Monday, November 16, 2015

ICS-CERT Publishes Sept-Oct 2015 Monitor

This afternoon the DHS ICS-CERT published the latest version of the ICS-CERT Monitor. I have been a pretty harsh critic of recent issues of this publication, but, with this issue, I am returning to recommending that ICS-CERT owners read and circulate the document.

I was disappointed with the initial article on information sharing, particularly since it was started with a report of a potential control system compromise on a system that wasn’t compromised. I understand that this is probably a not-unusual occurrence, but it would have made a stronger case for incident reporting if the lead-in story was about a compromised system that was caught before the compromise was exploited. Having said that, a very good point was made in the article about the importance of system logging.

The two lengthy articles in this issue were both well done. The discussion about trends in malware will probably be a little basic for security savvy IT or operations administrators, but it would be a good article to share with plant management. It is a nice overview of malware history leading into potential problems with IIOT.

The second article should, on the other hand, be required reading for everyone in the cyber enterprise, not just industrial control systems. The problem of the disposal of inadequately scrubbed computers spans IT, ICS and personal computing. And it gives nice props to Wighman, Sistrunk and Toecker who worked on the problem with ICS-CERT.

There are a number of short articles that may be of interest to those of us keeping up with things going on in the ICS world. They include:

• ICS-CERT at DEF CON and Black Hat;
• Section 508 and Accessibility;
• ICS-CERT Virtual Learning Portal Upgrade;
• Industrial Control Systems Joint Working Group Meetings;


Again, this issue is much improved over those that were produced recently. I really want to encourage ICS-CERT to keep up the quality and applicability of the information presented in the Monitor. If they do, this will be another valuable tool for that organization to share information with the control system security community.

Congressional Hearings – Week of 11-15-15

This week the House and Senate return to Washington after their extended Veterans Day holiday. Currently there is only one hearing scheduled this week that may be of specific interest to readers of this blog; looking at automotive cybersecurity.

Auto Cybersecurity

The Transportation and Public Assets Subcommittee of the House Oversight and Government Committee will hold a hearing on Wednesday on “The Internet of Cars”. There is no witness list currently available.

On the Floor

There are two bills that will be considered under suspension of the rules in the House this week that may be of specific interest to readers of this blog:

HR 1073 - Critical Infrastructure Protection Act; and
HR 3996 – The Surface Transportation Extension Act of 2015, part II (introduced today)


HR 1073 is an electromagnetic pulse protection bill with no funding or regulatory authority. HR 3996 is another short term extension of the Surface Transportation Extension Act while the House and Senate Conferees work out the differences in the two versions of HR 22. The draft of the bill from the House Transportation Committee looks to be a relatively clean bill this time. Both bills will pass without significant opposition.

Sunday, November 15, 2015

More Secure Portal Rumors

This has been an interesting weekend for rumors about ICS-CERT releases on the US-CERT Secure Portal. First I have heard from multiple sources that there may be two or more control system advisories from ICS-CERT currently listed on the Secure Portal. With this you get the normal reminder that critical infrastructure owners and legitimate security researchers may request access to the Secure Portal; see instructions on the bottom of the ICS-CERT landing page.

I have had a single source tell me that the Unitronics advisory I described earlier this week was, in fact, originally released to the Secure Portal on October 1st as I surmised, but that an updated version was released on that portal on November 3rd as described in the publicly released version of the advisory. That reasonably explains the discrepancy that I noted in that earlier post.


Finally I am hearing a disturbing rumor (admittedly from a different single source) that there is a control system vulnerability that has been released to a government-only limited distribution section of the Secure Portal. I can certainly see a need for a really limited initial disclosure of an advisory if it was dealing with military hardware for instance. What is disturbing to me is that there is reportedly (again single source without verifiable details) not going to be a public disclosure of the vulnerability. Again, if this would only affect military hardware, that is perfectly legitimate. I just don’t have enough details to make the call.

Saturday, November 14, 2015

HR 3994 Introduced – SPY Car Study Act of 2015

Earlier this month, Rep. Wilson (R,SC) introduced HR 3994, the Security and Privacy in Your (SPY) Car Study Act of 2015. The bill would require the Administrator of the National Highway Traffic Safety Administration (NHTSA) to report to Congress on potential cybersecurity standards for automobiles made and/or sold in the United States.

