Monday, April 9, 2018

HR 5366 Introduced – UAS Interdiction


Last month Rep. Hartzler (R,MO) introduced HR 5366, the Safeguarding America’s Skies Act of 2018. The bill would authorize DHS and DOJ personnel to take actions to interdict unmanned aerial systems around selected critical infrastructure facilities.

Authorized Actions


The bill would add a new section to 18 USC would give the Secretary of Homeland Security and the Attorney General the authority to “authorize officers, employees, and contractors of the department assigned with duties that include safety, security, or protection of personnel, facilities, or assets of the department” to take actions to mitigate a threat “that an unauthorized UAV poses to the safety or security of a covered facility or asset” {new §28(a)}. The authorized actions include {new §28(b)}:

• Detect, identify, monitor, and track, without prior consent, a UAV, to evaluate whether the UAV poses a reasonable threat to the safety or security of a covered facility or asset
• Warn the operator of the UAV;
• Redirect, alter control, disable, disrupt, seize, or confiscate, without prior consent, a UAV that poses a reasonable threat, including by intercepting, substituting, or disrupting wire, oral, electronic, or radio communications or signals transmitted to or by UAV;
• Use reasonable force to disable, disrupt, damage, or destroy a small unmanned aircraft, unmanned aircraft system, unmanned aircraft, or unmanned aircraft’s attached system, payload, or cargo that poses a reasonable threat to the safety or security of a covered facility or asset.
Conduct research, testing, training on, or evaluation of any equipment, including any electronic equipment, to determine its capability and utility to enable (sic).

The definition of the term ‘covered facility or asset’ describes facilities designated by the Secretary or Attorney General that could include {new §28(h)(2)(C)}:

• Buildings and grounds leased, owned, or operated by or for the Federal Government, including Federal Facility protection operations;
• Authorized protective operations, including but not limited to the protection of Federal jurists, court officers, witnesses, and other persons;
• Penal, detention, correctional, and judicial operations;
• National Security Special Events, Special Event Assessment Ratings Events, or other mass gatherings or events that are reasonably assessed by the Department of Justice to be a potential target for terrorism or other criminal activity;
• Active Federal law enforcement investigations;
• Operations that counter terrorism, narcotics, and transnational criminal organizations;
• Securing authorized vessels, whether moored or underway;
• Protection operations pursuant to section 3056;
• Critical infrastructure;
• Emergency Response Operations;
• National Disaster Areas, Natural, or Hazardous Disaster Areas if it is determined by the • Secretary of Homeland Security that unauthorized access to the airspace would restrict recovery efforts;
• Other areas identified by the President.

The other key term ‘critical infrastructure’ is defined {new §28(h)(6)} by reference to 18 USC 2339D that uses the broad definition of “systems and assets vital to national defense, national security, economic security, public health or safety including both regional and national infrastructure” instead of one of the more restrictive definitions {see for example 42 USC 5195c(e)} that uses the phrase “…so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact…”.

The bill would provide certain restrictions on the actions authorized to be taken. In addition to specific privacy restrictions outlined in the new §28(3) the bill would also require DHS and DOJ to {new §28(a)}:

• Avoid any infringement of the privacy and civil rights of the people of the United States and the freedom of the press consistent with the First and Fourth Amendments, including with regard the testing of any equipment and the interception or acquisition of communications;
• Limit the geographic reach and the duration of such actions to only those areas and timeframes that are reasonably necessary to address a reasonable threat; and
• Use reasonable care not to interfere with non-targeted manned or unmanned aircraft, communications, equipment, facilities, or services.

Information Disclosure


The new §28(d) provides that:

“Information pertaining to the technology, procedures, and protocols used to carry out this section, including any regulations or guidance issued to carry out this section, shall be exempt from disclosure under section 552(b)(3) of title 5 and exempt from disclosure under State and local law requiring the disclosure of information.”

DOT Action Required


The new §28(b)(5) would require DOT within one year to “issue a final rule requiring remote identification and tracking of UAVs, including UAVs for recreational use, to ensure that cooperative aircraft are identified”.

