Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published an alert for a vulnerability in the Siemens SIMATIC S7-200, S7-300, and S7-400 PLCs. ICS-CERT is reporting that this vulnerability is the same replay attack vulnerability that was included in the Dillon Beresford vulnerabilities identified in the S7-1200 SIMATIC PLCs. Actually this Alert provides more details about this particular vulnerability than did the earlier alert.
The replay vulnerability allows an attacker with access to the control system network to intercept the unencrypted password used in communications between the PLC and other control system elements. This could allow an attacker to make unauthorized changes to the PLC operation.
According to the Alert, ICS-CERT is working with Siemens to develop specific mitigation measures for this vulnerability and is recommending some generic security measures as an interim strategy for owners of these PLCs. Siemens has a document describing the vulnerability in these PLCs available on their web site.
This Alert comes at an inopportune time for Siemens. Last week at an automation conference Siemens had done a lot to convince the cyber security community that it had become more proactive in dealing with security issues. Then ICS-CERT published an Advisory Friday for a Siemens WinCC vulnerability and now this Alert, neither of which was addressed by Siemens last week at the Conference.
An interesting TWITTER conversation (See @digitalbond, @tofinosecurity, @mtoecker and @pjcoyle) had already developed this weekend about why Siemens had not announced the Friday vulnerability at the Conference that they knew would be reported by ICS-CERT the day after the conference ended. This Alert further calls into question Siemens commitment to openly discuss security issues with the ICS community and their customers.
Wednesday, July 6, 2011
Tuesday, July 5, 2011
Congressional Hearings Week of July 4th
Both Houses of Congress will be in session this week but there are no committee hearings scheduled that will be of specific interest to the chemical security or cyber security communities. There are lots of House hearings, but nothing of specific interest. The Senate was not originally scheduled to be in Washington this week so there are very few hearings scheduled for that body’s Committees.
The big thing to watch this week from a security perspective will be the Full House consideration of HR 2219. The House will meet in proforma session today which will allow for additional filing of amendments to HR 2219 that may be considered in the two days of debate that the House leadership currently has scheduled for the DOD Appropriations Bill. Roll call votes tomorrow will be held until the evening and the Majority Leader’s web page warns: “Members are advised that the 6:30 p.m. vote series is expected to last longer than usual.”
The big thing to watch this week from a security perspective will be the Full House consideration of HR 2219. The House will meet in proforma session today which will allow for additional filing of amendments to HR 2219 that may be considered in the two days of debate that the House leadership currently has scheduled for the DOD Appropriations Bill. Roll call votes tomorrow will be held until the evening and the Majority Leader’s web page warns: “Members are advised that the 6:30 p.m. vote series is expected to last longer than usual.”
Railroad Transloading Facilities and CFATS
Generally speaking, CFATS does not affect railroad facilities; DHS has taken the stance that such facilities are addressed under TSA regulations. Additionally, they note that railroads and pipelines are inherently different than the chemical facilities that are covered under CFATS. Last week I ran across an article that describes a railroad facility that I think crosses those lines and should be considered a chemical facility under the definition used by CFATS.
Transflo Facility
The article discusses some of the public concerns about a Transflo facility that is being planned for a redeveloped CSX rail yard. While the article is short on a detailed description of the operation of the planned facility in Westborough, MA it is clear that the facility will be a transfer facility where bulk chemical railcars are transloaded into tank trucks. A CSX consultant is quoted as saying that the facility would handle about 30 truck loadings per day.
CSX is being naturally reticent about publicly listing exactly what chemicals will be handled at the facility. They do note that, although about 30% of the traffic will be hazardous chemicals, “explosives and dangerous chemicals like chlorine and ammonium [anhydrous ammonia?] will never go through there”. That still leaves a large number of chemicals that could be handled at the facility that could require Top Screen submissions.
Lack of TSA Coverage
TSA chemical regulations for rail shipments is limited to a small number of very hazardous chemical, essentially toxic inhalation hazard (TIH) chemicals like chlorine and anhydrous ammonia and explosives. If the currently planned restrictions on the handling of these types of chemicals at the facility is maintained, there will be no TSA regulation of security measures at this facility.