A Study and Report to Congress

Section 2(a) of the bill would require the NHTSA Administrator to conduct a study “to determine appropriate standards for the regulation of the cybersecurity of motor vehicles manufactured or imported for sale in the United States that should be adopted by the Administration and any other appropriate Federal agencies”. The study would be conducted in consultation with:

• The Federal Trade Commission;
• The Director of the National Institute of Standards and Technology;
• The Secretary of Defense;
• The Automotive Information Sharing and Analysis Center;
• SAE International;
• Manufacturers of motor vehicles and original motor vehicle equipment; and
• Relevant academic institutions.

The study would be designed to identify:

• The isolation measures that are necessary to separate critical software systems from other software systems;
• The measures that are necessary to detect and prevent or minimize the effects of anomalous code associated with malicious behavior;
• The techniques that are necessary to detect and prevent, discourage, or mitigate intrusions into the software systems of motor vehicles and other cybersecurity risks in motor vehicles; and
• Best practices to secure driving data collected by the electronic systems of motor vehicles while such data are stored onboard the vehicle, in transit from the vehicle to another location, and in off-vehicle storage.
Interestingly the term ‘critical software system’ is specifically defined in the bill. It describes “a software system of a motor vehicle that can affect the driver’s control of the movement of the vehicle” {§2(c)(2)}. Driving data is also defined to include vehicle status information and personal information about the owner, driver or passengers.

NHTSA would have one year to complete the study and then six months more to present a report to Congress about the results of the study. The report to Congress would be unclassified and would include recommendations for “any legislation that may be necessary to authorize the adoption of such standards [recommended in the study]” {§2(b)(2)}.

Moving Forward

Neither Wilson nor his cosponsor {Rep. Lieu (D,CA)} are members of the House Energy and Commerce Committee to which this bill was referred. Thus it is unlikely that there is the political pull to get this bill considered by the Committee. If the bill were to make it to the floor it would likely pass since it just requires a study and report. The automotive industry would almost certainly object to any regulation of automotive cybersecurity, but would probably hold-off opposing the bill since they would be able to influence the results of the study.

Commentary

I certainly can’t fault Wilson for trying to get a group of experts to determine what cybersecurity regulations might be necessary to ensure that automotive control systems are reasonably safe from cyber-attacks. And I agree that NHTSA, the government agency responsible for automotive safety, should probably be the agency to regulate that security; the Transportation Security Administration certainly is not a viable alternative. Having said that, I do think that there is a DHS agency that should be included in the study effort and that is ICS-CERT. They have the most knowledge of control systems within the government.

There are two agencies that I’m not sure that I agree should have anything to do with this study; the FTC and the DOD. The FTC’s cybersecurity knowledge is pretty limited and certainly does not include control systems. While they do have some regulatory experience, NHTSA already has a great deal of experience in dealing with automotive safety regulations. DOD certainly is developing cybersecurity expertise, but little of it has to do with protecting control systems. They certainly do not have the level of expertise in that arena that the ICS-CERT would have.

I’ll give Wilson’s staff credit for addressing the main areas of interest with automotive control systems, but some of their attempts at ‘technical language’ should not have been attempted. In §2(a)(2) for instance they attempt to describe preventing hacking as “prevent or minimize in the software systems of motor vehicles anomalous codes associated with malicious behavior”; close but not quite there.  Then in §2(a)(2) in describing potential security techniques they suggest “continuous penetration testing and on-demand risk assessments”. Congress should leave as much of the technical language as possible to the folks in the Executive Branch that actually work with the technology.

Two things are missing from the study and report requirements. First is a failure to address how cybersecurity deficiencies interface with the current recall process including a definition of how software updates fit into that process. And second, is the failure to establish software/firmware vulnerability disclosures, including allowing legitimate security researchers to legally test automotive cybersecurity systems without falling afoul of the Digital Millennium Copyright Act

(DMCA). Both of these will have to be addressed in any legislation authorizing regulation of automotive cybersecurity.

Intelligent Technologies Initiative Act of 2015

Last month Rep. Takano (D,CA) introduced HR 3852, the Intelligent Technologies Initiative Act of 2015. The bill would require the DOT to establish a grant program to fund a grant program for funding intelligent transportation system (ITS) projects.

Grant Program

Section 3 of the bill would require the Secretary to establish an Intelligent Technology Initiative to provide “grants to eligible entities to establish deployment sites for large scale installation and operation of ITS to improve safety, efficiency, system performance, and return on investment” {§3(a)}. The program would provide grants to 6 entities for projects for up to five years. The bill would authorize $200 million per year thru 2020.

