Monday, December 23, 2019

Cyber Hunt Team Provisions in HR 1865


When the Senate passed (by a vote of 71 to 23) HR 1865, the second half of the two-part FY 2020 spending bill, last week and the President signed the bill into law, Title L (pg 556), the DHS Cyber Hunt and Incident Response Teams, was included in that bill. The provisions were the same language that had been adopted by the Senate in their consideration of the original version of HR 1158, a bill of the same name as Title L.

Title L authorizes the current US-CERT and ICSCERT action teams and provides for the use of private sector contractors on those teams. No additional funding was authorized in the Title L and no specific funding (too small to be listed) was provided in the general increase in the  Cybersecurity and Infrastructure Security Agency (CISA) funding provisions in Division F of HR 1158, the first half of the two-part FY 2020 spending bill.

OMB Approves Remote UAS ID NPRM


On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the notice of proposed rulemaking (NPRM) from the DOT’s Federal Aviation Administration (FAA) for remote identification of unmanned aircraft systems. This NPRM was submitted to OIRA back in September.

The abstract in the Fall 2019 Unified Agenda listing for this rulemaking notes that this regulation would only affect “certain unmanned aircraft systems” without identifying which systems. I suspect that it would be larger commercial UAS.

Sunday, December 22, 2019

HR 5394 Introduced – Cybersecurity Coordination


Earlier this month Rep Taylor (R,TX) introduced HR 5394, the Strengthening State and Local Cybersecurity Defenses Act. The bill would amend 6 USC 659; adding a number of coordination, education and assistance responsibilities to the Cybersecurity and Infrastructure Security Agency (CISA) charter to provide cybersecurity support to a wide variety of public and private entities in the country.

Definitions


The bill would add a new definition to 6 USC 651; ‘entity’. This term would be very broadly defined as including {new §651(4)}:

• An association, corporation, whether for-profit or nonprofit, partnership, proprietorship, organization, institution, establishment, or individual, whether domestic or foreign;
• A government agency or other governmental entity, whether domestic or foreign, including State, local, Tribal, and territorial government entities; and
• The general public.

New CISA Coordination Responsibilities


The bill would add a new paragraph (n) to 6 USC 659, entitled ‘Coordination’. That paragraph would require CISA to coordinate (to the extent practicable) with Federal and non-Federal entities (specifically including the Multi-State Information Sharing and Analysis Center) to:

• Conduct exercises with Federal and non-Federal entities;
• Provide operational and technical cybersecurity training related to cyber threat indicators, defensive measures, cybersecurity risks, and incidents to entities to address cybersecurity risks or incidents, with or without reimbursement;
• Assist entities, upon request, in sharing cyber threat indicators, defensive measures, cybersecurity risks, and incidents from and to the Federal Government as well as among entities, in order to increase situational awareness and help prevent incidents;
• Provide entities timely notifications containing specific incident and malware information that may affect such entities or individuals with respect to whom such entities have a relationship;
• Provide and periodically update via a web portal and other means tools, products, resources, policies, guidelines, controls, procedures, and other cybersecurity standards and best practices and procedures related to information security;
• Work with senior Federal and non-Federal officials, including State and local Chief Information Officers, senior election officials, and through national associations, to coordinate a nationwide effort to ensure effective implementation of tools, products, resources, policies, guidelines, controls, procedures, and other cybersecurity standards and best practices and procedures related to information security to secure and ensure the resiliency of Federal and non-Federal information systems, including election systems;
• Provide, upon request, operational and technical assistance to entities to implement tools, products, resources, policies, guidelines, controls, procedures, and other cybersecurity standards and best practices and procedures related to information security, including by, as appropriate, deploying and sustaining cybersecurity technologies, such as an intrusion detection capability, to assist such entities in detecting cybersecurity risks and incidents;
• Assist entities in developing policies and procedures for coordinating vulnerability disclosures, to the extent practicable, consistent with international and national standards in the information technology industry;
• Ensure that entities, as appropriate, are made aware of the tools, products, resources, policies, guidelines, controls, procedures, and other cybersecurity standards and best practices and procedures related to information security developed by the Department and other appropriate Federal entities for ensuring the security and resiliency of civilian information systems; and
• Promote cybersecurity education and awareness through engagements with Federal and non-Federal entities.

