Wednesday, February 19, 2020

EO 13905 – Responsible Use of PNT Services


Yesterday the President published a new executive order in the Federal Register (85 FR 9359-9361) on “Strengthening National Resilience Through Responsible Use of Positioning, Navigation, and Timing (PNT) Services”. EO 13905 will require actions by various agencies of the Federal Government to “foster the responsible use of PNT services by critical infrastructure owners and operators”.

Definitions:


Section 2 of the order provides a listing of the critical definitions used; they include:

PNT services – any system, network, or capability that provides a reference to calculate or augment the calculation of longitude, latitude, altitude, or transmission of time or frequency data, or any combination thereof.

Responsible use of PNT services – the deliberate, risk-informed use of PNT services, including their acquisition, integration, and deployment, such that disruption or manipulation of PNT services minimally affects national security, the economy, public health, and the critical functions of the Federal Government.

PNT profile – a description of the responsible use of PNT services—aligned to standards, guidelines, and sector-specific requirements—selected for a particular system to address the potential disruption or manipulation of PNT services.

PNT Profiles


Section 4 of the Order requires the Department of Commerce (DOC) to develop PNT profiles. Those profiles will {§4(a)}:

• Enable the public and private sectors to identify systems, networks, and assets dependent on PNT services;
• Identify appropriate PNT services;
• Detect the disruption and manipulation of PNT services; and
• Manage the associated risks to the systems, networks, and assets dependent on PNT services

PNT profiles will be referenced in the Coast Guard’s Federal Radionavigation Plan.

DHS will develop a plan to “test the vulnerabilities of critical infrastructure systems, networks, and assets in the event of disruption and manipulation of PNT services.” The results of the tests will be used to update PNT profiles.

Where appropriate, PNT profiles will be referenced in Federal acquisition contracts “with the goal of encouraging the private sector to use additional PNT services and develop new robust and secure PNT services.”

DOT, DOE and DHS will develop pilot programs “to engage with critical infrastructure owners or operators to evaluate the responsible use of PNT services.” These pilot programs will help inform efforts by the Director of The White House Office of Science and Technology Policy (OSTP) to develop a national plan “for the R&D and pilot testing of additional, robust, and secure PNT services that are not dependent on global navigation satellite systems (GNSS).” In support of this effort, the DOC will “make available a GNSS-independent source of Coordinated Universal Time, to support the needs of critical infrastructure owners and operators”.

Commentary


This is not the first presidential policy on PNT issues. In 2004, President Bush updated the 1996 based policy document on U.S. Space-Based Positioning, Navigation, and Timing Policy. That effort, however, was based upon optimizing the use of the GPS based GNSS. Since that time, it has become obvious that spoofing the satellite signals has become an operational reality, posing a potential danger to the continued use of GNSS based PNT. This potential danger was publicly recognized as early as 2014 by the PNT Advisory Board. In 2015 DOT started looking at the use of the eLoran system as an alternative to GNSS PNT.

It will be interesting to see how DOC and the rest of the government deals with the PNT profiles mandated in this EO. The large the number of ‘profiles’ developed the more useful they will be for private sector use in the internal evaluation of the use of PNT services. On the other hand, minimizing the number of profiles developed will make things easier for government agencies to develop broad, minimally specific guidance documents.

Of particular usefulness would be detailed information on how to ‘detect the disruption and manipulation of PNT services’. Again, user/operators will be best served by the most detailed information available. Government agencies, however, may feel better served by providing only the most generic information.

Tuesday, February 18, 2020

4 Advisories and 1 Update Published – 2-18-20


Today the CISA NCCIC-ICS published two control system security advisories for products from Emerson and Honeywell, two medical device security advisories for products from GE and Spacelabs, and 1 update for products from Interpeak.

Emerson Advisory


This advisory describes a heap-based buffer overflow vulnerability in the Emerson OpenEnterprise SCADA Server. The vulnerability was reported by Roman Lozko of Kaspersky ICS CERT. Emerson has an upgrade that mitigates the vulnerability. There is no indication that Lozko has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that an uncharacterized attacker could remotely exploit this vulnerability to allow an attacker to execute code on an OpenEnterprise SCADA Server.

Honeywell Advisory


This advisory describes a clear-text storage of sensitive information vulnerability in the Honeywell INNCOM INNControl 3 energy management platform. The vulnerability is self-reported. Honeywell has an upgrade available to mitigate the vulnerability.