Moving Forward

Takano is not a member of the House Transportation and Infrastructure Committee, so it seem unlikely that he has the pull to move this bill through the Committee Process. While $200 million is a relatively small amount of money in surface transportation program, the money would still have to come out of some other program so it is likely that there would be some significant opposition to this bill when if it came to the House floor.

Commentary

There are a number of ITS projects that seem almost inevitable, if program bugs can be worked out. In my opinion one of the biggest obstacles to effective ITS deployment is that the various systems that are being talked about have some serious potential cybersecurity problems that must be solved before the systems can be safely deployed.

Unfortunately, this bill is completely devoid of any mention of cybersecurity issues. There is no requirement for a cybersecurity component in any of the systems to be considered for the grant program. Nor is there any requirement in any of the required reports to Congress to include any information about cybersecurity issues.

I would like to see in any grant program for ITS deployment a clear requirement to address cybersecurity issues in any deployment scheme. Further, it would seem to me that a portion of the grant program should be set aside for specific studies on ITS cybersecurity issues. Failure to take these two requirements in an ITS implementation grant program clearly mark the program as being short sighted and not worthy of the limited transportation funding system.

Friday, November 13, 2015

OMB Approves FMCSA Prohibition of Coercion Final Rule

The OMB’s Office of Information and Regulatory Affairs (OIRA) announced yesterday that it had approved the final rule for DOT’s FMCSA regulation prohibiting coercion of truck drivers to violate federal trucking safety standards. The NPRM for this rule was published in May of 2014 and drew 95 comments, many from active and former truckers.

The Unified Agenda notes that Congress required the publication of new “regulations governing commercial motor vehicle safety [to] ‘ensure ... an operator of a commercial motor vehicle is not coerced by a motor carrier, shipper, receiver, or transportation intermediary to operate a commercial vehicle in violation of a regulation promulgated under 49 U.S.C. section 31136 or chapters 51 or 313 of title 49, U.S.C.’”


This rule will probably be published next week.

Building Control Systems Conference

Thanks to the folks at the SCADASEC listshare I heard about an interesting 3-day cybersecurity conference being put on by the Department of Commerce of all folks. The “Cyber Resilience of Building Control Systems” workshop is being sponsored by the Federal Facilities Council on November 17th, 2015 in Washington, DC and it is being webcast (something I would like to see more conferences doing, at least with select, high-profile presentations).

Some presentations of potential interest to readers of this blog include:

• Federal Perspective Keynote – Global/National Landscape: Former Congressman Steve Stockman – Overarching commentary on cyber legislation and challenges (privacy, encryption, information sharing);
• DHS - NPPD/Office of Cyber and Infrastructure Analysis - Susan Stevens – National Protection and Programs Directorate (NPPD) efforts to address the needs of all 16 Sectors to understand and manage cybersecurity risks for the multitude of facility and building types;
• DHS - NPPD/Office of Cybersecurity and Communications/ICS-CERT - Marty Edwards – • Building Control System cyber threats and vulnerabilities; role of ICS-CERT;
• USCYBERCOM – Bob Leverton – Overview of Joint Base Architecture for Secure ICS (J-BASICS) Tactics, Techniques & Procedures (TTPs);
• Whole Building Design Initiative: Rick Tyler, US Navy – Overview of draft Unified Facility Criteria 4-010-06 CYBERSECURITY OF FACILITY-RELATED CONTROL SYSTEMS;
• Cyber Ranges - DoD National Cyber Range – Dr. Robert Tamburello – Overview of Control System Test and Evaluation Events at the DoD National Cyber Range;
• Billy Rios – WhiteScope – Overview of Building Automation Systems continuous monitoring solutions, enumeration of internet-facing BAS using Shodan;
• Jason McHuen – Parsons – Hands-on demonstration of Kali Linux, Metasploit targeting and attacking Building Control Systems; and
• Alex Tarter – Ultra Electronics, 3eti – Cybersecuring Control System End-Point devices.

There will also be presentations and then separate hands-on workshops by ICS-CERT (CSET) and NSA (GrassMarlin) on the optional 3rd day of the workshop. It is not clear if the hands-on workshops will be webcast (my guess – not).

You can register on-line (also required for web cast) here. I’ll be there via the webcast; no travel budget, you know.

BTW: The agenda for this workshop indicates that there is a GrassMarlin module that can be downloaded with the ICS-CERT CSET. Nothing about that on the ICS-CERT pages. Again, ICS-CERT does a poor job in talking about the capabilities of their tools.
 
/* Use this with templates/template-twocol.html */