Tuesday, December 4, 2018

Bills Introduced – 12-03-18


With both the House and Senate in session yesterday, there were 14 bills introduced. I will be watching three of these in the short time left in the 115th Congress:

HR 7213 To amend the Homeland Security Act of 2002 to establish the Countering Weapons of Mass Destruction Office, and for other purposes. Rep. Donovan, Daniel M., Jr. [R-NY-11]

HR 7214 To direct the Secretary of Education to establish a pilot program to award competitive grants for the integration of cybersecurity education, and for other purposes. Rep. Langevin, James R. [D-RI-2]

HJ Res 143 Making further continuing appropriations for fiscal year 2019, and for other purposes. Rep. Frelinghuysen, Rodney P. [R-NJ-11]

HR 7213 is a perennial favorite, but I suspect this version is unique in that it would include CISA language. I am interested in this bill for possible provisions concerning chemical weapons and more importantly the weaponization of industrial chemicals.

HR 7214 looks like an interesting concept from a Congressman noted for his interest in cybersecurity issues. Note: he will be a tad bit more important next year in the Democratic House and this bill will almost certainly reappear then.

HJ Res 143 is a two-week continuing resolution that continues funding those portions of the Government without a passed funding bill (principally DHS and State) until December 21st, 2018. Ostensibly this is required because the House and Senate will be honoring the late President HW Bush today and tomorrow and they will not be able to work on the actual spending bill during that time. This is a relatively ‘clean’ CR as the only added provision is a similar extension of the flood insurance program. This bill will be passed in the House on Thursday and either Thursday or Friday in the Senate.

NOTE: Only HJ Res 143 will see any action in this session; the other two are ‘look what I have done’ bills.

Monday, December 3, 2018

ICS as a Service


Jake Brodsky has an interesting article over at SCADASEC Magazine about the need for and the costs associated with establishing an ICS lab; it is well worth the read for both technical folks and people who use industrial control systems. What struck me, however, was how expensive an operation this would be and how it would be justified to management.

A refinery, big-pharma, or an automobile manufacturing plant; sure they could afford it (and probably could not afford not to have it, sorry about the double negative), but I come from a background of small specialty chemical manufacturing plants. The biggest OT staff that I have worked with was a single control system engineer supported by a lonely tech. Other times, it was only a tech who was also the plant electrician. I suspect that the largest number of automated facilities have similar levels of staffing; the minimum number to keep an outside designed and integrated system in operation. Major problems…. Call the contractor.

And that reminds me, who has a security operations center (SOC)? Certainly not the places that I have worked. Again, could not afford the expense. But, both operations would really make any industrial control system more efficient, safe and reliable in the long run. Anyone that relies on an automated control system to keep product flowing out the front gate really needs the support provided by both an ICS-Lab and an SOC.

Maybe it is time for smaller organizations to stop relying on integrators to set up their control systems and start looking for a supplier of ICS as a service (ICSaaS; there you go, it is now a thing complete with fancy *aa* acronym). This would be a one stop shop that would provide integration services, security and efficiency monitoring, operator training, and patch/upgrade testing services. They could also provide data analysis services for process problem diagnostics and process improvement activities. In short, all of the ICS bells and whistles that the big guys take for granted and the small guys just cannot afford to even dream about.

And these ICSaaS guys could certainly afford Jakes ICS lab.

BTW: Jakes ICS lab would also be a good place to train ICS security folks. Just saying.

Sunday, December 2, 2018

HR 7188 Introduced – CFATS Extension


Last week Rep. Ratcliffe (R,TX) introduced HR 7188, the Chemical Facility Anti-Terrorism Standards Program Extension Act. The bill is a ‘clean’ extension of the current authority for the Chemical Facility Anti-Terrorism Standards (CFATS) program adding two years to the expiration in the current legislation.

While the original description of the bill included the phrase “and for other purposes”, there are no other provisions in the bill.

The bill is not currently on the schedule for consideration in the House, but the schedule this close to the end of the session is a tad bit more flexible than we normally see in the House.

This bill has the right sponsorship to see broad bipartisan support if/when the bill comes to the floor. As it currently stands there is one Senator firmly standing in the way of this bill being considered in the Senate, Sen. Johnson (R,WI). He said last week on the floor of the Senate that he would rather see the CFATS program shut down than see this bill pass.

