Tuesday, October 9, 2018

S 3513 Introduced – UAS Restricted Areas

Last month Sen Cortez-Masto (D,NV) introduced S 3513, the UAS Critical Infrastructure Protection Act. The bill would amend provisions in the 2016 FAA Extension, Safety, and Security Act of 2016 (PL 114-190) that would allow facilities to petition the FAA to be declared restricted flight zones for unmanned aircraft.

UAS Restricted Areas


Section 2 of the bill would add ‘railroad facilities’ to the limited list of facilities that should be authorized to request that the FAA “prohibit or restrict the operation of an unmanned aircraft in close proximity” {PL 114-190 §2209(a), (130 STAT. 634)} to the facility.

The bill would also establish a deadline of March 31, 2019 for the FAA to publish a notice of proposed rulemaking to carry out §2209 and a requirement to publish the final rule within one year of that date.

Moving Forward


Both Cortez-Masto and her single cosponsor {Sen. Fischer (R,NE)} are members of the Senate Commerce, Science, and Transportation Committee to which this bill was assigned for consideration. Earlier in the session this might have allowed for their influence to ensure that this bill was considered in Committee. It is certainly less likely now, however, that this bill will receive any additional attention in the closing days of the session. The bill is likely to be re-introduced in the 116th Congress.

The original authorization bill that this bill amends received bipartisan support in both the House and Senate. There is nothing in this bill that would raise the prospects for significant opposition. If the bill were to be considered in this session it would likely pass in both Committee and on the floor with bipartisan support.

Commentary


The practical problem with this bill and the underlying requirement for establishing critical infrastructure ‘no fly zones’ is that there is currently no way to enforce the restrictions. Unmanned aerial systems (UAS) are typically too small to have readily identifiable identification numbers while they are in flight and it is currently illegal for anyone in the private sector or non-federal law enforcement to interfere with the operation of UAS or intercept the communications between the UAS and its controller. Even the recent authorization (sent to the President on October 4th) for DHS or DOJ physical action against UAS would not apply at these facilities.

The inclusion of a new deadline for the FAA to take regulatory action on the requirements of §2209 is interesting. The original legislation already required the FAA to establish the facility registration program within 180-days of the enactment of HR 636 (July 15th, 2016). The only way that Congress has of forcing compliance with such deadlines is by restricting funding for Department operations until the requirements are met, something for which there is very little political will to support.

Monday, October 8, 2018

HR 6913 Introduced – Blockchain Technology


Last month Rep. Guthrie (R,KY) introduced HR 6913, the Blockchain Promotion Act of 2018. The bill would require the Secretary of Commerce to establish a Blockchain Working Group.

Blockchain Working Group


The Blockchain Working Group (BWG) would consist of members representing both the federal government and the private sector. The Secretary would select the federal agencies to be represented with a view to ensuring “representation of a cross-section of Federal agencies that could use or benefit from blockchain technology” {2(b)(2)(A)}. The private sector members would be selected to include representatives from the following {§2(b)(2)(B)(i)}:

• Information and communications technology manufacturers, suppliers, software providers, service providers, and vendors.
• Subject matter experts representing industrial sectors other than the technology sector that the Secretary determines can benefit from blockchain technology.
• Small, medium, and large businesses.
• Individuals and institutions engaged in academic research relating to blockchain technology.
• Nonprofit organizations and consumer advocacy groups engaged in activities relating to blockchain technology.
Rural and urban stakeholders.

Within a year the BWG would be required to report to Congress a recommended definition of ‘blockchain technology’ along with recommendations for {§2(c)(1)(B)}:

• A study to be conducted by the Assistant Secretary of Commerce for Communications and Information, in coordination with the Federal Communications Commission, on the impact of blockchain technology on electromagnetic spectrum policy;
• A study that examines a range of potential applications, including non-financial applications, for blockchain technology; and
• Opportunities within Federal agencies to use blockchain technology.

Moving Forward


Both Guthrie and his single cosponsor {Rep. Matsui (D,CA)} are members of the House Energy and Commerce Committee, one of the two committees to which this bill was assigned for consideration. Earlier in the session this might have allowed for sufficient influence to ensure that the bill was considered in Committee. Now any consideration would have to take place during the post-election section of the session which is unlikely.

If this bill were considered, it is likely that it would receive bipartisan support, both in Committee and on the floor of the House. No money is being allocated and no regulations are being proposed, so there should be no basis for any serious opposition to the bill.

The bill will likely be re-introduced in the 116th Congress.

Commentary


I rather frequently disparage bills that require the Executive Branch to report to Congress as a buck-passing measure. There are times, however, when this is the most appropriate way for Congress to gather the necessary information to determine if legislative action is necessary. With blockchain becoming the tech-pop culture answer to all of the world’s problems, I think that this is an appropriate area for a study and report bill.

