Friday, August 10, 2018

CFATS Reauthorization – Emergency Response


This is part of a continuing series of blog posts on my proposed changes to the CFATS authorization. The current authorization for the program ends on December 18th, 2018. These posts address some of the language that I would like to see in any re-authorization bill. Earlier posts in the series include:


In light of the recent GAO report on the Chemical Facility Anti-Terrorism Standards (CFATS) program and its findings on problems with information sharing between DHS and local first responders, I would like to suggest the following language on information sharing:

Section 636 – Information Sharing

(a) IP Gateway - The Secretary will establish an on-line portal for sharing information about covered facilities with the local first responder community and local emergency response planners.

(A) The portal will provide information in two tiers of accessibility:

(I) The Tier One will allow open access to information that will include the following information about all covered facilities:

(i)  Name;
(ii) Location;
(iii) Geospatial information; and
(iv) Inventory and location information for all COI reported on the current Top Screen that are subject to the reporting requirements of §§ 311 and 312 of the Emergency Planning and Community Right-to-Know Act (EPCRA) regardless of the threshold quantities of that Act.

(II) The Tier Two will include additional information that is protected by the Chemical-Terrorism Vulnerability Information (CVI) program described in 6 CFR 27.400, including:

(i) Complete list of COIs, to include amounts and locations;
(ii) Facility tiering information; and
(iii) Facility security information.

(B) The Secretary will establish procedures to register and authorize access to the portal for all members of a recognized Local Emergency Planning Committee (LEPC) established under EPCRA, and at least one designated representative from each local law enforcement agency (LLEA), fire department and hospital operating within 10 miles of each covered facility. Access will be provided on the following basis:

(I) Registered LEPC members will be provided access to both tiers of information described in (A) for all facilities in their county or within 10 miles of their county;
(II) Registered LLEA representatives will be provided access to both tiers of information described in (A) for all facilities in jurisdiction or within 10 miles of their jurisdiction;
(III) Registered fire department representatives will be provided access to all Tier One information and Tier Two information specifically related to COI for all facilities in jurisdiction or within 10 miles of their jurisdiction; and
(IV) Registered hospital representatives will be provided access to all Tier One information and Tier Two information specifically related to the types COI (excluding amounts and locations) for all facilities in jurisdiction or within 10 miles of their jurisdiction.

(C) The LEPC members and designated representatives from LLEA, fire departments, and hospitals listed above will be considered to be a covered person under §27.400 and deemed to have a need-to-know under the CVI rules for information about covered facilities.

(D) The Secretary will contact each LEPC, LEEA, fire department and hospital within 10 miles of each covered facility explaining the existence of the portal described in (a), the procedures for registering for the portal, and the requirements for protecting CVI provided in the portal.

(b) Facility information sharing requirements. Each CFATS covered facility is required to:

(1) Contact in writing their local LEPC, LLEA, fire department and nearby hospital and inform them about the existence of the portal described in (a).

(2) Designate a security representative to the local LEPC in addition to any other facility representation to the LEPC. If a local LEPC does not exist, that fact will be reported in writing to the Director, Infrastructure Security Compliance Division.

(3) Invite a representative of the local LEPC, LLEA, local fire station and nearby hospital to participate in or observe each security exercise conducted by the facility.

(4) Conduct an annual training class for representatives from each local LEPC, LLEA, fire station and nearby hospital about the chemical hazards associated with each release security issue COI reported on the most recent facility Top Screen.

(5) Conduct an annual training class for representatives from each local LEPC and LLEA with the potential chemical weapon or improvised explosive device hazard associated with each theft/diversion security issue COI reported on the most recent facility Top Screen.

(c) Joint Exercises

(1) The Secretary will encourage each LEPC, LLEA, fire department and nearby hospital to participate in annual security exercises conducted by each CFATS covered facility. This encouragement may include providing access to FEMA grants for such exercises.

(2) 15 USC 2229(c) is amended by adding:

“(4) FEMA is directed to give priority consideration to grants providing for planning, training, and the conduct of exercises involving facilities covered under 6 USC Part 27.”

(3) 6 USC 609 is amended by inserting a new:

“(14) Planning for emergency response to attacks on chemical facilities covered under 6 USC Part 27, to include the conduct of exercises under the resulting plans; and”

Thursday, August 9, 2018

ICS-CERT Publishes Two Advisories


Today the DHS ICS-CERT published two control system security advisories for products from NetComm and Crestron.

