Wednesday, January 19, 2011

NIAC to Include Chem Sector in Information Sharing Study

Thanks to Patrick Miller’s Tweet about the National Infrastructure Advisory Council’s Information Sharing Study, I was reminded that the NIAC meeting was held yesterday. Reader’s might remember that I wrote about the scheduled meeting earlier this month. In that blog I wrote about the need to form a Chemical Fusion Center to provide CFATS facilities an intelligence sharing environment. I sent a copy of that blog as a public comment to be included in the discussion at yesterday’s meeting.

Since I wasn’t able to attend the meeting I don’t know how much attention was paid to my submitted comments. But, since I submitted my comments early I would like to think that the study committee had a chance to review them prior to the development of their presentation that was made at yesterday’s meeting. Again, we only have a copy of their slide presentation, which lacks the additional information included in the oral presentation accompanying the slides, but there are some interesting parallels between their presentation and my comments.

The study proposal presented at the meeting expects for the group to take a year to accomplish this study. It will primarily focus on ‘leading executives and subject matter experts (SME) in business and government’ as the primary information sources. Among other things it will specifically “identify initial set of issues related to private sector participation and interaction” (slide 9) with existing fusion centers and identify “initial set of information sharing challenges, gaps, and best practices”.

The study group also expects to do some case studies using five of NIPP critical sectors;

● Chemical Sector
● Commercial Facilities Sector
● Healthcare and Public Health Sector
● Oil & Natural Gas Sector
● Financial Services Sector
Interestingly CFATS covered facilities can be found in all but one of those sectors, the Financial Services Sector.

Training Resource Page Updated 01-18-11

Yesterday, the Chemical Sector-Specific Agency (SSA) of the DHS Office of Infrastructure Protection updated their Chemical Sector Training and Resources web page. The revised page provides new information concerning the Chemical Sector Explosive Threat Awareness Training Program (CSETAT) and the Security Seminar & Exercise Series for Chemical Industry Stakeholders program..

Chemical Sector Explosive Threat Awareness Training Program

The new information on the CSETAT Program is the listing of the currently scheduled training dates for 2011. Those locations and dates [NOTE: ‘TBD’ will be announced later] for those training sessions are:

• Barceloneta, Puerto Rico (1/25);
• Orlando, FL (March TBD);
• Long Beach, CA (4/20);
• New Orleans, LA (5/11);
• Cedar Rapids, IA (June TBD); and
• Baltimore, MD (7/8)
Security Seminar & Exercise Series

The new information on the Security Seminar and Exercise Series is also the provision of current scheduled training dates for 2011. The scheduled dates and locations are:

• Willowbrook, IL (3/15);
• Columbus, OH (April TBD);
• Puerto Rico (April TBD);
• Tucson, AZ (5/23); and
• Baltimore, MD(7/8)
Additional Information

Additional information on either program can be had by requesting the information from the Chemical SSA at ChemicalSector@dhs.gov.

Tuesday, January 18, 2011

DHS ICS-CERT Issues Two Advisories

Yesterday the DHS Industrial Control System Cyber Emergency Response Team issued two advisories for different industrial control systems. The first updated a previously issued alert for the WellinTech KingView system. The second outlined a vulnerability in the Sielco Sistemi Winlog.

KingView Update

Last week I reported on the ICS-CERT Alert that had been issued on a reported heap overflow vulnerability in the WellinTech KingView system. At that time ICS-CERT didn’t have much more information than a published report of the vulnerability with exploit code. Since then ThreatPost.com reported on the communications problems that resulted in the lack of response to the security researcher’s reports to CN-CERT that ultimately led to the publication of the exploit code.

Yesterday’s advisory provided more information on the details of the vulnerability along with the mitigation recommendations that include a patch provided by WellinTech. The vulnerability could allow an attacker to crash the system via a heap overflow in the HistorySrv process. Even with the publicly available exploit code, ICS-CERT estimates that it would take an attacker with at least an intermediate skill level to exploit this vulnerability.

DHS ICS-CERT recommends the following mitigation measures be considered after conducting an impact assessment on the system:

• Implement network or host-based firewall rules to limit network access to Port 777/TCP.

