Tuesday, October 15, 2019

Committee Hearings – Week of 10-13-19


This week both the House and Senate will be in session. Spending bills are being worked on behind closed doors. We do have one cybersecurity related hearing and a markup hearing of the ARPA-E Reauthorization bill.

Supply Chain Security


On Wednesday the House Homeland Security Committee will hold a hearing on “Public-Private Initiatives to Secure the Supply Chain”. The witness list includes:

Robert Kolasky, CISA;
Robert Mayer, U.S. Telecom; and
John Miller, Information and Technology Industry Council

Markup Hearing


On Thursday the House Science, Space and Technology Committee will hold a markup hearing on three bills; including HR 4091, the ARPA-E Reauthorization Act of 2019.

Monday, October 14, 2019

CISA Publishes ICSJWG Quarterly Newsletter – 10-14-19


Today the Cybersecurity and Infrastructure Security Agency (CISA) published the September 2019 issue of the Industrial Control System Joint Working Group (ICSJWG) Quarterly Newsletter. This publication is not to be confused with the old ICS-CERT Monitor (last published in January 2018). Articles in this issue include:

2019 Biannual Meetings – Springfield;
National Cybersecurity Awareness Month;
ICSJWG Webinar Series;
Call to Action: Mobilizing Community Discussion to Improve Information Sharing About Vulnerabilities in Industrial Control Systems and Critical Infrastructure

The last two items are just the first couple of paragraphs from the longer articles (for which I have provided links). Neither author is an employee at CISA, and their article introductions are proceeded by a “Contributed Content Disclaimer” notice. The CISA Industrial Security landing page is actively soliciting article submissions for the December 2019 edition. Such submissions will be accepted up until December 9th, 2019. There is no clear information about how to submit, but I suspect that the ICSJWG.Communications@hq.dhs.gov email address is probably the way to go.

Commentary


Looking at the ICSJWG web page it looks like these newsletters have been published since 2009. I am sorry that I had missed them. The problems that plagued the official Monitor (four-color glossy corporate report format) are not present in this newsletter. I particularly like the fact they include articles about ICS cybersecurity issues that are not government speak nor vendor advertorials. I am glad that CISA is now advertising these publications and I look forward to the December issue.

ISCD Publishes CFATS Quarterly – 10-08-19


Last week the CISA Infrastructure Security Compliance Division (ISCD) published the latest version of their Chemical Security Quarterly. Along with a large number of informational links, this version includes articles on:

CISA Leadership Updates;
House Hearing on CFATS Reauthorization;
Close-up on the Personnel Surety Program (PSP);
National Cybersecurity Awareness Month;
Chemical Sector Security Summit Presentations;
Counter Unmanned Aircraft Systems (UAS) Authorities;

PSP


Along with the brief article on the Tier III and Tier IV implementation of the PSP terrorist screening process there is a list of frequently asked questions along with the ISCD response. The article provides a nice high-level (upper management) overview of the PSP while the FAQs provide a deeper (but not too deep) dive into the mechanics of the PSP. Finally, there is a section that includes links to a number of resources on the PSP.

One minor complaint, the Chemical Security Inspectors and Compliance Analysts is a little misleading. It is just an email link to CSAT@hq.dhs.gov. A detailed email to that address will get some sort of appropriate assistance response, but not necessarily from a CSI or compliance analyst.

Counter UAS


An interesting collection of information about UAS operations in or near critical infrastructure; unfortunately, there is nothing that directly concerns counter UAS operations at CFATS regulated facilities. The reason for this is that the legal basis for counter UAS operations is very cloudy with lots of deadly lightning bolts (to extend the ‘cloudy’ metaphor) at this point, again unfortunately, that is not made clear in this article or any of the linked information sites.

CFATS Information Updates


This section provides links to new or revised CFATS resources. In this instance the ‘new resources’ includes links to a Risk-Based Performance Standard (RBPS) 10 web page and fact sheet. This RBPS concerns maintaining all records of maintenance, testing, and calibration of security equipment, as specified in 6 CFR §27.255(a)(4).

This section notes that ISCD has revised their ‘Detect and Delay’ web site and fact sheet. The changes appear to be more editorial than substantive.

I was disappointed to see this update information here and not on the CFATS Knowledge Center page when the changes occurred. The new RBPS 10 information was apparently updated earlier this month so there was no major delay there; but the Detect and Delay information was apparently updated last May. That is hardly timely information sharing. Caveat; I am predicating my ‘timing’ information on the dates provided on the two fact sheets; there are no dates on these (or most of the) ISCD web pages.