Other 18 USC Amendments


Section 2(c) of the bill amends various other portions of 18 USC to exempt actions taken under the proposed §28. These include:

18 USC 32 - Destruction of aircraft or aircraft facilities;
18 USC 1030 - Fraud and related activity in connection with computers;
18 USC 1632 - Communication lines, stations or systems;
18 USC 1367 - Interference with the operation of a satellite;
18 USC Chapter 119 - Wire and Electronic Communications Interception and Interception of Oral Communications; and
18 USC Chapter 206 - Pen Registers and Trap and Trace Devices

Moving Forward


Neither Hartzler nor her two co-sponsors {Scott (GA) and Hanabusa (HI)} are members of any of the three committees (Judiciary, Homeland Security, and Transportation and Infrastructure) to which this bill was assigned for consideration. This means that the bill is unlikely to receive consideration in any of the committees. I suspect that even if it were considered in committee it would not receive majority support; it is too radical a change in the way that aircraft are protected in law to receive the necessary support.

Commentary


For about a year now I have been advocating for changes to US statutes to specifically allow for interdiction of drones over high-risk chemical facilities (and other critical infrastructure). This bill provides a good look at just how complicated that type legislation could be. Section 2(c) of the bill provides a pretty good insight into what laws might have to be revised to allow for the interdiction of UAS.

BTW: You can see my effort to craft a more limited drone interdiction authorization here.

The bill takes an odd turn when it only allows agents of the United States (employees and contractors of DHS and DOJ) to interdict UAS. I see this as a method to keep tight control of the technology and weapons involved. Unfortunately, this would probably result in as many problems as it would solve. Neither DHS nor DOJ has enough manpower to assign UAS control teams to critical public buildings on a long-term basis, much less privately owned critical infrastructure. This would mean that both agencies would have to have UAS response teams that could be tasked to support (on a short-term response basis) individual sites that are having (or reasonably expect to have UAS overflight problems that would potentially affect the security of the site or the safety of personnel on the site.

Another odd provision is found in the information disclosure paragraph. While I certainly understand the crafters concerns about the protection of information obtained during the unintended interception of communications with UAS that really should not be intercepted under the rules envisioned by this bill. Unfortunately, the crafters either poorly worded the paragraph or they specifically intended DHS and DOJ to write the rules required by this bill without sharing those rules with the public. I really hope it is an English usage problem and not an attempt at specifying unnecessary government secrecy.  

Sunday, April 8, 2018

Committee Hearings – Week of 4-7-18


Both the House and Senate are coming back to Washington this week after their two-week Easter Recess. There are no hearings of specific interest to readers of this blog in the strictest sense, but there are two categories of hearings that may be of general interest. They deal with (non-ICS) cybersecurity and money.

Cyber Hearings


April 10th, Senate Judiciary, “Facebook, Social Media Privacy, and the Use and Abuse of Data”;
April 11th, House Energy and Commerce, “Facebook: Transparency and Use of Consumer Data”;
April 11th, House Armed Services, “Cyber Operations Today: Preparing for 21st Century Challenges in an Information-Enabled Society”;
April 11th, Emerging Threats and Capabilities Subcommittee (House Armed Services), “A Review and Assessment of the Department of Defense Budget, Strategy, Policy, and Programs for Cyber Operations and U.S. Cyber Command for Fiscal Year 2019”;

Zuckerberg gets a chance to respond to Congressional critics and the military will talk about cyber operations.

Budget and Spending Hearings


April 11th, Homeland Security Subcommittee (House Appropriations), “FY 2019 Department of Homeland Security”;
April 12th, Transportation and Protective Security Subcommittee (House Transportation), “Examining the President’s FY 2019 Budget Request for the Transportation Security Administration”;

We are still too early in the FY 2019 process for any particular details to begin to emerge but, listening to the questions asked at these hearings can give a picture of what may be coming down the road.

Thursday, April 5, 2018

ICS-CERT Publishes 3 Advisories and 2 Siemens Updates


Today the DHS ICS-CERT published three control system security updates for products from Leão Consultoria e Desenvolvimento de Sistemas (LCDS), Moxa, and Rockwell. They also updated two previously published control system security advisories for products from Siemens.

LCDS Advisory


This advisory describes an improper check of handling of exceptional conditions vulnerability in the LCDS LAquis SCADA. The vulnerability was reported by Karn Ganeshen. LCDS has a new version that mitigates the vulnerability. There is no indication that Ganeshen has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a highly-skilled attacker with local access could exploit this vulnerability to cause the device an attacker is accessing to crash, resulting in a structured exception handler overflow condition, which may allow code execution.

