Thursday, April 17, 2014

Two Views of Today's Cyber Risks

This week I've had the chance to view two reports that gave me -- and I expect others -- a powerful view of the cyber challenges we face.  One report was a global view our reliance on the Web and the "...increasing danger of global shocks initiated and amplified by the interconnected nature of the internet."

The second article was a survey done by Control Engineering magazine on the global views of cyber security of the industrial controls domain.  The survey revealed that almost 50% of the respondents perceive the control system threat in their organizations to be at a moderate level, but 25% cite a "high" or "severe" threat level in their systems.

So, rather than provide detailed reviews of each document, let me help aim you to the appropriate links with some summary notes added:

Risk Nexus - Beyond Data Breaches: Global Interconnections of Cyber Risk -- Zurich and Atlantic Council

(LINK) 
This well-written report (30 pages) consistently raises the bar of the global risk relative to our reliance on the Internet and ecommerce in a manner similar to the annual World Economic Forum's Risk Reports.  Perhaps we are so closely connected to the Internet that we put our selves in harm's way relative to our economic -- and maybe even mental well being (?).

One quote that I find especially telling is:

"The internet of tomorrow will both initiate and amplify global shocks in ways for which risk managers, corporate executives, board directors, and government officials may not be adequately prepared."

Finally, take a look at Page 8 of the report...they include 7 aggregations of cyber risk that certainly made me think:


  1. Internal IT enterprise (hardware, software, servers, and related people and processes)
  2. Counterparties and partners (relationship between competing/cooperating entities, etc.)
  3. Outsourced and contract (IT and cloud providers, contract manufacturing)
  4. Supply chain (Exposure to a single country, counterfeit or tampered products, risks of disrupted supply chain)
  5. Disruptive technologies (internet of things, smart grid, embedded medical devices, driverless cars...)
  6. Upstream infrastructure (submarine cables, internet governance and operation)
  7. External shocks (major international conflicts, malware pandemics)

At a minimum I'd suggest you pass this report to your Board of Directors and Executive Management so they get a sense of another view of risks that need to be addressed and mitigated.


Control Engineering Cyber Security Study - April 2014 (Registration Required)

(LINK)
Compliments to the Director of Research for Control Engineering, Ms. Amanda McLeman and her colleague Mark Hoske for this summary report.  The report is based on a survey of about 190 respondents from February 7 to March 2, 2014.  So the data is fairly contemporary.

This summary report is a collection of graphs showing the demographics of the respondents as well as the summary results of the questions.

A good summary graph of the Threats considered by the respondents is below:


If you cannot adequately read the graphic above the top three system components the respondents are most concerned about are:

  1. Computer assets that are running commercial operating systems
  2. Connections to other internal systems
  3. Network devices
Finally a summary of key "bullets" from the report include:
  • 24% of respondents said they had NEVER performed a systems security vulnerability test
  • 25% of those surveyed indicated their computer emergency response team appears well trained and capable
  • 41% agreed having industry-required standards without government involvement would improve or enable their efforts to implement proper control system cybersecurity.  (So, maybe the NIST Cyber Security Framework has some hope?)
Thanks for taking the time to read my comments and have a good week!

###








Thursday, April 3, 2014

A Month-Long View of Industrial Controls Security Training

For the past four weeks I have been immersed in Industrial Controls Systems (ICS ) security training.  My journey began on March 12th where I spent five days in the SANS ICS training in Orlando followed by about 15 hours of web-based ICS training from ICS-CERT then two days in Burbank, California attending the ISA training on the ANSI/ISA-62443 Standards.  (By the way, the 62443 standard used to be called the ISA99 standard.)

What I'd like to do is offer a view of these different training options to give you a sense of why some professionals will need this training and how the ICS-CERT training can be especially helpful for managers and supervisors overseeing work on ICS.  Also, I'll let you know about free training that does not require travel or substantial resources.

Why am I Taking These Classes?

