Thursday, November 14, 2019

HR 4987 Introduced – FDPREP Act


Last week Rep Herrera Beutler (R,WA) introduced HR 4987, the Fire Department Proper Response and Equipment Prioritization (FDPREP) Act. The bill would require the Federal Emergency Management Agency (FEMA) to give priority in administration of firefighter assistance grants to grant requests related to crude-by-rail or ethanol-by-rail response.

The bill amends 15 USC 2229(c) (Assistance to firefighters grants) by adding a new paragraph (4) that would require FEMA to “give high priority consideration to grants providing for planning, training, and equipment to firefighters for crude oil-by-rail and ethanol-by-rail derailment and incident response”.

Moving Forward


Herrera Beutler is a member of the House Science, Space, and Technology Committee to which this bill is assigned. She should have adequate influence to see this bill considered in Committee. There is nothing in the language of this bill that would engender any significant opposition since no new funds are being allocated. This bill would probably have enough bipartisan support to have it considered on the floor of the House under the suspension of rules process.

Commentary


Herrera Beutler is an interesting case, a Republican opponent of crude-by-rail. This is an important issue for her constituents. Her district sits astride the main rail corridor for Bakken crude oil destined for west coast refineries.

This very simple and direct bill addresses the very real problem of how local fire departments pay for planning and training for, and the execution of, emergency response measures for a low-probability, high-consequence event like an oil-train fire.

This is not a total solution to the problem, as these grants are relatively limited and there are hundreds of communities potentially affected by this issue. But it is certainly a step forward in helping these fire departments.

Wednesday, November 13, 2019

S 2775 Introduced – HACKED Act


Last week Sen Wicker (R,MS) introduced  S 2775, the Harvesting American Cybersecurity Knowledge through Education (HACKED) Act of 2019. The bill would modify a number of existing federal computer training related programs to specifically include cybersecurity training.

Programs Amended


This bill would make amendments to the following programs under the National Institute for Standards and Technology (NIST):

15 USC 7451 – National cybersecurity awareness and education program;
15 USC 7442 – Federal Cyber Scholarship-for-Service Program; and
15 USC 278g-3 – Computer standards program

This bill would make amendments to the following programs under the National Science Foundation (NSF):

42 USC 1862s-7 - Computer science education research;
42 USC 1862i – Scientific and technical education;
42 USC 1869c – Low-income scholarship program;
42 USC 1869 – Scholarships and graduate fellowships;
42 USC 1881b – Presidential awards for teaching excellence;
42 USC 1862s-6 – Presidential awards for excellence in STEM mentoring; and
42 USC 6621 - Coordination of Federal STEM education

This bill would make amendments to the following programs under the Department of Transportation:

49 USC 5505 - University transportation centers program;
49 USC 6503 - Transportation research and development 5-year strategic plan

Moving Forward


Wicker is the Chair of the Senate Commerce, Science, and Transportation Committee to which this bill was assigned for consideration. The bill is scheduled to be taken up by that Committee today as part of a business meeting. The bill will almost certainly be adopted by a significant bipartisan vote since no new funds are authorized by the bill.

Commentary


The biggest problem with this bill is that there is no definition of ‘cybersecurity’ anywhere in the bill. The underlying definitions for the NIST portions of the bill come from PL113-274. In my blog post about that bill I noted that while “industrial or supervisory control systems” are specifically mentioned in the underlying bill {§2(2)} they are only addressed in reference to IT specific information systems.

There are no definitions of ‘cybersecurity’ in any of the referenced NSF programs or DOT programs.

Now I have previously addressed a number of definitional issues related to cybersecurity. My most comprehensive attempt at coming up with cybersecurity definitions that were clearly applicable to both information and operational cyber systems can be found here. Unfortunately, I did not specifically address the term ‘cybersecurity’. I will try to take that up here.

I do not expect that this bill would be a good place (nor is this Committee the appropriate agent) to address each of the definitions that I proposed earlier, so I will try to accomplish this with just addressing two terms; ‘cybersecurity threat’ and ‘cybersecurity’. First, I would use the existing definition of ‘cybersecurity threat’ from 6 USC 1501; remember that definition relies on the ICS inclusive definition of ‘information system’ from that section. Then I would define ‘cybersecurity’:

Cybersecurity – The term cybersecurity means any actions, policies or procedures utilized to protect an information system (as that term is defined in 6 USC 1501) from a cybersecurity threat (as that term is defined in the same section) or mitigate the effects of a cybersecurity threat against such cybersecurity threat.

Bills Introduced – 11-12-19


Yesterday with both the House and Senate in session there were 46 bills introduced. One of those bills may receive additional coverage in this blog:

S 2840 A bill to authorize appropriations for fiscal year 2020 for military activities of the Department of Defense, for military construction, and for defense activities of the Department of Energy, and for other purposes. Sen. Inhofe, James M. [R-OK]

This will be the third version (earlier versions were S 1790 and S 2731) of the National Defense Authorization Act that Inhofe has introduced this year. He is still making an attempt to move this ‘must pass’ legislation forward while keeping both the President and the House Democrats happy. It will be interesting to see what cybersecurity provisions remain in this one.

