Tuesday, December 8, 2015

Bills Introduced – 12-07-15

Both the House and Senate were back in Washington for what may be their last week of the year. A total of 8 bills were introduced; one of which may be of specific interest to readers of this blog:

S 2361 A bill to enhance airport security, and for other purposes. Sen. Thune, John [R-SD]


I’m not intending to branch out into the security theater that is airport security, but the phrase “and for other purposes” always gets my attention. There is a remote possibility that there is some sort of cybersecurity language here.

Monday, December 7, 2015

FDA Announces Cybersecurity Workshop

Today the Food and Drug Administration (FDA) published a meeting notice in the Federal Register (80 FR 76022-76025) for a public workshop entitled “Moving Forward: Collaborative Approaches to Medical Device Cybersecurity”. The two-day workshop will be held in Silver Springs, MD on January 20-21st, 2016. The workshop will be webcast.

Agenda

According to the meeting notice the FDA, in conjunction with the National Health Information Sharing Analysis Center (NH-ISAC), the Department of Health and Human Services, and the Department of Homeland Security, wishes to address the following questions related to coordinated disclosure:

• How might the stakeholder community create incentives to encourage stakeholder participation?
• What do individual stakeholders need to understand and be aware of regarding coordinated disclosure?
• What current tools and models presently exist that may aid stakeholders in implementing disclosure and vulnerability management?
• How can the security researcher community work in collaboration with HPH stakeholders to identify, assess, and mitigate vulnerabilities?

Additional topics of interest include:

• Sharing FDA's current thinking on the implementation of the Framework in the medical device total product lifecycle.
• Adapting cybersecurity and/or risk assessment tools such as CVSS for the medical device operational environment.
• Adapting and/or implementing existing cybersecurity standards for medical devices.
• Understanding the challenges that manufacturers face as they increase collaboration with external third parties (cybersecurity researchers, ISAOs, and end users), to resolve cybersecurity vulnerabilities that impact their devices.
• Gaining situational awareness of the current activities in the HPH sector to enhance medical device cybersecurity.
• Identifying cybersecurity gaps and challenges that persist in the medical device ecosystem and begin crafting action plans to address them.

Registration

Those wishing to attend the workshop in person may register on-line. Early registration is recommended due to the limited seating at the venue.

Registration is not required for the web cast, but the web cast link will not be available until January 13th, 2016.

Public Comments


The FDA is soliciting public comments on the topics to be covered in the workshop. Written comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # FDA-2014-N-1286). Comments will be accepted until February 22, 2016.

Commentary

The one thing that looks to be missing from this workshop is a discussion of how reported cybersecurity vulnerabilities will be related to device recalls. More on this in a later blog post.

Saturday, December 5, 2015

OMB Approves Revised PHMSA Pipeline Accident Reporting ICR

On Thursday the OMB’s Office of Information and Regulatory Affairs (OIRA) reported that it had approved the revised information collection request for the Pipeline and Hazardous Material Safety Administration’s (PHMSA) Transportation of Hazardous Liquids by Pipeline: Record keeping and Accident Reporting program. The revision was required because of some changes in the instructions on the PHMSA F 7000-1 [.PDF Download] Accident Report – Hazardous Liquid Pipeline Systems form. There were no changes made to the burden estimates on the ICR.

This was the fifth revision of this ICR in the last five years.

Modified Instructions

Changes were made to the instructions for the following questions in Part A of the form:

• Question 9 - “volume of commodity released unintentionally” clarification; and
• Question 11, “volume of commodity recovered” clarification

A complete explanation for the clarifications involved can be found in the Supporting Statement [Word download] submitted to OIRA. The intent of the changes appears to be to reduce the reporting of the amount of liquid that was not actually involved in the pipeline accident.

Short Extension

PHMSA had requested a 36 month extension of the ICR date along with reporting these changes; this is the typical length of an ICR approval. OIRA, however, only approved a one-year extension. The reason for the short extension is that OIRA directed DOT to look into combining this ICR with the Federal Railroad Administration’s (FRA) ICR for train accident reporting as well as other PHMSA hazardous material accident reporting ICRs. The ‘Terms of Clearance’ section of the ICR approval explains:

“DOT is asked to provide OMB by no later than the date this approval expires one of the following: a joint PHMSA-FRA plan, coordinated with OST, to create a single system for electronically reporting accident information involving trains, pipelines, and hazardous materials and eliminates duplicative reporting requirements and redundant agency IT systems to the extent feasible OR a joint PHMSA-FRA report, coordinated with OST, indicating the reasons why developing such a plan is neither consistent with the PRA’s purposes nor otherwise in the public’s interest, the process used to arrive at this conclusion, and the extent public stakeholders were consulted. As part of the plan, PHMSA and FRA may explore whether additional or modified information should be collected to improve execution of agency missions and the utility of the information collected, consistent with the PRA. OMB plans to add these terms of clearance to all relevant PHMSA and FRA accident reporting collections, as appropriate.”

Commentary

The point of the whole ICR process is to reduce the burden on the reporting public by ensuring that only the information necessary for the legitimate needs of Federal Agencies is collected from the public and that it is done in the least burdensome method possible. While there is a certain amount of overlap between PHMSA and each of the modal agencies in DOT when it comes to hazardous material shipments, it is not clear to me that there is much overlap in the accident reporting requirements.

What this looks like to me is more of a government efficiency move than a move to reduce redundant reporting requirements. Government efficiency is always a good thing and OMB does have a mandate to oversee improvements in that area. Unfortunately, it does not seem that it has much actual power to force intradepartmental coordination. So it looks like OIRA is being used as a new tool to make that work.