Right now my employer -- Securicon -- is focusing on industrial control security and the SANS certification program -- GICSP - discussed later -- may be a key cert to have in the company for future work at some select global energy/oil/gas companies.  Secondly, one vendor we work with has asked us to complete the ISA training on the ISA-62443 standards.  Therefore, I'm the designated player for the company and have been sent to these courses - not that I'm complaining!  I love this stuff and I'm up for another security certification in this domain.

SANS ICS410 ICS/SCADA Security Essentials (~$4,395 + $599 for GICSP test)



This course is offered in a classroom (and now as an online option) by SANS.  I was privileged to be in a class in Orlando with about 57 other students from literally around the globe.  The instructor was Mr. Justin Searle who is by far one of the best IT security instructors I have ever experienced as either a student or co-instructor.

The course runs for five consecutive days with class beginning at 9 AM and ending at 5 PM with breaks and a lunch in between.  The days were broken down into the following:


  • Day 1 - Industrial Control Systems (ICS) Overview
  • Day 2 - ICS Attack Surface
  • Day 3 - Defending ICS Servers and Workstations
  • Day 4 - Defending ICS Networks and Devices
  • Day 5 - ICS Governance and Resources 
Each day some hands-on exercises were included.  

At the end of the training you receive a certificate of completion; however, the true goal for myself and many others is to pass the Global Industrial Controls Security Professional (GICSP) certification from SANS.



The GICSP certification involves a separate test which requires the student pass with a minimum passing score of 69%.  I hope to take this test before the end of April.

For more details on the GICSP and the class please go to these links:  GICSP, ICS410, SANS ICS Security.

ISA - Using the ANSI/ISA-62443 Standards to Secure Your Control System (~$1,510)



I just finished this course on April 2nd in Burbank, CA.  The class is a two-day event and this recent course was taught by Mr. John Cusimano -- again, another very good and knowledgeable instructor.  The class size was very conducive to open dialogue with the instructor and other students.

The focus of these two days was on the following key topics:

Day 1:
  • Introduction to Control Systems Security and ISA/IEC62443 Standards
  • Terminology, Concepts, Models and Metrics
  • Networking Basics (Do you know your OSI Model??)
  • Network Security Basics
Day 2:
  • Creating an ICS Security Management Program
  • Designing/Validating Secure Systems
  • Developing Secure Products and Systems
And like the SANS Course, some hands-on exercises were included using tools such as Wireshark and the command line (e.g., Netstat -a).

Upon completion of this test you are eligible to take a proctored test called the ISA99 Exam.  Passing this test will give you the ISA99 certificate from ISA that demonstrates your knowledge and capabilities with the ISA standards used to secure industrial control systems.

For more information you can go the ISA Cybersecurity site.

I hope to take this test before the end of April.

ICS-CERT Online Training -- Excellent Resource! (Free)



Finally, for my "spare time" between the SANS and ISA training I've been working on two courses offered at no charge by the US Department of Homeland Security ICS-CERT organization.

The two courses are both web-based and only require that you register with the Training Portal.

The first class I took was 100W - Operational Security (OPSEC) for Control Systems.  This is a one-hour on-line class that is focused on ways to protect your industrial control systems by being cautious about releasing network information outside the company or to those who don't have a need to know.  The course also addresses phishing attacks, etc.  You get a certificate "...suitable for framing..." at the end of the course.

The second course -- which I highly recommend to executives, managers, supervisors and engineers interested in learning more about ICS security -- was 210W - Cybersecurity for Industrial Control Systems.  This course was excellent and took about 15-20 hours to complete.  

There are 10 separate modules that are listed below:
  • Differences in Deployments of ICS
  • Influence of Common IT Components on ICS
  • Common ICS Components
  • Cybersecurity within IT and ICS Domains
  • Cybersecurity Risk
  • Current Trends (Threats)
  • Current Trends (Vulnerabilities)
  • Determining the Impacts of a Cybersecurity Incident
  • Attack Methodologies in IT and ICS
  • Mapping IT Defense-in-Depth Security Solutions for ICS (longest but best module!)
Again, this training does not require any money but only requires your time to take the modules (which you can stagger over time).