NCCIC reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to escalate user privileges within the INNControl application.

GE Advisory


This advisory describes a protection measure failure vulnerability in the GE Ultrasound Products. The vulnerability was reported by Marc Ruef and Rocco Gagliardi of scip AG. GE has provided generic workarounds to mitigate the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with local access could exploit the vulnerability to allow an attacker to gain access to the operating system of affected devices.

Spacelabs Advisory


This advisory describes the BlueKeep vulnerability in the Spacelabs Xhibit Telemetry Receiver. Spacelabs has an updated version that mitigates the vulnerability.

NOTE: A number of other vendors in both the control system and medical device realms issued advisories on this vulnerability (see my blog post here for example) beginning in May of last year. This is the first acknowledgement of vendor actions on this vulnerability from NCCIC-ICS though there was an obscure advisory on the vulnerability published by NCCIC-ICS.

Interpeak Update


This update provides additional information on the Urgent/11 advisory that was originally published on October 1st, 2019 and most recently updated on December 10th, 2019. The new information includes a link to a vendor advisory from Mitsubishi.

Pipeline Safety and Cybersecurity


The Pipeline and Hazardous Material Safety Administration (PHMSA) has increasingly begun to require technological solutions to on going safety problems with both gas transmission and hazardous material pipelines. A good example of that reliance can be found in the notice of proposed rulemaking (NPRM) that PHMSA issued earlier this month requiring the use of automated valves to limit the damage caused when pipelines rupture. Unfortunately, PHMSA’s failure to address cybersecurity issues related to the sensors and control systems associated with such technological solutions reduces the effectiveness of those measures.

Part of the reason that PHMSA has failed to act is that Congress has not provided PHMSA or DOT in general with specific authority to regulate the cybersecurity of pipeline infrastructure. The primary responsibility for pipeline security rests with the under funded and woefully understaffed surface transportation security folks within the Transportation Security Administration (TSA). But TSA has been both unwilling and unable to address cybersecurity issues beyond issuing broad guidelines and hoping for industry voluntary compliance with those guidelines.

The time has come for PHMSA to realize that it has an inherent responsibility to ensure that the technologies that it mandates for pipeline safety purposes are specifically protected against cyberattacks and that the failure of cybersecurity protections should trigger the same reporting requirements that accompany the failure of physical controls.

For example, in the current NPRM PHMSA could change the wording of the new §192.745(c) to read:

(c )For each valve installed under § 192.179(e) and each rupture-mitigation valve under § 192.634 that is a remote control shut-off or automatic shut-off valve, or that is based on alternative equivalent technology, the operator must:

(1) conduct a point-to-point verification between SCADA displays and the mainline valve, sensors, and communications equipment in accordance with § 192.631(c) and (e);

(2) demonstrate that the SCADA system, the mainline valve, sensors, and communications equipment are covered under a written cybersecurity plan that identifies:

(A) each of the open ports on each component and the processes, controls or devices protecting each open port against unauthorized communications attempts;

(B) procedures that are in place to ensure that all vendor security notices and advisories for each device are:

(I) reviewed in a timely manner, and
(II) the subject of a subsequent security risk assessment where appropriately adopted risk mitigation measures are implemented in a timely manner;

(C) the reporting processes that will be used to notify management of any incidents, equipment failures or loss of process view or control that might indicate a cyber intrusion or attack, and

(D) how the organization will respond to vulnerability reports from both within and outside of the organization.

NOTE: A copy of this post will be submitted as a comment on the NPRM in question.

Monday, February 17, 2020

HR 5428 Amended and Adopted in Committee – Energy Security Research


Last week the House Science, Space, and Technology Committee held a markup hearing where HR 5428, the Grid Modernization Research and Development Act of 2019, was amended and adopted by the Committee by a voice vote.  A minor amendment had been previously adopted by the Committee’s Energy Subcommittee in December.

The Amendment


The amendment was offered by Rep Fletcher (D,TX). It would insert a new paragraph (f) to the proposed §1304a. That paragraph would add a requirement for DOE to “conduct research and development on tools and technologies that improve the interoperability and compatibility of new and emerging components, technologies, and systems with existing electric grid infrastructure”.

