Wednesday, December 2, 2015

HR 22 Conference Report Rule

This afternoon the House Rules Committee met to craft the rule for the House consideration of the Conference Report on HR 22, the Fixing America’s Surface Transportation (FAST) Act. The rule provides for one hour of debate and a single vote on the bill. Consideration of the bill will probably take place tomorrow. An official summary of the bill is available.

Provisions of Interest

The Conference Report provides new language for HR 22 that combines portions of both the House and Senate passed versions of the bill. The 1317 page bill contains a large number of provisions but only 15 would be of specific interest to readers of this blog:


Sec. 1407. Vehicle-to-infrastructure equipment [Grant program].
Sec. 7201. National emergency and disaster response [Waiving compliance].
Sec. 7206. Wetlines [Withdraw proposed rule].
Sec. 7301. Community safety grants [Training grant program].
Sec. 7302. Real-time emergency response information.
Sec. 7303. Emergency response [GAO study].
Sec. 7304. Phase-out of all tank cars used to transport Class 3 flammable liquids [Revised phase-out schedule].
Sec. 7305. Thermal blankets [For DOT 117 and DOT 117R].
Sec. 7306. Minimum requirements for top fittings protection for class DOT–
117R tank cars.
Sec. 7307. Rulemaking on oil spill response plans [Congressional reporting requirement].
Sec. 7308. Modification reporting [DOT 117R conversion reporting to Congress].
Sec. 7309. Report on crude oil characteristics research study [Report to Congress].
Sec. 7310. Hazardous materials by rail liability study [Report to Congress].
Sec. 7311. Study and testing of electronically controlled pneumatic brakes [GAO study].
Sec. 61003. Critical electric infrastructure security.

Most of these provisions are relatively short and easy to understand. Two of them, however, are more complex; §7302 and §61003. Fortunately, I have addressed both of these is some detail as in earlier blog posts.

The §7302 requirements were originally included as §7012 in HR 3763; it would require that regulations implementing the SERC oil-train notification requirements would specifically outline what information would be protected from public disclosure as Sensitive Security Information.

The §61003 requirements were originally included in HR 2271 and then modified as §1104 of HR 8 (and still remain in that bill). This would officially establish Critical Energy Infrastructure Information (CEII) as an official Controlled Unclassified Information which would receive special treatment under the new CUI regulations being promulgated by the National Archives and Records Administration.

Moving Forward


This Conference Report will almost certainly be approved by both the House and Senate by substantial bipartisan majorities and the President has indicated that he intends to sign the bill.

ISCD Publishes December CFATS Update

Today the DHS Infrastructure Security Compliance Division (ISCD) published the December CFATS Update. The Chemical Facility Anti-Terrorism Standards continues to show modest increases in the number of authorized and approved site security plans (SSPs) and larger numbers of compliance inspections. And the number of covered facilities continues to decline.


November 2015
December 2015
Covered Facilities
3,146
3,110
Authorized SSPs
3,242
3,258
Approved SSPs
2,256
2,271
Compliance Inspections
295
378

There has been a sharp decline in the rate of increase in the number of authorized and approved SSPs. Since ISCD is continuing to report the total number of SSPs authorized instead of the current number of facilities with authorized SSPs it is hard to tell if the decline in the rates of authorizations and approvals is due to a dwindling pool of facilities with submitted but not yet acted upon SSPs or if it is due to resources being switched to conducting compliance inspections. Complicating the assessment of the reason for the lowered rates is the knowledge that there are at least 21 open Chemical Security Inspector positions.

Again the Department continues to report declining numbers of covered facilities without offering an explanation of why the facilities have been able to leave the program. Since these reports from ISCD do not include a tally of the new facilities that are added to the program (probably not a high number on a monthly basis) there is not even a way to make a reasonable attempt to determine how many facilities have actually left the program beyond the ‘More than 3,000’ that is listed every month.

HR 4127 Introduced – Intelligence Authorization Act

On Monday Rep. Nunes (R,CA) introduced HR 4127, the Intelligence Authorization Act for Fiscal Year 2016. The bill was then considered by the House yesterday and passed by a largely bipartisan vote of 364 to 58 (22 Republicans voted No).

