bill reported to the House. I expect to see an official version of the bill published this week. The House Rules Committee has announced that it is accepting proposed amendments to the bill through Thursday morning. This means that it will probably be considered on the floor of the House next week.

The Senate Armed Services Committee is starting the mark-up process for their version of the NDAA (not yet introduced) this week with subcommittee mark-ups. The Subcommittees of potential interest here include:

• Subcommittee on Cybersecurity; and
Subcommittee on Emerging Threats

Both will hold their mark-ups on Tuesday. Both will be closed hearings.

Cybersecurity Mark-Up


On Wednesday the House Homeland Security Committee will be holding a mark-up hearing to consider nine bills. HR 5733, the DHS Industrial Control Systems Capabilities Enhancement Act of 2018, is one of the bills being considered. No word yet on any possible amendments.

Sunday, May 13, 2018

HR 5733 Introduced – ICS Cybersecurity


Last week Rep Bacon (R,NE) introduced HR 5733, the DHS Industrial Control Systems Capabilities Enhancement Act of 2018 (Note: the link is to a Committee draft of the bill not the official GPO version). The bill would amend 6 USC 148 to provide specific requirements for the National Cybersecurity and Communications Integration Center (NCCIC) to address industrial control system security issues.

Section 148 Amendments


The bill would make two specific amendments to §148. First it would add to the list of principles outlined in paragraph (3)(1) the following language: “activities of the Center address the security of both information technology and operational technology, including industrial control systems;”.

Second the bill would add a new paragraph (f) that would require the NCCIC to “maintain capabilities to identify and address threats and vulnerabilities to products and technologies intended for use in the automated control of critical infrastructure processes.” This would specifically include requirements to:

• Lead, in coordination with relevant sector specific agencies, Federal Government efforts to identify and mitigate cybersecurity threats to industrial control systems, including supervisory control and data acquisition systems;
• Maintain cross-sector incident response capabilities to respond to industrial control system cybersecurity incidents;
• Provide cybersecurity technical assistance to industry end-users, product manufacturers, and other industrial control system stakeholders to identify and mitigate vulnerabilities; and
Conduct such other efforts and assistance as the Secretary determines appropriate.

Moving Forward


Bacon and both of his cosponsors {Rep. McCaul (R,TX) and Rep. Ratcliff (R,TX)} are members of the House Homeland Security Committee to which this bill was assigned. The bill is currently scheduled to be marked-up by that Committee on Wednesday. While there are no Democratic sponsors for the bill, I expect that it will receive bipartisan support in the Committee and on the floor of the House. It would likely be considered under the suspension of the rules provisions in the House (limited debate, no floor amendments).

Commentary


While I certainly applaud the addition of control system language to this bill, the lack of a definition and changes to other definitions in §148 is likely to cause problems down the road. I would like to offer this definition for addition to §148(a):

Industrial Control System - The term ‘control system’ means a discrete set of information resources, sensors, communications interfaces and physical devices organized to monitor, control and/or report on physical processes including but not limited to; manufacturing, transportation, access control, and facility environmental controls;

Additionally, the following existing definitions need revision:

Cybersecurity Risk - The term ‘cybersecurity risk’ means:

(A) threats to and vulnerabilities of information, information systems, or control systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of such information, information systems, or control systems, including such related consequences caused by an act of terrorism; and

(B) does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement;

Incident - The term ‘incident’ means an occurrence that actually, or imminently jeopardizes, without lawful authority:

(A) the integrity, confidentiality, or availability of information on an information system,

(B) the timely availability of accurate process information, the predictable control of the designed process or the confidentiality of process information, or

(C) an information system or a control system;

I am disappointed that there was no specific mention of cyber emergency response teams, either US-CERT or ICS-CERT. This bill would have been a good place to add mention of them in §148(d)(1)(C). With the addition of industrial control systems to the areas of NCCIC oversight the mention of ICS-CERT would certainly be appropriate, and that mention could not be made without also including US-CERT.

Finally, I am astounded that this bill did not modify the ‘functions’ of the NCCIC, as outlined in §148(c). If the definitions I suggested above were made, at least part of that problem would be corrected because of the frequent references to ‘cybersecurity risk’ and ‘incidents’. Even so the language of §147(c)(7) would still need to add mention of industrial control systems to ensure that the NCCIC appropriately addresses the cybersecurity issues associated with control systems.

 
/* Use this with templates/template-twocol.html */