NetComm Advisory


This advisory describes four vulnerabilities in the NetComm 4G LTE Light Industrial M2M Router. The vulnerabilities were reported by Aditya K. Sood. NetComm has new firmware that mitigates the vulnerabilities. There is no indication that Sood has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Information exposure - CVE-2018-14782;
• Cross-site request forgery - CVE-2018-14783;
• Cross-site scripting - CVE-2018-14784; and
Information exposure through directory listing - CVE-2018-14785

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow for the exposure of sensitive information.

Crestron Advisory


This advisory describes four vulnerabilities in the Crestron TSW-X60 and MC3 products. The vulnerabilities were independently reported by Jackson Thuraisamy (via Security Compass) and Ricky “HeadlessZeke” Lawshae (via the Zero Day Initiative). Crestron has firmware versions available that mitigate the vulnerabilities. There is no indication that either researcher has been offered an opportunity to verify efficacy of the fix.

The four reported vulnerabilities are:

• OS command injection (2) - CVE-2018-11228 and CVE-2018-11229);
• Improper access control - CVE-2018-10630; and
• Insufficiently protected credentials - CVE-2018-13341

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow remote code execution with escalated system privileges.

NOTE: Is it just me or does it seem odd that the same vulnerabilities are found in a touch-screen device and a control system processor controller?

GAO Publishes CFATS Report – 08-08-18


Yesterday the Government Accountability Office (GAO) published their latest report on the Chemical Facility Anti-Terrorism Standards (CFATS) program. This report was requested by Congress as part of the efforts leading up to the re-authorization of the CFATS program. Generally, the GAO was satisfied with the progress that the DHS Infrastructure Security Compliance Division (ISCD) has made with improvements to the CFATS program and issued two Recommendations. GAO provides both a copy of the report and one-page summary on their web site.

Measuring Program Performance


While the GAO report is generally positive in its reporting on improvements made to the CFATS program (and specifically to responses to previous GAO recommendations) they do note one on-going problem that ISCD has only partially addressed. That reflects on the ability of ISCD and DHS to measure the success of the CFATS program in reducing the risk of terrorist attack on high-risk chemical facilities.

Specifically, they recommend that ISCD “should incorporate vulnerability into the CFATS site security scoring methodology to help measure the reduction in the vulnerability of high-risk facilities to a terrorist attack, and use that data in assessing the CFATS program's performance in lowering risk and enhancing national security.” (pg 33)

DHS has concurred with this recommendation (pg 39) and notes on-going activities to improve the calculation of the change in ‘security score’ that the Department uses to measure and report the program performance in ‘lowering risk and improving national security’. To more fully comply with the recommendation DHS reports that (pgs 39-40):

“To develop a system that could numerically evaluate vulnerabilities likely would require revising the regulatory language describing CFATS vulnerability assessments, modifying CFATS processes, and updating tools used to gather vulnerability assessments. This would be a significant burden on both industry and government and NPPD does not believe this would result in a better measure for evaluating the security enhancing effectiveness of the CFATS program, compared to the new performance measure the Department intends to implement.”

Information Sharing


While the GAO report recognizes that ISCD has taken positive steps to share information about CFATS covered facilities with first responders and emergency planners through the establishment of their IP Gateway, their investigation showed that the information available is not effectively reaching the targeted audience (see the lengthy discussion on pages 29-32.

The GAO recommends that DHS “should take actions to encourage access to and wider use of the IP Gateway and explore other opportunities to improve information-sharing with first responders and emergency planners.” (pg 33-4).

The DHS response to this recommendation includes a discussion (pgs 40-1) of efforts that it has taken to date (mostly identified in the GAO report) including a program requirement (Risk Based Performance Standard 9) that requires facilities to “have regular and recurring contact with their local first responders” (pg 41). DHS then goes on to explain that this last “is the most effective way to get information to first responders as it involves direct communication between the high-risk chemical facilities and their local responders. DHS then notes that they “cannot require first responders to access the IP Gateway or respond to facility requests for visits”. They do report that they “will ensure contact is made with LEPCs representing the top 25 percent of the CFATS high-risk chemical facilities no later than the end of the second quarter FY 2019” (pg 41).

