This week both the Senate and House will be in Washington at the same time. This actually results in a decrease in the number of hearings that might be of interest to the chemical security community; this week there will only be two such hearings; both addressing chemical transportation issues. I’ll be watching a third Congressional development this week, the Ag spending bill, for potential chemical security provisions.
Emerging Rail Threat
The Senate Committee on Commerce, Science, and Transportation will hold a hearing on Tuesday looking at the ‘emerging threats’ to rail security. I suspect that the bulk of the hearing will address people moving issues, but the topic of freight rail security (which is principally a discussion of toxic inhalation hazard (TIH) chemical transportation security issues) will certainly be addressed.
Pipeline Safety
The Energy and Power Subcommittee of the House Energy and Commerce Committee will hold a hearing on pipeline safety on Thursday. Scheduled witnesses include PHMSA Administrator Quarterman and representatives from the American Petroleum Institute, the Interstate Natural Gas Association of American and the Natural Resources Defense Council. Industrial safety and security are naturally intertwined, but there is only a very limited chance that pipeline security will be even briefly addressed in this hearing.
AG Budget
This week the House will take up HR 2112, the budget for the Department of Agriculture and related agencies with the House Rules Committee meeting on Monday to formulate the rule. This is not a hot bed of chemical security interest, but the agriculture budget bill has included chemical security provisions in the past, specifically a tax credit provision for reimbursing food producers for chemical security measures in the 2008 bill. With impending (maybe) regulation of ammonium nitrate sales, there may be a similar move for ammonium nitrate producers and distributors.
Sunday, June 12, 2011
Coast Guard Chemical Transport Advisory Committee
The Department of Homeland Security published a notice in Monday’s (available on-line Saturday) Federal Register (76 FR 34240-34241) announcing that the Secretary planned to establish a Chemical Transportation Advisory Committee (CTAC) to advise the Secretary through the Commandant of the Coast Guard “on matters concerning the safe and secure marine transportation of hazardous materials in bulk” (76 FR 34241).
The proposed Committee would consist of up to 25 members representing the following private sector groups:
The proposed Committee would consist of up to 25 members representing the following private sector groups:
• Chemical manufacturing companies;Public comments on this proposed committee are being solicited by DHS. Comments may be submitted via the Federal eRulemaking Portal (www.regulations.gov; Docket # USCG-2011-0225). Comments should be submitted by July 13, 2011.
• Companies that handle or transport chemicals in the marine environment;
• Vessel design and construction companies;
• Marine safety or security companies; and
• Marine environmental protection groups.
S 1159 Introduced – Cybersecurity Workforce
Last week Sen. Gillibrand (D, NY) introduced S 1159, the Cyberspace Warriors Act of 2011. As the name would suggest, this bill addresses cybersecurity personnel issues in the Department of Defense. Increasing the size of the cyber security workforce in the Active, Reserve, and civilian components of the Defense Department will have inevitable short term and long term effects on the cybersecurity workforce working on industrial control system issues.
Cyber Security Workforce Study
This bill would require the Secretary of Defense to hire an outside entity to review the cybersecurity workforce situation in DOD, specifically concentrating the recruitment, retention and development of ‘cyberspace experts’. An important component of the study would be the production of a “statement of capabilities and number of cyberspace operations personnel required to meet the defensive and offensive cyberspace operation requirements of the Department of Defense” {§2(b)(2)(A)}.
Along with the statement of personnel requirements for DOD’s cybersecurity workforce the study would be required to assess “the sufficiency of the numbers and types of personnel available for cyberspace operations, including an assessment of the balance of military personnel, Department of Defense civilian employees, and contractor positions” {§2(b)(2)(B)}.
The study would also look at the variety of “recruiting, training, and affiliation mechanisms” the Department could use “to address challenges to recruitment, retention, and training” {§2(b)(2)(D)} along with the identification of the types of incentives that DOD could use to overcome those challenges.
Finally, the study would look at the “legal, policy, or administrative impediments to attracting and retaining cyberspace operations personnel” {§2(b)(2)(F)} and propose “for legislative or policy changes necessary to increase the availability of cyberspace operations personnel” {§2(b)(2)(G)}.
Potential Effects on ICS Security
Not addressed in the current language of this bill would be the potential effects on the civilian cybersecurity situation caused by this increase in cybersecurity staffing at DOD. In the short term one would expect, because of the general shortage of cyber security personnel, particularly in the industrial control system realm, that any increase in the recruitment of personnel with current expertise for the DOD program would have a negative effect on the availability of personnel for civilian cybersecurity work.
Over the longer term, as DOD training and incentives for college training of cyber security increased, the overall size of the cybersecurity workforce would be expected to increase. Since military personnel with high-value skill sets have relatively low retention rates due to compensation (both base pay and bonuses) limits imposed by Congress, there would be an expected long-term increase in the availability of experienced cybersecurity personnel in the civilian sector.
