Tuesday, January 20, 2015

HR 53 Introduced – Cybersecurity Education

As I reported in an earlier post Rep. Jackson-Lee (D,TX) introduced HR 53, the Cyber Security Education and Federal Workforce Enhancement Act. This bill would formally establish the current the Cybersecurity Education and Awareness Branch (CEA) within the Department of Homeland Security’s (DHS) Office of Cybersecurity and Communications (CS&C). The CEA manages the National Initiative for Cybersecurity Careers and Studies (NICCS).

This program in DHS is not specifically mentioned in the Explanatory Statement that accompanied HR 240 (the current DHS funding bill). Presumably the funding for this program comes out of the $15 million for education listed under ‘Global Security Management’. This bill would do nothing to increase that funding, but might raise the level of visibility to the point where it might get mentioned in the future.

The programs identified in the bill would help foster federal cybersecurity workforce development. There would certainly be some spillover effect into the private sector as personnel moved out of the government and the education programs produced cybersecurity trained personnel excess to the government needs.


If Ms. Jackson-Lee can convince the Republican leadership in three committees (Homeland Security, Science and Technology, and Education and Workforce) to consider this bill then the bill might make it to the floor in the House. There is nothing in the bill that would seem to inspire specific opposition, so it would probably pass if considered.

Monday, January 19, 2015

First HR 4007 Deadline Passes

Saturday the first deadline for HR 4007 came and went. This marked 30 days since the President signed the bill into law. This means that 6 USC 21 is now the governing law for the Chemical Facility Anti-Terrorism Standards (CFATS) and the old §550 authorization no longer applies.

Revocation Rule Deadline

As I predicted last month the Secretary missed the deadline to publish a rule revoking those provisions of 6 CFR 27 that are “duplicative of, or conflicts with” {§2107(b)} 6 USC 21. To be fair, I still have not found any specific provisions of the CFATS regulations that fall under this requirement. So it may not have been necessary to issue any revoking language. If that had been the case, it might have been nice for ISCD to issue a statement to that effect.

Grandfathered SSPs

We still have not heard any official (or unofficial for that matter) word from DHS about the status of the Site Security Plans that have been authorized or approved since the President signed HR 4007 into law. You might recall that §2102(c)(3)(B) provides that any facilities with approved site security plans (SSPs) as of the date of the President’s signature on HR 4007 (12-18-14) cannot be required to submit new SSPs just because Title XXI has become law. Plans approved since that date do not have that legal protection.


I don’t expect that the management at ISCD will want to increase the workload of their chemical security inspectors by going back and revisiting the site security plans approved in the last month (not that that will have been a very large number because of the holidays), but legally these site security plans have not been approved under the standards set by the current law. It would be helpful (if not actually legally binding) for the Secretary to publish a notice in the Federal Register laying out the status of SSPs being approved while the new CFATS regulations are being written.

Friday, January 16, 2015

ICS-CERT Publishes 2 Advisories

Yesterday the DHS ICS-CERT published two ‘new’ advisories that had been previously published on the US-CERT Secure Portal; one for a GE application and one for an application from Arbiter Systems.

GE Advisory

This advisory describes a memory access violation vulnerability in the GE CIMPLICITY CimView application. The vulnerability was reported by Said Arfi. GE has produced an update that mitigates the vulnerability but there is no report of Arfi verifying the efficacy of the update.

ICS-CERT reports that a moderately skilled attacker could exploit this vulnerability to execute arbitrary code. While the advisory states that this vulnerability could not be remotely exploited, it does note that user interaction is required to exploit. That would seem to mean that a specially crafted social engineering attack could cause a local user to upload the .CIM file needed  to exploit this vulnerability.

This is the second GE advisory this week that has been withheld from public view for almost 90 days after it was released on the US-CERT Secure Portal. It is hard to understand why it would take that length of time for GE systems owners to mitigate this vulnerability, especially since the vulnerability is not supposed to be remotely exploitable.

Arbiter Systems Advisory

This advisory describes a GPS clock spoofing vulnerability. This vulnerability was apparently self-reported. Arbiter Systems has developed a new product that does not have the reported vulnerability.

ICS-CERT reports that while the vulnerability is remotely exploitable the vendor believes that it would be difficult to craft a workable exploit. They are so sure of this, in fact, that Arbiter Systems still intends to sell the vulnerable system. ICS-CERT does explain that a successful exploit could disrupt the clock.


What is not explained in the advisory is that disrupting a clock in a SCADA system will interfere with the coordination of the actions of physically separated components of that system. The potential effects would be determined by what controls were mis-coordinated.

Thursday, January 15, 2015

HR 60 – Cyber Defense National Guard

As I mentioned in an earlier post Rep. Jackson-Lee (D,TX) introduced HR 60, the Cyber Defense National Guard Act. The bill would require the Director of National Intelligence to prepare a report for Congress on the feasibility of establishing a Cyber Defense National Guard (CDNG).

The bill does not establish any requirements for this CDNG beyond the most basic. The purpose provided in the bill would be to “to defend the critical infrastructure of the United States from a cyber attack [sic] or manmade intentional or unintentional catastrophic incident” {§2(b)(2)}. The wording is a little bit awkward and it does not specifically cover potential natural cyber catastrophes such as solar storms, or even hurricanes destroying cyber infrastructure.  

Beyond that basic mission description it is pretty much up to the DNI (in consultation with DOD and DHS) how the CDNG would be constituted, supported, trained and deployed. At this point it is not even clear that the CDNG would be a State supported/commanded force like the current National Guard.