Having said that, there are two problems that I see with this bill as written. First it is way to vague in its definition of which federal agencies should be represented on the BWG. And second there is no reference to including representatives from State and local governments on the BWG.

There are two main areas where blockchain is touted as a panacea for the ills of the world; in finance and security. At the very least the Treasury Department, Homeland Security and DOD should have been listed as agencies that should be represented on the BWG.

If blockchain is actually going to be able to solve a multitude of societal problems (I am not holding my breath) then State and local governments will also need to get into the blockchain act and should have at least some representation on the BWG to ensure that their concerns are addressed in the subsequent studies.

Saturday, October 6, 2018

ISCD Updates CSAT 2.0 Users Manual – 09-28-18


This week the DHS Infrastructure Security Compliance Division posted a link to a new version of the Chemical Security Assessment Tool (CSAT) 2.0 Portal User Manual. The new version is dated 09-28-18. This Chemical Facility Anti-Terrorism Standards (CFATS) manual is a major revision from the March 1, 2017 version. Major changes include additions for the personnel surety program and password changes.

The table of contents additions tells the tale of the changes to this manual. The following new items show up:

3 CSAT Personnel Surety Program (PSP) User Roles
5.1 Forgot Password
5.3 Rules of Behavior
10.4.1 Export User List
10.4.2 View User Information
10.4.3 Forget Password
10.4.4 Delete User Account
10.4.6 Personnel Surety Program (PSP) Submitter Access
10.5 Groups
11.1 Search Affected Individuals
11.2 Affected Individuals
11.3 User Defined Fields
12.3 Two-Factor Authentication / Self-Password Reset

There is a link to this new manual on the CFATS Knowledge Center, but there is no notice on that page announcing the presence of the new manual nor is there one on the CSAT web page.

Public ICS Disclosures – Week of 09-29-18


This week we have two new vendor notifications for products from Schneider Electric and PTC. We also have a vendor update from BD.

Schneider Advisory


This advisory describes an insufficient verification of data authenticity vulnerability in the Schneider Modicon M221. The vulnerability was reported by Eran Goldstein of CRITIFENCE. Schneider reports on workarounds to mitigate the vulnerability. There is no indication that Goldstein has been provided an opportunity to verify the efficacy of the fix.

PTC Advisory


This advisory describes three vulnerabilities in the PTC ThingWorx Platform. The vulnerability was reported by Matteo Tomaselli from the SEC Consult Vulnerability Lab. PTC has new versions that mitigate the vulnerabilities. There is no indication that Tomaselli has been provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities are:

• Disclosure of User Password Hashes to Privileged Users - CVE-2018-17216;
• Disclosure of Encrypted Credentials and Use of Hard-Coded Passwords - CVE-2018-17217; and
Reflected Cross-Site Scripting - CVE-2018-17218

BD Update


This update provides additional information on an advisory that was originally published on May 22, 2018. The update provides previously promised mitigation measures.

Bills Introduced – 10-05-18


With the Senate in full session and the House in pro forma session there were 24 bills introduced yesterday. Of those only one may received additional coverage here:

HR 7045 To require the Federal Aviation Administration to address cybersecurity concerns for aircraft avionics systems, including software components. Rep. Meng, Grace [D-NY-6]

NOTE: The Senate is still officially in session for Friday as I write this and there are no Senate bills included in the ‘24’ mentioned above. Once the Kavanaugh nomination is finally dealt with the Friday session will end and we may yet see some bills from the Senate side of the Hill.

Friday, October 5, 2018

ICS Advisory and 2 Medical Device Advisories


Yesterday the DHS NCCIC-ICS published a controls system security advisory for products from WECON and two medical device security advisories for products from Change Healthcare and Carestream.

WECON Advisory


This advisory describes four vulnerabilities in the WECON PI Studio, a HMI project programmer. The vulnerabilities were reported by Mat Powell and Natnael Samson (Natti) via the Zero Day Initiative. WECON is working on mitigation measures.

The four reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2018-14818;
• Out-of-bounds write - CVE-2018-14810;
• Information exposure through XML external entity reference - CVE-2018-17889; and
Out-of-bounds read - CVE-2018-14814

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution, execution of code in the context of an administrator, read past the end of an allocated object or allow an attacker to disclose sensitive information under the context of administrator.

Change Healthcare Advisory


This advisory describes an information exposure through error message vulnerability in the Change Healthcare PeerVue Web Server. The vulnerability was reported by Dan Regalado of Zingbox. Change Healthcare has a patch available to mitigate the vulnerability. There is no indication that Regalado has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker on an adjacent network could exploit the vulnerability to allow an attacker to obtain technical information about the PeerVue Web Server, allowing an attacker to target a system for attack.