Moxa Advisory


This advisory describes an information exposure vulnerability in the Moxa MXview, network management software. The vulnerability was reported by Michael DePlante of Leahy Center for Digital Investigation at Champlain College. Moxa developed a new version to mitigate the vulnerability. There is no indication that DePlante has been provided an opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit this vulnerability to read the private key of the web server, which may allow a remote attacker to decrypt encrypted information.

Rockwell Advisory


This advisory describes six vulnerabilities in the Rockwell MicroLogix Controller. The vulnerabilities were reported by Jared Rittle and Patrick DeSantis of Cisco. Rockwell has provided mitigation strategies in their customer notification (registration required). There is no indication that the researchers were provided an opportunity to verify the efficacy of the fixes.

The six reported vulnerabilities (according to ICS-CERT) are:

Improper authentication (6) - CVE-2017-12088, CVE-2017-12089, CVE-2017-12090, CVE-2017-12092, and CVE-2017-12093

NOTE: Rockwell does not use the ‘improper authentication’ description for any of the six (actually 17) vulnerabilities. Instead they report (using the same CVE numbers):

• Denial of service via ethernet functionality - CVE-2017-12088;
• Denial of service via download functionality - CVE-2017-12089;
• Denial of service – SNMP-set request - CVE-2017-12090;
• Access control vulnerabilities (12) - CVE-2017-14462 thru CVE-2017-14473;
• File-write vulnerability in memory module - CVE-2017-1209; and
• Malicious register session packets lead to communication loss - CVE-2017-12093

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to cause denial of service, disclosure of sensitive information, communication loss, and modification of settings or ladder logic.

SCALANCE Update


This update provides additional details on an advisory that was originally published on November 28th, 2017. The new version provides updated mitigation information for the SCALANCE W1750D.

Building Technologies Products Update


This update provides additional details on an advisory that was originally published on April 3rd, 2017. The new information provides a link to the updated LMS. I mentioned this new information in my earlier post.

Wednesday, April 4, 2018

ISCD Updates CFATS Monthly Update Page – 04-03-18


Yesterday the DHS Infrastructure Security Compliance Division (ISCD) updated the Chemical Facility Anti-Terrorism Standards (CFATS) Monthly Update web page. This page provides a summary of ISCD activities and CFATS facility status over the previous month. The data presented continues to show progress on the implementation of the CFATS program.

The table below shows the reported ISCD activities over the last two months. The ‘to Date’ lines show the numbers for the activity since the program was started in 2007. The ‘Month’ lines show numbers for the same activity in the indicated month.

CFATS Activities
Feb-18
Mar-18
Authorization Inspections to Date
3352
3496
Authorization Inspections Month
133
149
Compliances Inspections to Date
3249
3349
Compliances Inspections Month
79
90
Compliance Assistance Visits to Date
4007
4096
Compliance Assistance Visits Month
172
86

The numbers continue to reflect the maturation of the CFATS program. As more of the new facilities from the CSAT 2.0 implementation submit their site security plan (SSP) and have it authorized, we will continue to see increases in the monthly rate of authorization inspections and a decline in the compliance assistance inspections. And as more facilities have their SSP approved we will see an increase in the number of compliance inspections.

The table below shows the status of the facilities in the CFATS program over the last two months. Tiered facilities are those that have had their submitted Top Screen reviewed by ISCD and have been notified that they are covered facilities under the CFATS program and have been assigned their risk-based Tier ranking. The Authorized and Approved facilities refer to the status of the facility’s SSP. Approved facilities are in the compliance phase of the program where they will receive periodic compliance inspections by ISCD to ensure that the facility is in compliance with its negotiated SSP standards.

CFATS Facility Status
Feb-18
Mar-18
Tiered
474
387
Authorized
665
681
Approved
2345
2373
Total
3485
3441

The decline in the number of Tiered facilities is to be expected as the facility begin to move through the SSP submission and approval process. We may see minor periodic upticks in that number as ISCD continues its facility outreach program to identify chemical facilities that may be required to submit Top Screens.