In a typical urban or suburban rail yard this very selective chemical security regulation can be justified by the fact that such railcars are typically in transit and in place for only a short periods of time. Add to that the difficulty that an outsider would have in even locating a specific railcar and the natural resistance of railcars to all but the most robust attacks while stationary and the problems with providing classical security measures are typically outweighed by the reduced risk of attack.
Higher Risks for Transloading Facility
In transloading facilities like this many of the traditional mitigating factors no longer apply. First, the actual schedule of hazardous materials moving through the facility becomes much more publicly available. Truck drivers, dispatchers and brokers all are given specific information about the timing and location of hazardous material railcars. The increased number of people given access to sensitive security information increases the likelihood that the information can be compromised either through poor information security practices or actual recruitment or compromise of someone with legitimate access to the information.
The increased number of people with legitimate access to the facility also reduces another typical rail yard security measure; the ease of identification of unauthorized personnel. The number of people with authorized access to rail yards is very small and railroads are a relatively tight knit family. Outsiders are fairly easy to recognize as not belonging to the facility. As the number of legitimate outsiders moving through the facility increases it becomes much less likely that attackers would be quickly identified.
One of the most effective attack vectors against the reinforced railcars is vehicle borne improvised explosive device (VBIED). In a typical rail yard it is next to impossible to get a VBIED anywhere near a target railcar. There are very few places where even a small truck can physically get close enough to a hazmat railcar. At a transloading facility, however, specific provisions are being made for bringing large tank trucks right up to the rail cars. Additionally, transfer lines are much more vulnerable to small IED’s or even small arms fire and the control systems for such operations add another potential route of attack.
CFATS Coverage?
To my mind it is clear that facilities of this type are no different than traditional chemical distribution facilities that accept deliveries of hazardous materials by rail and ship the same material by tank truck or load the material into other smaller containers. It is less clear that railroads will make the distinction between this type of operation and their more traditional transportation operations. Nor is it clear that DHS will be proactive in this matter; ISCD has enough problems on it plate with the regulation of the current CFATS facilities. This is an issue that needs public discussion.
Transflo Facility
The article discusses some of the public concerns about a Transflo facility that is being planned for a redeveloped CSX rail yard. While the article is short on a detailed description of the operation of the planned facility in Westborough, MA it is clear that the facility will be a transfer facility where bulk chemical railcars are transloaded into tank trucks. A CSX consultant is quoted as saying that the facility would handle about 30 truck loadings per day.
CSX is being naturally reticent about publicly listing exactly what chemicals will be handled at the facility. They do note that, although about 30% of the traffic will be hazardous chemicals, “explosives and dangerous chemicals like chlorine and ammonium [anhydrous ammonia?] will never go through there”. That still leaves a large number of chemicals that could be handled at the facility that could require Top Screen submissions.
Lack of TSA Coverage
TSA chemical regulations for rail shipments is limited to a small number of very hazardous chemical, essentially toxic inhalation hazard (TIH) chemicals like chlorine and anhydrous ammonia and explosives. If the currently planned restrictions on the handling of these types of chemicals at the facility is maintained, there will be no TSA regulation of security measures at this facility.
In a typical urban or suburban rail yard this very selective chemical security regulation can be justified by the fact that such railcars are typically in transit and in place for only a short periods of time. Add to that the difficulty that an outsider would have in even locating a specific railcar and the natural resistance of railcars to all but the most robust attacks while stationary and the problems with providing classical security measures are typically outweighed by the reduced risk of attack.
Higher Risks for Transloading Facility
In transloading facilities like this many of the traditional mitigating factors no longer apply. First, the actual schedule of hazardous materials moving through the facility becomes much more publicly available. Truck drivers, dispatchers and brokers all are given specific information about the timing and location of hazardous material railcars. The increased number of people given access to sensitive security information increases the likelihood that the information can be compromised either through poor information security practices or actual recruitment or compromise of someone with legitimate access to the information.
The increased number of people with legitimate access to the facility also reduces another typical rail yard security measure; the ease of identification of unauthorized personnel. The number of people with authorized access to rail yards is very small and railroads are a relatively tight knit family. Outsiders are fairly easy to recognize as not belonging to the facility. As the number of legitimate outsiders moving through the facility increases it becomes much less likely that attackers would be quickly identified.