Carestream Advisory


This advisory describes an information exposure through an error message vulnerability in the Carestream Vue RIS, a web-based radiology information system. The vulnerability was reported by Dan Regalado of Zingbox. Carestream has a new version that mitigates the vulnerability and has provided workarounds. There is no indication that Regalado has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker with access to the network can exploit the vulnerability to passively read traffic.

NOTE: It is always interesting to see a researcher who has found an unusual vulnerability in one system to then look for the same type vulnerability in other related systems. It makes me wonder if developers reading these advisories (and of course they do, right?) ask themselves if their systems have the same vulnerability.

Thursday, October 4, 2018

Senate Amends and Passes HR 3359 – DHS Reorganization


Yesterday the Senate amended and passed HR 3359, the ‘Cybersecurity and Infrastructure Security Agency Act of 2018. The bill creates the Cybersecurity and Infrastructure Security Agency within DHS. The bill was passed earlier this year in the House. Two amendments were made; the first (SA 4403, pg S6497) substitute language from Sen. Johnson (R,WI) and the second a minor amendment (SA 4404, pg S6502) from Sen. Murkowski (D,MO). Both amendments and the bill were adopted without debate or vote. The bill will now have to be reconsidered by the House.

Substitute Language


Most of the additions made by the Johnson amendment added references to ‘Sector-Specific Agency’. This included a new definition of that term added in the new §2201.

The language regarding the transfer of the DHS Federal Protective Service {§3(b)} was greatly expanded. The original bill provided that DHS could transfer the FPS to the new CISA. The substitute language approved yesterday expands on that by providing instructions on what needs to occur if DHS declines to make that move. This would include specific notifications to Congress and the involvement of the OMB in subsequent evaluation of what to do with the FPS.

A new §4 of the bill was added that requires a report to Congress by DHS on the “leadership role of the Department in cloud-based cybersecurity deployments for civilian Federal departments and agencies” {§4(b)}.

There were a number of wording deletions made by the substitute language. These include the rather inconsequential deleting of the definitions of the terms ‘federal entity’ and ‘non-federal entity’.

One potentially significant deletion in the new §2202 is made in paragraph (e)(1) where the responsibilities of the new CISA Director are enumerated. Sub-paragraph (M) was deleted. That originally read:

“To ensure, in conjunction with the chief information officer of the Department, that any information databases and analytical tools developed or utilized by the Department—
“(i) are compatible with one another and with relevant information databases of other Federal Government agencies; and
“(ii) treat information in such databases in a manner that complies with applicable Federal law on privacy.”

Finally a change was made to the wording in the bill dealing with the Chemical Facility Anti-Terrorism Standards (CFATS) program. In explicating the responsibilities of the new Assistant Director for the new Infrastructure Security Division we see both an addition and deletion made to the wording of the original bill. The quote below shows both the addition (underlined) and the deletion (struck-through) made to §2204(b)(2).

“(2) carry out efforts, at the direction of the Director, to secure the United States high-risk chemicals and chemical facilities consistent with law, including the Chemical Facilities Anti-Terrorism Standards Program established under title XXI and the secure handling of ammonium nitrate program established under subtitle J of title VIII, or any successor programs;”

Commentary


I continue to believe that this change to the status of the current National Protection and Programs Directorate is mainly a smoke and mirrors change. I have had a number of people with closer connection to the operation of DHS inform me that this has to do mainly with the status of the new Director and the authority of the new agency to deal with administrative and spending matters; none of which is directly addressed in the language of the bill.

The change in wording of §2204(b)(2) has me a little bit concerned. Neither the addition or deletion has any direct affect on the CFATS program. The added ‘any successor’ language is typically a legal distinction addressing the fact that Congress could change the name of the program at any time. Similarly, the deleted words have no apparent practical effect on the inclusion of the CFATS program in the new Infrastructure Security Division. But, there is a nagging question in my mind as to why Johnson made these specific changes to the wording about the CFATS program; is there something in the works?

I am more concerned, however, with the deletion of §2202(e)(1)(M). I am not an active privacy advocate particularly when it comes to the Federal government; mainly because I suspect that we have completely surrendered any pretense of privacy protection and any attempts to put the genie back in the bottle are mainly for show rather than for any practical effect. Having said that, I am concerned that Johnson thought that it was appropriate to remove language from the bill that provided some modicum of privacy protection to information collected by DHS. It probably was not going to be very effective, but it at least made a show of being concerned.

 
/* Use this with templates/template-twocol.html */