Hiển thị các bài đăng có nhãn physical security. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn physical security. Hiển thị tất cả bài đăng

Energy Security Postscript and Next Chapter

Long-time readers of the SGSB might have wondered if they'd ever see another post. Me too. After producing an average of 1+ posts per week since its inception 5 years ago, I cut way back after leaving IBM in 2013 to give myself more time to focus on consulting. And now there's a new development to report.

4 month ago I shuttered my security strategy business and began my first day on the job at Idaho National Laboratory (INL). It's one of the Department of Energy's national labs, and it's the one most squarely positioned at the intersection of energy infrastructure and national security. Let's call that energy security.

My INL title: Senior Cyber & Energy Security Strategist - may sound a little pretentious, but it pretty accurately captures what I was hired to do. If you visit the lab's home page or the INL Twitter feed it seems like nuclear energy research and related nuclear work are its dominant activities. But while nuclear energy research and fuels fabrication were its origin in the 1940's and its historic mission, with the help of its massive and remote test range that includes grid-scale transmission, distribution and communications assets, the lab I just joined does a ton of research and applied work on power and industrial control systems, Smart Grid and wireless communications, cyber and physical security and resilience, renewables, microgrids, energy storage and more.

Nuclear energy R&D, and full nuclear fuel lifecycle work (including non proliferation) will always be a significant part of that nation's requirements, and the INL mission, but nuclear energy is arguably the most reliable portion of our non fossil fuel baseload, but INL is quietly becoming something much more - and more important - than its nuclear legacy might suggest.

Without going into too much detail, the lab's customers now include not just DOE's nuclear energy organizations, but also DOE's renewables, resilience and cyber-physical security components too. DHS has become a major customer, as the lab hosts the ICS-CERT cyber security overwatch function for the US grid and other critical infrastructures, and performs other leading edge cyber and physical security roles as well. DoD is a very large customer too, for energy, security and communications test functions, rounded out by direct work with utilities and energy and telecom technology suppliers.

In short, INL in 2014 is not the lab many people think it is. While it's yet to update its image online, a visit to Idaho Falls quickly confirms that this is one of the nation's preeminent Energy Security lab resources. Nuclear energy is and likely always will be a key element, but without making much noise about it, INL has become so much more, and I'm very very lucky to be a part of it.

------------------------------

Postscript to the Postscript post: Though my blogs are in suspended animation, I continue to speak in public, and albeit more frequently and tersely, on Twitter @andybochman. As the Twitter profile reveals, I continue to work out of my home office in Boston while hitting the road most often for DC, and of course, now, Idaho.


A Social Summary of SANS ICS Security Summit 2014

Since I went solo there's been less time for blogging but I hope to catch up a little with this mega post on the just-concluded, 9th annual SANS ICS Security Summit which took place in the Contemporary Hotel at Disney.

Where I can I'll include Twitter IDs, as for many of us, Twitter is how we stay abreast of what we find interesting and what we're thinking about in between real world meet-ups. (Note: I only include these when they're unique to the individual and not shared by a company or org.)

I won't cover all the talks because I didn't attend all of them, and I apologize to those presenters I don't cover here. Nor was I at "Game Night" (though I wish I was) which from what I heard later was a fantastic and grueling hack-fest that extended into the wee hours before champions finally emerged.


For those of us lucky to be at the hotel Sunday night, and to know what was going on, a four-act play called "Exposure to Closure" or "The Heist" penned by Ben Miller @electricfork was really something. With MC Tim Roxey @ScubaNuke providing intro's, transitions, and running commentary, all injected with equal parts wisdom and levity, and a cast of characters from the really-not-ready-for-prime time-SANSICS players, for me it was the highlight of the trip, even before the conference officially started.

The audience got to see, in four acts and sixteen scenes, the full sequence of an attack on a utility control center, the confusion, analysis and corporate squirming that ensues, and how it resolves relatively peacefully (in this case) in the end. Mark Fabro stole the show with a swift and spooky transformation from dweebish uber-geek to a credible threat to another actor's physical security.

Chris Sistrunk @chrissistrunk and Adam Crain @automatak kicked things off smartly as twin fuzzing brothers from different mothers providing an overview of the many flavors of fuzzing, and the DNP3 protocol and how it's being made more secure (less insecure).  At one point, Chris noted that with much of the initial badness having been attended to, "We're starting to look at the back yard and are finding it a bit overgrown. Some things are turning up there - like cars." They make a great instructor duo.