It is interesting that the DNI has been designated as the point person for conducting this study. If this were intended to be just a new type of National Guard unit, the point would have been someone from DOD. If the idea were for this to be some sort of new cyber-emergency response agency it probably would have been a DHS study; probably under the auspices of FEMA.

Keeping with the old saw that if the tool you have is a hammer, all problems look like nails, giving this study tasking to the DNI will almost insure that at least one of the prime missions of the CDNG will be to detect and deter cyberattacks before they become reality. It can certainly be argued that this is the current mission of NSA, but given the bad press that NSA has suffered during the last couple of years, providing a separate agency to look at cybersecurity intelligence activities for critical infrastructure may make such activities more palatable to people outside of the defense community.


Ms Jackson-Lee has a reasonably good working relation with the Chairman of the Homeland Security Committee and if that Committee had been given responsibility for the review of this bill I would expect that it would be considered by that committee sometime this year. But since the DNI was given reporting responsibility the bill was assigned to the Permanent Select Committee on Intelligence. Ms Jackson-Lee is not a member of that committee so I suspect that this bill will die unexamined.

HR 54 Requires Hacker Support

When I reviewed HR 54, the Frank Lautenberg Memorial Secure Chemical Facilities Act, I did not go into any great detail because the bill is dead in the water. I saw a TWEET yesterday from @5ean5ullivan that made me go back and look at one section much more closely. It seems that Rep. Jackson-Lee (D,TX) wants covered chemical facilities to employ hackers to checkout their cybersecurity.

Cybersecurity Requirements

Section 2111(b)(6) requires: “the conduct of tests of facilities should include blue hat, red hat, and white hat hackers to validate the security measures instituted to address cyber based threats”.

Interestingly this requirement does not come in the portion of the legislation that discusses site security plans or risk-based performance standards for security measures. Instead it is found in the section of the bill that deals with Methods to Reduce the Consequences of a Terrorist Attack, commonly referred to inherently safer technology (IST).

In the discussion of the required assessment of IST measures the §2111(b) describes the various things that a facility must look at in conducting their assessment. In an apparent after thought (and certainly never included in earlier versions of Democrat bills on chemical security) are two sub-paragraphs dealing with cybersecurity issues.

The first requires: the design of computing systems and development of plans, exercises, and drills to re-engage computing systems used in the processing, transport, storage of chemicals that are designed [should be ‘designated’] as a ‘‘risk’’ by the Secretary using protocols for trusted recovery under the worse case [worst case?] conditions” {§2111(b)(5)}.

This certainly sounds like a reasonable requirement, but it probably should have been included in §2103(d)(8) the discussion of deterring cyber sabotage in the risk based performance criteria that would be required by this bill.

The requirements to use hackers described above is also out of place in the discussion of IST requirements. I am not so sure, however, that this was intended to be part of the planning requirements for facility security plans. It actually looks like it should have been included in §2104, Site Inspections. If that were the case it would call for DHS to use hackers to evaluate the cybersecurity protections that are part of the site security plan. That would be a radically new type of cybersecurity requirement that I have not seen suggested in any other regulatory program.

Problems with Hacker Requirement

Now I understand how this might sound like a good idea to some congress critter. This would seem to be the only way to verify that proper protective actions have been taken. But as a practical matter, this will cause more problems than it could possible solve. Before we get into any of the technical reasons why this is not a good idea we only need to look at the lack of personnel available to be able to do this type of hack. There are probably not 100 people world-wide familiar enough with control systems to conduct such an evaluation and I would venture to guess that none of them are familiar enough with all of the different types of control systems and components to be able to do a complete evaluation.

Secondly, as many recent presentations have pointed out (see my post here and upcoming posts on DigitalBond.com from S4x15) have pointed out, it will take a team of people, various control systems experts and chemical engineers, to cause catastrophic damage at a chemical facility. This is, in many ways good news as it is unlikely that the average terrorist group (particularly home-grown terrorists) will have that level of expertise available to conduct such an attack.

Finally, no chemical facility owner/operator is going to allow any outsider to hack into a live control system involved with the handling, storage or manufacture of hazardous chemicals. The potential for problems is just too high. And taking a system down to allow for such an evaluation off-line is just too costly for most chemical facilities.

Congress and Cybersecurity

It is good to see that Congress is starting to seriously think about cyber security. But provisions like this hacker requirement shows just how far removed from reality too many of these congress critters really are. It will be interesting to see how many problems congress tries to institute as they address the complicated problem of cybersecurity.

Wednesday, January 14, 2015

Bills Introduced – 01-13-15

Some congressional staffers were busy over the weekend as 87 bills were introduced in the House and Senate yesterday. Only one of those bills may be of specific interest to readers of this blog:

HR 291 - To establish a WaterSense program, and for other purposes. Rep. Napolitano, Grace F. [D-CA-32]


This bill may only deal with California drought response so I may not mention it again, but you never can tell.

DHS Updates Chemical Sector Training Page

Yesterday the DHS Chemical Sector-Specific Agency (SSA) updated their training page. They now list a number of on-line training courses available from DHS on subjects related to security awareness. The topics include:


These are not chemical facility specific training, but the folks at the Chemical SSA apparently feel that they would be appropriate for chemical facility awareness training.


Unfortunately the link to the previously listed web-based Chemical Security Awareness Training program is no longer provided on this web site. As of 9:30 EST today this link to that training is still good.
 
/* Use this with templates/template-twocol.html */