It would be interesting to see if this study identifies industrial control system security as one of the specific skill sets necessary for the DOD cybersecurity program. I would expect that any offensive cyber operations would need the capability to affect industrial control systems of various sorts. Defensive cyber operations conducted by DOD could also require protection of a variety of industrial control systems.
I would expect that there would be much more focus on information technology systems, but this study could have a long-term effect on the industrial control system security personnel situation.
Cyber Security Workforce Study
This bill would require the Secretary of Defense to hire an outside entity to review the cybersecurity workforce situation in DOD, specifically concentrating the recruitment, retention and development of ‘cyberspace experts’. An important component of the study would be the production of a “statement of capabilities and number of cyberspace operations personnel required to meet the defensive and offensive cyberspace operation requirements of the Department of Defense” {§2(b)(2)(A)}.
Along with the statement of personnel requirements for DOD’s cybersecurity workforce the study would be required to assess “the sufficiency of the numbers and types of personnel available for cyberspace operations, including an assessment of the balance of military personnel, Department of Defense civilian employees, and contractor positions” {§2(b)(2)(B)}.
The study would also look at the variety of “recruiting, training, and affiliation mechanisms” the Department could use “to address challenges to recruitment, retention, and training” {§2(b)(2)(D)} along with the identification of the types of incentives that DOD could use to overcome those challenges.
Finally, the study would look at the “legal, policy, or administrative impediments to attracting and retaining cyberspace operations personnel” {§2(b)(2)(F)} and propose “for legislative or policy changes necessary to increase the availability of cyberspace operations personnel” {§2(b)(2)(G)}.
Potential Effects on ICS Security
Not addressed in the current language of this bill would be the potential effects on the civilian cybersecurity situation caused by this increase in cybersecurity staffing at DOD. In the short term one would expect, because of the general shortage of cyber security personnel, particularly in the industrial control system realm, that any increase in the recruitment of personnel with current expertise for the DOD program would have a negative effect on the availability of personnel for civilian cybersecurity work.
Over the longer term, as DOD training and incentives for college training of cyber security increased, the overall size of the cybersecurity workforce would be expected to increase. Since military personnel with high-value skill sets have relatively low retention rates due to compensation (both base pay and bonuses) limits imposed by Congress, there would be an expected long-term increase in the availability of experienced cybersecurity personnel in the civilian sector.
It would be interesting to see if this study identifies industrial control system security as one of the specific skill sets necessary for the DOD cybersecurity program. I would expect that any offensive cyber operations would need the capability to affect industrial control systems of various sorts. Defensive cyber operations conducted by DOD could also require protection of a variety of industrial control systems.
I would expect that there would be much more focus on information technology systems, but this study could have a long-term effect on the industrial control system security personnel situation.
Saturday, June 11, 2011
OMB Approves PHMSA Rule on Pipeline Control Room Management
On Thursday the Office of Management and Budget (OMB) approved ‘consistent with change’ a final rule from the Pipeline and Hazardous Material Safety Administration (PHMSA) concerning control room management for natural gas and hazardous material pipelines. Actually there may be some confusion on whether this is a final rule or a proposed rule. The OMB announcement calls it a final rule while the Regulatory Agenda web page calls it a proposed rule.
The Regulatory Agenda says that this rule would change the compliance dates for the previous rule on control room management published in December 2009 (74 FR 63310). . This rule would expedite the program implementation deadline to August 1, 2011 (from August 1, 2012), for most of the requirements, except for certain provisions regarding adequate information and alarm management, which would have a program implementation deadline of August 1, 2012.
This rule was included in the Regulatory Agenda for the first time in the Fall 2010 Agenda. There it had a projected NPRM publication date of December 2010. That would have provided a pretty quick turn-around for the rule making process to have an effective date allowing for the August 1, 2011 deadline. I suspect that this ended up being a direct final rule. This would make the ‘consistent with change’ portion of the OMB announcement probably mean a change in the August 1, 2011 deadline to some time in September. The August 1, 2012 deadline would probably remain the same.
If that is the total extent of the changes required by OMB, then this rule could be published this week. Any more extensive changes would probably delay the publication for another week.
The Regulatory Agenda says that this rule would change the compliance dates for the previous rule on control room management published in December 2009 (74 FR 63310). . This rule would expedite the program implementation deadline to August 1, 2011 (from August 1, 2012), for most of the requirements, except for certain provisions regarding adequate information and alarm management, which would have a program implementation deadline of August 1, 2012.