One of the most effective attack vectors against the reinforced railcars is vehicle borne improvised explosive device (VBIED). In a typical rail yard it is next to impossible to get a VBIED anywhere near a target railcar. There are very few places where even a small truck can physically get close enough to a hazmat railcar. At a transloading facility, however, specific provisions are being made for bringing large tank trucks right up to the rail cars. Additionally, transfer lines are much more vulnerable to small IED’s or even small arms fire and the control systems for such operations add another potential route of attack.
CFATS Coverage?
To my mind it is clear that facilities of this type are no different than traditional chemical distribution facilities that accept deliveries of hazardous materials by rail and ship the same material by tank truck or load the material into other smaller containers. It is less clear that railroads will make the distinction between this type of operation and their more traditional transportation operations. Nor is it clear that DHS will be proactive in this matter; ISCD has enough problems on it plate with the regulation of the current CFATS facilities. This is an issue that needs public discussion.
Sunday, July 3, 2011
S 1254 Introduced – Another DOD Authorization Bill
Back on June 22nd the day that Sen. Levin (D, MI) introduced S 1253, the National Defense Authorization Act for Fiscal Year 2012, he also introduced S 1254, the Department of Defense Authorization Act for Fiscal Year 2012. The two bills are very similar; actually they are identical through §1534 which is the final section of S 1254. This second bill does not contain the following divisions found in the other bill:
Intra-House Politics
I would assume that the reason for these nearly identical bills has to deal with the way that the Senate handles legislation. Typically if both the Senate and the House craft bills on the same topic and the House bill is passed before the Senate bill completes its consideration process, the appropriate Committee Chair will offer the language of the Senate bill as an ‘amendment in the form of a substitute’. S 1253 covers the same topics as HR 1540; so if the Senate takes up HR 1540 it will substitute the language found in S 1253.
This bill, along with S 1255 and S 1256 would, allow the leadership of the Senate to take up each of the different components of S 1253 separately. I’m not sure what the impetus would be to handle the authorization process this way. One thing is certain though; it didn’t take much extra work to introduce the three additional pieces of legislation once S 1253 was written; just cut and paste.
Cyber Security Provisions
All of the cyber security provisions that I discussed in my blog on the introduction of S 1253 are found in this bill, so their discussion is applicable here. The issues raised in the Committee Report for S 1253 should also apply to this bill as well. Technically this bill was reported ‘without written report’ but the portion of the S 1253 Committee report that deals with ‘Division A’ found in this bill would apply if this bill is passed. That means the issues I discussed about that report apply to this bill as well.
The Way Forward
Since I don’t completely understand why Sen. Levin introduced these bills (this one and S 1255 and S 1256) I can’t tell for sure how likely it will be that these three bills will reach the Senate floor instead of S 1253. I suspect that the Senate will take the easy way out and take up HR 1540 in the traditional manner and substitute the language of S 1253. If they took this alternative they would then have to pass the other two bills and deal with the inevitable conference committee haggling after the bills were modified in the House.
● Division B – Military Construction Authorizations;Those other divisions are included separately in S 1255 and S 1256. No cyber security provisions there, so I’ll ignore them.
● Division C – Department of Energy National Security Authorizations and Other Authorizations; and
● Division D – Funding Tables.
Intra-House Politics
I would assume that the reason for these nearly identical bills has to deal with the way that the Senate handles legislation. Typically if both the Senate and the House craft bills on the same topic and the House bill is passed before the Senate bill completes its consideration process, the appropriate Committee Chair will offer the language of the Senate bill as an ‘amendment in the form of a substitute’. S 1253 covers the same topics as HR 1540; so if the Senate takes up HR 1540 it will substitute the language found in S 1253.
This bill, along with S 1255 and S 1256 would, allow the leadership of the Senate to take up each of the different components of S 1253 separately. I’m not sure what the impetus would be to handle the authorization process this way. One thing is certain though; it didn’t take much extra work to introduce the three additional pieces of legislation once S 1253 was written; just cut and paste.
Cyber Security Provisions
All of the cyber security provisions that I discussed in my blog on the introduction of S 1253 are found in this bill, so their discussion is applicable here. The issues raised in the Committee Report for S 1253 should also apply to this bill as well. Technically this bill was reported ‘without written report’ but the portion of the S 1253 Committee report that deals with ‘Division A’ found in this bill would apply if this bill is passed. That means the issues I discussed about that report apply to this bill as well.