Moving Forward


Once the Committee publishes their report on this markup the bill will be cleared for consideration by the full House. The bill would likely be taken up under the suspension of the rules process where it would pass with substantial bipartisan support.

Saturday, February 15, 2020

Public ICS Disclosure – Week of 2-7-20


This week we have eight vendor disclosures for products from Siemens (2), Schneider Electric, Phoenix Contact, HMS, ABB (2) and Moxa. We also have three advisory updates from Siemens and one from Schneider.

Siemens Advisories


Siemens published an advisory describing three vulnerabilities found in Intel chips used in Siemens products. The vulnerabilities were identified and reported (advisory links below) by Intel. Siemens has provided generic workarounds to mitigate the vulnerabilities.

The three reported vulnerabilities are:

• Insufficient memory protection (2) - CVE-2019-0151 and CVE-2019-0152; and
• Heap-based buffer overflow - CVE-2019-0169

Siemens published an advisory describing a resource allocation vulnerability in their Profinet-IO stack. The vulnerability was reported by Yuval Ardon and Matan Dobrushin from OTORIO. Siemens has updates that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Schneider Advisory


Schneider Published an advisory describing an uncontrolled search path element vulnerability in their ProSoft Configurator. The vulnerability was reported by Yongjun Liu from nsfocus. Schneider has a new version that mitigates the vulnerability. There is no indication that Yongiun has been provided an opportunity to verify the efficacy of the fix.

Phoenix Contact Advisory


Phoenix Contact has published an advisory [.PDF download link] describing a remote configuration vulnerability in their Emalytics Controllers. The vulnerability was reported by Anil Parmar. Phoenix Contact has a new firmware version that mitigates the vulnerability. There is no indication that Parmar has been provided an opportunity to verify the efficacy of the fix.

HMS Advisory


HMS has published an advisory describing a cross-site scripting vulnerability in their Flexy and Cosy products. The vulnerability was reported by Ander Martínez from Titanium Industrial Security. HMS has a new firmware version that mitigates the vulnerability. There is no indication that Martinez has been provided an opportunity to verify the efficacy of the fix.

ABB Advisories


ABB published an advisory describing a direct object reference vulnerability in their Asset Suite product. The vulnerability is self-reported. ABB has a new version that mitigates the vulnerability.

ABB published an advisory describing 14 vulnerabilities in their eSOMS product. The vulnerabilities are self-reported. ABB has a new version that mitigates the vulnerabilities.

Moxa Advisory


Moxa published an advisory describing 8 vulnerabilities in their OnCell cellular gateway. The vulnerabilities were reported by Alexander Zaytsev from Kaspersky Lab. Moxa has new firmware versions that mitigate the vulnerabilities. There is no indication that Zaytsey has been provided an opportunity to verify the efficacy of the fix.

Siemens Updates


Siemens published an update to their  Linux TCP SACK PANIC advisory for Industrial Products that was originally published on September 10th, 2019 and most recently updated on November 14th, 2019. The new information includes revised version data and mitigation links for:

• TIM 1531 IRC;
• SIMATIC CP 1242-7, CP 1243-7 LTE (EU andUS versions), CP 1243-1, CP 1243-8 IRC, CP 1543-1, CP 1542SP-1, CP 1542SP1 IRC, CP 1543SP-1; and
• SCALANCE W1700.

NOTE: NCCIC-ICS updated their advisory on February 11th, but did not list it on their web site.

Siemens published an update for their ZombieLoad advisory that was originally published on July 9th, 2019 and most recently updated on December 10th, 2019. The new information includes updated version data and mitigation links for:

• SIMATIC IPC547E;
• SIMATIC IPC347E; and
• SIMATIC IPC3000 SMART V2
Siemens published an update for their GNU/Linux subsystem vulnerabilities advisory that was originally published on November 27th, 2018 and most recently updated on January 14th, 2020. The new information includes adding the following new vulnerabilities;

• CVE-2019-5188;
• CVE-2019-11190;
• CVE-2019-19956;
• CVE-2019-20054,
• CVE-2019-20079;
• CVE-2019-20388; and
• CVE-2020-7595

Schneider Update


Schneider published an update for their U.motion Builder advisory that was originally published on April 5th, 2018. The new information includes an updated remediation section.