• Upgrade to the latest Version 6.53(2010-12-15) and install the patch. Users can download the patch at: http://en.wellintech.com/products/detail.aspx?contentid=25

• Minimize network exposure for all control system devices. Control system devices should not directly face the Internet.1

• Control system networks and devices should be located behind firewalls, and be isolated from the business network. If remote access is required, secure methods such as Virtual Private Networks (VPNs) should be used.
Sielco Sistemi Winlog Vulnerability

The second advisory issued by ICS-CERT deals with a newly reported vulnerability in the WinLog Lite and WinLog Pro HMI software produced by Sielco Sistemi. The vulnerability is found in all versions through 2.07.00. The vulnerability could allow a remote attacker to initiate a stack overflow, potentially resulting in the attacker being able to remotely execute arbitrary code. Even though exploit code is publicly available, ICS-CERT estimates that it would take a skill high-level to exploit this vulnerability.

DHS ICS-CERT recommends the following mitigation measures be considered after conducting an impact assessment on the system:

• Update Winlog Lite and WinLog Pro to the latest Version (2.07.01).
www.sielcosistemi.com/download/WinlogLite_Setup.exe
www.sielcosistemi.com/download/Winlog_Setup_SF.exe
For additional information, customers can contact Sielco Sistemi’s support at:
http://www.sielcosistemi.com/en/support/

• Minimize network exposure for all control system devices. Critical devices should not directly face the Internet. Control system networks and remote devices should be located behind firewalls and be isolated from the business network. If remote access is required, secure methods such as Virtual Private Networks (VPNs) should be used.

Monday, January 17, 2011

Ralph Langner Review

Readers of this blog will be well familiar with the name of Ralph Langner who has done so much work on decoding the targeting tools of the Stuxnet worm. I’ve written about his blog posts on a number of occasions. Well, Ralph has finally combined his descriptions of the various parts of that worm into a single article available at ControlGlobal.com. While this article was written for control systems engineers (and thus contains a lot of ‘code injection’, data block names, and other technical information) in my opinion the most important part of the article is the less technical discussion found in the last section.

Once again Ralph makes a very strong case for his warning that the Stuxnet codes can be re-used by skilled attackers. This could allow them to craft new attack codes that could be used to attack completely different process systems. He explains that the most effective attacks would still require similar levels of target process knowledge, but that generic attacks could be executed with next to no process information. I have discussed both of these possibilities in earlier blogs, but Ralph’s technical background and detailed Stuxnet knowledge lends much more credence to this prediction.

Ralph provides a very brief description of what he thinks it will take to defend against these Stuxnet-like attacks. He briefly dismisses ‘defense-in-depth’ because it doesn’t address the issue of controller compromise. I think this dismissal may be a little overdone because these techniques may make the compromise of controllers more difficult. But Ralph is correct, current cyber security measures do not specifically prevent controller level problems.

Ralph does, however, provide a brief description of a more effective preventive measure:

“The most effective prevention of controller hijacking would be digitally signed controller code and configuration. With today's technology, this can be implemented easily [emphasis added]. It can be expected that controller vendors will see this as a major business opportunity because the outlook to replace millions of controllers before end-of-lifetime with upgraded product versions means a multi-million dollar market.”
Since English is a second language for Ralph (though he uses it better than many native speaking bloggers) it is hard to tell if the use of the term ‘implemented easily’ is sarcasm or just grossly understating the difficulties involved. He does mention the cost of the controllers, but completely ignores the process upsets that whole sale replacement of controllers would cause.

I do love the final sentence of the article, though. Ralph writes:

“Less efficient, but much cheaper solutions have just become available that detect and report configuration and code changes of network-attached S7 controllers.”
Readers of this blog will remember that Ralph’s company is the one that is selling this ‘solution’. Ralph has been clear that it does not prevent someone from modifying controller programming, but it does alert the user to any such change, hopefully allowing the controller to be shut down before there is any serious damage done to the process. Of course, in many chemical processes that shutdown may cause serious repercussions.