Overall Rating – Good Job


I am typically disappointed in publications like this Quarterly report. As I have noted on numerous occasions with other agencies, they are more like Corporate Annual Reports (look how great we are) rather than information sharing efforts. ISCD continues to concentrate on information sharing rather than grandstanding.

I continue to refer to this as the ‘CFATS Quarterly’, but CISA has rebranded this the ‘Chemical Security Quarterly’. Most of the information in this issue is targeted at CFATS facilities, but the UAS article shows that CISA is trying to target this at a larger audience. I applaud them on that effort, we will see how well they expand this outreach in future editions.

Sunday, October 13, 2019

S 2556 Introduced – Cybersecurity Investments

Last month Sen. Murkowski (R,AK) introduced the Protecting Resources on the Electric Grid with Cybersecurity Technology (PROTECT) Act of 2019. The bill would provide energy cybersecurity investment incentives.

Incentives


Section 2 of the bill would amend the Federal Power Act (16 USC Chapter 12) by adding a new §219A, Incentives for Cybersecurity Investments. The new section begins by defining two new terms {new §219A(a)}:

• Advanced Cybersecurity Technology – any technology, operational capability, or service, including computer hardware, software, or a related asset, that enhances the security posture of public utilities through improvements in the ability to protect against, detect, respond to, or recover from a cybersecurity threat (as defined in 6 USC 1501).

• ADVANCED CYBERSECURITY TECHNOLOGY INFORMATION – information relating to advanced cybersecurity technology or proposed advanced cybersecurity technology that is generated by or provided to the Commission or another Federal agency.

Subsection (b) would require the Federal Energy Regulatory Commission (FERC) to “conduct a study to identify incentive-based, including performance-based, rate treatments for the transmission of electric energy subject to the jurisdiction of the Commission that could be used to encourage”:

• Investment by public utilities in advanced cybersecurity technology; and
• Participation by public utilities in cybersecurity threat information sharing programs.

Subsection (c) would require FERC to establish a rule providing for “incentive-based, including performance-based, rate treatments for the transmission of electric energy in interstate commerce by public utilities for the purpose of benefitting consumers by encouraging” the same investments and participation describe above. FERC may also include in that rulemaking additional incentives for {§219A(d)}:

• Defense critical electric infrastructure (as defined in section 215A(a)) and other facilities subject to the jurisdiction of the Commission that are critical to public safety, national defense, or homeland security, as determined by the Commission; and
• Facilities of small- or medium-sized public utilities with limited cybersecurity resources, as determined by the Commission.

Subsection (g) would provide protection against disclosure of advanced “cybersecurity technology information that is provided to, generated by, or collected by the Federal Government under subsection (b), (c), or (f)” by considering the information to be critical electric infrastructure information (CEII) under 16 USC 824o-1.

Grant Program


Section 3 of the bill would require the Department of Energy to establish the Rural and Municipal Utility Advanced Cybersecurity Grant and Technical Assistance Program to “to provide grants and technical assistance to, and enter into cooperative agreements with, eligible entities to protect against, detect, respond to, and recover from cybersecurity threats” {§3(b)}. The following types of entities would be eligible to apply for such grants or assistance {§3(a)}:

• A rural electric cooperative;
• A utility owned by a political subdivision of a State, such as a municipally owned electric utility;
• A utility owned by any agency, authority, corporation, or instrumentality of one or more political subdivisions of a State; and
• A not-for-profit entity that is in a partnership with not fewer than 6 entities described in subparagraph (A), (B), or (C).

DOE would be required to prioritize grants and technical assistance by giving priority to an eligible entity that, as determined by the Secretary {§3(d)(2)}:

• Has limited cybersecurity resources;
• Owns assets critical to the reliability of the bulk power system; or
• Owns defense critical electric infrastructure (as defined in 16 USC 824o–1(a).”

The bill would authorize $50 million per year for the next four years for this grant/assistance program.

Information provided to FERC or collected by FERC under this program would be protected from public disclosure, but would not specifically be considered CEII.

Moving Forward


Murkowski is the Chair of the Senate Energy and Natural Resources Committee to which this bill is assigned for consideration. Her cosponsors include Sen. Manchin (D,WV) who is the Ranking member of the Committee, and three other influential members of the Committee. This bill will almost certainly be considered in Committee and the bipartisan sponsorship would seem to indicate that the bill will receive significant bipartisan support in the Committee.