I noted in a blog post yesterday that there were three sections of the public (unclassified) portion of the bill that might be of specific interest to readers of this blog. All three dealt with reports to Congress. After closer review it looks like only one may be of substantial interest; §313 – Cyber attack standards of measurement study.

The bill would require the Director of National Intelligence (DNI), in conjunction with DHS and DOD, to conduct a study to determine standards that “can be used to measure the damage of cyber incidents for the purposes of determining the response to such incidents” {§313(a)(1)}. The only specific requirement for the study is that it includes “a method for quantifying the damage caused to affected computers, systems, and devices” {§313(a)(2)}.

Moving Forward

With the bill having been considered yesterday under the suspension of rules process it is apparent that Chairman Nunes has done a good job of crafting a bill that has raised no substantial opposition.

This bill is a substitute for HR 2596 that was passed on more partisan lines back in June. The Senate version of the intel authorization bill is S 1705 that was reported out of Committee in July by unanimous vote, but has not been taken up by the Senate. If the Senate takes up HR 4127 they could still substitute the language from S 1705 before voting on the bill. Differences then would be settled by a conference committee.

Commentary

I have some minor concerns about the wording of §313. As currently constructed it would appear to limit the report to the consideration of damage to the actual computer systems attacked, not the consequences of the loss or compromise of data involved in IT system breaches or the cyber physical consequences of an attack on an industrial control system. I think that any consideration of a potential response to a cyber-attack would have to take those consequences into account.

The DNI is not prohibited from including those considerations in his report to Congress, but I would have thought that Congress would have wanted those items to be specifically considered. This is especially true when in any significant cyber attack those consequences would certainly be of higher ‘value’ than any specific damage to just the computer systems.


Since §313 is unlikely to be amended at this point, I suppose that we are going to have to rely on the DNI to expand on the limited congressional guidance provided for this report to include more relevant information than that required by Congress. I suspect, however, that there is little incentive for the DNI to do so.

Tuesday, December 1, 2015

HR 8 Amendments

The House Rules Committee met this afternoon to craft the rule for the consideration of amendments to HR 8, the North American Energy Security and Infrastructure Act of 2015, on the floor of the House. A structured rule was approved with 38 amendments to be considered during the floor debate.

Amendments of Possible Concern

Of the six amendments that I discussed yesterday only four were included for possible consideration on the floor. Those four are:

4. Franks (R,AZ) #93 (LATE) (REVISED) Secures the most critical components of America's electrical infrastructure against the threat posed by a potentially catastrophic electromagnetic pulse.
9. Jackson-Lee (D,TX) #84 (LATE) Directs the Secretary of Energy to submit to the Committees on Energy and Commerce and Natural Resources of the House of Representatives and the Committee on Energy and Natural Resources of the Senate a report on methods to increase electric grid (10 minutes) resilience with respect to all threats, including cyber attacks, vandalism, terrorism, and severe weather, no later than 120 days after the date of enactment of the Act.
32. DeSaulnier (D,CA), Lowey (D,NY), Garamendi (D,CA) #34 Requires the Department of Energy to study the maximum level of volatility that is consistent with the safest practicable shipment of crude oil.
38. Norcross (D,NJ) #19 (REVISED) Directs the Secretary of Energy to study weaknesses in the security architecture of certain smart meters currently available.

The revision to the Franks amendment added an exemption from the requirements of the amendment for the Tennessee Valley Authority and the Bonneville Power Administration.  The revision to the Norcross amendment adds a requirement for the Secretary to ‘promulgate rules’ to correct the weaknesses discovered in the required study.

Moving Forward

The amendment process will probably start tomorrow. With only 10 minutes of ‘debate’ on each amendment it should go pretty quickly. I expect that there will be a final vote on the bill tomorrow. While the bill will almost certainly pass, the question will be how many Democrats vote for the bill. With the President promising a veto of the bill the Republicans need a total of 290 votes to override aveto.

ICS-CERT Publishes Three Advisories

This afternoon the DHS ICS-CERT published three advisories for industrial control system vulnerabilities in systems from Siemens, Schneider and Saia Burgess Controls. ICS-CERT also announced an alternative method for notification of the release of advisories, alerts, and other publications.

