Stop An IP Camera Hack

How’s this for a nightmare scenario? Stealthy bad hats sneak up on an IP video camera attached to a remote fence and unplug it from its Ethernet cable. In its place, they jack in a laptop computer and -- voila! -- they’re now inside that surveillance network where they can manipulate other cameras, reprogram door locks, fiddle with access credentials and perhaps wreak havoc all over the target organization’s intranet.

Or maybe not. If that branch of the network is secured by a new appliance developed by Waterfall Solutions Ltd., a Tel Aviv-based startup, these intruders might find themselves staring at what amounts to a virtual wall situated just a few meters down the network.

Waterfall claims its appliance, employing a clever combination of hardware and software, can isolate network segments in a way that’s completely impenetrable.

“I can give you full control -- password, administration rights, and more,” says Lior Frenkel, chief technology officer and co-founder of Waterfall. There’s no way through, he adds. “Standard firewalls and gateways are vulnerable to hacking or misconfiguration. Our appliance is not.”

Waterfall’s IP Surveillance Enabler exploits the fact that IP networks rely on a constant two-way flow of information.

Data packets, containing images from a camera, for instance, flow one way. Traffic control signals -- short data bursts that acknowledge that the originating data packets have been received or, if not, request a resend -- flow the other way. By blocking all of that downstream traffic control data and passing only upstream data packets,Waterfall’s box makes sure that any device located on the other side of the box will be unable to acknowledge packets sent to it by the intruders’ laptop. As a result, the laptop will be unable to engage with, much less manipulate, any device beyond the local network segment.

What stops hackers from receiving a single bit of downstream data? Within Waterfall’s box, inbound packets get turned into pulses of light, sent down a short piece of optical fiber, and then turned back into electronic pulses to continue their journey as usual. And it’s absolutely impossible, says Frenkel, for any data to travel the opposite direction across this electro-optical divide.

Waterfall says it also has worked out methods, based on a proprietary protocol, to keep the camera none the wiser about its isolation from the broader network. The camera will still be addressable from the management system, remote polling and control will continue to work and managers can even upgrade the device, all with no sacrifice in security.

Frenkel declines to quote specific prices, but says the company’s goal is to make sure its device costs no more than 10 percent of the overall investment a customer is making in surveillance, including cameras, software and networking. For now, the Waterfall device will likely be deployed only to protect certain cameras and other devices that are remotely located and therefore particularly vulnerable to physical attack. Waterfall has begun shipments, has several pilot projects in the works and has signed one customer, in Israel.

Privately financed, the firm is now scrambling to make its product smaller and less costly to produce, qualities that enabled once-costly and arcane network firewall products to take off a decade ago. Says Frenkel: “Today’s highend solutions always become tomorrow’s common solutions.”

About the Author

John W. Verity is a freelance writer based in South Orange, N.J.

Featured

  • Gun Violence Report Finds Retail Spaces, K-12 Schools Most Targeted

    ZeroEyes, the creators of the only AI-based gun detection video analytics platform that holds the U.S. Department of Homeland Security SAFETY Act Designation, today announced the release of its annual Gun Violence Report, offering a deep dive into the landscape of gun-related incidents across the United States. This analysis extends beyond mass fatality events, providing a more nuanced understanding of when, where, and why shootings occur. Read Now

  • Agentic AI Will Revolutionize Cybercrime in 2025 According to New Report

    Malwarebytes, a provider in real-time cyber protection, recently released its 2025 State of Malware report, which reveals insight into the emergence of agentic artificial intelligence (AI), plus the year’s most prominent threats and cybercrime tactics. The report details a significant uptick in the number of known ransomware attacks, the total value of ransoms paid in 2024, and how IT teams can address them. Read Now

  • ESX 2025 Announces Expanded Schedule of Events

    ESX has announced its dynamic 2025 schedule, set to provide an unparalleled experience for professionals in the electronic security and life safety industry. Taking place June 16-19 at the Cobb Galleria Centre, this year’s event features an expanded lineup of educational sessions, hands-on workshops, inspiring main stage speakers, networking opportunities, and an engaging expo floor showcasing the latest technology. Read Now

  • City of New Orleans Launches NOLA Ready Public Safety App Before Super Bowl

    The City of New Orleans Office of Homeland Security and Emergency Preparedness (NOHSEP) is pleased to announce the official launch of the NOLA Ready Public Safety App, powered by Motorola Solutions. This new mobile application is designed to enhance public safety and emergency preparedness for both residents and visitors. All individuals planning to attend major events in New Orleans, including the Super Bowl, Mardi Gras, and other large gatherings, are encouraged to download the app. Read Now

New Products

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • Hanwha QNO-7012R

    Hanwha QNO-7012R

    The Q Series cameras are equipped with an Open Platform chipset for easy and seamless integration with third-party systems and solutions, and analog video output (CVBS) support for easy camera positioning during installation. A suite of on-board intelligent video analytics covers tampering, directional/virtual line detection, defocus detection, enter/exit, and motion detection.