Conclusion

ICS security continues to get focus from the industry and government.  That is why SANS, ISA and ICS-CERT are continuing to bring in training modules for a broad range of players from journeymen electricians to utility executives.  Take advantage of the training -- at least the free classes -- so you better understand how to best defend your Industrial Control systems.

###





Wednesday, March 26, 2014

Today's Cybercrime - The Market is "Growing Up"

I've been a student of cybercrime since my full-time entry into cybersecurity in 2001.  When I had some time on my hands recovering from an accident I actually spent a month reading every document I could find on the Internet covering the subject.

Well, I wouldn't recommend that you spend a month recuperating in front of the Internet but you will find a report from RAND Corporation on today's cybercrime market fascinating and disturbing and will give you a sense of the maturity of the cybercrime market and its "workers and leaders."

http://www.rand.org/pubs/research_reports/RR610.html

The Rand report (picture above) is 83 pages of discussion about today's black market for such things as credit cards, passwords, identities, etc.  To quote the preface of the report...

This report describes the fundamental characteristics of these markets and how they have
grown into their current state in order to give insight into how their existence can harm the
information security environment. Understanding the current and predicted landscape for
these markets lays the groundwork for follow-on exploration of options that could minimize
the potentially harmful influence these markets impart. This report assumes the reader has a
basic understanding of the cyber, criminal, and economic domains, but includes a glossary to
supplement any gaps.

The final take-away to offer is another quotable quote from the report:

In certain respects, the black market can be more profitable than the
illegal drug trade; the links to end-users are more direct, and because worldwide distribution
is accomplished electronically, the requirements are negligible.

Action:  To my fellow security professionals, take a moment to give this to your boss and maybe the CEO and Board of Directors.  They need to see that the threat is real and the opportunities for the miscreants are increasing.  Hence, you need more resources - money, qualified staff, tools, techniques -- to do your job.

###



Thursday, March 6, 2014

New Policy Approaches to Address Cyber Threats Impacting the Electric Grid

In February the Bipartisan Policy Center released a report focused on cybersecurity and the North American Electric grid.  At first I was worried that this report would be another collection of the same ol' ideas of leaning on the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) standards as the panacea -- fortunately, this report is very good and really has some excellent ideas to help protect the electric grid from and during a cyber attack.


In a simple way I'd strongly suggest you skim this report if you are in any way/shape/form involved with electric grid cybersecurity defense, policy, funding or response.

The key areas of discussion in the report include:

  • The Existing Landscape for Electric Grid Cybersecurity Governance
  • Standards and Best Practices for Cybersecurity
  • Information Sharing
  • Responding to a Cyber Attack on the North American Electric Grid
  • Paying for Electric Grid Cybersecurity
The report is very refreshing and offers some new ideas on ways to defend the grid and respond to cyberattacks.  

One idea that has some merit is the concept of implementing an "Institute" similar to the Institute of Nuclear Power Operations (INPO) that would focus in continuous improvement of cybersecurity of the electric grid.  I sent the following email to one of the Advisory Board members supporting this idea.  In my email I observed:


The Institute of Nuclear Power Operations (INPO) was used as a model agency for oversight of the security of the grid.  I worked at INPO from 1986 to 1992 and when I left I was the Secretary of the Corporation and an evaluation Team Manager.  

Of note, the recently published Cybersecurity Framework (CSF) has an approach very similar to INPO's.  That is the CSF is "performance-based" rather than "compliance-based" which is an approach that INPO pursued.  INPO published a document entitled Performance Objectives and Criteria for Operating and Near-Term Operating Nuclear Plants that really focused on what would be viewed as optimal performance in particular areas (e.g., management, administration, operations, maintenance, etc.) with a collection of criteria that supported the performance objectives (similar to the CSF).  However, the process was not focused on compliance to the performance objectives but instead to how the plant truly performed.