I suspect that DOT will make a pro forma attempt at complying with the OIRA mandate, but will end up finding that the information collected in these different hazardous material accident reports is so different in scope and details that combining the reporting requirements would be more of a burden on the public sector. If true, that would certainly be a legitimate reason for not combining the collection efforts.

I believe, however, that with modern computer technology (and all of these reports are now being submitted on-line) it would be a relatively simple matter to make the reporting system show only the mode specific questions to the reporting entity once the mode of transportation involved in the accident is identified in a single initial check box type arrangement. It would be as easy to ensure that the modal agencies could abstract the information they need from the resulting accident reporting data base.

The combined data base would also make it easier for the Department to get a better look at the hazardous material shipping safety profiles of companies across the modal spectrum. I don’t believe that the Department now has the means to make a quick check to see how many hazardous material shipping accidents a particular company has across the whole spectrum of transportation modes.

There is, however, a significant downside to combining these ICRs. Whenever a change is made in the reporting requirements or estimated burden response for an ICR, a new ICR is required to go through the OIRA approval process. With multiple offices in PHMSA and other modal agencies making legitimate changes to their reporting process there is going to be an ICR revision coordination problem. The only real solution to that problem would be to add another team in the Office of the Secretary to handle the ICR paperwork and coordination for this super-ICR. That additional layer of bureaucracy is going to defeat the whole idea of increasing efficiency that is the real reason for starting this combining of ICRs in the first place.


It will be interesting to see what DOT does with this new requirement.

Thursday, December 3, 2015

ICS-CERT Published Two Advisories

This afternoon the DHS ICS-CERT published to control system advisories for products from Honeywell and SearchBlox.


Honeywell Advisory

This advisory describes two vulnerabilities in the Honeywell Midas gas detector. The vulnerabilities were reported by Maxim Rupp. Honeywell has produced new firmware versions to mitigate the vulnerabilities, but there is no indication that Rupp was provided the opportunity to verify the efficacy of the fix.

The two vulnerabilities are:

• Path traversal - CVE-2015-7907; and
• Clear text transmission of sensitive information - CVE-2015-7908.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to make unauthorized configuration changes to the device.

This advisory was originally released to the US CERT Secure Portal on November 5, 2015. Again, if you were authorized access to the Secure Portal (see the bottom of the ICS-CERT landing page for instructions on how to request access) you could have already applied the new firmware to your detectors.

Note: The link in the ICS-CERT advisory for the Honeywell Security Notice is incorrect. It should be: http://www.honeywellanalytics.com/en/support/product-notifications/midas-security-notification-firmware-update-available

SearchBlox Advisory

This advisory describes an information exposure vulnerability in the SearchBlox web-based proprietary search engine application. The vulnerability was reported by Oana Murarasu of Ixia. SearchBlox has developed a new version that mitigates the vulnerability, but there is no indication that Murarasu has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to export of the config file without admin login, overwrite the config file without admin login, and add or delete (nonadmin) users.

Missing Alert?


I was really expecting to see ICS-CERT publish an alert today on the Advantech EKI vulnerabilities that were reported on Tuesday by Rapid7, especially since there is already a Metasploit module available for the vulnerabilities. The reason might be that these are actually ‘old’ vulnerabilities (Heartbleed, Shellshock and a previously reported buffer overflow) that apparently made their way back into the firmware update for the latest ICS-CERT reported advisory (ISCA-15-309-01).

HR 22 Conference Report Agreed to in House

This afternoon the House agreed to HR 22 (the FAST Act) Conference Report by an overwhelmingly bipartisan vote of 359 to 65. All of the dissenting votes came from Republicans. A similar vote is expected in the Senate before the December 4th deadline.

House Amends and Passes HR 8

This morning the House passed HR 8 by a mainly party-line vote of 249 to 174. The House concluded their consideration of the 35 amendments to the bill before the vote. All four of the amendments I discussed Tuesday passed by voice votes yesterday.


With a Presidential veto promised if this bill passes a Senate vote today’s vote did not indicate that there was anywhere near enough support for this bill to overcome a veto if the bill were passed in the Senate. It is unlikely, however, that this bill will be considered in the Senate with the solid Democratic opposition to the bill.

FAA Sends UAS Registration Rule to OMB

Tuesday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a proposed interim final rule (IFR) from the Federal Aviation Administration (FAA) concerning UAS Registration. This is almost certainly the rule that has been under public discussion for the last month or so.

The FAA is probably using the December 31st, 2015 deadline to “develop and implement operational and certification requirements for the operation of public unmanned aircraft systems in the national airspace system” found in §334(b) of the FAA Modernization and Reform Act of 2012 (PL 112-95).

Unfortunately, if the published work of the ‘Drone Task Force’ is any indication of the contents and intent of this IFR, then the FAA is completely disregarding the provisions of §336 of the same bill which specifically states that the FAA may not “promulgate any rule or regulation regarding a model aircraft, or an aircraft being developed as a model aircraft”. A key component of the definition of ‘model aircraft’ is that it includes UAS that are “flown for hobby or recreational purposes” {§336(c)(3)}.

It will be interesting to see how long OIRA sits on this rulemaking.


BTW: Readers of this blog will notice that this post comes a day later than normal. I try to make these posts the day after the regulation is submitted to OIRA. Unfortunately, OIRA is no longer able to get these posted to its web site by the next morning. I know that it is the holiday season so that may explain why it takes an additional day to get two rulemakings posted to their site.
 
/* Use this with templates/template-twocol.html */