Network Protection At An Overlooked Spot

How’s this for a nightmare scenario? Stealthy bad hats sneak up on an IP video camera attached to a remote fence and unplug it from its Ethernet cable. In its place, they jack in a laptop computer and -- voila! -- they’re now inside that surveillance network where they can manipulate other cameras, reprogram door locks, fiddle with access credentials and perhaps wreak havoc all over the target organization’s intranet.

Or maybe not. If that branch of the network is secured by a new appliance developed by Waterfall Solutions Ltd., a Tel Aviv-based startup, these intruders might find themselves staring at what amounts to a virtual wall situated just a few meters down the network. Waterfall claims its appliance, employing a clever combination of hardware and software, can isolate network segments in a way that’s completely impenetrable.
 
“I can give you full control -- password, administration rights, and more,” says Lior Frenkel, chief technology officer and co-founder of Waterfall. There’s no way through, he adds. “Standard firewalls and gateways are vulnerable to hacking or misconfiguration. Our appliance is not.”

Waterfall’s IP Surveillance Enabler exploits the fact that IP networks rely on a constant two-way flow of information. Data packets, containing images from a camera, for instance, flow one way. Traffic control signals -- short data bursts that acknowledge that the originating data packets have been received or, if not, request a resend--flow the other way. By blocking all of that downstream traffic control data and passing only upstream data packets, Waterfall’s box makes sure that any device located on the other side of the box will be unable to acknowledge packets sent to it by the intruders’ laptop. As a result, the laptop will be unable to engage with, much less manipulate, any device beyond the local network segment.

What stops hackers from receiving a single bit of downstream data? Within Waterfall’s box, inbound packets get turned into pulses of light, sent down a short piece of optical fiber, and then turned back into electronic pulses to continue their journey as usual. And it’s absolutely impossible, says Frenkel, for any data to travel the opposite direction across this electro-optical divide. Waterfall says it also has worked out methods, based on a proprietary protocol, to keep the camera none the wiser about its isolation from the broader network. The camera will still be addressable from the management system, remote polling and control will continue to work and managers can even upgrade the device, all with no sacrifice in security.

Frenkel declines to quote specific prices, but says the company’s goal is to make sure its device costs no more than 10 percent of the overall investment a customer is making in surveillance, including cameras, software and networking. For now, the Waterfall device will likely be deployed only to protect certain cameras and other devices that are remotely located and therefore particularly vulnerable to physical attack. Waterfall has begun shipments, has several pilot projects in the works, and has signed one customer, in Israel. Privately financed, the firm is now scrambling to make its product smaller and less costly to produce -- qualities that enabled once-costly and arcane network firewall products to take off a decade ago. Says Frenkel: “Today’s high-end solutions always become tomorrow’s common solutions.

About the Author

John W. Verity is a freelance writer based in South Orange, N.J.

Featured

  • Maximizing Your Security Budget This Year

    7 Ways You Can Secure a High-Traffic Commercial Security Gate  

    Your commercial security gate is one of your most powerful tools to keep thieves off your property. Without a security gate, your commercial perimeter security plan is all for nothing. Read Now

  • New Report Says Vulnerability Exploitation Boom Threatens Cybersecurity

    Verizon Business recently released the findings of its 17th-annual Data Breach Investigations Report (DBIR), which analyzed a record-high 30,458 security incidents and 10,626 confirmed breaches in 2023—a two-fold increase over 2022. Read Now

  • Surveillance Cameras Provide Peace of Mind for New Florida Homeowners

    Managing a large estate is never easy. Tack on 2 acres of property and keeping track of the comings and goings of family and visitors becomes nearly impossible. Needless to say, the new owner of a $10 million spec home in Florida was eager for a simple way to monitor and manage his 15,000-square-foot residence, 2,800-square-foot clubhouse and expansive outdoor areas. Read Now

  • Survey: 72% of CISOs Are Concerned Generative AI Solutions Could Result In Security Breach

    Metomic recently released its “2024 CISO Survey: Insights from the Security Leaders Keeping Critical Business Data Safe.” Metomic surveyed more than 400 Chief Information Security Officers (CISOs) from the U.S. and UK to gain deeper insights on the state of data security. The report includes survey findings on various cybersecurity issues, including security leaders’ top priorities and challenges, SaaS app usage across their organization, and biggest concerns with implementing generative AI solutions. Read Now

Featured Cybersecurity

Webinars

New Products

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles. 3

  • Hanwha QNO-7012R

    Hanwha QNO-7012R

    The Q Series cameras are equipped with an Open Platform chipset for easy and seamless integration with third-party systems and solutions, and analog video output (CVBS) support for easy camera positioning during installation. A suite of on-board intelligent video analytics covers tampering, directional/virtual line detection, defocus detection, enter/exit, and motion detection. 3

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation. 3