The Way Forward
Since I don’t completely understand why Sen. Levin introduced these bills (this one and S 1255 and S 1256) I can’t tell for sure how likely it will be that these three bills will reach the Senate floor instead of S 1253. I suspect that the Senate will take the easy way out and take up HR 1540 in the traditional manner and substitute the language of S 1253. If they took this alternative they would then have to pass the other two bills and deal with the inevitable conference committee haggling after the bills were modified in the House.
Saturday, July 2, 2011
ICS-CERT Publishes 3 Advisories
Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published three new advisories for vulnerabilities identified in SCADA systems from two different vendors; Siemens and Iconics. The three advisories address vulnerabilities significantly different than the standard run of HMI vulnerabilities that we have become used to seeing.
Siemens Vulnerabilities
The Siemens advisory deals with exploitable crash vulnerabilities in the WinCC system. These vulnerabilities are not related to those Siemens vulnerabilities identified by Dillon Beresford that caused so much controversy back in May. A restricted access version of this advisory was previously published on the US-CERT site.
According to ICS-CERT this vulnerability could be exploited by a moderately skilled attacker and potentially result in execution of arbitrary code. An attacker would need to employ a social engineering vector to get a user to load a corrupted file.
Siemens has released a patch for the identified vulnerabilities.
ICONICS Vulnerabilities
Two separate advisories were published for vulnerabilities in the ICONICS GENESIS32 and BizViz systems. The first details a vulnerability in the ActiveX control that allows an arbitrary domain to be set to the trusted zone. The second describes a vulnerability in the Security Login Controls that could allow execution of arbitrary code or denial of service. The reason for the separate advisories is that these vulnerabilities are found in different version of the systems.
The trusted zone vulnerability is remotely exploitable. A moderately skilled attacker could create the website required to exploit this vulnerability. There is no known publicly available exploit of this vulnerability. An upgrade is recommended but a patch is also available on the ICONICS web site.
The login control vulnerability requires the creation of a specifically crafted password to exploit. A low skill level attacker could exploit this vulnerability to execute a denial of service attack, but more skill would be required to use the vulnerability to execute arbitrary code. Both types of exploits can be implemented remotely. Again a system upgrade is recommended but a patch is available.
ICONICS has updated their security whitepaper to reflect both of these vulnerabilities. Both patches and the white paper are available on the ICONICS web site.
Coordinated Disclosures
All three of these advisories were based upon vulnerabilities reported by the same pair of independent security researchers; Billy Rios and Terry McCorkle. ICS-CERT received the reports and coordinated their release with the vendors. The researchers have validated the patches.
Siemens Vulnerabilities
The Siemens advisory deals with exploitable crash vulnerabilities in the WinCC system. These vulnerabilities are not related to those Siemens vulnerabilities identified by Dillon Beresford that caused so much controversy back in May. A restricted access version of this advisory was previously published on the US-CERT site.
According to ICS-CERT this vulnerability could be exploited by a moderately skilled attacker and potentially result in execution of arbitrary code. An attacker would need to employ a social engineering vector to get a user to load a corrupted file.
Siemens has released a patch for the identified vulnerabilities.
ICONICS Vulnerabilities
Two separate advisories were published for vulnerabilities in the ICONICS GENESIS32 and BizViz systems. The first details a vulnerability in the ActiveX control that allows an arbitrary domain to be set to the trusted zone. The second describes a vulnerability in the Security Login Controls that could allow execution of arbitrary code or denial of service. The reason for the separate advisories is that these vulnerabilities are found in different version of the systems.
The trusted zone vulnerability is remotely exploitable. A moderately skilled attacker could create the website required to exploit this vulnerability. There is no known publicly available exploit of this vulnerability. An upgrade is recommended but a patch is also available on the ICONICS web site.
The login control vulnerability requires the creation of a specifically crafted password to exploit. A low skill level attacker could exploit this vulnerability to execute a denial of service attack, but more skill would be required to use the vulnerability to execute arbitrary code. Both types of exploits can be implemented remotely. Again a system upgrade is recommended but a patch is available.