Tuesday, November 12, 2019

1 Update Published – 11-12-19



Today the CISA NCCIC-ICS published an update to an industrial control system security advisory for products from Siemens.

Siemens Update


This update provides additional information on an advisory that was originally published on August 15th, 2019. The new information includes updated version data and mitigation measures for SINAMICS SL150 V4.7.

Other Siemens Advisories


Siemens also published 3 new advisories and an additional four updates today as part of their monthly advisory drop. NCCIC-ICS will probably address some of them on Thursday. The remainder I will discuss Saturday.

Committee Hearings – Week of 11-10-19


This week both the House and Senate will be in Washington. Of course impeachment hearings will be all in the news, but there are two cybersecurity hearings that may be of interest; one a markup and one an oversight hearing.

Cybersecurity Markup


On Wednesday the Senate Commerce, Science, and Technology Committee will hold a business meeting where 22 bills, four nominations and a routine Coast Guard promotion list will be considered. Among the bills being considered in HR 2775, the Harvesting American Cybersecurity Knowledge through Education (HACKED) Act of 2019.

This bill was introduced last week, and the official copy of the language has yet to be printed. The hearing page has a link to a committee print of the bill. It addresses a wide range of existing cyber training programs. I have not had a chance to peruse it in detail, but there is little in the way of specific reference to control system security training issues beyond a brief mention of issues with automated driving systems.

Cybersecurity Oversight


On Thursday the Technology Modernization Subcommittee of the House Veterans Affairs Committee will hold an oversight hearing on “Cybersecurity Challenges and Cyber Risk Management at the Department of Veterans Affairs.” A witness list has not yet been published.

The hearing web page notes that: “The purpose of the hearing is to assess how the Department of Veterans Affairs (VA) manages its cybersecurity program, including controlling access to confidential data, supply-chain management, and the safeguarding of information technology assets.” I guess that means that medical device security issues will not be a major (probably not even a minor) issue in the hearing.

Saturday, November 9, 2019

Public ICS Disclosures – Week of 11-02-19


This week we have two vendor notifications from PEPPERL+Fuchs and Moxa. We also have a 0-day vulnerability report for products from Siemens. Plus there is an interesting look at the out-of-service problem and a follow-up to the ABB advisory I discussed last week.

PEPPERL+Fuchs Advisory


CERT VDE published an advisory describing a use after free vulnerability in the PEPPERL+Fuchs ecom Mobile Devices. The vulnerability was reported by Maddie Stone from Google Project Zero. This is a previously reported third-party (Linux) vulnerability in the underlying Android operating system. The vulnerable products are out of support.

NOTE: Other vendors using Android based devices will likely have similar vulnerabilities.

Moxa Advisory


Moxa published an advisory describing two GET command vulnerabilities in the Moxa EDS-405A Series Ethernet Switches. The vulnerabilities are self-reported. Moxa has a patch available to mitigate the vulnerabilities.

Siemens Vulnerability


There is an interesting article over on DARKReading.com (thanks to @PatrickCMiller for pointing me at the article) describing an interesting feature/vulnerability in the Siemens Siemens' S7-1200 PLCs. The article notes that Siemens has been notified (okay, so not technically a 0-day), but there has not yet been an advisory or fix from Siemens. I expect we may see an advisory on Tuesday during the monthly Siemens advisory drop.

If it ain’t broke don’t fix it Department


There is an interesting announcement from Omron about the pending ‘out-of-support’ status for Windows 7®. The information is rather generic and references no specific Omron products. It does, however, provide a unique view of why it may be difficult for control system owners to transfer systems to newer versions of the Windows® operating system (or any updating to any new OS for that matter).

Omron notes that:

When upgrading an old control system including obsolete PCs and operating systems make sure you consider the following:
• Which Operating System should you upgrade to - the next OS or the latest OS?
• Will your PC hardware (CPU, disk space etc) support your new OS or will you need to purchase new hardware too?
• Will your existing software applications support your new OS or will you need to purchase a software upgrade?

Given the fact that industrial control systems are custom installations, potentially involving large numbers of vendors, it is easy to see that upgrading to a supported OS could get to be quite expensive in time and money. It is no wonder that we still have large numbers of systems operating on Windows XP®.

ABB Follow-up


An interesting tweet and associated blog post from Rikard Bodfros on last week’s ABB vulnerability report.

Friday, November 8, 2019

Bills Introduced – 11-07-19


Yesterday with just the Senate in session there were 30 bills introduced. One of these bills will receive future coverage in this blog:

S 2818 A bill to require the Secretary of the Interior to issue regulations to ban the venting and flaring of gas in oil and gas production operations in the United States, and for other purposes. Sen. Markey, Edward J. [D-MA]

Okay, I will admit to a viscerally horrified objection to this bill when I read the descriptive title above, but we will have to see what the wording of the prohibition actually is before we can tell if this is a totally misguided attempt to prohibit a legitimate and necessary safety process. I understand that methane gas is a powerful greenhouse gas and that venting it as a ‘waste disposal process’ is probably an insanely wasteful environmental mistake, but there are severe safety issues that must be taken into account.

Enough of the rant, I will wait for the bill to be published and report accordingly.

 
/* Use this with templates/template-twocol.html */