Recommendation

In any case, anyone that is responsible for security of control systems ought to read this article. I also think that congressional staffers working on cyber security legislation also need to take note of what Ralph is talking about. We can no longer afford to ignore control system cyber security when we discuss protecting computer systems.

Firewall Description

I’m an information junkie, something that my long time readers will probably have guessed by the breadth of the topics about which I write. One of the best things about writing a blog is that I get to share all of the tidbits of information that I collect. It really gets good, however, when my blog causes more information to come my way. Typically that comes in the form of comments, emails and phone calls; all of which are good. Every once in a while it comes in the form of another blogger making a post to explain in more detail a fact that I shared, but didn’t fully understand.

That happened last week when Eric Byres at TofinoSecurity.com did a post explaining the fixed configuration firewall concept behind the new Honeywell Modbus Read-Only Firewall, a product based upon some Tofino Security technology. And Eric very generously credits one of my blog posts as the inspiration for that post. So it seems that we have an inter-blog conversation going; producing even more information. An info junkie's life just can’t get any better.

What is a Firewall?

Eric provides a good description in his blog about how a fixed configuration firewall works and in the process schooled me, at least, in the general operation of a firewall. I’ve understood what a firewall is designed to accomplish, but never quite bothered to find out how it works. Now Eric’s discussion will not allow me to actually configure a firewall (Eric is a good explainer, but it is, after all only a single blog post), but I do have a better understanding of what’s going on.

Now, I’ve been exposed to computers for closing in on 50 years now (I helped write my first computer program in 1964), but I am not a true computer geek, I’m more of a technically knowledgeable user. I can talk to geeks without them laughing at me and I always respectfully listen when they try to explain something to me; it helps make me a better user.

I realize that most of my readers, however, have probably never seen the inside of a computer and would have difficulty recognizing a line of code if they saw it. How to explain the operation of a firewall to them? I guess the best way is to go back to the namesake of the computer firewall, the fire safety firewall.

In fire safety a firewall is a non-flammable barrier protecting stuff on one side from a fire on another. First you have to understand that ‘non-flammable’ is not an absolute term. If the temperature is high enough, then just about anything will burn. So the designer of a firewall makes an educated guess about the maximum temperature of the potential fire on the other side of the barrier and selects a barrier composition to match that temperature.

Now firewalls do not provide absolute protection against the spread of fires, generally they just delay the spread of a fire until other fire response efforts can deal with the situation. Given that, a firewall is rated in the number of minutes that it will hold back a fire. You pay more for more minutes of protection. And of course you need to have a plan for detecting the fire and mobilizing your other fire protection measures in a timely manner.

The best firewalls have no openings in them. Unfortunately, in the real world a wall with no openings is seldom very useful, but any opening is going to provide a route for fire to get through the firewall. So fire safety engineers have developed over the years a number of ways of closing off these openings in the event of a fire. For people sized openings and larger, we call these devices fire doors.

The best of these fire doors normally remain closed and are only opened when something must move through the wall. In a high traffic area this is frequently a pain in the butt and eventually someone figures out that it is easier to just prop the door open. Then you no longer have a fire door, but instead have an unprotected hole in the firewall. Realizing that you can’t engineer human nature, fire safety people have come up with fire doors for high traffic openings that are normally open, but close automatically in the event of a fire. A flash fire or explosion will get through before they can close, but they are better than a normally closed fire door that has been wedged open for the sake of convenience.

A computer firewall provides a similar type protection to a computer system. Instead of protecting against the spread of fire, it prevents the unapproved movement of information. They help to prevent intruders accessing the system or the unauthorized sending of information out of the system. The best protection allows no flow of information (no holes in the firewall or ‘air gapped’ in computer-speak), but that is seldom practical. The next best solution is to provide a communication node through the firewall that is normally closed, but can be opened when necessary with appropriate restrictions on who/what can do the opening.. That is followed by a normally open channel that automatically closes when a threat is detected. The least amount of protection is provided by a normally open port that has no threat detection capability protecting it. Actually, I guess the least protection is provided by the port that no one knows is open. In all cases, restricting what information can flow through the opening increases the level of protection.