Commentary


The first issue is a program measurement issue that needs to be resolved between DHS and Congress. Congress rightly wants to know that the programs that it authorizes and funds are having a beneficial effect. How to measure that performance in a meaningful way in this particular instance, is going to be difficult to establish. DHS has an important point in that the measures of program performance should not unduly increase the burden on the regulated community.

The second issue is much more problematic and important to the ultimate success of the CFATS program. All CFATS covered facilities have to rely to some extent on the resources of the local community to respond to a successful attack on the facility. Even facilities with dedicated on-site emergency response personnel are going to have to rely on off-site responders to deal with effects of an attack on the local community. Sharing information with local response agencies (including police, ambulance and hospitals serving the area around CFATS facilities) is an important pre-requisite to having an effective response a successful terrorist attack.

I was disappointed in this portion of the GAO report in that the investigators did not apparently dig deeper into why “officials representing 13 of the 15 LEPCs stated that they do not have access to CFATS information within the IP Gateway” (pg 31). While seven of those officials reportedly were not aware of the IP Gateway, it is disconcerting that GAO did not attempt to ascertain why the other 8 could not accesses the available information.

I suspect that the reason has to do with the provisions that require that before an individual can access the most detailed (and important) information they have to be cleared for access to Chemical-Terrorism Vulnerability Information (CVI). This clearance requires completing an on-line training program, establishing a need-to-know (should be a priori established for LEPC members), and maintaining the information security requirements (a post access requirement) of the CVI program {which have yet to be upgraded to comply with Federal controlled unclassified information (CUI) standards}. Gaining the CVI access is not terribly difficult, but it does require some investigation and action by the LEPC officials desiring access to the information.

Much of the information currently protected by the CVI designation in the IP Gateways probably should not be protected as it should be available to LEPCs under the EPA reporting requirements of the Emergency Planning and Community Right-to-Know Act of 1986 (EPCRA). Interestingly, the GAO reports note that 200 of the 300+ chemicals covered under the CFATS program {DHS chemicals of interest (COI)} are not covered under the reporting requirements of EPCRA. Not mentioned in the report is the fact that (presumably most of) these 200 chemicals are covered under the CFATS program because of their potential use in manufacturing improvised chemical munitions or improvised chemical weapons, not because they are an air-pollution release-risk covered under the EPCRA requirements.

Adequately addressing this information sharing problem is not one that ISCD is going to be able to resolve on its own. It will require congressional action as part of the CFATS reauthorization process. I will address this issue more completely in a future blog post.

Wednesday, August 8, 2018

ISCD Publishes CFATS Update – 08-07-18


Yesterday the DHS Infrastructure Security Compliance Division (ISCD) updated their Chemical Facility Anti-Terrorism Standards (CFATS) Monthly Statistics page to reflect the current status of the implementation of the CFATS program. The reported numbers show small changes in facility status and a decline in ISCD activity.

ISCD Activity


The table below shows the reported numbers for ISCD activities for the month of July. It shows a decline in all activities during the month of July with a sharp decline in the number of compliance inspections conducted. The decline in numbers may be due to vacations; Chemical Security Inspectors do deserve time off too.

CFATS Activities
May-18
Jun-18
Jul-18
Authorization Inspections to Date
3652
3713
3768
Authorization Inspections Month
59
66
44
Compliance Inspections to Date
3553
3684
3752
Compliance Inspections Month
140
131
59
Compliance Assistance Visits to Date
4359
4463
4598
Compliance Assistance Visits Month
109
113
103

The numbers reported continue to show statistical anomalies. I continue to expect that the number of activities reported for the month should match with the change in that activity ‘to Date’. The numbers do not match and there is no consistency (month-to-month or category-to-category) in the variation. The only consistency is that the number of reported monthly activities is typically smaller (never larger) than the change in the ‘to Date’ numbers reported.

I have given up trying to explain potential reasons for this discrepancy, but it does make any statistical analysis of the reported numbers suspect.

Facility Status


The next table shows the reported numbers for CFATS facility status. The changes from last month are in the expected directions but the magnitude of the changes are much smaller than expected, even given the lower activity levels reported for the month.

CFATS Facility Status
May-18
Jun-18
Jul-18
Tiered
293
216
213
Authorized
628
623
618
Approved
2468
2528
2531
Total
3389
3367
3362

The number of ‘Tiered’ facilities should generally decline as newly tiered facilities start to get their site security plans authorized. We could see periodic upticks when ISCD identifies a new class of facilities that should have (but has not yet) submitted Top Screens, but this should be relatively infrequent at this point in the program.