This rule was included in the Regulatory Agenda for the first time in the Fall 2010 Agenda. There it had a projected NPRM publication date of December 2010. That would have provided a pretty quick turn-around for the rule making process to have an effective date allowing for the August 1, 2011 deadline. I suspect that this ended up being a direct final rule. This would make the ‘consistent with change’ portion of the OMB announcement probably mean a change in the August 1, 2011 deadline to some time in September. The August 1, 2012 deadline would probably remain the same.
If that is the total extent of the changes required by OMB, then this rule could be published this week. Any more extensive changes would probably delay the publication for another week.
Friday, June 10, 2011
Two ICS-CERT Vulnerability Notes – Includes Siemens S7-1200 PLC
Today the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published two new control system vulnerability notices on its web site, including the long expected alert on the Siemens S7-1200 PLCs. The other vulnerability was identified in a product from another large ICS vendor – Rockwell.
Siemens S7-1200 PLC
Well the ICS security community has been waiting for this Alert since May 19th when Dillon Beresford pulled his Siemens vulnerability talk at Takedown. We have been hearing talk about an FOUO version of this alert for the last couple of days, but now we have a ‘properly sanitized’ version for public consumption. The Alert notes that “ICS-CERT and Siemens have confirmed that these vulnerabilities [reported by Dillon] could allow an attacker with automation network access to execute various unauthorized commands against the S7-1200 PLC”.
The Alert goes on to say that today Siemens published “a Security Advisory and patch to address a portion of the reported vulnerabilities [emphasis added]”. Both the advisory and patch are available on the Siemens web site. The ICS-CERT Alert also includes the following additional mitigation measures:
More interestingly, this alert does not provide even a general description of the vulnerabilities that were ‘patched’ in this initial Siemens response. I understand the reluctance to describe the un-patched vulnerabilities, but not providing a generic description of the patched vulnerabilities makes one think that the patch is not really that successful.
Rockwell RSLinx Classic Advisory
This Advisory comes via the CERT Coordination Center and it concerns a program bundled with Rockwell’s RSLinx Classic, the Electronic Data Sheet (EDS) Hardware Installation Tool. The buffer overflow vulnerability in that tool could allow an attacker to execute arbitrary code that could be used to “subvert any other security service” (an interesting new phrase for an ICS-CERT advisory).
The Advisory notes that this attack would require an authorized user to load a malformed EDS file. This would, according to the advisory, not allow the attacker to “initiate the exploit from a remote machine”. That may be technically true, except that the spear phishing or other social engineering attack that tricked the user into loading the compromised file could certainly be sent from a remote machine.
Rockwell does have a patch available and ICS-CERT provides links to two documents that contain information about spear phishing and other social engineering attacks.
BTW: The ICS vulnerability numbering system gets a little annoying here. Both of these vulnerabilities have the same number (11-161-01) with different prefixes (‘ICSA’ and ‘ICS – Alert’). With just a quick glance one might assume that they are the same document. We are supposed to be more alert than that, but I wouldn’t have designed the numbering system this way.
Siemens S7-1200 PLC
Well the ICS security community has been waiting for this Alert since May 19th when Dillon Beresford pulled his Siemens vulnerability talk at Takedown. We have been hearing talk about an FOUO version of this alert for the last couple of days, but now we have a ‘properly sanitized’ version for public consumption. The Alert notes that “ICS-CERT and Siemens have confirmed that these vulnerabilities [reported by Dillon] could allow an attacker with automation network access to execute various unauthorized commands against the S7-1200 PLC”.
The Alert goes on to say that today Siemens published “a Security Advisory and patch to address a portion of the reported vulnerabilities [emphasis added]”. Both the advisory and patch are available on the Siemens web site. The ICS-CERT Alert also includes the following additional mitigation measures:
• ICS-CERT and Siemens recommend that customers disable the embedded web server in TIA Portal Version 11 if it is not critical to operations.There are an awful lot of qualifiers in those recommendations. That seems to indicate that ICS-CERT doesn’t really think that it will probably be practical to implement all of the suggested security measures. Oh well, we didn’t really want secure control systems did we?
• ICS-CERT and Siemens recommend that customers apply a properly configured, strong password. The same password should not be reused across the automation network, where possible.
• Apply defense-in-depth strategies for both enterprise and control system networks;
• Restrict connections between the enterprise and control system networks, where possible.
• Restrict remote access to enterprise and control system networks and diligently monitor any remote connections allowed; employ Virtual Private Network (VPN) connections for any remote system access.
More interestingly, this alert does not provide even a general description of the vulnerabilities that were ‘patched’ in this initial Siemens response. I understand the reluctance to describe the un-patched vulnerabilities, but not providing a generic description of the patched vulnerabilities makes one think that the patch is not really that successful.
