Friday, July 12, 2019

Bills Introduced – 07-11-19


Yesterday with both the House and Senate in session there were 64 bills introduced. Four of those bills may see additional coverage in this blog:

HR 3699 To codify the Transportation Security Administration's responsibility relating to securing pipelines against cybersecurity threats, acts of terrorism, and other nefarious acts that jeopardize the physical security or cybersecurity of pipelines, and for other purposes. Rep. Cleaver, Emanuel [D-MO-5]

HR 3710 To amend the Homeland Security Act of 2002 to provide for the remediation of cybersecurity vulnerabilities, and for other purposes. Rep. Jackson Lee, Sheila [D-TX-18]

HR 3714 To amend title 18, United States Code, to reauthorize and expand the National Threat Assessment Center of the Department of Homeland Security. Rep. Deutch, Theodore E. [D-FL-22]

S 2095 A bill to provide for certain programs and developments in the Department of Energy concerning the cybersecurity and vulnerabilities of, and physical threat to, the electric grid, and for other purposes. Sen. Gardner, Cory [R-CO]

I will be watching HR 3710 and S 2095 for specific language referring to industrial control system security issues. For HR 3714 I will be watching for general cybersecurity language while hoping for ICS mentions.

Thursday, July 11, 2019

DHS Publishes PSP Program Announcement – 07-09-19


On Tuesday the DHS Cybersecurity and Infrastructure Security Agency (CISA) published a notice in the Federal Register (84 FR 32768-32777) outlining the implementation process for the expansion of the Personnel Surety Program (PSP) to Tier III and IV facilities. Yesterday they updated the Chemical Facility Anti-Terrorism Standards (CFATS) program landing page with a note about that expansion that pointed at the revised PSP web site.

Overview


Back in 2016 the DHS Infrastructure Security Compliance Division (ISCD, now part of CISA) implemented the portion of the PSP that provided for identifying CFATS employees and contractors or visitors with unaccompanied access to critical areas in covered facilities that may have ties to terrorist. The initial implementation was limited to Tier I and II facilities. In late 2017, ISCD started the process to expand the PSP process to Tier III and IV facilities.

The PSP web site has an interesting graphic that conceptually explains the PSP implementation process:



First, once notified by ISCD that the facility will begin the implementation process (and that notice will start the 60-day clock implementation clock), the facility will update their site security plan to include information about how they will implement the process at their facility. This weeks’ notice provides a look at what types of information ISCD will be looking for in that SSP modification. When ISCD approves that amended SSP the clock will again start on the facility’s actual implementation of that facility specific process.

ISCD will phase this implementation in over the next two years or so. They will provide each Tier III and IV facility with a notice of when they will officially begin the implementation process and the date of that notice begins the 60-day period in which the facility must submit a revised SSP. Facilities can begin work on that SSP revision now, or they can wait until they receive the notice. Facilities can even submit the amended SSP before they receive their notice.

Tier III and IV facilities that have not yet had their SSP approved (or perhaps even authorized) should expect that their SSP will have to include PSP implementation before ISCD give approval to the plan.

PSP Options


The CFATS PSP provides four different options that facilities may use to screen individuals for possible terrorist ties; actually five since ISCD included an obligatory possibility for facilities to propose some sort of alternative that would accomplish the same thing. Facilities may use any option or combination of options that they wish.

The notice describes each of these four options (imaginatively entitled: Option 1, Option 2, Option 3 and Option 4) in some detail. In my 2016 blog post I described them this way:

Option 1 – Facility submits data and ISCD has TSA conduct screening;
Option 2 – Facility submits data on personnel with previous screening and ISCD has TSA confirm that screening is current;
Option 3 – Facility uses TWIC Reader to verify identity and screening status of Transportation Workers Identification Credential (TWIC) holder; and
Option 4 – Facility visually inspects TSDB based identity document to verify that person had been screened against TSDB.

Commentary


I will keep this brief today since I already said most of what I want to say back in 2016. In fact, I did an entire blog post about what problems I expected facilities to face in implementing the PSP. I have not seen anything since then that would significantly change those observations.

Most facilities are going to find that they need a blended approach using two or more of the options that ISCD has provided. I think that every facility should probably expect to use all four options at one point or another. If the initial SSP revision addresses all four options, then the facility will have the maximum amount of flexibility in the PSP implementation. It would certainly save time down the road.