Then we had an analyst panel, moderated by John Pescatore @john_pescatore and including Bob Lockhart, Sid Snitkin and myself.  It seemed to go pretty well.

Eric Byres @tofinosecurity followed by thoroughly excoriating the concept of patching ICS systems and transitioned to a tour-de-force explanation of deep packet inspection (DPI) that, like a good Bugs Bunny cartoon, communicated on many levels.  Meaning: I think I understood most of it, but the more experienced folks around me seemed to get insights from it as well.

The presentation by Marc Ayala @ICS_SCADA and Eric Forner demonstrated an attack on a mini water pump which turned the stage momentarily into Sea World, serving as a warm-up act for Kyle Wilhoit's @lowcalspam real-world honey pot presentation the next day documenting how global bad guys pursued what they believed to be the control system of a far more substantial pump, constructed by Kyle, at a municipal water tower. We all learned a lot from these two presos.

Nadya Bartol @NadyaBartol presented on ICS supply chain security issues and by the time she was done, the scope and complexity of supply chain challenges to ICS became all-too-clear.  Ernie Hayden, sitting next to me, tried to lighten my mood by informing me that there are 127 BIOS vendors alone.

I missed the presentation on the new Global Industrial Cyber Security Professional (GISCP) certification, but in case you did too, I've put a link to it HERE.

The first presentation I made it to on day 2 was "Cybersecuring DoD Industrial Control Systems", during which Michael Chipley provided more content, pound for pound, than all of Monday's presenters combined. Each of his many slides was a universe in and of itself, and there were a multiverse of them. But that's the DoD we know and love, and Michael did a great job of plotting its progress, in which he plays no small part, from DITSCAP to DIACAP to the NIST CSF structure in which they're inserting, among other other things, the most up-to-date guidance on control system security.  As masterful conference MC & Chairman Michael Assante said afterwards, "leave it to DoD to build a model where elevators and anti-ballistic missile systems are in the same category."

I had a good lobby talk after that preso with Michael and Chris Blask @chrisblask. We were keying on how the I in ICS serves to exclude a big chunk of the systems and devices we all care about, and mused on whether the term would eventually transition to something more all-encompassing like Cyber Physical Systems (CPS), Internet of Things (IoT, though that's not quite right) or simply, control systems.

Then we had another panel session, this one on the framework of the moment, the NIST Cybersecurity Framework and its relationship to DOE's Risk Management Process guide and C2M2 family. The group included Ed Goff, Jason Christopher @jdchristopher and substituting for the snowed-in Samara Moore, Nadya Bartol. These three did a great job and now we all understand perfectly how these guidance documents fit together. Moderator Michael Assante pointed out, more than once, that Nadya's cogent and succinct statements qualified her for service in the Executive branch of government.

Air Force Lieutenant and famous writer Robert M. Lee @RobertMLee, author of the I-call-'em-like-I-see-'em 2013 article "The Failing of Air Force Cyber," and its companion piece SCADA and Me: a Book for Children and Managers, basically stole the show at this point. Not an expert, but rather a "lifelong learner," Rob reviewed the book's simple messages, and highlighted some of the more disturbing reactions to it, including:
  • A Pentagon General who told him "I keep your book on my desk and share it with management." Which led Rob to suggest to the SANS audience: "At some point in your career you must admit that YOU ARE MANAGEMENT." 
  • He also shared a one-star Amazon review along the lines of "I've been a nuclear engineer for 10 years and I got nothing out of this book."

Towards the end,  Rob said the book has been translated into multiple languages and then flashed the cover of SCADA y Yo: Un Libro Para Niños Y Directores. I'm not sure why that was so funny, but it sure was.

I mentioned Kyle's talk earlier, so that brings us to the penultimate preso, Stacy Cannady's overview of how OEM's can improve the integrity of their products despite the many threats they face, and vulnerabilities they can't help but include. It was very well done.

Of my own preso on Security Governance at utilities, all I can say is I wish it went more smoothly.  I should have known better, following a presentation on trusting and not trusting devices, that the slide-advancing pointer in my hand might turn against me.  I've got a solution though: I'm going to cut my slide count from 30 to 1, and who knows, maybe 1 is 1 too many these days.