Rockwell RSLinx Classic Advisory
This Advisory comes via the CERT Coordination Center and it concerns a program bundled with Rockwell’s RSLinx Classic, the Electronic Data Sheet (EDS) Hardware Installation Tool. The buffer overflow vulnerability in that tool could allow an attacker to execute arbitrary code that could be used to “subvert any other security service” (an interesting new phrase for an ICS-CERT advisory).
The Advisory notes that this attack would require an authorized user to load a malformed EDS file. This would, according to the advisory, not allow the attacker to “initiate the exploit from a remote machine”. That may be technically true, except that the spear phishing or other social engineering attack that tricked the user into loading the compromised file could certainly be sent from a remote machine.
Rockwell does have a patch available and ICS-CERT provides links to two documents that contain information about spear phishing and other social engineering attacks.
BTW: The ICS vulnerability numbering system gets a little annoying here. Both of these vulnerabilities have the same number (11-161-01) with different prefixes (‘ICSA’ and ‘ICS – Alert’). With just a quick glance one might assume that they are the same document. We are supposed to be more alert than that, but I wouldn’t have designed the numbering system this way.
STB Response to Canexus Complaint
On Wednesday the Surface Transportation Board (STB) published their ‘decision’ in the Canexus v BNSF complaint about rail transportation of chlorine. This decision is not a final action in any sense of the term; it is merely a notice to BNSF that it must formally reply to the complaint by June 15th. Additionally, because of the time issue raised in the Canexus complaint the Board provided notice that if a hearing is necessary it would be scheduled for June 23rd.
The Board apparently agrees with my initial assessment that this may end up being a TIH routing issue. It has notified UP, the second railroad involved in this conflict, that it should “submit a pleading addressing its legal obligation, if any, to interchange with BNSF at Spokane and Portland”.
The Board apparently agrees with my initial assessment that this may end up being a TIH routing issue. It has notified UP, the second railroad involved in this conflict, that it should “submit a pleading addressing its legal obligation, if any, to interchange with BNSF at Spokane and Portland”.
Explosives Transport Safe Haven Rule
On Tuesday the Pipeline and Hazardous Material Safety Administration published their final rule on safe havens for enroute storage of explosives. This final rule incorporates by reference the National Fire Protective Association’s standard (NFPA 498) and establishes this as an acceptable standard for the establishment of safe havens for unattended storage of explosives incident to transportation.
Security Standards
PHMSA did not establish any security requirements above the minimal recommendations in NFPA 498. They did note that each shipper and carrier already has responsibility for establishing a security plan for the transportation of the Division 1.1, 1.2, and 1.3 explosives covered in this rule. That plan should address the security requirements for storage incident to transportation at these safe havens.
Federal Preemption
PHMSA did not establish the NFPA standard as the requirement for safe havens; it merely said that safe havens established to the NFPA standard would be acceptable to DOT. This means that State and local agencies can still establish local rules for safe havens that could potentially conflict with the NFPA standards without running afoul of Federal preemption rules.
CFATS Issue
Not addressed in this rule is the CFATS status of these safe havens. Since these explosives are chemicals and most of those chemicals are listed in Appendix A, any storage of the listed COI above the screening threshold quantity (STQ) listed in Appendix A would trigger Top Screen reporting requirements. The CFATS rules do not provide any exception for short term inventory. According to §27.200(b)(2):
Security Standards
PHMSA did not establish any security requirements above the minimal recommendations in NFPA 498. They did note that each shipper and carrier already has responsibility for establishing a security plan for the transportation of the Division 1.1, 1.2, and 1.3 explosives covered in this rule. That plan should address the security requirements for storage incident to transportation at these safe havens.
Federal Preemption
PHMSA did not establish the NFPA standard as the requirement for safe havens; it merely said that safe havens established to the NFPA standard would be acceptable to DOT. This means that State and local agencies can still establish local rules for safe havens that could potentially conflict with the NFPA standards without running afoul of Federal preemption rules.
CFATS Issue
Not addressed in this rule is the CFATS status of these safe havens. Since these explosives are chemicals and most of those chemicals are listed in Appendix A, any storage of the listed COI above the screening threshold quantity (STQ) listed in Appendix A would trigger Top Screen reporting requirements. The CFATS rules do not provide any exception for short term inventory. According to §27.200(b)(2):
“A facility must complete and submit a Top-Screen in accordance with the schedule provided in § 27.210, the calculation provisions in § 27.203, and the minimum concentration provisions in § 27.204 if it possesses any of the chemicals listed in Appendix A to this part at or above the STQ for any applicable Security Issue.”The security plan for such safe havens will be complicated by the fact that most commercial explosive pose both a bulk-release hazard and packaged theft-diversion hazard. Further complicating matters is the potential that these facilities will spend significant amounts of time without any inventory on site.
Subscribe to:
Posts (Atom)