Thursday, June 8, 2017

Bills Introduced – 06-07-17

Yesterday with both the House and Senate in session there were 49 bills introduced. Of those three may be of specific interest to readers of this blog:

HR 2807 To amend title 10, United States Code, to require congressional notification concerning sensitive military cyber operations and cyber weapons, and for other purposes. Rep. Thornberry, Mac [R-TX-13]

HR 2810 To authorize appropriations for fiscal year 2018 for military activities of the Department of Defense and for military construction, to prescribe military personnel strengths for such fiscal year, and for other purposes. Rep. Thornberry, Mac [R-TX-13]

HR 2812 To direct the President to develop a strategy for the offensive use of cyber capabilities, and for other purposes. Rep. Correa, J. Luis [D-CA-46] 

I promise that this is not being turned into a military blog (GRIN), but military cyber weapons and strategy will probably have a serious impact on cybersecurity for control systems in critical infrastructure. We should certainly, for example, be prepared to defend critical infrastructure facilities from those types of control system attacks that our military contemplates executing against such facilities in enemy countries.

I will be watching HR 2807 for the critical definitions involved in outlining ‘sensitive military cyber operations and cyber weapons’ to see if Congress is intending to keep an eye on counter control system operations.

As always, I watch the military authorization and spending bills for cybersecurity provisions.


Last session there were a number of efforts (see HR 2708, HR 3039, and HR 5220 for example) related to requiring the President to establish norms for deciding what types of cyber-attacks would be considered ‘acts of war’. It will be interesting to see how HR 2812 differs from these earlier unsuccessful attempts.

Wednesday, June 7, 2017

Bills Introduced – 06-06-17

With both the House and Senate in session there were 35 bills introduced yesterday. Of those, two may be of specific interest to readers of this blog:

HR 2774 To establish a bug bounty pilot program within the Department of Homeland Security, and for other purposes. Rep. Lieu, Ted [D-CA-33]

HR 2778 To direct the Secretary of Transportation to establish a Smart Technology Traffic Signals Grant Program, and for other purposes. Rep. Cardenas, Tony [D-CA-29]

HR 2774 is probably a companion bill to S 1281 which I have not yet seen.


I will only report on HR 2778 if it includes cybersecurity provisions.

Tuesday, June 6, 2017

ICS-CERT Publishes Two Advisories

Today the DHS ICS-CERT published two control system security advisories for products from Digital Canal Structural and Rockwell.

Digital Canal Advisory


This advisory describes a stack-based buffer overflow vulnerability in the Digital Canal Wind Analysis structural engineering analysis software. The vulnerability was reported by Peter Cheng. Digital Canal reports that the current version mitigates the vulnerability. There is no indication that Cheng has verified the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to cause the device that the attacker is accessing to become unavailable, resulting in a denial of service.

Rockwell Advisory


This advisory describes a missing authorization vulnerability in the Rockwell PanelView Plus 6 700-1500. The vulnerability was self-reported by Rockwell. Rockwell has identified firmware versions that mitigate the vulnerability. Rockwell also reports that graphic terminals running OS 2.31 or greater are not affected by this vulnerability.


ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability to remotely access the device to potentially retrieve data or disrupt the availability of the device.

Committee Hearings – Week of 06-04-17

With both the House and Senate back in Washington this week the main focus in Committee hearings will be the FY 2018 budget, but there will be some other hearings that will address cybersecurity issues.

Budget


Budget hearings are really high-level policy discussions with little or no details about program implementation, so there will be little here that will be of specific interest to readers of this blog. The only possible exception will be the DHS hearings because of their focus on cybersecurity.

The Senate Homeland Security and Governmental Affairs Committee will meet on Tuesday to look at the DHS budget request. The House Homeland Security Committee will hold their hearing on Wednesday. The written testimony from Secretary Kelly will be virtually identical for both hearings.

Again, with the high-level policy focus of this hearing there will probably be no mention of control system security.

Healthcare Cybersecurity


On Thursday, the Oversight and Investigations Subcommittee of the House Energy and Commerce Committee will be holding a hearing on “Examining the Role of the Department of Health and Human Services in Health Care Cybersecurity”. The witness list includes:

• Mr. Emery, Health Care Industry Cybersecurity Task Force
• Mr. Steve Curren, US Department of Health and Human Services
• Mr. Leo Scanlon, U.S. Department of Health and Human Services

With no direct testimony from the FDA, it is unlikely that there will be any substantive mention of medical device cybersecurity.