An example to demonstrate this approach would be relative to CIP-008, incident response.  The NERC approach to reviewing CIP-008 is to actually sight the utility's incident response procedure; however, they do not check to see that it actually is a workable, accurate document (i.e., are the phone numbers/email addresses accurate, can it truly be used as written, is it practiced, etc.).  On the other hand the INPO approach would be to view the document but with emphasis on watching the utility perform the incident response process and observe strengths, weaknesses, etc. and highlight areas needing improvement.

In other words the assessment was based on the true performance of the utility; not a simple view of its paperwork -- a serious flaw with the NERC approach (in my opinion).

I am very pleased with the tone, content and ideas put forth in this report and I look forward to the "new" dialogue that surfaces in this domain different from the old, stale ideas that really don't solve the problem for the entire electric grid from generator to transmission line to distribution system to the toaster in your home.

Again, compliments to the authors and advisory group on this report!

###

Monday, March 3, 2014

Funding Terrorism via Poaching and Organized Crime

In early January 2014 Mr. Johan Bergenas of the Stimson Center prepared a report called Killing Animals, Buying Arms.  This brief 17-page report woke me up to the concerns of rhino and elephant poaching in East Africa and its eventual financial support for local and global terrorists.  It is a disconcerting state of affairs.


Some disturbing facts that are not well publicized include:

  • Wildlife has become the 4th largest illicitly traded product in the world.  It is a $19B USD industry.  Illegal wildlife trade is larger than illicit trafficking of small arms, diamonds, gold and oil.
  • Transnational criminals and terrorist organizations such as Al-Shabaab and the Lord's Resistance Army make hundreds of thousands of dollars every month by partaking directly or indirectly in the killing and sale of animal parts.  Part of their proceeds go towards buying guns and bombs, paying their members, and planning and executing terrorist attacks.
  • The Elephant Action League -- an independent organization fighting elephant exploitation and poaching -- asserts that Al-Shabaab exports poached ivory via southern Somalia ports.  The tusks are cut into blocks and hidden in crates of charcoal.  Their monthly income is reported to be $200,000 to $600,000 USD per month.  The ivory sells for $3,000 per 2.2 pounds (kilogram) in China.
  • A rhino horn is worth $50,000 USD per pound on the black market -- more than gold or platinum.  A rhino is killed by a poacher every 11 hours.
The United Nations Office on Drugs and Crime (UNODC) has published several studies on organized crime and its global and regional impact.  In its seminal report issued in 2010, the UNODC depicted the geographic challenges with ivory export as shown below:



In its 2013 regional report on organized crime in Eastern Africa (UNODC) the theme of money being made from ivory continued.  In the report they note "It is estimated that between 5,600 and 15,400 elephants are poached in Eastern Africa annually, producing between 56 and 154 metric tons of illicit ivory, of which two-thirds (37 tons) is destined for Asia, worth around US$30 million in 2011."  But the area is also a concentration of illegal -- and profitable -- activities such as human trafficking, heroin transportation, and piracy -- besides ivory and rhino horn poaching.

At a US Senate hearing in May 2012, Mr. Tom Cardamone of Global Financial Integrity observed in his  written testimony that ever since the terrorist attacks of 9/11 and actions taken by Congress/Administration to target terrorist financing has nearly eliminated shell banks and decapitated Al Qaeda's central command.  As such the terrorists are cash-starved and looking for new sources of funding.  Hence, illicit trafficking of wildlife is one way the Al Qaeda affiliates have chosen to raise money.  As an example, two Bangladesh-based Islamic terrorist groups affiliated with Al Qaeda are raising funds for their operations via illegal poaching of ivory, tiger pelts and Rhino horns in the jungles of northeastern India.  And, during its years of war with Northern Sudan, the Sudan People’s Liberation Army  is alleged to have poached “...elephants with grenades and rocket‐propelled guns.”