ICONICS has updated their security whitepaper to reflect both of these vulnerabilities. Both patches and the white paper are available on the ICONICS web site.
Coordinated Disclosures
All three of these advisories were based upon vulnerabilities reported by the same pair of independent security researchers; Billy Rios and Terry McCorkle. ICS-CERT received the reports and coordinated their release with the vendors. The researchers have validated the patches.
Friday, July 1, 2011
Anhydrous Ammonia Theft
I haven’t talked about this issue in a while but I ran across an interesting article about one of the larger anhydrous ammonia thefts that I have ever seen. The article notes that a trailer used to apply anhydrous ammonia fertilizer to fields was stolen from a farm outside of Kalamazoo, MI. The empty 1,000-gallon tank was later recovered.
Terrorist Weapon?
As with presumably all such thefts to date this trailer was taken and emptied in support of the illicit manufacture of methamphetamines. If that was the case her, the thieves have a problem on their hand; according to the article “the ammonia was treated with GloTell, a substance that dyes the product bright pink and makes it unsuitable for meth production”.
With that said, could this type theft be a precursor for a terrorist chemical attack? It certainly could as any toxic inhalation chemical could be used in an attack. That is why anhydrous ammonia is a DHS chemical of interest (COI). It is listed in Appendix A as a release – toxic chemical and as such has a screening threshold quantity (STQ) of 10,000 lbs. While agricultural production facilities are exempted submitting Top Screens, if this farmer never had more than the quantity found in this trailer (reportedly 4,000 lbs) on site no Top Screen submission would be required.
Does that mean that this smaller quantity could not be used as a terrorist weapon? Certainly not. In many ways this quantity, in a portable tank, is much more useable as a weapon as it could be delivered to an appropriate target and the TIH material released there. In normal transport or in fixed tanks the material would have to be in the right place at the right time for it to be an effective weapon.
Why Not a Theft Diversion COI?
This begs the question, why isn’t anhydrous ammonia listed in Appendix A as a theft-diversion COI as well as a release COI? Chlorine gas, for example, is dual listed and these two chemicals share many traits; both are readily available TIH industrial chemicals. They both cause serious damage to the respiratory system in less than lethal concentrations. Chlorine is listed as a theft-WME (weapon of mass effect) COI with an STQ of 500 lbs in portable containers.
Technically, chlorine is listed as a theft-WME COI and anhydrous ammonia isn’t because chlorine was used as a war gas in WWI and is listed in the Chemical Weapons Convention list of chemical weapons. Anhydrous ammonia was never used or seriously considered for chemical weapons use and is not included in the Convention’s list of chemical weapons or their precursors.
Anhydrous ammonia was not considered for use as a chemical weapon because of its affinity for water, even water vapor in the air. This could seriously inhibit its functionality as a war gas. This wouldn’t have any practical effect on the effectiveness of its use against terrorist targets especially within buildings like shopping malls, schools, churches or other soft targets.
Agriculture Exemption
I am relatively certain that this CWC technicality was not the main reason that anhydrous ammonia was never considered as a theft-diversion COI when DHS put together Appendix A. One of the industries that use huge quantities of this material is agriculture where it is used as a very effective and cheap nitrogen fertilizer. It is typically hauled to fields in these 1,000-gallon tanks (they look like large propane tanks on wheels) and these tanks are then used to disperse the material into the ground before planting.
If DHS had included anhydrous ammonia as a theft-diversion COI it would have raised the cost of the use of this fertilizer and the agriculture industry would have raised fits. If you don’t think that this had any influence on the listing decision consider the case of propane. Because of the concerns of the agriculture industry and their tame Senators the STQ for propane (widely used on farms and other production facilities for a variety of heating uses) was set at 60,000 lbs instead of the 10,000 pounds set for similar release flammable COI.
Or consider the fact that the farmers, or their employees, hauling these trailers from the local supplier to their fields do not have to have hazardous material endorsements on their commercial driver’s license. PHMSA has given them a blanket agricultural exemption from that requirement.
Appendix A Review
This is another chemical of concern that needs to have its status reviewed during the current discussions about amendments to Appendix A of the CFATS regulations. This is particularly true since State regulations trying to prevent the theft of anhydrous ammonia for use in the manufacture of methamphetamines.