The big problem facing this bill is getting it to the Senate floor for consideration. There is just too much going on during the remainder of the year for this to be considered under the normal process. I do not suspect that this will be able to be considered under the unanimous consent process; too many Senators would see this bill as an ideal vehicle to add their own pet energy projects.

There may be a relatively short window next year that this bill could be considered before the election silly season gets into full swing.

Commentary


I am glad to see that Murkowski’s staff used the §1501 definition of ‘cybersecurity threat’ in their definition of ‘advanced cybersecurity technology’ since that definition relies on the ICS inclusive definition of ‘information system’. Having said that, the definition of ‘cybersecurity threat’ is still grossly lacking when it comes to energy system security since it relies on the IT triad of “availability, confidentiality, or integrity of an information system”. It does not specifically address the potential physical consequences of a cyber-attack on electric grid cyber assets.

I have addressed this definitional issue is some detail. Unfortunately, I doubt that my entire proposed solution will be attempted in this bill. Instead I would suggest the addition of the below listed definitions and the deletion of the reference to §1501 in the existing definition.

(5) the term ‘control system’ means a discrete set of information resources, sensors, communications interfaces and physical devices organized to monitor, control and/or report on physical processes, including power production, electric transmission or distribution, access control, and facility environmental controls;

(6) the term ‘cybersecurity threat’ means:

(A) threats to and vulnerabilities of information, information systems, or control systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of such information, information systems, or control systems, including such related consequences caused by an act of terrorism; and

(B) does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement; and

(7) the term "information system" has the meaning given that term in section 3502(8) of title 44.

The other problem with this bill is the inclusion of the protection of information under the provisions of CEII. While a great deal of the information addressed in this bill could well fit under the CEII designation, I question how much information provided in the rate filings under §219A(f) should receive that protection. The public deserves the right to see why rates are being changed. With that in mind I would re-write subsection (f):

(f) SINGLE-ISSUE RATE FILINGS.

(a) The Commission shall permit public utilities to apply for incentive based rate treatment under the rule issued under this section on a single-issue basis by submitting to the Commission a tariff schedule under section 205 that permits recovery of costs and incentives over the depreciable life of the applicable assets, without regard to changes in receipts or other costs of the public utility.

(b) Data submitted to the Commission to justify the rate change will include a sensitive annex listing computer hardware, software and services that will constitute the advanced cybersecurity technology justifying the incentive based rate treatment in (a). The sensitive data will be protected as critical electric infrastructure information (CEII) under 16 USC 824o-1.

(c) The information in the sensitive annex will include a detailed listing of costs and the depreciable life of the computer hardware, software and services described in (b). A summary of the costs and depreciable life of those assets will be included under the listing of ‘advanced cybersecurity technology’ in the public information provided to the Commission.

HR 4552 Introduced – TWICs for Veterans


Last month Rep. Babin (R,TX) introduced HR 4552, the Honorably Discharged Transportation Worker Identification Credential Act of 2019. The bill would require DHS to establish a program for issuing honorably discharged veterans an interim Transportation Workers Identification Credential (TWIC) pending the normal processing of a TWIC application.

Requirements


The bill would amend 46 USC 70105 by adding a new subsection (r), Provisional Security Cards. The amendment would require DHS to establish provisional transportation security cards (PTSC). Such cards would “be used during the beginning on the date a covered veteran applies for a transportation security card issued under subsection (b) and ending on the date on which such card is issued or denied to such veteran” {new §70105(r)(1)}. The PTSC would “authorize such covered veterans to have access to secure areas in the same manner as transportation security cards issued under subsection (b)” {new §70105(r)(1)}.

A ‘covered veteran’ would be a person who {new §70105(r)(3)}:

Served in the active military, naval, or air service, and who was discharged or released there from under honorable conditions; and
During such service was subjected to a rigorous security screening

DHS would be allowed, in consultation with DOD and the Department of Veterans Affairs, “prescribe a time period following discharge or separation from service in the Armed Forces during which an individual may be considered a covered veteran” {new §70105(r)(4)}.

Moving Forward


Babin is not a member of the House Homeland Security Committee to which this bill was assigned for consideration. This means that the bill is unlikely to be considered in Committee. I do not see anything in this bill which would engender any organized opposition to the bill if it were considered.