On Wednesday the Energy and Commerce Committee will be holding a markup hearing looking at a number of bills. Of specific potential interest here is HR 2430, the FDA Reauthorization Act of 2017. I have not specifically reported on this bill because there are no cybersecurity provisions in the bill as introduced. There is a remote chance that there could be some medical device cybersecurity provisions added in this markup.

Saturday, June 3, 2017

DHS Announces 2017 CSSS Registration

Earlier this week DHS announced the opening of registration for the 2017 Chemical Sector Security Summit (CSSS) that will be held in Houston, TX on July 19-21, 2017. As with the 2016 CSSS, you can register to attend the actual Summit in Houston, or you can watch the live webcasts of most of the presentations.

Last year’s CSSS was the first time that DHS provided webcasts of some of the presentations and they look like they are expanding the webcast coverage. Instead of trying to list all of the webcast presentations (listed here) I will provide a list of those that are not being webcast.

• An Evolving World: Analyzing Threats to the Chemical Sector, Thursday, 0900-1000;
• DHS Tools and Resources Exchange, various times;
• How Vulnerable Are You?: Effective Strategies for Assessing Cybersecurity Risk, Thursday, 1330-1430;
• DHS and Chemical Innovations: S&T Research and Development, Thursday, 1330-1340;
• Digital Intruders: Blinkey Demo, Thursday, 1455-1605;
• Run, Hide, Fight: Preparing Your Facility for an Active Shooter, Thursday, 1455-1605;
• How Digital Devices Communicate: Understanding the Internet of Things, Thursday, 1620-1730;
• Global Partnerships: International Chemical Security Efforts, Thursday, 1620-1730;

You will notice that the last six are pairs of presentations being conducted at the same time. There are actually three ‘breakout’ periods being conducted on Thursday with three presentations being give during each period. It looks like DHS attempted to select the three (probably) most popular presentations to be webcast. Those are:

• Left of Boom: Bombing Prevention Awareness Program Update
• What to Expect during a CFATS Inspection
• When Disaster Strikes: Security Roles During a Disaster

Personally, I would have preferred to see the cybersecurity risk assessment strategy talk instead of the bomb prevention talk, but I have some hands on experience with explosives (conventional and improvised), so my preferences may be skewed.


As usual this looks like it will be an interesting meeting. If you can attend the ‘no-cost’ (no cost for the actual meetings; DHS cannot do anything about travel and lodging costs) conference you probably should. The chance to talk to folks from DHS and other CFATS covered facilities should be well worth the trip.

Friday, June 2, 2017

EPA Sends Second New TSCA NPRM to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that the Environmental Protection Administration (EPA) had submitted a notice of proposed rulemaking (NPRM) as part of the implementation of the regulatory requirements of the Frank R. Lautenberg Chemical Safety for the 21st Century Act (PL 114-182). This rulemaking would implement the requirements of §6(b)(4) (130 Stat 463) that requires the Administrator to establish a rule for the EPA’s conduct of risk evaluations of chemicals identified under §6(b)(2)(A) (130 Stat 462).

As with the earlier EPA TSCA implementation rule that was forwarded to OIRA last month, the Trump Administration is legally obligated to complete this rulemaking. They will not, however, meet the incredibly (and completely unrealistically) short legal deadline for producing the final rule (one-year after enactment of the law; or June 22, 2017). The Obama Administration would not have met the deadline either; they submitted their version of this NPRM to OIRA on November 10th, 2016 and it was approved by OIRA on January 13th.


It will be interesting to see if the EPA includes in the NPRM the two regulations that it intends to vacate as part of the Trump regulatory reduction executive order (EO 13771) requirements.

Thursday, June 1, 2017

ICS-CERT Publishes Phoenix Broadband Advisory

Today the DHS ICS-CERT published a control system security advisory for products from Phoenix Broadband Technologies. The advisory describes an hard-coded password vulnerability in the Phoenix PowerAgent SC3 Site Controller. The vulnerability was reported by Iñaki Rodríguez. Phoenix Broadband has produced a new firmware version to mitigate the vulnerability. ICS-CERT reports that Rodriguez has tested the new version and confirms its efficacy.


ICS-CERT reports that a relatively unskilled attacker could remotely exploit the vulnerability to gain access to the battery monitoring system.
 
/* Use this with templates/template-twocol.html */