Friday, May 21, 2010

FCC’s ERIC Rule

Yesterday the Federal Communications Commission published their Final Rule for the establishment of the Emergency Response Interoperability Center (ERIC). According to the preamble to the rule “ERIC will be tasked with implementing national interoperability standards and developing technical and operational procedures for the 700 MHz public safety broadband wireless network” (75 FR 28207).

The rule establishes ERIC within the Public Safety and Homeland Security Bureau (PSHSB), but the details of the internal operation of ERIC were largely excluded from the final rule “because the adopted rules are rules of agency organization, procedure, or practice that do not substantially affect the rights or obligations of non-agency parties”. The rule does provide for the appointment of advisory bodies to advise ERIC. There is nothing in the rule that would specifically affect the chemical security community, but it does give me a chance to continue to plug for ensuring that security programs at high-risk chemical facilities can and do routinely communicate with local law enforcement.

The development of the use of the 700 MHz for broadband wireless communications for the public safety community provides an excellent opportunity to tie both the security teams and emergency response teams at high-risk chemical facilities into the communications capabilities of local law enforcement and first response community. In most cases where there is a serious incident, either accidental or as the result of an attack, at these facilities the on-site personnel will already be attempting to deal with the situation by the time that local response arrives on scene.

As the local incident commander takes control of the scene, gaining up-to-date information from the facility response teams will be critical in planning and executing the off-site response. This informational exchange can only be enhanced if the on-site personnel have interoperable communications and have trained with the local responders.

 Of particular importance in this interoperable communications will be the provisions for high-speed data communications to share information like live video from on-site surveillance cameras. Additionally a wide range of process sensors could provide invaluable information about the physical conditions of critical storage tanks and process equipment. Facilities with a network of chemical detectors to identify and track leaks would find that the local responders would greatly appreciate that information.

So, I’m taking this opportunity to stand on my soap box to urge the FCC, through ERIC, to take into consideration the high-speed data communications requirements between high-risk chemical facilities (and obviously other critical infrastructure and key resource facilities) and local first responders and law enforcement when they plan. Unfortunately the FCC did not make provisions for public comments in the publication of this rule, so I just stand here on my soap box. Perhaps Congress could include provisions in any CFATS reauthorization (if and when) mandating the establishment of such communications channels.

Thursday, May 20, 2010

HR 4842 Committee Report

The House Homeland Security Committee published their report on HR 4842, the Homeland Security Science and Technology Authorization Act of 2010 on Tuesday, though the report was not available from the GPO until Thursday. The bill was then assigned to the House Committee on Science and Technology for a period ending not later than June 18, 2010. Depending on how fast the Science and Technology Committee gets through their review, it is just barely possible that this bill could get to the floor of the House before the July 4th recess. Lacking that, it still has a decent chance of making it to the floor before the summer recess on August 6th. Whether or not it has any chance of making it through the Senate during this session remains to be seen. The chemical security related provisions that I described in an earlier blog remain intact and unchanged. There have been a number of new provisions added to the bill during the two markup hearings that were held in the Homeland Security Committee. Only one of those provisions will have any significant effect on the chemical security community. The Commission Section 701 of the revised bill provides for the establishment of the Commission on the Protection of Critical Electric and Electronic Infrastructures. Mainly directed at assessing the vulnerabilities of the electrical grid it also covers ‘electronic infrastructures’ that includes “all computerized control systems used in all United States critical infrastructure sectors” {§701(b)(1)(A)(ii)}. The Homeland Security Committee intends for the Commission “to take up where the former Commission to Assess the Threat to the United States from Electromagnetic Pulse (EMP) Attack—often referred to as the EMP Commission—left off when its authorization expired in December of 2008” (pg 48 of House Report 111-486). They have however, greatly expanded the scope of threats to assess.
“The Commission shall give particular attention to threats that can disrupt or damage critical electric and electronic infrastructures, including— “(A) cyber attacks or unintentional cyber disruption [emphasis added]; “(B) electromagnetic phenomena such as geomagnetically induced currents, intentional electromagnetic interference, and electromagnetic pulses caused by nuclear weapons; and “(C) other physical attack, act of nature, or accident [emphasis added].”
I think that it is entirely appropriate that the Commission is specifically being tasked to look at cyber disruptions that have nothing to do with intentional acts. Cyber attacks will almost certainly remain much less common than the accidents, equipment failures and weather events that will be a common part of our world for a long time to come. Their ability to disrupt the operation of critical cyber systems will vary from the inconvenient to catastrophic. But, they will inevitably cause more problems than actual terrorist attacks. The authorization for this Commission includes funding for two years. That is certainly reasonable for a comprehensive study like that envisioned in HR 4842. That is also the main shortcoming of these types of studies. They take too long to complete and then Congress will play with the results for a while before they have any chance of putting substantive legislation together Then there will be a lengthy rule making process started in motion. Even if this bill were approved this summer it would be late 2012 before we could possibly see even obvious measures make their way through the political system. The controversial recommendations could take much longer to move through the political maze.