ISCD Publishes Hatchery Advisory Opinion


This week the DHS Infrastructure Security Compliance Division (ISCD) published their 5th advisory opinion. This one deals with fish hatcheries and the ‘temporary’ agricultural exemption for filing a Top Screen. The Opinion actually dates back to 2015 when ISCD addressed this issue in response to a letter from the California Department of Fish and Wildlife.

In short, ISCD has taken the position that fish hatcheries are not ‘agricultural facilities’ in the meaning used in their exemption (73 FR 1640). This means that fish hatcheries possessing DHS chemicals of interest (COI) at or above the screening threshold quantity are required to complete a Top Screen. ISCD tangentially addressed this issue back in December 2017 when they published “Protect Your Fishery and Hatchery Chemicals from Use in a Terrorist Attack”.

I would assume that someone has recently raised this issue and that ISCD felt it was now necessary to publicly address it by publishing this Advisory Opinion.

Friday, February 14, 2020

HR 5760 Introduced – Energy Security Research


Earlier this month Rep Bera (D,CA) introduced HR 5760, the Grid Security Research and Development Act. The bill would require DOE to fund a variety of electric sector cybersecurity research efforts. The bill would also authorize funding for such activities. The bill would amend Title XIII of the Energy Independence and Security Act of 2007 (42 USC 17381 et seq.) by adding nine new sections.

Definitions


The new §1317 would add definitions for the Smart Grid Title. Key definitions include:

• The term ‘cybersecurity’ means protecting an information system or information that is stored on, processed by, or transiting an information system from a cybersecurity threat or security vulnerability.
• The term ‘cybersecurity threat’ has the meaning given the term in section 102 of the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501).
• The term ‘information system’—has the meaning given the term in section 102 of the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501); and includes operational technology, information technology, and communications.
• The term ‘security vulnerability’ has the meaning given the term in section 102 of the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501).
• The term ‘transient devices’ means removable media, including floppy disks, compact disks, USB flash drives, external hard drives, mobile devices, and other devices that utilize wireless connections.

R&D Program


Section 1310 would require DOE “to carry out a research, development, and demonstration program to protect the electric grid and energy systems, including assets connected to the distribution grid, from cyber and physical attacks” {new §1310(a)}. The program would include the award of research, development, and demonstration grants to {new §1310(b)}:

• Identify cybersecurity risks to information systems within, and impacting, the electricity sector, energy systems, and energy infrastructure;
• Develop methods and tools to rapidly detect cyber intrusions and cyber incidents, such as intrusion detection, and security information and event management systems, to validate and verify system behavior;
• Assess emerging cybersecurity capabilities that could be applied to energy systems and develop technologies that integrate cybersecurity features and procedures into the design and development of existing and emerging grid technologies, including renewable energy, storage, and demand-side management technologies;
• Identify existing vulnerabilities in intelligent electronic devices, advanced analytics systems, and information systems;
• Develop technologies that improve the physical security of information systems, including remote assets;
Integrate human factors research into the design and development of advanced tools and processes for dynamic monitoring, detection, protection, mitigation, response, and cyber situational awareness;
• Evaluate and understand the potential consequences of practices used to maintain the cybersecurity of information systems and intelligent electronic devices;
• Develop or expand the capabilities of existing cybersecurity test beds to simulate impacts of cyber attacks and combined cyber-physical attacks on information systems and electronic devices; and
• Develop technologies that reduce the cost of implementing effective cybersecurity technologies and tools, including updates to these technologies and tools, in the energy sector.

Additionally, DOE would be required to work with relevant entities to develop technologies or concepts that build or retrofit cybersecurity features and procedures into work with relevant entities to develop technologies or concepts that build or retrofit cybersecurity features and procedures into {new §1310(b)(5)}:

• Information and energy management system devices, components, software, firmware, and hardware, including distributed control and management systems, and building management systems;
• Data storage systems, data management systems, and data analysis processes;
• Automated- and manually-controlled devices and equipment for monitoring and stabilizing the electric grid;
• Technologies used to synchronize time and develop guidance for operational contingency plans when time synchronization technologies, are compromised;
• Power system delivery and end user systems and devices that connect to the grid
• The supply chain of electric grid management system components;

Resilience and Response


Section 1311 would require DOE to establish a separate grant program “to enhance resilience and strengthen emergency response and management pertaining to the energy sector” {new §1311(a)}. Grants would be awarded for {new §1311(b)}:

• Developing methods to improve community and governmental preparation for and emergency response to large-area, long-duration electricity interruptions;
• Developing tools to help utilities and communities ensure the continuous delivery of electricity to critical facilities;
• Developing tools to improve coordination between utilities and relevant Federal agencies to enable communication, information-sharing, and situational awareness in the event of a physical or cyber-attack on the electric grid;
• Developing technologies and capabilities to withstand and address the current and projected impact of the changing climate on energy sector infrastructure, including extreme weather events and other natural disasters;
• Developing technologies capable of early detection of deteriorating electrical equipment on the transmission and distribution grid, including detection of spark ignition causing wildfires and risks of vegetation contact; and
• Assessing upgrades and additions needed to energy sector infrastructure due to projected changes in the energy generation mix and energy demand.

Best Practices and Guidance


Section 1312 would require DOE to “coordinate the development of guidance documents for research, development, and demonstration activities to improve the cybersecurity capabilities of the energy sector through participating agencies” {new §1312(a)}. This would include updating {new §1312(a)(1)}:

• The Roadmap to Achieve Energy Delivery Systems Cybersecurity;
• The Cybersecurity Procurement Language for Energy Delivery Systems; and
• The Electricity Subsector Cybersecurity Capability Maturity Model, including the development of metrics to measure changes in cybersecurity readiness.

The changes to the cybersecurity procurement language document would include suggestions for {new §1312(a)(1)(B)}:

• Contracting with third parties to conduct vulnerability testing for information systems used across the energy production, delivery, storage, and end use systems;
• Contracting with third parties that utilize transient devices to access information systems; and
• Managing supply chain risks.

DOE would also be required to work with the National Institute of Standards and Technology (NIST) to convene relevant stakeholders to develop consensus-based best practices to improve cybersecurity for {new §1312(b)(1)}:

• Emerging energy technologies;
• Distributed generation and storage technologies, and other distributed energy resources;
• Electric vehicles and electric vehicle charging stations; and
• Other technologies and devices that connect to the electric grid.

Section 1312(c) specifically states that none of the activities authorized by this section “shall be construed to authorize regulatory actions”.

Funding


Section 1318 authorizes funding for the programs outlined in this bill. Funding would start at $150 million in 2021 and increase each year to $182 million in 2025.

Amendments


On Wednesday the House Science, Space, and Technology Committee held a markup hearing that included consideration of HR 5760. Three amendments were offered by:

Bera;
Rep Lofgren (D,CA); and
Rep Waltz (R,FL)

All three amendments were adopted by voice vote as was the amended bill. Most of the changes made by the three amendments were relatively minor wording changes. The most significant change was made by the Waltz amendment. It would add a new §4, Critical Infrastructure Research and Construction, to the bill (not another change to the Energy Independence and Security Act of 2007).

The new §4 would require DOE to establish and operate a Critical Infrastructure Test Facility “that allows for scalable physical and cyber performance testing to be conducted on industry-scale critical infrastructure systems” {§4(d)}. The Test Facility would focus on cybersecurity test beds and electric grid test beds. The Test Facility would be authorized to operate for five years with the possibility of a single 5-year extension by DOE.

Moving Forward


This bill received bipartisan support in Committee, and I expect that it would receive similar support on the floor of the House. This bill could be brought to the floor under the suspension of the rules process or it could be added to a DOE authorization or spending bill. Because of the monies authorized for the grant programs, I suspect that this bill would receive less opposition if it were included in an authorization bill.

Commentary


You have to give the Committee Staff credit; this is a very comprehensive cybersecurity research program outlined in the bill. Unfortunately, the paltry amount of funding authorized in the bill will hardly make a start of a dent in the research program outlined. That amount of money, however, is probably about as much as Congress is going to allocate for cybersecurity research.

One thing that is interesting about this bill is the recognition by the Staff that grid security is going to be affected by not just by grid operators, but also by any number of entities that will be increasing connecting to the grid. The rise of the ‘smart grid’ is increasing the amount of cyber communication between grid operators and their customers. Those communications channels are going to be an increasingly important pathway for attackers to gain effective access to grid control mechanisms. The sooner cybersecurity research starts focusing on that process access route, the sooner defenses can begin to be appropriately arrayed to protect the grid.

 
/* Use this with templates/template-twocol.html */