Terrorist Weapon?
As with presumably all such thefts to date this trailer was taken and emptied in support of the illicit manufacture of methamphetamines. If that was the case her, the thieves have a problem on their hand; according to the article “the ammonia was treated with GloTell, a substance that dyes the product bright pink and makes it unsuitable for meth production”.
With that said, could this type theft be a precursor for a terrorist chemical attack? It certainly could as any toxic inhalation chemical could be used in an attack. That is why anhydrous ammonia is a DHS chemical of interest (COI). It is listed in Appendix A as a release – toxic chemical and as such has a screening threshold quantity (STQ) of 10,000 lbs. While agricultural production facilities are exempted submitting Top Screens, if this farmer never had more than the quantity found in this trailer (reportedly 4,000 lbs) on site no Top Screen submission would be required.
Does that mean that this smaller quantity could not be used as a terrorist weapon? Certainly not. In many ways this quantity, in a portable tank, is much more useable as a weapon as it could be delivered to an appropriate target and the TIH material released there. In normal transport or in fixed tanks the material would have to be in the right place at the right time for it to be an effective weapon.
Why Not a Theft Diversion COI?
This begs the question, why isn’t anhydrous ammonia listed in Appendix A as a theft-diversion COI as well as a release COI? Chlorine gas, for example, is dual listed and these two chemicals share many traits; both are readily available TIH industrial chemicals. They both cause serious damage to the respiratory system in less than lethal concentrations. Chlorine is listed as a theft-WME (weapon of mass effect) COI with an STQ of 500 lbs in portable containers.
Technically, chlorine is listed as a theft-WME COI and anhydrous ammonia isn’t because chlorine was used as a war gas in WWI and is listed in the Chemical Weapons Convention list of chemical weapons. Anhydrous ammonia was never used or seriously considered for chemical weapons use and is not included in the Convention’s list of chemical weapons or their precursors.
Anhydrous ammonia was not considered for use as a chemical weapon because of its affinity for water, even water vapor in the air. This could seriously inhibit its functionality as a war gas. This wouldn’t have any practical effect on the effectiveness of its use against terrorist targets especially within buildings like shopping malls, schools, churches or other soft targets.
Agriculture Exemption
I am relatively certain that this CWC technicality was not the main reason that anhydrous ammonia was never considered as a theft-diversion COI when DHS put together Appendix A. One of the industries that use huge quantities of this material is agriculture where it is used as a very effective and cheap nitrogen fertilizer. It is typically hauled to fields in these 1,000-gallon tanks (they look like large propane tanks on wheels) and these tanks are then used to disperse the material into the ground before planting.
If DHS had included anhydrous ammonia as a theft-diversion COI it would have raised the cost of the use of this fertilizer and the agriculture industry would have raised fits. If you don’t think that this had any influence on the listing decision consider the case of propane. Because of the concerns of the agriculture industry and their tame Senators the STQ for propane (widely used on farms and other production facilities for a variety of heating uses) was set at 60,000 lbs instead of the 10,000 pounds set for similar release flammable COI.
Or consider the fact that the farmers, or their employees, hauling these trailers from the local supplier to their fields do not have to have hazardous material endorsements on their commercial driver’s license. PHMSA has given them a blanket agricultural exemption from that requirement.
Appendix A Review
This is another chemical of concern that needs to have its status reviewed during the current discussions about amendments to Appendix A of the CFATS regulations. This is particularly true since State regulations trying to prevent the theft of anhydrous ammonia for use in the manufacture of methamphetamines.
SSP Questions Manual Changes Identified
As I noted in a blog posting yesterday DHS has published a new version of their CSAT SSP Questions manual. I did a detailed review and found only a relatively minor yet necessary change. In the questions for RBPS 13 ISCD has changed the question headings to reflect the recent change from old color-coded Homeland Security Alert System (HSAS) to the new National Terrorism Advisory System (NTAS).
• ‘National Terrorism Advisory System’ for ‘Homeland Security Alert System’
• ‘NTAS’ for ‘HSAS’
• ‘Elevated Threat Alert’ for ‘Orange Level’
• ‘Imminent Threat Alert’ for ‘Red Level’
Subscribe to:
Posts (Atom)