CIKR Learning Series Page Updated 05-20-10

Today DHS updated their Critical Infrastructure and Key Resources (CIKR) Learning Series web page. They moved the listing for the webinar that was held earlier this month to the “Review past CIKR Learning Series webinars” list on the page. Clicking on the “2010 Hurricane Season: Tools for Understanding Risk” will take one to a recorded version of that webinar.

Wednesday, May 19, 2010

Right-to-Know vs Security

Not long after the 9/11 dust settled on the streets of New York the Environmental Protection Agency was required to remove a great deal of information about chemical facilities from its web sites. The community right-to-know information had been posted on the web site to allow any US citizen to know what dangerous chemicals were being used in large quantities in their neighborhoods. The security folks decided that the same information could be used by the likes of al Qaeda to select their next target, high-risk chemical facilities. The Information This last Monday, the pendulum started officially swinging in the other direction. The EPA posted a press release on its web site announcing that it had “added more than 6,300 chemicals and 3,800 chemical facilities regulated under the Toxic Substances Control Act (TSCA) to a public database called Envirofacts”. This was being done as “part of Administrator Lisa P. Jackson’s commitment to increase public access to information on chemicals”. The Envirofacts database includes “facility name and address information, aerial image of the facility and surrounding area, map location of the facility, and links to other EPA information on the facility”. It also includes information on nearby populations, including sex, age, ethnic background and income. The data base can be searched by chemical or by geographic area. The Uses This information is valuable to environmental activists to help them identify and target facilities that are ‘likely’ to be having a negative impact on the health of their neighbors. The information could be used to initiate investigations into populations to see if they have higher than normal rates of medical issues related to chronic exposure to chemicals reported to be released from the nearby facilities. Unfortunately, it could also be used by terrorists looking for potential targets. A search could be done by toxic chemical and then each facility in a geographic area holding that chemical could be evaluated to determine which targets would have the highest off-site impact. The population data, maps and aerial photographs of the facility could provide initial planning information. The information available on the site would not be enough to provide the necessary details about chemical storage locations and security arrangements to conduct the actual attack, but it could provide necessary data for target selection. I remember how the environmentalists complained in the fall of 2001 about how this valuable information was taken down without any discussion of the pros and cons; without any discussion of how legitimate security concerns could be addressed while allowing for public dissemination of the information. I would have hoped that they had also remembered, but I guess it is just another example of turn-about being fair play. The Barn Door is Open It is too late to reverse disclosure. The internet is a vastly different place than it was 9 years ago. I am sure that there are copies of the information on a number of repeater sites as well as postings on independent environmental sites. There is no sense in fighting this disclosure, it is a done deal and no amount of court rulings or legal threats will change that. All we can do now is to see how this will play out. Fortunately we as a nation do have one thing going in our favor this time. The CFATS program is in place and we are improving the security at the highest-risk sites (except water facilities of course). We will be much better prepared to counter terrorist attacks on those facilities than we would have been in 2002. BTW: The data base is full of holes. I did a quick check on some facilities that I am familiar with and there are a number of critical chemicals are not listed for one reason or another; just another example of the efficacy of the EPA’s regulatory reach.

