Wednesday, February 11, 2015

DHS Updates CFATS Knowledge Center


Yesterday the folks at DHS Infrastructure Security Compliance Division (ISCD) updated the CFATS Knowledge Center. They added a link in the Documentation section of the page for the February 2012 CFATS Update and removed older copies of the Update.

Interestingly there is still no mention of the passage of HR 4007 and its potential impact on the CFATS program.

Tuesday, February 10, 2015

EPA Sends 2016 Methyl Bromide CUE to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) reported that it had received the 2016 Critical Use Exemption from the Phaseout of Methyl Bromide notice of proposed rulemaking from the EPA. This is almost a full month earlier than last year’s rulemaking on this topic.

NOTE 1: For some reason this annual rulemaking did not make it into the Fall 2014 Unified Agenda.

NOTE 2: I’ll same my standard methyl bromide COI rant until the NPRM is actually published.

Sunday, February 8, 2015

Committee Hearings – Week of 2-8-15

Both the House and Senate will be in Washington this week. There are a number of threat/intel type hearings on the House side of the Capital and one internet of things (IOT) hearing in the Senate. Other than that, nothing of potential specific interest to readers of this blog.

Threat/Intel

None of the currently scheduled threat/intelligence hearings are specifically looking at chemical security. Cybersecurity will be specifically addressed in one hearing, but there will probably not be any significant discussion of control system security issues. And, of course, there will be no actionable threat information discussed; these are all open hearings. But you never can tell what interesting tidbits might be dropped. The three hearings are:

Countering Violent Islamist Extremism: The Urgent Threat of Foreign Fighters and Homegrown Terror." Committee on Homeland Security Wednesday
State Sponsor of Terror: The Global Threat of Iran Subcommittee on Terrorism, Nonproliferation, and Trade (Committee on Foreign Affairs) Wednesday
Emerging Threats and Technologies to Protect the Homeland Subcommittee on Cybersecurity, Infrastructure Protection, and Security Technologies (Committee on Homeland Security) Thursday

Internet of Things

On Wednesday the Senate Commerce, Science and Transportation Committee will be holding a hearing on The Connected World: Examining the Internet of Things. This is going to be an anti-regulation hearing as can be seen by the following statement from Chairman Thune:

By engaging early in this debate, Congress can ensure that any government efforts to protect consumers are tailored for actual problems and avoid regulatory overreach.”

Since Thune will be one of the controllers of what cybersecurity legislation will pass in the 114th Congress, the tenor of his questions during this hearing will provide some valuable insight into what kind of legislation on cybersecurity issues we might see coming out of his Committee.

On the Floor

The Senate will continue to play chicken with HR 240, the FY 2015 DHS spending bill. The Republicans obviously don’t have the vote to bring the bill to the floor for a vote and the Democrats don’t have the votes to remove the restrictions on the President’s immigration executive actions. At some point before the February 27th deadline I expect Majority Leader McConnell bring a clean bill to the floor which will pass with a close bipartisan vote.


The House will bring a trio of homeland security related bills to the floor under suspension of rule. Of specific interest to readers of this blog will be HR 710. Rep Jackson-Lee’s (D,TX) bill was introduced last Wednesday and still hasn’t been published by the Government Printing Office. I suspect that it is a repeat of last session’s HR 3202 which passed easily in the House but was not taken up by the Senate. It will pass again this week with large bipartisan support.

Friday, February 6, 2015

DOT Tank Car Final Rule to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a copy of DOT’s final rule on Enhanced Tank Car Standards and Operational Controls for High-Hazard Flammable Trains from the Pipeline and Hazardous Material Safety Administration (PHMSA).

The notice of proposed rulemaking (NPRM) for this rule was published just a little over six months ago. With the large number of comments (over 3,000) received on that NPRM it is remarkable that PHMSA was able to get a final rule to OMB in just over six months. It is, frankly, a measure of the political pressure the Administration is under to ‘get something done’ on this issue.


Because of the complexity of the issues involved and the amount of political pressure on both sides of the issue, there is no telling how long it will take OMB to clear this final rule for publication. In the little over two months that OIRA considered the NPRM it held 19 reported meetings with interested parties. I expect that a similar number will be held during the consideration of this final rule.

Thursday, February 5, 2015

ISC-CERT Updates DTP and HART-DTM Information

Today the DHS ICS-CERT published two new HART-DTM related advisories, updated the CodeWrights HART-DTM advisory, updated the NTP Advisory and published their promised NTP supplement. It was a busy information afternoon for ICS-CERT.

NTP Information

The third update to the ICS-CERT advisory on the NTP vulnerabilities was simply a change to add a link to the promised supplement addressing vendor specific information about how those vulnerabilities are implemented in specific products. That Supplement currently lists affected products (and mitigation measures) from/for the following vendors:

Arbiter Systems;
● Innomoninate;
● Meinberg;
● Siemens; and
● Wind River System;

The Supplement does not currently list reportedly unaffected products. Updates to this Supplement are expected.