Similarly, the count of ‘Authorized’ facilities should generally decline as facilities transition through the category from 'Tiered' to ‘Approved’. The ‘Approved’ category is more difficult to predict at this point in the program. I would expect that generally the number of facilities transitioning from ‘Authorized’ to ‘Approved’ should be greater than the number of facilities that are leaving the program. That will change as the program continues to mature and the number of ‘new’ covered facilities continues to decline.

The problem this month is that the changes in status, while in the expected direction, are so small in magnitude. For example, there is only a small increase (3) in the number of ‘Approved’ facilities while there were 44 (reported) authorization inspections conducted. I do not expect that those two numbers should be the same; there is after all a lag to be expected between the conduct of the inspection and the actual approval of the site security plan as ISCD headquarters reviews the inspection results. The numbers should, however, be close since there should be some carryover approval from the inspections completed during the previous month. And, we cannot explain the discrepancy by assuming that an inordinate number of previously approved facilities were dropped from the program; we only had a small decline (5) in the number of covered facilities.

Again, I have no explanation for the discrepancies. I do not think that ISCD is cooking the books; that should lead to discrepancies of exaggeration not minimization. I do think, however, that these anomalies should be looked at and explained. Hopefully, the expected GAO report on the program will do so.

Regional Meeting News


With the completion of the third (and final) regional meeting last week, ISCD announced on its CFATS landing page that they will be publishing copies of some of the presentation slides on the Chemical Sector Regional Events web page. I’m looking forward to that.

Tuesday, August 7, 2018

ICS-CERT Publishes 3 Advisories


Today the DHS ICS-CERT published one control system security advisory for products from Delta Electronics and two medical device security advisories for products from Medtronic.

Delta Advisory


This advisory describes two vulnerabilities in the Delta CNCSoft and ScreenEditor products. The vulnerability was reported by Mat Powell via the Zero Day Initiative. Delta has an updated version of CNCSoft that mitigates the vulnerabilities. There is no indication that Powell was provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-10636; and
Out-of-bounds read - CVE-2018-10598

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerability to gain remote code execution with administrator privileges.

MiniMed Advisory


This advisory describes two vulnerabilities in the Medtronic MiniMed 508 Insulin Pump. The vulnerabilities were reported by Billy Rios, Jesse Young, and Jonathan Butts of Whitescope LLC. Medtronic does not intend to develop a mitigation for these vulnerabilities (see note below).

The two reported vulnerabilities are:

• Cleartext transmission of sensitive information - CVE-2018-10634; and
• Authentication bypass by capture replay - CVE-2018-14781

ICS-CERT reports that an uncharacterized attacker could remotely exploit these vulnerabilities to allow an attacker to replay captured wireless communications and cause an insulin (bolus) delivery.

NOTE: The Medtronic security advisory reports that the following must occur for these vulnerabilities to be exploited:

1. The remote option for the pump would need to be enabled. This is not a factory-delivered default, and a user must choose this option.
2. The user’s remote controller ID needs to be registered to the pump.
3. The easy bolus option would need to be turned on and easy bolus step size programmed in the pump.
4. An unauthorized individual would need to be within close proximity to the user, with
necessary equipment to copy the RF signals activated, when the user is delivering a bolus
using the remote controller.
5. The unauthorized individual would need to be within the vicinity of the userto play back the RF signals to deliver a malicious remote bolus.
6. The user would need to ignore the pump alerts, which indicates that a remote bolus is being delivered.

MyCareLink Advisory


This advisory describes two vulnerabilities in the Medtronic MyCareLink Patient Monitor. The vulnerabilities were reported by Billy Rios, Jesse Young, and Jonathan Butts of Whitescope LLC. Medtronic is making (has made for one of the vulnerabilities) server side updates to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Insufficient verification of data authenticity - CVE-2018-10626; and
• Storing passwords in a recoverable format - CVE-2018-10622

ICS-CERT reports that an uncharacterized attacker with physical access to the device could exploit the vulnerabilities to obtain per-product credentials that are utilized to authenticate data uploads and encrypt data at rest. Additionally, an attacker with access to a set of these credentials and additional identifiers can upload invalid data to the Medtronic CareLink network.