Moving Forward


Taylor and four of his cosponsors {Ranking Member Rogers (R,AL), Green (D,TX), Guest (R,MS) and Slotkin (D,MI)} are members of the House Homeland Security Committee to which this bill was assigned for consideration. This bill will almost certainly be considered in Committee early next year. There is nothing in the language of the bill that would engender any significant opposition to the bill.

When the bill is considered (and it is likely to reach the floor) it will receive significant bipartisan support. When it is considered on the floor of the House it will be considered under the suspension of the rules process; limited debate, no floor amendments and will require a super-majority to pass.

Commentary


This is another one of the cybersecurity bills being considered this session that are purely motherhood and apple pie attempts by Congress to make it look like they are doing something about cybersecurity. There is nothing in the bill that CISA is not already doing or DHS has not been doing for quite some time before before the investiture of CISA.

If Taylor really wants this bill to accomplish something, he could straighten out the definitions in §659 that officially (though not actually in practice) limits CISA from looking at control system security, by excluding all but pure information technology systems from their purview. Again, I would refer Taylor, and the Committee Staff, to my blog post from February where I discuss the cybersecurity definition problem in detail and provide legislative language to correct those problems.

LNG by Rail NPRM Comments – 12-22-19


With one week to go to the original cut off of the comment period on the Liquified Natural Gas (LNG) by Rail notice of proposed rulemaking, the comments that the DOT’s Pipeline and Hazardous Material Safety Administration will have to pay attention to in formulating their final rule have started to come in in larger numbers. I addressed the ones that came in the previous week here. This week’s batch includes comments from:

Association of American Railroads (AAR) and The American Short Line and Regional Railroad Association (ASLRRA);

Lack of Safety Information


A continuing thread seen in comments is the lack of safety information about the proposed shipments of LNG with many commenters quoting the NPRM’s comment that: “It is difficult to estimate the failure rate of the DOT-113 tank car in derailments because railroads are not required to report incidents to PHMSA or FRA unless they meet a baseline threshold.”

Fire Hazards


The NASFM comment notes that there is still a fire hazard from an intact LNG railcar involved in a multicar derailment; stating that: “This is due to several factors, including the time the product would be in the tanks while cleanup is conducted, as they would off-gas from those tanks during cleanup, creating significant hazards.” (pg 2)

The ZFRD comment makes the following comparisons between an LNG release and a liquified propane gas (LPG) release:

• The flammable range for LNG is 35% greater than LPG;
• A gallon of LNG converts to 625 gallons of vapor, for LPG the number is 270 gallons; and
• The LNG ignition temperature is 999˚F, the LPG temperature was not given, but is 410 to 580˚F.

Asphyxiant Hazard


The NASFM comment raises the issue of LNG being an asphyxiant hazard as noted in the NPRM. They note that while the AAR OT-55 quoted in the NPRM makes a training containing a single toxic-inhalation hazard railcar a ‘key train’ that does not apply to asphyxiant hazard containing railcars.

Sloshing


The EJTF comment notes that since the filling density of LNG will be limited by the proposed rule to 32.5%, there will be significant free headspace (they calculate 9.192 gallons) in ‘filled’ railcars which will lead to sloshing of the liquid while the railcars are in motion. They propose that this sloshing in multiple railcars in a consist could contribute to derailments.

DOT 113C120 Railcars


The railroad comment notes that there is a task force (including PHMSA) ‘evaluating the DOT-113 specification for LNG’. Their report should be available next summer. A separate study that has already been completed by AAR recommends the following changes to the current 113C120 tank car standards to improve crash worthiness:

• Increasing the outer tank thickness from 7/16” (the thickness of a standard DOT-113C120 tank car) to 9/16”;
• Increasing the head from 1/2” to 9/16”;
• Increasing the gross rail load to 286,000-pound; and
• Additional hardening of the protective housing for valves and fittings.

The comment from Chart Industries corrects a statement about the LNG railcar in the NPRM. They note that:

“Mylar is a plastic material that is not compatible with the potential flammable gas being in the annular space. The common wrapped insulation used in such tanks is often referred to as Multi-Layer Insulation (MLI), Super Insulation (SI) or Multi Layer Super Insulation.”