Hopefully, the behind the scenes wrangling continues. And the possibility still remains that the same extension could find its way into the DHS spending bill that will probably be considered this week.

Saturday, December 1, 2018

Public ICS Disclosure – Week of 11-24-18


This week we have three vendor disclosures from Schneider Electric, ABB and Siemens, exploit code for a previously disclosed vulnerability and a disclosure from a researcher which is probably been coordinated with Moxa. And there is a special non-disclosure disclosure at the end of the post.

Schneider Advisory


This advisory describes five vulnerabilities in the Schneider Embedded Web Servers for Modicon V1.1 PLC’s. The vulnerabilities were reported by Tenable. Schneider has provided generic fixes to mitigate the vulnerability. There is no indication that Tenable has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Unverified password change (2) - CVE-2018-7811 and CVE-2018-7809;
• Cross-site scripting - CVE-2018-7810;
• Basic XSS - CVE-2018-7831; and
HTTP response splitting - CVE-2018-7830

ABB Advisory


This advisory describes an improper input validation vulnerability in the ABB CP400 Panel Builder TextEditor 2.0. The vulnerability was reported by Ivan Sanchez from Nullcode Team. ABB has an updated version of the affected products to mitigate the vulnerability. ABB reports that Sanchez has verified the efficacy of the fix.

Siemens Advisory


This advisory describes 21 vulnerabilities in GNU/Linux subsystem of
the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP. The vulnerabilities were reported by an unidentified ‘external source’. Siemens reports that the vulnerabilities will be corrected in the next firmware version and currently provides generic mitigation advice.

The advisory provides links to 21 CVE’s without a description of the associated vulnerability or risk evaluation of the vulnerability in the affected system. I have clicked through on a couple of these links to the Debian.org reports on the vulnerabilities and there are a wide variety of vulnerabilities involved here with reports of public exploits for many of them. Those exploits are not specifically for the Siemens implementation of these processes, but a reasonably competent hacker could probably use them to craft a Siemens specific exploit.

NOTE: Insert standard blurb about 3rd party vulnerabilities potentially being found in products from other vendors. Fortunately (sarcasm warning) Linux is a rather obscure OS and is seldom seen in real operations. (SIGH)

Schneider Exploit


PHOTUBIAS published an exploit for a session calculation authentication bypass vulnerability in the Schneider Modicon PLCs. This vulnerability was previously reported by ICS-CERT.

NOTE: Exploit-DB.com has ‘updated’ the layout of their site. Larger print in headers, more colorful, but unfortunately harder to read. Too bad.

Moxa Vulnerabilities


Maxim Khazov reports two OS command injection vulnerabilities in the Moxa NPort W2x50A wireless device servers. The report includes proof of concept exploit instructions. Khazov reports that Moxa has fixed these vulnerabilities in a newer version, but it is not clear if this is a coordinated disclosure.

Bonus Non-Disclosure Disclosure


This week OSIsoft released a new version of PI Integrator for Business Analytics. In the release notes (pg 12) OSIsoft notes that:

“For this release of the PI Integrator for Business Analytics, one security vulnerability was identified and fixed. The resolved issue was rated using the Common Vulnerability Scoring System (CVSS).”

The only other information provided was that the CVSS score was rated as low (0.1 to 3.9).

Now I have a lot of respect for OSIsoft’s commitment to security and I am a big fan of their PI Processbook application, but the way OSIsoft has handled this non-disclosure is disappointing. It is great that they have fixed this unidentified, low-risk security vulnerability, but they have provided no security incentive to owners of this product to upgrade to this new version. The other fixes enumerated in the release notes may provide adequate incentive to upgrade, but if folks have not had problems with those listed issues, a defined security problem might make a difference.

BTW: I really hate it when people set security on .PDF documents so that they will not allow cutting and pasting from the documents. Really? I like to make sure that when I quote a document, I do it accurately. Cutting and pasting is the easiest, most efficient way of doing that. Re-typing just sets me up for making errors. And, the quote is still there.