Remember, facilities can (should) begin their SSP revision process before they receive their notice from ISCD. I would not recommend submitting the revised SSP before that notice is received, because the official notice is also going to trigger specific Chemical Security Inspector support for the revision process.

Wednesday, July 10, 2019

5 Advisories and 4 Updates Published – 07-09-19


Yesterday the DHS NCCIC-ICS published four control system security advisories {Siemens (2), Schneider Electric, Rockwell and Emerson}, one medical device security advisory for products from GE, and updated four previously published advisories for products from Siemens.

SIPROTEC Advisory


This advisory describes two improper input validation vulnerabilities in the Siemens SIPROTEC 5 and DIGISI 5 products. The vulnerability was reported by Pierre Capillon, Nicolas Iooss, and Jean-Baptiste Galet from Agence Nationale de la Sécurité des Systèmes d’Information (ANSSI). Siemens has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow a denial-of-service condition and limited control of file upload, download, and delete functions.

Spectrum Power Advisory


This advisory describes a cross-site scripting vulnerability in the Siemens Spectrum Power product. The vulnerability was reported by Ismail Mert AY AK of Biznet Bilisim AS. Siemens has an update available that mitigates the vulnerability. There is no indication that Mert has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to inject arbitrary code in a specially crafted HTTP request and monitor information.

NOTE 1: The Siemens advisory uses new terminology for reporting NCCIC-ICS coordination efforts, it cites “CISA-Industrial Control System Vulnerability Disclosure team” as the coordinating agency. I am wondering if this is an official designation of a specific group of people operating at NCCIC or just another smoke and mirrors name change.

NOTE 2: Siemens published four other advisories yesterday in addition to these two. If they are not addressed by NCCIC-ICS later this week, I will be looking at them Saturday.

Schneider Advisory


This advisory describes a use after free vulnerability in the Schneider Zelio Soft programming platform. The vulnerability was reported by 9sg Security Team via the Zero Day Initiative. Schneider has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow remote code execution through the opening of a specially crafted project file.

NOTE 1: NCCIC-ICS does not provide a link to the Schneider Zelio Soft advisory.

NOTE 2: Schneider published five other advisories yesterday as well as the Zelio Soft advisory. It was a busy ICS security day.

Rockwell Advisory


This advisory describes an improper access control vulnerability in the Rockwell PanelView 5510 HMI. This vulnerability is self-reported. Rockwell has new versions that mitigate the vulnerability.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit this vulnerability to allow a remote unauthenticated user to gain root privileges on the device.

Emerson Advisory


This advisory describes a hard-coded credential vulnerability in the Emerson DeltaV Distributed Control System (DCS) software platform. The vulnerability was reported by Benjamin Crosasso of Sanofi. Emerson has a patch available to mitigate the vulnerability. There is no indication that Crosasso has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to gain administrative access to DeltaV Smart Switches.

GE Advisory


This advisory describes an improper authentication vulnerability in the GE Aestiva and Aespire Anesthesia Machines. The vulnerability was reported by Elad Luz of CyberMDX. GE has provided generic workarounds to mitigate the vulnerability. The FDA has not published a safety communication on this vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker the ability to remotely modify GE Healthcare anesthesia device parameters.

SIMATIC PCS Update


This update provides additional information on an advisory that was originally published on May 14th, 2019. The new information includes updated version data and links to mitigation measures for:

SIMATIC WinCC V7.4;
SIMATIC PCS 7 V8.2; and
SIMATIC PCS 7 V9.0

SIMATIC Update


This update provides additional information on an advisory that was originally published on April 9th, 2019 and updated on May 14th, 2019 and June 11th, 2019. The new information includes updated version data and links to mitigation measures for:

SIMATIC RF600R;
SIMATIC RF185C;
SIMATIC RF186C; and
SIMATIC RF188C

Industrial Products Update


This update provides additional information on an advisory that was originally published on April 9th, 2019 and updated on May 14th, 2019 and June 11th, 2019. The new information includes updated version data and links to mitigation measures for:

SIMATIC RF600R;
SIMATIC RF188C; and
SINEMA Server

CP 1604 Update


This update provides additional information on an advisory that was originally published on February 12th, 2019. The new information includes:

Update version information and mitigations; and
Add fixes for older product versions for CVE-2018-13808

NOTE: Siemens published four additional advisory updates yesterday. NCCIC-ICS is unlikely to address them so I will on Saturday.