Emergency Response Training


The ZFRD comment notes that:

“Fire departments are not well trained or equipped to control, extinguish or mitigate a fire involving one or more LNG tank cars. It is not realistic to think that existing fire department resources, including response of mutual aid fire departments, can intervene and mitigate a fire caused by LNG tank cars in a timely manner.”

The comment above was supported by similar comments from IAFF and IRC.

Saturday, December 21, 2019

Public ICS Disclosures – Week of 12-14-19


This week we have five vendor disclosures for products from WAGO, ABB, 3S, BD and Symantech. There is also an updated advisory from 3S.

WAGO Advisory


CERT-VDE published an advisory describing 9 vulnerabilities in the WAGO Series PFC100 and Series PFC200 devices. The vulnerabilities were reported (CVE links to individual reports) by Kelly Leuschner of Cisco Talos. WAGO has a specific workaround and firmware updates to mitigate the vulnerabilities. There is no indication that Leuschner has been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

• Information exposure through sent data - CVE-2019-5073;
• Buffer access with incorrect length value (2) - CVE-2019-5074 and CVE-2019-5075;
• Missing authentication for critical function (3) - CVE-2019-5077, CVE-2019-5078 and CVE-2019-5080; and
Classic buffer overflow (3) - CVE-2019-5079, CVE-2019-5081 and CVE-2019-5082

NOTE1: The following Talos reports include exploit code: CVE-2019-5073; CVE-2019-5074; CVE-2019-5075; CVE-2019-5079; CVE-2019-5081; CVE-2019-5082

NOTE2: Talos reports that some of these vulnerabilities are in third-party components from 3S.

ABB Advisory


ABB published an advisory that describes four vulnerabilities in their PB610 Panel Builder 600. The vulnerabilities were reported by NSFOCUS. ABB has a new version that mitigates the vulnerabilities. There is no indication that NSFOCUS was provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• PB610 HMIStudio crashes after launching an empty *.JPR application file;
• PB610 HMISimulator does not check content-length of the HTTP request;
• PB610 HMIStudio accepts malicious DLL file in an application; and
• PB610 HMISimulator provides interface with access to arbitrary files

3S Advisory


3S published an advisory [.PDF download link] describing a null pointer dereference vulnerability in their CODESYS V2 runtime systems. The vulnerability was reported by Chen Jie from NSFOCUS. 3S has new versions that mitigate the vulnerability. There is no indication that Chen has been provided an opportunity to verify the efficacy of the fix.

3S Update


3S published an update [.PDF download link] of an advisory that was originally published on November 20th, 2019. The new data includes updated exploit information.

BD Advisory


BD has published an advisory describing the impact of the Internet Explorer® Scripting Engine Memory Corruption Vulnerability in their products. The vulnerability is self-reported. BD is working to test and validate the Microsoft patch for BD products that use the affected third-party components.

Symantec Advisory


Symantec has published an advisory describing an improper authentication vulnerability in their Industrial Control System Protection product. The vulnerability was reported by Tyler Holland at Horne Cyber Solutions. Symantec has an update that mitigates the vulnerability. There is no indication that Holland has been provided an opportunity to verify the efficacy of the fix.

PHMSA Extends Comment Period on LNG by Rail NPRM


The DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) published a notice in Monday’s (available online today) Federal Register (84 FR 70491-70492) announcing that they were extending the deadline for comments on their Liquified Natural Gas by Rail NPRM. The additional time was added because PHMSA published their LNG by Rail Special Permit and included the operational controls specified in that document as potential controls in the NPRM. The new closing date for comments is January 13th, 2020.

Friday, December 20, 2019

Bills Introduced – 12-19-19


As the House and Senate were preparing to leave Washington yesterday for their end-of-year, end-of-session break there were 96 bills introduced. One of those bills may see future coverage in this blog:

HR 5527 To require the Secretary of Energy to establish a program to provide financial assistance for projects relating to the modernization of the electric grid, and for other purposes. Rep. Sarbanes, John P. [D-MD-3]

I will be watching this bill for language or definitions that specifically includes, or perhaps requires, coverage of cybersecurity technology as part of ‘modernization of the electric grid’.

 
/* Use this with templates/template-twocol.html */