ICS Incident Reporting

The DHS-CERT Control Systems Security Program (CCPS) web page recently had a major change in the reporting procedures that they have for industrial control systems (ICS) incidents. In addition to providing reporting mechanisms they offer additional investigative and resolution assistance for such incidents. New Information In addition to the on-line reporting form that also appeared on the old page, the new page provides some new contact information, including:
ICS-CERT Watch Floor: 1-877-776-7585 ICS related cyber activity: ics-cert@dhs.gov General cyber activity: soc@us-cert.gov Phone: 1-888-282-0870
On the ICS-CERT web page they provide a valuable piece of additional advice for on-line reporting (in my opinion it should be located on the reporting page as well, but no one is perfect). To protect sensitive business or systems information ICS-CERT recommends that that type of information should be encrypted and provides a public-key to accomplish that encryption. Old Information The old version of the CSSP page had some additional information that would still be of value. Fortunately the links from that old page are still active so I will provide the links here. First is the reporting of Phishing attacks. While these are not uniquely an ICS issue, I found that the Phishing reporting procedure can be very helpful. The second set of links provides a method of reporting vulnerability issues for industrial control systems. Reporting newly identified vulnerabilities is an important part of improving the overall security of control systems across the industry. ICS-CERT Assistance The CSSP page provides the information below about the assistance available from ICS-CERT. Unfortunately there is no specific information about how to request that assistance. I can only suggest that such requests should be included when contacting CERT with the information about the incident.
“The ICS-CERT encourages organizations to report vulnerabilities, suspicious activity, and cyber incidents that could have an impact on critical infrastructure control systems. The ICS-CERT will analyze the information and provide mitigation strategies as needed. In addition, the ICS-CERT is able to provide onsite assistance, free of charge, to organizations that require immediate investigation and resolve in responding to a cyber attack.”
When an ICS incident, deliberate attack or miscellaneous system upset, occurs any additional assistance that can be had to help alleviate the situation means that the facility can get their critical systems up and working just that much faster.

Protection Against Explosions

Earlier this week I was asked by a long time reader if I could discuss ways to protect critical assets from an attack by a vehicle borne improvised explosive device. The facility at which he worked was trying to figure out what they could do to address this particular attack scenario. As always I am more than happy to express my thoughts on security related topics.

Standard caveat; I am not an engineer; I am a chemist by schooling. I do have some experience with explosives from the Army, but I am not an explosives expert and I have never detonated anything as large as a VBIED (if someone wants to let me push the plunger on one in a controlled test, I will certainly be there). Finally, before you actually install some protective device make sure that you are dealing with an engineering firm that has some experience in the field.

Prevent Detonation

The most obvious protective technique is the prevention of the detonation of the explosive device. While most of the responsibility for this lies with the intelligence and law enforcement people, the facility does have some basic techniques that they can employ to aid in the effort. The most obvious is the employment of an active counter-surveillance program. Any effective terrorist attack is going to be preceded by a variety of surveillance efforts.

The earlier efforts may be harder to detect, but as attack planning advances the terrorists will have to acquire more detailed information about facility security procedures. Facility employees and security personnel should always be on the watch for suspicious personnel hanging around the facility. The facility counter-surveillance plan should include an educational component to make personnel aware of the potential threat and their responsibility to be aware of what goes on around the facility. There needs to be a clear reporting procedure and the reports need to be promptly forwarded to local law enforcement for follow-up investigation.

Standoff 

The closer you can get an explosion to your target the more effect it will have. Conversely the further you can keep the explosion away from critical areas of the facility the less effect it will have. For a standard, non-focused explosion the force of the explosion should falloff as a square of the distance from the explosion. This means that even a small increase in the distance from the explosion can have a significant effect in force reduction.

Of course, the size of the explosion has an effect on the distance as well. I mean if you have a dry-box trailer packed with 40,000 lbs of commercial grade explosives the standoff distance will have to be much larger than if you have 500 lbs of homemade explosives in a panel van. So, to determine how far you have to keep the VBIED away from the potential target, you have to know how large a VBIED the terrorists will use against that target.

Obviously the terrorists are not going to tell you how large a VBIED they are going to use. So you have to guess; hopefully an educated guess, but a guess none the less. The guess should be based upon the potential risk; I would expect that a Tier 1 facility should expect a bigger VBIED than would probably be used against it than against a Tier 4 facility.