Committee Adopts Rule for Consideration of HR 2500 – FY 2020 NDAA


Last night the House Rules Committee formulated the Rule for the consideration of HR 2500, the FY 2020 National Defense Authorization Act (NDAA). It is a structured rule with 439 amendments that may be offered (with provisions for en bloc consideration of amendments. I will be watching five of those amendments. Consideration of the bill begins this afternoon.

The Five Amendments


These are the five amendments that I will be watching. These are the five that I briefly listed last week in my post about the report on HR 2500.

53. Aguilar (D,CA) #244 Expands the Department of Defense Cyber Scholarship Program (formerly known as the Information Assurance Scholarship Program) to include students attending certificate programs that span 1 to 2 years.

158. Gallego (D,AZ) #415 Requires a report on the National Guard's capacity to meet Homeland Defense missions.

200. Jackson-Lee (D,TX) #160 (REVISED) Requires that a report from the Secretary of Defense 240 days after the date of the enactment to the congressional defense committees that accounts for all of the efforts, programs, initiatives, and investments of the Department of Defense to train elementary, secondary, and postsecondary students in fields related to cybersecurity, cyber defense, and cyber operations.

363. Speier (D,CA) #395 (REVISED) Increases funding for the Defense Security Service by $5,206,997 for the purposes of procurement of advanced cyber threat detection sensors, hunt and response mechanisms, and commercial cyber threat intelligence to ensure Defense Industrial Base networks remain protected from nation state adversaries.

381. Torres, Norma (D,CA), Panetta (CA), Cisneros (CA), Stevens (MI) #457 (REVISED) Requires the Department of Defense, in consultation with the Manufacturing Extension Partnership program, to develop policies to assist small- and mid-sized manufacturers to meet cybersecurity requirements.

The Gallego amendment is interesting. It would require a DOD report to Congress setting out “the roles and missions, structure, capabilities, and training of the National Guard and the United States Northern Command, and an identification of emerging gaps and shortfalls in light of current homeland security threats to our country” {new §520(1)}. Critical infrastructure cybersecurity is never explicitly mentioned in the amendment (an odd oversight) but would almost certainly be covered in any DOD report submitted in response to this amendment.

The one specific threat that is mentioned is a “multi-State electromagnetic pulse event” {new §520(2)}. Presumably DOD would also include a geomagnetic storm event in any report on the topic as the response to the two would be similar.

Moving Forward


None of the amendments listed above are very controversial and only one provides a specific spending authorization. Spier would off-set that spending increase by decreasing the spending on “in section 101 for other procurement, Air Force” {new §16XX(b)}. I suspect that all five of these amendments will be adopted; most will be included in en bloc amendments.

HR 2500 will pass, probably along a nearly party-line vote. The Senate already passed their version of the NDAA, S 1790, so differences between the two bills will have to be worked out (probably over the summer recess) in a conference committee. Normally, that reported version of the NDAA would be expected to pass, but with the whimsical nature of the current occupant of the White House, that is not a guarantee that anyone would be willing to make.

Monday, July 8, 2019

Committee Hearings – Week of 07-07-19


With both the House and Senate back in Washington after their 4th of July recess there is a relatively light committee hearing schedule. Only two hearings of interest here; one on grid cybersecurity and a Rules Committee hearing on the House version of the NDAA.

Grid Cybersecurity


On Friday, the Energy Subcommittee of the House Energy and Commerce Committee will hold a hearing on “Keeping The Lights On: Addressing Cyber Threats To The Grid”. The witness list is not yet available.

HR 2500 Rule


On Tuesday the House Rules Committee will meet to consider HR 2500, the FY 2020 National Defense Authorization Act. To date, a total of 658 amendments have been submitted to the Committee for consideration. This hearing will determine which of those amendments will be considered on the Floor of the House.

The bill is currently scheduled to be considered on the floor starting on Wednesday with a final vote likely on Friday.

NOTE: While there had been some talk about including the DHS appropriations bill (still not published by the House Appropriations Committee) in this bill as a way to move that forward, it does not look like that will happen.

Saturday, July 6, 2019

HR 3318 Introduced – TSA Threat Analysis

Last month Rep. Joyce (R,PA) introduced HR 3318, the Emerging Transportation Security Threats Act of 2019. The bill would require the Transportation Security Administration (TSA) to “establish a task force to conduct an analysis of emerging and potential future threats to transportation security” {§2(a)}. No specific funding for the task force is authorized in the bill.