HART-DTM Information

The third update to the CodeWrights HART-DTM advisory provides some new information about affected systems, including adding Honeywell to the list of potentially affected vendors. Interestingly GE-MAKTec was not included on the list even though ICS-CERT published an advisory about their HART-DTM vulnerabilities today. The Update has also provided links to ICS-CERT advisories for Emerson, Honeywell, Magnetrol, and Pepperl+Fuchs.

There is some additional clarification about the potential impact of successful exploits of this vulnerability. ICS-CERT notes that it only affects the Field Device Tool (FDT) Frame Application. Since that application is only used for configuration changes, ICS-CERT reports that a successful exploit “does not result in loss of information, control, or view by the control system of the HART devices on the 4-20 mA HART Loop”.

ICS-CERT continues to emphasize how difficult it would be to craft an exploit for this vulnerability. Interestingly, they have removed the comments about compromised physical access to the 4 mA to 20 mA current loop. They emphasize that an exploit is possible from “any adjacent network that receives or passes packets from the HART Device DTM”.

The new advisories for Pepperel+Fuchs products and products from GE and MAKTec (GE provides the DTM software for the MAKTec Bullet Adapter DTM according to a GE Advisory) provide basically the same information as the current CodeWrights advisory.

Consistency of Information Sharing

It seems odd that ICS-CERT is issuing individual advisories for vendors affected by the HART-DTM vulnerability but issues a supplement for the advisory that lists those affected by the DTP vulnerability. In most ways it really does not make a difference which process ICS-CERT uses and they are under no mandate or obligation to maintain any sort of consistency in their methodology.


Having said that the multiple advisory process being used with the HART-DTM vulnerability does present a problem. The two advisories issued today share the same language as that found in the current version of the CodeWrights advisory. The Emerson and Magnetrol advisories share the language with the previous version of the CodeWrights advisory. This means that ICS-CERT really should have offered updates of those two advisories today as well. And when the next change takes place, they will have to update all five advisories (plus any others issued in the interim). Using the DTP advisory/supplement model, only one advisory needs to be updated when information on the base vulnerability changes.

Bills Introduced – 2-4-15

There were 82 bills introduced in the House and Senate yesterday. Five of the bills may be of specific interest to readers of this blog:

HR 702 To adapt to changing crude oil market conditions. Rep. Barton, Joe [R-TX-6]

HR 705 To amend the authorization in title 49, United States Code, for capital grants for rail line relocation projects. Rep. Maloney, Sean Patrick [D-NY-18]

HR 710 To require the Secretary of Homeland Security to prepare a comprehensive security assessment of the transportation security card program, and for other purposes. Rep. Jackson Lee, Sheila [D-TX-18]

HR 726 To prohibit Federal agencies from mandating the deployment of vulnerabilities in data security technologies. Rep. Lofgren, Zoe [D-CA-19]

S 356 A bill to improve the provisions relating to the privacy of electronic communications. Sen. Lee, Mike [R-UT]

HR 702 was actually introduced the day before, but it was assigned the number ‘HR 666’. Apparently this was considered a bad sign by Congressman Barton so the bill was re-introduced today. To be fair, anything that makes it hard for any member to vote for a bill is probably something to be avoided.


The two cybersecurity bills will probably not receive future mention here as I suspect that they are principally IT related bills. Control system language could creep in though.

Wednesday, February 4, 2015

ICS-CERT Updates NTP Advisory

Today the DHS ICS-CERT published an updated version of their advisory on the Network Time Protocol vulnerabilities. This is a fairly extensive update with five separate areas of the advisory being revised. The revisions deal with:

● The scope of the covered systems;
● The scope of the vulnerabilities;
● Additional background information;
● Additional mitigation information; and
● A link to a new document on best practices for using time reference services.

Scope Changes

ICS-CERT acknowledges in this new version that a number of vendor systems will be affected by this open source vulnerability. They note that they are working with vendors to determine which systems are specifically vulnerable. They will be publishing a supplement to this advisory that provides additional information on affected systems and unique mitigation measures.

In a rather unusual move ICS-CERT has added two new vulnerabilities to this advisory. They are:

● Authentication bypass by spoofing - CVE-2014-9297; and
● Improper check for unusual or exceptional conditions - CVE-2014-9298

Best Practices

This best practices document is interesting in a lot of ways. First off it has no organizational markings on it and it is prominently labeled “Unclassified”. This kind of leads me to believe that it may be a military document. There is a reference on page one to notifying the Coast Guard in case of a problem with a GPS signal.

About half of the document deals with GPS issues, about 1/3 deals with NPT issues and the remaining space is taken up with a discussion of Cessium clock issues and Time and Frequency Distribution System considerations.

Systemic Issues


We are seeing an increasing number of systemic vulnerabilities in industrial control systems that affect products from a number of vendors. These type issues make it easier for a serious attacker to develop tools that would be effective across a wide range of control system platforms. This would make things easier for people developing cyber-warfare weapons. A pretty sound argument could be made that a large portion of the ICS-CERT assets should be focused on these types of issues. Advisories of this sort (and the promised future updates and supplements) show that ICS-CERT is taking this type of issue seriously. Whether it is seriously enough, only time will tell.
 
/* Use this with templates/template-twocol.html */