I highly recommend you block off your calendar for the 10th annual version of this event next year. It's going to be on 1 April or thereabouts if I heard Mike right. This one was more educational and more fun than any conference I've been at in recent memory.

Andy @andybochman




Please Remain Calm: My Metcalf Substation Physical Security Take-Aways

Valentines Day update - Two more good links have surfaced for you since I wrote the original post a few days ago:
PBS Interview with Jon Wellinghof and Mark Weatherford 
A 3rd WSJ article, this one largely a counterpoint to the more FUD-oriented first one
----

It's been nearly 10 days now since the Wall Street Journal published its big story on the attack on a transmission substation outside Silicon Valley in California.  Since then, the media, keying on words like "assault, military-style, terrorism" have had a pre-apocalyptic field day.

So in my own way, I've been running a counter-alarmism campaign when speaking with the press as well as with infrastructure security experts about to go live on one of the hysterical "news shows."

My main points are:

  • This attack was significant but it didn't cause a blackout
  • So be concerned, but don't overreact
  • You can thank the hard work and preparation by Pacific Gas & Electric (PG&E) for at least 2 things: 1) rerouting energy flows so there was no perceptible customer impact despite the loss of many transformers, and, 2) getting the substation fully back on line within one month
  • This was a great opportunity for utilities to refresh their physical security policies, and that's what they're doing right now
  • Utilities are already taking concrete steps to deter this type of attack, including: erecting screens or walls to block a would-be shooter's view of his/her intended targets, inviting citizens living near substations to call their utilities if they see something suspicious, in the spirit of the "if you see something, say something" transit security campaign, and looking at the transformer stockpiling and loaner program 
My more-than-slightly-frustrated-with-certain-people point is:

Physical security will now be top of mind for grid security experts for a while. But since some minds are smaller than others I've heard certain experts say maybe we worry about grid cyber security too much. Brilliant, a physical attack means we should slow down on cyber security. Why didn't I think of that? I'm sure that's how cyber attack types think. Seeing the near-success of the Metcalf attack, they're probably trading in their laptops for bricks and bullets right now.

You may or may not have access to the WSJ articles below, but in case you do, here are 3 links that help tell the story, including a first one from shortly after the attack, before the hyperbole started flowing:
As always, please keep calm and carry on. There's a lot of important work to do.

SANS gets Cyber-Physical with ICS Breach Response Guide


With apologies to Olivia Newton John, you may or may not be aware that some bad actors have been helping raise awareness about physical threats to electric infrastructure lately.  You might say, "Are we sure about this, or were they merely after some copper ... or groundnuts?"

Of course, it always pays to be skeptical, but in the age of video cameras, motion detectors and similar, it's clear that these were humans not after enrichment or nourishment, but rather, intent on destruction.

Mike Assante and Scott Swartz of security training firm SANS just released a how-to manual describing how you can help your utility proceed in the event of an attack.  In particular, they want utilities to be on the lookout for cyber security foul play as they investigate breaches of physical defenses.


Here's the intro for you:
The plans and success of any malicious cyber actor depend heavily on their target’s daily routine and complacency, and human nature’s tendency to not look beyond the obvious. This paper addresses the problem of blended intrusions by suggesting a cybersecurity response to facility break-ins that critical asset security managers can use to determine whether cyber assets might have been targeted during the physical breach. The response includes a systematic and graduated series of actions or checks for evaluating the integrity of cyberbased equipment once you have discovered evidence of a physical breach. Again, these are only suggestions, and any actions should be carefully considered in light of operational reliability, procedures and particular safety policies of the owners and operators.
So there's some human psychology involved in this too. You can (and should) click HERE to read the full paper.

Grid Attack Simulation Just Completed: “It was More Severe than Anything We’ve Drilled"


So said the President and COO of AEP subsidiary Southwestern Electric Power Company, of scenario she and her people faced during NERC's second GridEx exercise.

Sounds like NERC CEO Gerry Cauley and his team brewed up something pretty potent this time.  Heck, it even included 7 deaths and 150 casualties ... in quotes of course.

NERC will issue an "after action" report including objectives, what actually happened, lessons learned and recommendations as soon as they get some sleep.  In the meantime, this account from the NY Times Matthew Wald is pretty darn good.  You can check it out HERE.

Photo credit: The Guardian