And...when it comes to Al-Shabaab, the same 2013 report notes,  "Members of Al-Shabaab have been linked to ivory poaching in Kenya and to a Tanzanian Islamist group reportedly linked to heroin trafficking. They have also allegedly taxed pirates working from the ports they control..."


Conclusion
The Elephant Action League says it best, "If you buy ivory, you kill people."  But as noted in all three of the reports cited above, each one says that the task at hand is difficult and requires money and resources to even slow the poaching and subsequently the flow of money to the terrorists.  Border security needs to be stronger, needs to be enforced and the markets for the ivory and illicit items need to be closed.  Also, oversight of cash transfers need to be tightly regulated in the more "suspicious" parts of the world.

Sadly, this sounds daunting and challenging.  I hope this blog raises awareness and guides some action.

###










Monday, February 24, 2014

Useful Industrial Control Security References from ENISA

ENISA - the European Union Agency for Network and Information Security has been quietly building a collection of useful references for industrial control system (ICS) security.  Since 2011 with their publication of Protecting Industrial Control Systems.Recommendations for Europe and Member States, Dr. Konstantinos Moulianos and his staff have done a nice job facilitating development of useful publications for those of us in this domain.



What I'd like to do is to continue to tell you of the other ICS-security-related products that have been published that may be useful references for students and practitioners of ICS security.

In 2011 as ENISA was publishing the referenced document above (and shown in the photo) they also produced five separate Annexes as part of the Recommendations document.  These documents were certainly foundational to the continued expansion of the ENISA ICS Security "product line."  One document I found to be a useful introductory discussion of ICS security was the ENISA document Protecting Industrial Control Systems, Annex I: Desktop Research Results.  Similar to NIST 800-82, Guide to Industrial Control System (ICS) Security, this document is a helpful background "textbook" on the basic issues associated with ICS security, emerging issues, the challenges with securing ICS systems, and known good practices as of 2011.

Later in 2013, ENISA was very busy publishing several useful documents to aid in improving cybersecurity in Europe but of course helping the rest of the world with its guidance and studies.  In particular ENISA facilitated and funded a study on identifying ways to improve on ICS component and system testing in the EU. (I was honored to have been included in the interview process for this study.)  The result was the ENISA document Good Practices for an EU ICS Testing Coordination Capability.  This document certainly raised some awareness on how to proceed in Europe with development of an ICS testing capability but it can also be used in other nations just beginning to  examine their ICS security reviews.

One very useful desk reference that came out of the EU ICS Testing Coordination project was publication of ICS Security Related Working Groups, Standardsand Initiatives (2013).  This particular document is an excellent collection of the various global standards, guidelines and studies conducted that focus on ICS security issues.  This one is a "keeper!"



Finally, in late 2013 the ENISA team was very busy with some white papers and briefings on ICS security issues we are all facing.  The documents and their links are listed below:
I trust you found this an enlightening review of the ENISA ICS Security work since 2011 and I'd suggest you keep them on your mind when looking for ICS security resources and references to help improve and harden your security programs.



Friday, February 14, 2014

Focus on Information Sharing for Cybersecurity

At the end of 2013 I was invited by the NATO Energy Security Centre of Excellence to submit an article regarding the barriers to information sharing and their impact on critical energy infrastructure protection.



The actual e-zine was posted today and contains seven well-written articles by some global thought-leaders relative to information sharing, cooperation and security of the energy supply.  The e-zine can be downloaded at: this LINK.  A picture of the Table of Contents is shown below.



This is probably one of the first publications exclusively focused on the subject of information sharing for critical infrastructure protection. I'm very honored to have been invited to participate.  Of note, the conversations in this publication will be especially germane to the dialogue raised by the new release of the NIST Cybersecurity Framework this week -- especially since one of President Obama's objectives in his Executive Order was to improve and increase two-way information exchange to better protect critical assets.

Thanks for reading!

###