This bill could be offered as an amendment to a DHS spending bill or authorization bill (if either is actually considered with an amendment process this session).

Commentary


As a 15-year Army veteran I appreciate the thought behind this bill. Giving veterans assistance in their post service job search process is an admirable effort and should be encouraged. However, there are some serious problems with this rather simplistic bill.

First, providing someone a PTSC who has no chance of getting a TWIC is a sure recipe for creating a number of security issues at facilities where the possession of a TWIC is a prerequisite for unaccompanied access. There is a way to avoid most of these potential problems by requiring a covered veteran applicant to certify that their record contains none of the TWIC disqualifying offenses listed in §70105(c)(1). I would amend the bill by inserting a new paragraph (4):

(4) The Secretary will require applicants wishing to receive a PTSC to certify that they have none of the disqualifying actions described in (c)(1) in their record.

This will not eliminate all of the potential security issues, but it will significantly reduce them.

The remaining issues will have to be addressed by regulations and processes subsequently put in place by DHS. The immediate problem is whether or not the PTSC will include a biometric identification component or whether it would be just a visual inspection access control tool. If it does not include machine-readable biometric identification data then it will not provide access ‘in the same manner as transportation security cards issued under subsection (b)’. Providing for issuing a PTSC with machine-readable biometric data on demand at each TWIC application facility will be expensive.

This leads to the next problem overlooked by this bill. The Transportation Security Administration is currently required §70105(h) to charge each applicant for a TWIC a fee to cover the cost of processing the application. That should mean that veterans requesting a PTSC should be charged an additional fee for those credentials. Given the relatively small number of veterans that would be expected to apply for PTSC, this fee could be relatively high because of the additional equipment and training necessary to issue such documents. I think that this is counter to the intent of this bill, so I would further amend the bill by inserting a new paragraph (5):

(5) Notwithstanding the requirements of (h) in this section, the Secretary will not charge applicants any additional fees for the issuance of a PTSC.

Finally, there are no time requirements in the bill, either for initiation or termination of the program; or for feedback to Congress of the efficacy of the program. To address these issues, I would insert the following two paragraphs:

(6) The Secretary will begin issuing the PTSC described in (1) within one year of the passage of this bill. The PTSC program will terminate on the date five years from the passage of this bill.

(7) Within one year of start of issuance of PTSC, the Secretary will provide a report to Congress describing:

(A) The number of TWIC applicants who were issued a PTSC;

(B) The number of TWIC applicants who were provided a PTSC, but were subsequently denied a TWIC;

(C) The average length of time that individuals were required to rely on a PTSC for access under this section;

(D) The costs associated with the establishment and operation of the PTSC program and the fees that would have been required to be assed against applicants in the program for the first year to cover said costs;

(E) The fee which would be required going forward to be assessed for the issuance of a PTSC to cover costs of the continued operation of the program.

Saturday, October 12, 2019

Public ICS Disclosures – Week of 09-05-19


This week we have URGENT/11 updates from three ICS vendors; seven new vendor disclosures from Siemens, Schneider (4), Beckhoff (2) and Drager; six updates of previously issued advisories from Siemens (2), Schneider (3) and Yokogawa, and one exploit of a previously reported vulnerability for products from SMA Solar Technology.

URGENT/11 Updates



Siemens Advisory


Siemens published an advisory describing twelve vulnerabilities in the Siemens SIMATIC WinAC
RTX (F) 2010. These vulnerabilities are known as Spectre, Meltdown, Spectre-NG, Foreshadow, L1 Terminal Fault (L1TF), ZombieLoad, and Microarchitectural Data Sampling (MDS). These vulnerabilities were reported by various researchers. Siemens has an update that mitigates the vulnerabilities.

Schneider Advisories


Modicon Controllers Advisory #1

Schneider published an advisory describing a file and directory information disclosure vulnerability in the Schneider Modicon brand of programmable logic controllers. The vulnerability was reported by Jared Rittle (Cisco Talos); the report includes proof-of-concept (POC) code. Schneider provides generic workarounds to mitigate the vulnerability.

Modicon Controllers Advisory #2

Schneider published an advisory describing six vulnerabilities in the Schneider Modicon brand of programmable logic controllers. The vulnerabilities were reported by Jared Rittle and Patrick DeSantis (Cisco Talos) (the CVE links below are to the individual reports which contain POC code). Schneider provides generic workarounds to mitigate the vulnerability.