Friday, November 30, 2018

S 3405 Dies in the Senate


Yesterday Sen. Johnson (R,WI), Chair of the Senate Homeland Security and Governmental Affairs Committee, called for the Senate to consider S 3405, the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2018, under the unanimous consent process. Instead of the substitute language reported out of Committee, Johnson offered a second substitute as an amendment. Sen. Carper (D,DE) objected, and the consideration was prevented.

Sen. Johnson published a press release on the situation that would make it appear that he was being blindsided by the opposition to the bill. A reading of the Congressional Record for the debate between Johnson and Carper makes it clear that the situation is complicated. What is clear from the debate however is that Johnson is clearly upset by the failure of the two House committees to come up with a reauthorization bill and then at the last minute come up with a two-year extension of the CFATS program that apparently disregards the work done by the Senate Committee. The fact that Johnson had to go to someone outside of the leadership of the two House committees with CFATS oversight responsibility to get a companion bill introduced made it clear that he knew about the opposition to his proposed reforms in the House.

Unfortunately, the version of S 3405 that Johnson asked the Senate to approve (essentially unseen) was not printed in the Congressional Record. Neither was the extension bill that Carper said in the debate he was introducing.

Carper offered Johnson a way out of yesterday’s immediate conflict; withdraw the unanimous consent request. Johnson declined. They both agreed to continue to work together to work out the problems with the S 3405. Johnson, however, said that he would rather see the CFATS program die than see a short-term extension approved without some sort of program reforms. It was not clear from yesterday’s debate what reforms would be the minimum acceptable.

I suspect that the minimum would be the explosive exception and the recognition program. Unfortunately, it may be just those reforms that Secretary Nielson was concerned about when she sent her letter to Johnson (and presumably Rep. McCaul (R,TX) and Rep. Walden (R,OR). That is not certain because that letter has not yet been made public.

I have not yet seen the Committee Report on S 3405 (still not published), but the reported language has been published. It was nearly identical to the language that was proposed in HR 6992. Of course, that language was still not the language that Johnson was asking to have adopted today.

Johnson faces a difficult decision on the CFATS authorization. The bipartisan support Johnson received in Committee for the industry favorable reforms included in S 3405 indicates that they might survive a Democratic House next year, but the opposition of the DHS to those reforms indicates that there may be opposition from his own party in subsequent Senate hearings. It apparently looks to him like those reforms have to pass in this session of Congress or not pass at all.

It’s just too bad that he did not try to get this bill to the Senate floor before Nielsen became aware of the problems. Or maybe it is not.

Now it comes down to how much time both sides have to work out a deal. Right now it looks like it might be easier to pass immigration reform.

PHMSA Harmonization NPRM – Corrosive Classification Process


Earlier this week I wrote about the recent publication of a notice of proposed rulemaking from DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) proposing the latest set of revisions to the hazardous material regulations (HMR) to harmonize those regulations with international hazmat shipping rules. Today I would like to address a specific portion of that NPRM; the classification process for corrosive materials in accordance with 49 CFR 173.137.

Overview


In section 4 of the NPRM, PHMSA briefly describes the changes to the HMR being proposed. With regards to the classification of corrosive materials it notes:

“Alternative criteria for classification of corrosive materials: PHMSA proposes to include non-testing alternatives for classifying corrosive mixtures that instead uses existing data on the chemical properties. Currently the HMR require offerors to classify Class 8 corrosive material and assign a packing group based on test data. The HMR authorize a skin corrosion test and various in vitro test methods that do not involve animal testing. However, data obtained from testing is currently the only data acceptable for classification and assigning a packing group. These alternatives would afford offerors the ability to make a classification and packing group assignment without the need to conduct physical tests.”

PHMSA is also proposing to update the incorporation by reference OECD Guidelines for the Testing of Chemicals to the 2015 version. Specifically, for the testing of corrosive materials for determination of packing group determination, this will affect OECD tests 404, 430, 431, and 435.
Along with the similar change to the definition of ‘corrosive material’ in 173.136, PHMSA is proposing to remove the phrase “full thickness destruction” and replace it with “irreversible damage” in all instances where it occurs in 173.137.

PHMSA is not proposing to add additional corrosivity testing protocols in this NPMR.