I continue to be concerned about the resumption in the decline in the number of covered facilities. On one hand, the facility risk reduction efforts necessary for leaving the CFATS program means that the risks of a successful terrorist attack on that facility are diminished; which is certainly a good thing. The potential downsides are that the facility risk reduction comes at the cost of increasing the risks to another facility (for example having a larger inventory of chemicals of interest at a supplier location instead of at the using facility) and/or by increasing the transportation risk by increasing the number of shipments of COI.

For a variety of reasons ISCD has not provided the regulated community with any kind of information about the ‘successful’ risk reduction efforts at the facilities that have departed the program. I am hoping that this will be one of the issues that Congress will address during its process of re-authorizing the CFATS program; either during hearings where David Wulf is testifying or in the various reports that Congress is sure to request (almost certainly already have requested) from both the DHS Inspector General and the Government Accounting Office.

ICS-CERT Publishes Siemens Advisory


Yesterday the DHS ICS-CERT published a control system advisory for products from Siemens. These are the vulnerabilities I reported on Saturday.

This advisory describes eight vulnerabilities in the Siemens Building Technologies Products. These are Gemalto Sentinel LDK RTE vulnerabilities that have been previously reported by Siemens in other products. The vulnerabilities were reported by Sergey Temnikov and Vladimir Dashchenko from Kaspersky Labs. Siemens has a newer version of the License Management System (LMS) that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The eight reported vulnerabilities are:

• Stack-based buffer overflow (2) - CVE-2017-11496, CVE-2017-11497;
• Security features - CVE-2017-12819;
• Improper restriction of operations within the bounds of a memory buffer - CVE-2017-12821;
• Null pointer dereference - CVE-2017-11498;
• XML entity expansion - CVE-2017-12818;
• Heap-based buffer overflow - CVE-2017-12820; and
Improper access control - CVE-2017-12822

Again, Siemens is not reporting all 14 of the Gemalto vulnerabilities. I would suspect that this is because the Siemens implementation of the license manager does not include the features affected by the other vulnerabilities.

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow arbitrary code execution, NTLM-relay attacks, denial of service of the remote process, remote denial of service, and/or allow the administrative interface to be remotely enabled and disabled without authentication.

NOTE: Siemens announced that it had updated this advisory yesterday. The update includes a link to download the LMS.

Tuesday, April 3, 2018

CFATS Reauthorization – Academic Laboratories


This is part of a continuing series of blog posts on my proposed changes to the CFATS authorization. The current authorization for the program ends on December 18th, 2018. These posts address some of the language that I would like to see in any re-authorization bill. Earlier posts in the series include:


A long-time reader forwarded me some information on a CFATS lobbying meeting that is scheduled for April 20th. These meetings are not unusual, the regulated community certainly has a legitimate interest in the reauthorization process. This meeting is being hosted by the American Chemical Society and is specifically interested in addressing how the CFATS program affects research and college & university campuses.

The research community has long had concerns with the costs associated with the CFATS program and has generally been concerned that they should not be lumped into a security program with commercial manufacturing facilities. When it comes to release concern chemicals of interest (COI) the large screening threshold quantities (STQ) associated with these COI provide a reasonable dividing line that generally precludes research facilities from CFATS coverage. There may still be university or college facilities that remain under reporting requirements for release security concern COI (ammonia related cooling systems for ice rinks or chlorination facilities for pools for example), but the same risk assessment criteria and risk based performance standards should be applied to those facilities as are used for commercial facilities with the same COI.

Theft/diversion security concern COI present an entirely different problem. These chemicals include explosives, chemical warfare agents, and the precursor chemicals for the same. The much lower STQ for these COI reflect the fact that these chemicals can be used to make improvised terrorist weapons capable of much more targeted attacks. While private sector labs probably have some reasonable level of security measures in place to protect their intellectual property; that security could be expanded to include physical COI protections.

Education laboratories are a completely different story. While locks may exist on chemical storeroom doors, the relatively unsupervised flow of personnel in these settings makes it extremely difficult to establish workable security processes. That combined with a not unusual interest in ‘exciting’ chemistry like explosives by some students and you have a very complicated security situation.

With that in mind, I would like to suggest the following language

Sec. 633 – Academic Laboratories

(a) Definitions -
(1) Academic Laboratory – The term ‘academic laboratory’ means a laboratory (lab), including associated chemical storage facilities, at an educational facility. It specifically includes labs used for hands-on instruction and labs used by researchers associated with the sponsoring educational facility who also have instructional responsibilities at the institution. It does not include laboratories that have release security issue chemical of interest (COI) as listed in Appendix A, to 6 CFR 27, in excess of the STQ reported for that COI.