To be most effective, any firewall needs to be protected by detection systems that tell someone when an intruder attempts to gain access or when someone attempts to transmit unauthorized information out of the system. And there must be a response capability that is triggered by the detection system.

So, now that you know what a firewall does, go read Eric’s explanation about the pitfalls of configuring firewalls and the benefit of fixed configuration firewalls.

Saturday, January 15, 2011

Personnel Problems at ISCD

For the last couple of months or so I have been trying to get an official statement from the Infrastructure Security Compliance Division about the status of the memorandum of understanding between the Coast Guard and ISCD concerning the treatment of security at MTSA covered chemical facilities. It’s been kind of a low priority thing; send off the occasional email, make the occasional telephone call. Unfortunately, I have been unable to get an official response; not a ‘no comment’, just no response. No return emails, no phone calls answered. Just an ISCD information black hole.

So this week I started to do some unofficial checking, checking with some people that can’t give me an official answer. Even there, I’ve been having problems getting information, but apparently there are some internal problems at ISCD, problems that are causing people to tip-toe around and only talk in whispers and to be careful about who they talk to.

Management Problems

Let’s start at the Top. Ever since the Obama administration came to town, ISCD has been run by acting folks; an acting director and acting assistant director. This was because the Director, Sue Armstrong, had been temporarily pushed upstairs to fill another acting position. Now this is not unusual with a change in Administration. The political appointees at the top leave with the old administration and the career folks step up into acting positions to fill the void. Then they return to their old jobs when the new political appointees step in.

It has been two years now and the political appointment at the top of the chain that leads to ISCD has yet to be made. Everyone knows that Obama has had problems getting appointments confirmed in the Senate. There have been additional problems in finding appointees willing or able to take on these positions without running afoul of the internal administration rules on lobbyists. I don’t know what the cause is here, but there is too much acting going on in NPPD this late in the game.

This delay in making political appointments at DHS causes problems. Political decisions are not being made about policy, they are either being put on hold, or being kicked upstairs for resolution. Even worse, somewhere down the line, the stepping up process has created an empty management position and routine decisions there are being delayed or just not happening.

To make matters worse, I’m now hearing that the acting director and the acting deputy director were relieved last month. I’ve heard no details on why or exactly when, just that they are gone. Instead of pulling someone up from inside ISCD (and to be fair it is not a real large group to begin with) the Administration brought in two other career people from outside of NPPD to fill the acting positions.

Being from outside of NPPD, one would assume that they have very limited, if any knowledge, of the CFATS program, but I’m also hearing that they don’t even have a background in security or chemistry. That means that whatever their skills and experience they had in their old jobs, here they are nothing but bureaucrats.

Hopefully this problem will be resolved when Sue Armstrong is able to step back down into her role as Director. She has the experience with CFATS and the two new people can get brought up to speed under her tutelage.

Labor Problems

Now, as if this management issue were not causing enough problems, it seems like there are additional problems down in the ranks. I’m hearing that the chemical facility inspectors are going to be voting on unionization in a couple of weeks. Whatever your position on unions in general, a union vote in today’s environment is a clear sign of a basic disconnect between labor and management.

I don’t know what the issues are here (and I would love to give the union folks a chance to air their grievances, they at least should be able to talk publicly about the issues; management can’t, not with a vote scheduled), but I can imagine that the daily life of a CFI is going to be rough, just because of the nature of the job. They have to spend most of their life on the road and the atmosphere on-site is going to vary from strained to confrontational. That makes for a tough work environment.

Add to that the political dissatisfaction with the pace of the inspection process, and I’m sure that there are enormous pressures put on these folks. Finally, they are still having to make-up the inspection process as they go as no one has done this kind of thing before. Complicating that further, each new facility that they go to is different than the ones before. That adds a whole new set of intellectual pressures, particularly with people that care about the mission.

That kind of work environment demands a management team that is involved and cares about the worker bees. It would help if they were experienced in the field and understood the work environment, but that is not possible here. There is no one with the experience or background. So it’s going to take a management team with an unusual amount of empathy and understanding to prevent the discord that leads to a unionization vote.