Corrosion Classification Alternatives


The proposed regulation provides two non-testing alternatives to determine the packing group containing mixtures of chemicals including one or more previously tested corrosive chemicals. The first, bridging {§173.137(d)(1)}, would be used when “there is sufficient data on both the individual ingredients and similar tested mixtures to adequately classify and assign a packing group for the mixture”. There are five bridging principals that could be applied to mixtures under this provision:

Dilution;
Batching;

The second technique is the calculation method {§173.137(d)(2)}. This technique uses known concentration data and regulatory information from the Hazmat Table to calculate which packing group a product would be in. A proposed Appendix I helps translate the calculations into actual packing group determination.

Calculation Process


By their very nature, regulatory documents are not real clear in explaining how a process will work. After some careful reading of the NPRM and the proposed changes to §173.137 and the new Appendix I, this is how I see the calculation process working.

First, someone is going to have to make a technical determination of whether or not any interactions (or chemical reactions) will enhance the corrosive effects of any of the constituent materials. It that determination is positive, then physical testing will be required, or the organization will have to assume PG I status for the material.

Next all of the corrosive constituents of the product will have to be identified. The Hazmat Table (§172.101 table) will then be used to determine the packing group and any minimum concentration limit associated with that material in the Table. That minimum concentration limit is called the ‘specific concentration limit (SCL)’ in this NPRM. Unfortunately, it is not specifically defined.

The first calculation will only involve PG I corrosive constituents of the product. For each PG I corrosive constituent the ratio of its concentration in the product to the SCL will be determined. For most corrosive materials, the Hazmat Table does not provide an SCL; for those chemicals a generic concentration limit (GCL; again, not specifically defined in the NPRM) of 1% will be assumed for this initial calculation. The sum of all of the PG1/SCL(GCL) ratios will be determined. If that sum is greater than or equal to one, Calculation #2 will be completed. If the sum is less than 1%, Calculation #3 will be completed.

Calculation #2. Again, just the concentration and GCL for the PG 1 corrosive materials in the product will be used. In this case (and in all subsequent calculations) the GCL will be equal to 5% and the concentration ratios for all PG I will be recalculated. If the sum of those ratios is greater than or equal to 5% then the material will be classified as Class 8, PG I. If the sum of those ratios is less than 5%, the material will be classified as Class 8, PG II.

Calculation #3. This calculation will use the same data from all PG I and PG II chemicals in the material being classified. Where a SCL is provided it will be used in the ratio calculation described above. Otherwise, a GCL of 5% will be used. The ratios for each of the PG I and PG II chemicals will be summed. If the sum is greater than or equal to 5%, the material will be classified as Class 8, PG II. If the sum is less than 5%, Calculation #4 will be completed.

Calculation #4. This calculation will use the same data from all PG I, PG II and PG III chemicals in the material being classified. Where a SCL is provided it will be used in the ratio calculation described above. Otherwise, a GCL of 5% will be used. The ratios for each of the PG I, PG II and PG III chemicals will be summed. If the sum is greater than or equal to 5%, the material will be classified as Class 8, PG III. If the sum is less than 5%, the material will not be classified in Class 8.

Bills Introduced – 11-29-18


Yesterday with both the House and Senate in Washington, there were 52 bills introduced. Three of those bills may see future coverage in this blog:

HR 7188 To extend by two years the Chemical Facility Anti-Terrorism Standards Program of the Department of Homeland Security, and for other purposes. Rep. Ratcliffe, John [R-TX-4]

HR 7192 To enhance the early warning reporting requirements for motor vehicle manufacturers, and for other purposes. Rep. Cartwright, Matt [D-PA-17] 

S 3677 A bill to provide for certain programs and developments in the Department of Energy concerning the cybersecurity and vulnerabilities of, and physical threats to, the electric grid, and for other purposes. Sen. Gardner, Cory [R-CO] 

With the Chair and Ranking Member of both the House Homeland Security and House Energy and Commerce Committees as cosponsors, HR 7188 will move to the floor of the House early next week. It will be interesting to see what “and for other purposes” are included in this bill. Needless to say this means that HR 6992 and S 3405 are effectively dead.

I would normally be watching HR 7192 specific cybersecurity reporting requirements, but this bill has little to no chance of being considered in the 115th Congress. We may see this again next year.

S 3677 could be interesting, but it will not see any action this year. Again, this will probably be reintroduced next year.

 
/* Use this with templates/template-twocol.html */