Monday, August 6, 2018

HR 6438 Introduced – Counter UAS Coordinator


Last month Rep. Perry (R,PA) introduced HR 6438, the DHS Countering Unmanned Aircraft Systems Coordinator Act. The bill would require the DHS Secretary to designate a Counter Unmanned Aircraft Systems (UAS) Coordinator to “coordinate with relevant Department offices and components on the development of policies and plans to counter threats associated with UAS”. The bill was adopted in markup hearing by the House Homeland Security Committee on July 24th, 2018 by unanimous consent without amendment.

Coordination


The bill would add a new §195g to 6 USC. It would require the Counter UAS Coordinator to work with elements of DHS to {new §195g(a)}:

• Counter UAS that may be used in a terrorist attack;
• Promote research and development of counter UAS technologies;
• Ensure the dissemination of information and guidance related to countering UAS threats; and
Serve as the Department point of contact for Federal, State, local, and tribal law enforcement entities and the private sector regarding the Department’s activities related to countering UAS;

The bill briefly addresses the conflict between counter UAS activities and a variety of current US laws by requiring the Coordinator to work “with relevant Department components and offices to
ensure testing, evaluation, or deployment of a system used to identify, assess, or defeat a UAS is carried out in accordance with applicable Federal laws” {new §195g(b)}.

Moving Forward


With the bill moving quickly through the Homeland Security Committee without opposition it is clear that this bill has bipartisan support. Whether that support is strong enough to have this bill make its way to the floor of the House (and subsequently the Senate) in the short (effective) time left in the 115th Congress remains to be seen. The saving grace for this bill is that it will almost certainly be considered under the suspension of the rules process in the House and under the unanimous consent process in the Senate; neither process would take up much legislative time.

Commentary


The reason that this bill commands such bipartisan support is that it does so very little. It requires the Secretary to ‘designate’ not appoint the coordinator; thus, no new hire or office is authorized. It does not authorize any spending, nor does it authorize the writing of any new regulations. In short it allows Congress to look like it is doing something to address the potential UAS threat without making any hard-political decisions about how to go about authorizing the government to take down aircraft in the national airspace. Even more importantly, it will allow Congress to point the finger at DHS when the inevitable UAS attack does take place.

There are processes in place to take down full size aircraft in the national airspace. They were discussed, in passing, in the wake of the 9-11 attacks, but there has never been a full public or political discussion about how those tough decisions will be made nor about who will suffer the legal consequences when such decisions are made in error or even just under questionable circumstances.

That may be why Congress is so reluctant to make such decisions on counter UAS activities; the FAA maintains the legal fiction that UAS are no different than manned aircraft. Thus, taking out an attacking UAS is legally the same as taking out a weaponized airliner. The consequences are radically different is scope, the legal fiction remains. Perhaps it is time to reexamine that legal fiction, particularly with regards counter aircraft operations; manned and unmanned.

Friday, August 3, 2018

ICS-CERT Publishes Antivirus Update Advice


Yesterday the DHS ICS-CERT published a new ‘Recommended Practice’ covering the process of updating antivirus software in industrial control systems. ICS-CERT originally addressed this issue in their ICS-CERT Monitor in 2017 and published a short-lived version of this document in January of this year.

The latest version of this recommended practice is very similar to both of the previous ICS-CERT iterations. This version has been at least partially re-written, and the graphics have been updated. For example, the new network architecture diagram now includes a separate ‘Remote SCADA, DCS, or Hybrid System #2’ in the Cell/Area Zone.

Most of the changes in the new version are minor editorial changes. One significant change is the addition of an entirely new paragraph in the ‘Considerations’ section of the document. That new paragraph reads:

“The recommended secure network architecture diagram (Figure 1) depicts the AV/WSUS/ patch server as a single server hosting three separate applications. This increases the risk of a compromise of either the server’s operating system or the applications. If possible, these applications (AV/WSUS/patch) should reside on their own hosts, either physical or virtual, and the hosts hardened and traffic restricted.”

The other significant change is the complete re-wording of the standard disclaimer at the beginning of the document. Most of the wording change will only be of interest to lawyers, but the new document does specify that the document is being shared as “TLP/White”, the least restrictive of the Traffic Light Protocol sharing limits. Interestingly the TLP system is not included in the government's controlled unclassified information regulations so the legal status of the TLP restrictions is iffy at best, though that is certainly not an issue with TLP/White.

 
/* Use this with templates/template-twocol.html */