This brings to mind an interesting question. Did Deziel and Klessman get canned because their bosses felt they were the cause of the union vote? Or perhaps it was a move to address some of the apparent management issues by bringing in a new management team, one with perhaps more labor-management experience. In any case, if it was in part to deal with this situation, that would explain the current strained relationships in the offices at ISCD.

Problem Resolution

Both of these problems, whether or not they are linked, have got to be having a negative effect on work being done by the folks at ISCD. The CFATS program and the yet to be completed Ammonium Nitrate regulations are just too complex not to be delayed and held-up by these issues. And, they are too important to be delayed any further.

Since these problems appear to be at least partially political in nature, maybe it is time to take a political look at the issues. A congressional hearing or two might bring the problems out into the public focus where it apparently needs to be.

Friday, January 14, 2011

HR 209 Introduced – CFATS

On January 6th, Rep Speier (D, CA) introduced HR 209, the Reducing Information Control Designations Act. The bill was finally made available by the GPO yesterday. The bill is designed to increase intra-governmental information sharing and ensuring that the public has proper access to that information by “by standardizing and limiting the use of information control designations” (§2). These designations are currently placed on unclassified but sensitive information, controlled unclassified information and information marked “For Official Use Only”.

This bill takes Executive Order 13556, Controlled Unclassified Information, promulgated last fall by President Obama, extends its provisions, and provides it with the force of Federal law. It makes each Federal agency responsible for reducing and minimizing its use of “of information control designations on information that is not classified” {§3(a)}

Regulating Information Control Designations

The Archivist of the United States is given the responsibility to establish the regulations governing the use of information control designations. Those regulations are specifically required to address {§3(b)(2)}:

● Standards for utilizing the information control designations in a manner that is narrowly tailored to maximize public access to information.

● The process by which information control designations will be removed.

Procedures for identifying, marking, dating, and tracking information assigned the information control designations, including the identity of officials making the designations.

● Provisions to ensure that the use of information control designations is minimized.

● Provisions to ensure that the presumption shall be that information control designations are not necessary.

● Methods to ensure that compliance with this Act protects national security and privacy rights.

● Procedures for members of the public to be heard regarding improper applications of information control designations.

● A procedure to ensure that all agency policies and standards for utilizing information control designations that are issued pursuant to subsection (c) be provided to the Archivist and that such policies and standards are made publicly available on the Web site of the National Archives and Records Administration.
Additionally the Archivist is expected to ensure that each piece of information marked with information control designations is also marked with information identifying the person applying the information control designation. This is being required to allow the agencies to track who is misusing such designations.

While EO 13556 specifically addresses the matter of information control designations that are established in law or regulation, and excepts those so established from possible elimination, there are no such provisions provided in this bill. Where information control designations are clearly established by law this sets up an interesting conflict, but where the basis of establishment in just by regulatory fiat, this bill (if passed) would clearly take precedent.

Chemical-Terrorism Vulnerability Information (CVI)

CVI is not specifically mentioned in this bill, but it is clearly one of the information control designations covered under its provisions. Since CVI has its underpinnings established in Federal Law, it is one of the designations for which there are potential conflicts. I don’t believe that this bill would allow for the elimination of CVI (though that is an interesting nit to pick for lawyers). Nor do I believe that the major disclosure provisions would be modified, since those are set forth in the §550 CFATS authorizing language. The detailed control and marking provisions would certainly be subject to potential revision.

The provision of this bill that would provide the most obvious problems from a CVI perspective would be the requirements for identifying the person responsible for the initial marking of the document. Since copies of the CFATS submission documents are electronically generated and designated CVI by regulation, it is not clear how copies printed at the regulated facility would receive this marking. One of the facility CSAT authorized personnel would clearly not be the Federal Official making the designation.

There will be similar types of problems with just about all of the information control designations currently in use.

No one who has worked with government agencies would disagree with the underlying premise of this bill; that there is a natural tendency for a number of understandable (and sometimes illegitimate) reasons for such agencies to over-classify information. Passage of this bill would do little to address the underlying problems causing that over-classification. Until that is done, the use of procedures like those outlined in this bill will do little more than muddy the waters and extend the bureaucracy even further.
 
/* Use this with templates/template-twocol.html */