Siemens Advisory

This advisory describes an authentication bypass vulnerability in a number of Siemens SIMATIC Communications Processor devices. The vulnerability was reported by Lei ChengLin (Z-0ne) from the Fengtai Technologies’ Security Research Team. Siemens has produced a firmware update for one of the devices (SIMATIC CP 343-1) and the other updates are in the works. There is no indication that Lei has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to perform administrative operations on the Communication Processor. Network access to Port 102/TCP is required and the Communication Processor’s configuration must be stored on its corresponding CPUs for the vulnerability to be exploited. Siemens notes that firewall functionality of Advanced-CPs must be turned off for port 102/TCP for the vulnerability to be exploited.

NOTE: This vulnerability was announced by Siemens on TWITTER last Friday.
                                       
Schneider Advisory

This advisory describes eleven ActiveX code injection vulnerabilities (listed under a single CVE) in the Schneider ProClima F1 Bookview ActiveX control application. The vulnerabilities were reported through the Zero Day Initiative by Ariele Caltabiano and Fritz Sands ( Sands was mentioned in the Schneider advisory but not the ICS-CERT Advisory). Schneider has produced an update to mitigate these vulnerabilities but there is no indication that Caltabiano was provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to modify arbitrary memory and lead to remote code execution.

Schneider reports that the vulnerabilities reside in the thermal calculation software.

Saia Burgess Controls Advisory

This advisory describes a hard-coded password vulnerability in the Saia Burgess Controls family of PCD controllers. The vulnerability was reported by Artyom Kurbatov. Saia has produced a new firmware version that mitigates the vulnerability and Kurbatov has validated the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to gain administrative access to the target device and resources.

Saia cautions that the upgraded firmware will still not protect the PCD controllers if they are connected directly to the Internet. Their Security Rules document provides recommended details for protecting the security of these controllers.

GovDelivery

You can now get ICS-CERT publications sent directly to your email via GovDelivery. Simply register for the service, click on which publications you want and wait for the emails. Publications from National Cyber Awareness System Mailing Lists and the Critical Infrastructure Cyber Community Voluntary Program (C3VP) are also available from this system.


DHS has tried these email notification systems for a number of their web sites. I’ve signed up for a bunch of them and the notifications seem to dry up after a while. Maybe this one will be different. Go ahead, give it a try; I did. We all take perverse pride in our inflated inboxes.

ICSD Infrastructure Protection Gateway

This afternoon the DHS Infrastructure Security Compliance Division (ISCD) published a fact sheet about their new Infrastructure Protection (IP) Gateway. A link to the IP Gateway was published on the CFATS Knowledge Center. The IP Gateway provides DHS with a method of sharing data about CFATS facilities with Federal, State, local, territorial, and tribal (SLTT) agencies as well as State and local fusion centers.

ISCD will provide information to the IP Gateway in two levels of data control; For Official Use Only (FOUO) data and Chemical-Terrorism Vulnerability Information (CVI) data. The FOUO data would include name, location, and geospatial information. This information would be available to all personnel given access to the IP Gateway.

The CVI data would include more protected information about chemical facilities; including Chemicals of Interest (COI), facility tiering information and facility security information. This information would only be accessible to those with a certified need to know. Access would be provided by ISCD Regional Directors, but only to personnel that have completed CVI training.


The IP Gateway is a new DHS product. It is initially being rolled out in Regions 1 and 5 (same as the EPA Regions). As additional regions are ramped up announcements will be made.

Bills Introduced – 11-30-15

Both the House and Senate were in session yesterday after returning from their Thanksgiving recess. A total of 18 bills were introduced and only one of those may be of specific interest to readers of this blog:

HR 4127 Intelligence Authorization Act for Fiscal Year 2016. Rep. Nunes, Devin [R-CA-22]

There is actually an official copy of this bill available this morning. While large portions of the bill are classified, a quick perusal of the unclassified portions show that there are three sections that may be of specific interest:

Sec. 313. Cyber attack standards of measurement study.
Sec. 705. Report on effects of data breach of Office of Personnel Management.
Sec. 706. Report on hiring of graduates of Cyber Corps Scholarship Program by intelligence community.

I’ll have a more detailed look at this bill in a later posting.
 
/* Use this with templates/template-twocol.html */