Don’t expect me to tell you what size to use; I just don’t have enough information to make even a lucky guess. Hopefully your security consultant will be able to provide a rationale for what ever size you pick. Once you have established your planning VBIED size you should be able to calculate (well the experts should be able to calculate, I haven’t seen the formulas) how far you have to keep the VBIED away from the target to have a reasonable chance of surviving without catastrophic damage.

If you want to keep your consultant on his toes, ask about max pressure and impulse effects. But, remember, you are going to need an expert. Anyone that tells you that there is a reasonable distance at which no damage will occur is either exaggerating or doesn’t understand explosions (a mile away from a 500 lb VBIED I would feel comfortable predicting little or no damage). With a VBIED attack if you can avoid catastrophic damage (ie: a quick, total drainage of a release-toxic COI from a large tank) you have achieved a reasonably successful defense. Your release mitigation techniques should be able to handle the results of non-catastrophic damage.

Blast protection The last type of protection is the one that probably requires the most expertise, physical blast protection. This can either be some sort of hardening of the target so that the blast will not affect it, or putting some sort of barrier between the potential blast and the target. Both require some special engineering skills and experience to properly design.

Once again, the size of the VBIED is a key design variable. If you dramatically underestimate the size of the device your blast barrier will become flying fragments that will contribute to the destruction of your target. One design element that needs to be considered is ‘line-of-sight’. Over longer ranges flying stuff from an explosion follow what is called a ‘ballistic arc’; the pieces fly up and out then fall to earth along an arc. The closer the initial trajectory is to 45° the further the projectile will fly.

At distances where blast effects predominate, however, the blast and projectiles are flying in essentially straight lines. Thus, any barrier must block the line of sight from the blast to the target. But, don’t forget to harden the top of the target to protect against falling debris.

Combination Plate The most effective VBIED protection scheme will utilize all three protective elements. Preventing detonation is, in my book, the most important element of the program. The lack of an explosion is the best protection. Remember, that the larger the VBIED, the more likely that there will be extensive pre-operational surveillance.

Putting together a large VBIED takes a lot of resources so the terrorists will do what ever is necessary to optimize their chance of a successful deployment; this means more surveillance. The last two, standoff and blast protection both require the services of someone who understands blast effects and blast protection engineering for optimal results. If you cut corners here you had better hope that your prevention program is very effective. A poorly designed protective program may actually increase the risk of a successful VBIED attack.

Special NOTE: Since this is a rather specialized field of study and application, I would certainly like to hear from practioners in the field. Discussion of the blast effect protection techniques would be particularly instructive.

Tuesday, May 18, 2010

Multiple Explosions

In a recent chemical facility fire in North Georgia there were reports of multiple explosions which hampered fire fighting efforts. There were no explosive chemicals stored on site so what caused the explosions? It was just another example of a phenomenon that I have discussed before, the BLEVE (boiling liquid expanding vapor explosion) writ small. In a fire any liquid chemicals in containers impacted by flames are likely going to quickly reach their boiling points. This is going to result in a rapid rise in pressure in the container. Larger storage containers should have pressure relief devices designed into the system to safely vent those fumes, protecting the containers from catastrophic failure. Unfortunately, drums do not come equipped with formal pressure relief devices. This means that they will burst. The two weakest points of the construction are where the bottoms and tops of the drums are joined to the side. One or the other of these seams will fail catastrophically, releasing a cloud of chemical vapors that will almost certainly ignite in a quick ball of fire. The loud boom is not technically an explosion; it is a pressure release event. To make matters worse, when the failure is along the base of the drum the upper portion of the drum is launched into the air like a rocket. It looks especially impressive at night as the flaming gasses shoots out of the bottom of the drum flying through the air. The flaming residues in the drums can cause an expansion of the fire perimeter depending on where they land. This is one of the reasons that fighting fires at chemical facilities can be so dangerous. Even when the drums are not launched into the air, drum lids and other pieces of flying metal are hazardous to fire fighters. The only way to prevent this problem is to keep the flames away from the drums; this requires a properly designed fire suppression system in chemical warehousing areas.
 
/* Use this with templates/template-twocol.html */