(2) Theft/Diversion COI – The term ‘theft/diversion COI’ mean those chemicals listed in Appendix A, to 6 CFR 27, identified as having a theft security issue

(3) Screening Threshold Quantity – The term ‘screening threshold quantity’ or ‘STQ’ means a quantity of a chemical identified in Appendix A, to 6 CFR 27, that triggers Top Screen reporting requirements under 6 CFR 27.200(b)(2).

(4) RBPS – The term ‘RBPS’ means the risk-based performance standards listed in 6 CFR 27.230;

(5) Laboratory employee – The term ‘laboratory employee’ means a paid employee (including students receiving a stipend for working in the laboratory) of the educational facility housing the academic laboratory specifically subject to the personnel surety requirements of 6 CFR 27.230(12); and

(6) Student – The term ‘student’ means a person studying at the educational facility that are not being paid for activities in the academic laboratory. Students are not subject to the personnel surety requirements of 6 CFR 27.230(12).

(b) The Secretary will:

(1) Within 180 days of adoption of this bill, publish a draft Academic Laboratory RBPS guidance document described in (c) below in the Federal Register for public comment; and

(2) Within one year of the adoption of this bill, publish a final version of the Academic Laboratory RBPS guidance document.

(c) Academic Laboratory RBPS Guidance Document – The guidance document described in (b) above will:

(1) Address all 19 of the standards outlined in 6 CFR 27.230, except those listed in (2) below;

(2) Academic Laboratories with only theft/diversion COI in excess of the STQ will be exempt from the following RBPS:

(A) Section 27.230(a)(3)(i);

(B) Section 27.230(a)(4)(i);

(C) Section 27.230(a)(4)(iii); and

(D) Section 27.230(a)(4)(iv);


(3) Specifically address the limited perimeter associated with academic laboratories, but will ensure that academic laboratories define the perimeter to include, at a minimum:

(A) The storage facilities used to store the theft/diversion COI;

(B) The laboratories where those COI are used; and

(C) The routes between (A) and (B) where the theft/diversion COI are moved;

(4) Require that a laboratory employee will be physically present in a laboratory where a theft/diversion COI is in use and students are present;

(5) Require that theft/diversion COI be stored in a locked container in a locked room when not in use and that only laboratory employees are provided unaccompanied access to the locked room where theft/diversion chemicals are stored;

(6) Require that inventories of theft/diversion COI be updated every time that the locked container in which they are stored is opened;

(7) Require that any suspected theft of a theft/diversion COI, or any inventory discrepancy of the theft/diversion chemical in excess of the published STQ for that COI, be reported to the local police; and

(8) Require that a copy of the police report for each incident described in (6) above will be:

(A) Included in the records required by 6 CFR 27.230(a)(16); and

(B) Be forwarded to DHS in fulfillment of the requirements of 6 CFR 27.230(a)(15).

(d) The Secretary will develop procedures for Academic Laboratories to request exemptions for any of the specific requirements set forth in (c) above.

DHS Publishes 2018 Penalty Adjustment Final Rule


Yesterday the Department of Homeland Security published a final rule in the Federal Register (83 FR 13826-13839) making the annual inflation adjustments to the statutory maxim penalty amounts for a large number of programs under its supervision. This was a direct final rule with an effective date of April 2nd, 2018.

For readers of this blog, four of the changes may be of specific interest. They are shown in the table below. The link in the program column is to the paragraph describing the program changes in the rulemaking. The TSA penalties apply to all surface transportation regulations.

Program
Reg Reference
Current
New
$33,333
$34,013
CG, MTSA
$33,333
$34,013
CG, MTSA
$59,893
$61,115
$11,182
$11,410

This annual direct rulemaking is required by §701 of the Bipartisan Budget Act of 2015 (PL 114-74). This year the final rule is a tad bit late, since it was supposed to be published by January 15th.

Interestingly, these new penalties can be assessed for any violations (not previously adjudicated, of course) that occurred since November 2nd, 2015 when the Bipartisan Budget Act was signed.

 
/* Use this with templates/template-twocol.html */