Emerging and Future Threats


The Task Force analysis would include emerging and potential future threats posed by the following {§2(b)}:

• Evolving tactics by terrorist organizations that may pose a catastrophic risk to an aviation or surface transportation entity.
• Explosive and explosive devices or attacks involving the use of explosives that may cause catastrophic damage to an aviation or surface transportation system.
• Chemical or biological agents being released in either aviation or surface transportation systems.
• Cyberthreat actors seeking to undermine confidence in transportation systems or cause service disruptions that jeopardize transportation security.
• Unmanned aerial systems with the capability of inflicting harm on transportation targets.
• Individuals or groups seeking to attack soft targets, public areas, or crowded spaces of transportation systems.
• Inconsistent or inadequate security screening protocols at last point of departure airports with direct flights to the United States.
• Information sharing challenges within the Federal Government and among partner governments.
• Information sharing challenges between the Administration or other relevant Federal agencies and transportation stakeholders, including air carriers, airport operators, surface transportation operators, and State and local law enforcement.
• Growth in passenger volume in both the aviation and surface transportation sectors.

Threat Mitigation


The bill would subsequently require the TSA to develop “a threat mitigation strategy for each of the threats examined in such analysis” {§2(c)}. This would include:

• Assigning appropriate resources of the Administration to address such threats, based on calculated risk; or
• Provide recommendations through the Department of Homeland Security to the appropriate Federal department or agency responsible for addressing such threats.

TSA would also be required to improve stakeholder engagement and provide a briefing to Congress.

Moving Forward


Joyce and his cosponsor, Rep. Rogers (R,AL) are both members of the House Homeland Security Committee (and Rogers is the Ranking Member of that Committee), so there is a reasonable chance that this bill could be considered by the Committee.

There is nothing in the bill that would engender any specific political or business opposition to the bill; study and report bills seldom do. I suspect that the bill would receive substantial bipartisan support in Committee. With such support the bill would be considered by the full House (if there were enough political influence to move the bill forward) under the suspension of the rules process.

Commentary


Joyce’s staff did a good job of ensuring that the language of the bill provided nearly equal coverage to threats against both airline and surface transportation assets. Unfortunately, the language is clearly focused on passenger transportation, and calls for scant scrutiny of freight transportation (either air or ground) or pipeline security. This is especially true when it comes to the one reference to chemical threats.

With that in mind, I would like to offer the following changes to some of the ‘elements’ of the threat that are be considered by the threat analysis in §2(b) (Highlighted words are added):


(1) Evolving tactics by terrorist organizations that may pose a catastrophic risk to an aviation or surface transportation entity including freight transportation in both modes.

(2) Explosive and explosive devices or attacks involving the use of explosives that may cause catastrophic damage to an aviation or surface transportation system or cause a release of hazardous industrial chemicals in surface freight transportation.

(4) Cyberthreat actors seeking to undermine confidence in transportation systems or cause service disruptions that jeopardize transportation security or cause catastrophic damage to a hazardous material or fuel pipeline.

The other problem that this bill ignores is the lack of specific authority provided to TSA to issue security regulations for surface transportation or the failure of TSA to implement the few regulations that it has been authorized to issue. With that in mind I would re-do paragraph (e) to read:

(e) BRIEFING TO CONGRESS.—The Administrator of the Transportation Security Administration shall brief the Committee on Homeland Security of the House of Representatives and the Committee on Commerce, Science, and Transportation of the Senate on: the results of the analysis required under subsection (a) and relevant mitigation strategies developed in accordance with subsection (c).
(1) The results of the analysis required under subsection (a);
(2) The relevant mitigation strategies developed in accordance with subsection (c);
(3) The status of current rulemakings authorized by Congress that might address the threats identified in subsection (a); and
(4) What rulemaking authorities that TSA or other Federal agencies might need from Congress to appropriately apply the mitigation strategies developed in accordance with subsection (c).

Public ICS Disclosure – Week of 06-29-19


This week we have a vendor update for the Microsoft® RDP vulnerability and seven researcher reports (okay is should be a single report with seven vulnerabilities) from Zero Science for products from FaceSentry.

Microsoft RDP Vulnerability Vendor Reports



FaceSentry Advisories


Zero Science published seven reports of vulnerabilities in the FaceSentry Access Control System. These are all zero-day reports with Zero Science reporting no response from iWT, the manufacturer.

The seven reported vulnerabilities (with proof of concept code) are:



 
/* Use this with templates/template-twocol.html */