The six reported vulnerabilities are:

Uncaught exception (5) - CVE-2019-6841, CVE-2019-6842, CVE-2019-6843, CVE-2019-6844 and CVE-2019-6847; and
Clear-text transmission of sensitive information - CVE-2019-6846;

Modicon Controllers Advisory #3

Schneider published an advisory describing a clear-text transmission of sensitive information vulnerability in the Schneider Modicon brand of programmable logic controllers. The vulnerability was reported by Jared Rittle (Cisco Talos). Schneider provides generic workarounds to mitigate the vulnerability.

Modicon Controllers Advisory #4

Schneider published an advisory describing three vulnerabilities in the Schneider Modicon brand of programmable logic controllers. The vulnerabilities were reported by Jared Rittle (Cisco Talos) (the CVE links below are to the individual reports which contain POC code). Schneider provides generic workarounds to mitigate the vulnerability.

The three reported vulnerabilities are:

Uncaught exception vulnerability - CVE-2019-6848; and
Information exposure (2) - CVE-2019-6849 and CVE-2019-6850

Beckhoff Advisories


TwinCat Advisory

VDE-CERT published an advisory describing a divide by zero vulnerability in the Beckhoff TwinCAT real-time controller. The vulnerability was reported by Andreas Galauner from Rapid7. The Beckhoff advisory on this vulnerability reports that they are working on an update to mitigate the vulnerability.

CE Remote Display Advisory

Beckhoff published an advisory describing an incorrect login response vulnerability in the Beckhoff CE Remote Display. The vulnerability was reported by Chen Jie from NSFOCUS and Tijl Deneut from University Howest. Beckhoff has updates that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Drager Advisory


Drager has published an advisory describing three vulnerabilities in the Drager Infinity® M300 patient monitor. Drager is self-reporting the vulnerabilities. Drager will be releasing a new version to mitigate the vulnerabilities in March 2020.

The three reported vulnerabilities are:

Network DDOS attack;
Repeated DDOS attacks; and
Information exposure

Siemens Updates


Industrial Products Update

Siemens published an update for an advisory that was originally published in May of 2017 and most recently updated on February 14th, 2019. The new information includes:

• Merged WinAC RTX 2010 SP2 and WinAC RTX F 2010 SP2 to SIMATIC WinAC RTX (F) 2010; and
• Added mitigation information for SIMATIC WinAC RTX (F) 2010

NOTE: I expect NCCIC-ICS to update their advisory this week.

SIMATIC S7 Update

Siemens published an update for an advisory that was originally reported in November 2018 and most recently updated on August 13th, 2019. The new information includes:

• Added CVE-2019-1125, CVE-2019-15666 and CVE-2019-15903; and
• Removed CVE2018-19591 from the list of fixed vulnerabilities

NOTE: NCCIC-ICS has not addressed these Linux vulnerabilities.

Schneider Updates


Floating License Manager Update

Schneider published an update for an advisory that was originally published in May 2019 and most recently updated on September 10th, 2019. The new information is updated remediations for EcoStruxure Power
Monitoring Expert.

NOTE: NCCIC-ICS may update their advisory, but they did not update for the last Schneider update.

SoMachine Update

Schneider published an update for an advisory that was originally published on August 13th, 2019. The new information is adding SoMove FDT to the list of affected products.

NOTE: NCCIC-ICS did not address this vulnerability.

Embedded Web Server Update

Schneider published an update for an advisory that was originally published in November 2018 and most recently updated on June 11th, 2019. The new information includes mitigation information for the M340 controller.

 NOTE: NCCIC-ICS did not address these vulnerabilities.

Yokogawa Update


Yokogawa published an update for an advisory that was originally published on September 27th, 2019. The new information includes updated affected version data and mitigation measures for Exaquantum.

NOTE: NCCIC-ICS will probably update their advisory this week.

SMA Exploit


Borja Merino published an exploit for a cross-site forgery vulnerability in the SMA Sunny WebBox. An advisory for the vulnerability was published on October 8th, 2019.

Bills Introduced – 10-11-19


Yesterday with both the House and Senate meeting in proforma session there were 43 bills introduced. One of those bills may receive additional coverage in this blog:

HR 4634 To reauthorize the Terrorism Risk Insurance Act of 2002, and for other purposes. Rep. Waters, Maxine [D-CA-43]

 
/* Use this with templates/template-twocol.html */