January 2010 Archives

webcast1.jpgThe SF Bay InfraGard Chapter has organized an InfraGard Members Only National Web Cast with speakers from McAfee discussing Operation Aurora and Adobe discussing Adobe's comprehensive security program and Adobe's road map of security and management capabilities for the widely deployed Adobe Reader and Adobe Flash Player products.

This one hour event will occur on Tuesday / Feb 2nd /10AM / PST.

If you are an InfraGard member and have not received notice of how to sign-up for this web cast contact: admin@sfbay-infragard.org

The Financial Services Information Sharing and Analysis Center (FS-ISAC) has invited financial institutions, retailers, card processors, and businesses of all sizes to participate in its Cyber Attack against Payment Processes (CAPP) Exercise, Feb 9-11, 2010.

MORE INFO

Cyber Attack against Payment Processes (CAPP) Exercise

FS-ISAC

Tech-Security Conference 2010

The San Jose Tech-Security Conference features vendor exhibits and several industry experts discussing current tech-security issues such as email security, VoIP, LAN security, wireless security, USB drives security & more.

MORE INFO ...

SD Forum Security SIG

SDForum_logo.gif
Topic: Strategic Considerations in Incident Response
6:30 pm - 9:00 pm / February 1, 2010
Hosted by Symantec, Mountain View, CA


MORE INFO...



Editorial in Homeland Security Today / Jan 21, 2010

During a crisis, information rarely flows effectively within or between organizations without fully developed plans and regular practice exercising procedures.

A coordinated homeland security effort requires more than just having "fusion centers" with information sharing and communication technology. Radios, email, phones, or "Information Sharing Environment" web portals alone will not ensure that information reaches the right people at the right time.

READ MORE...
FBI Director Robert Mueller recently told the Senate Judiciary Committee that law enforcement agencies have disrupted several plots in the past year as terrorists "remain determined to strike the United States."

The head of the FBI said the threat of a terrorist attack against the U.S. is becoming more worrisome "with each passing day."  READ MORE

Securing America's Safety: Improving the Effectiveness of Anti-Terrorism Tools and Inter-Agency Communication  Testimony by Robert S. Mueller, III, Director, FBI, Before the Senate Committee on the Judiciary, January 20, 2010
A partial transcript of the PCI Security Debate that appeared on CSO Senior Editor Bill Brenner's Security Insights podcast and Martin McKeay's Network Security podcast has been published.  MORE INFO...

One of the participants in this dialog was Michael Dahn, a member of the SF Bay InfraGard chapter.

If you want to hear the debate in full, you can listen to The Great PCI Security Debate of 2010: Part 1, and Part 2 at CSOonline
It appears that the DOJ / FBI are beginning the process to begin a survey of InfraGard members to assess and develop a Knowledge/Skills/Abilities database.

There has been a draft Membership Profile Questionnaire on the secure InfraGard.org web site for some time.

Read the DOJ/FBI notice in the Federal Register ...
A public-private group the Energy Department is forming to better secure the nation's electric grid from cyberattacks must be given strong regulatory and budgetary authority to drive sweeping changes to computer networks.  READ MORE
A Member's Opinion...

President Obama laid the blame on the recent Detroit bomber (Umar Farouk Abdulmutallab) fiasco on a "mix of human and systematic failures". His withering assessment indicated the extent of the failure is deep and widespread.  The same sort of failures in sharing information were cited in the aftermath of the 9/11 attacks. Prior to 9/11, intelligence agencies were unable to connect the dots between disparate clues that alone didn't seem to add up to much. But when taken together - if only in hindsight - it was clear they had the makings of a huge and sophisticated terrorist plot.  

Compare what happened with 9/11 and the Detroit incident to the lack of "connecting the dots" in Industrial Control System (ICS) cyber security. According to my ICS incident database there have been more than 170 control system cyber incidents - many of these of common origins and continuing to recur. There are many government, industry, and commercial organizations providing guidance for traditional IT threats - put in firewalls, isolate networks, etc. However, there is no guidance on what to do or even what to look for to prevent ICS-unique cyber incidents.  And, it is ICS-unique cyber incidents that have caused some of the most significant cyber events to date including those that have killed people, and caused major outages and equipment impacts.   ICS security is difficult to detect and prevent because:
- There is still limited use of ICS-unique policies and procedures to prevent incidents,
- The work force still is not trained to detect ICS-unique cyber incidents (this is not what IDS/IPS monitor)
- ICS cyber forensics are still lacking in even some of the newest systems, and
- Industry is still in denial about ICS security.
 

The Bellingham, WA pipeline rupture that killed three people and the Maroochy sewage spill incidents are the two most comprehensively documented ICS-cyber cases. There were a number of "red flags" that were missed (the Bellingham report prepared by MITRE is on the NIST website and we presented it at RSA in 2008). Many of the non-publicly identified ICS cyber incidents also had red flags that were missed. Does that sound similar to 9/11 and Detroit? As for continuing industry denial, Mike Assante's April 9th letter criticized the utility industry for their lack of identifying Critical Assets and the Control Engineering survey results from December 22nd had almost 25% of the respondents stating ICS cyber threats are not a risk to their business. Complicating this is the headlong dash for Smart Grid that will create untold number of cyber vulnerabilities with a scarcity of ICS cyber experts (see 12/29/09 blog). One can only hope government and industry take ICS cyber security seriously before consequences are unrecoverable. And make no mistake, ICS cyber incidents can cause consequences such as loss of electric power for months or major toxic releases.

This was submitted by a member of the SF Bay InfraGard chapter, Joseph Weiss.  Mr. Weiss is the principal at Applied Control Systems.  Mr. Weiss has presented and lectured extensively and testified to congressional committees on Industrial Control System security issues.