Stop An IP Camera Hack

How’s this for a nightmare scenario? Stealthy bad hats sneak up on an IP video camera attached to a remote fence and unplug it from its Ethernet cable. In its place, they jack in a laptop computer and -- voila! -- they’re now inside that surveillance network where they can manipulate other cameras, reprogram door locks, fiddle with access credentials and perhaps wreak havoc all over the target organization’s intranet.

Or maybe not. If that branch of the network is secured by a new appliance developed by Waterfall Solutions Ltd., a Tel Aviv-based startup, these intruders might find themselves staring at what amounts to a virtual wall situated just a few meters down the network.

Waterfall claims its appliance, employing a clever combination of hardware and software, can isolate network segments in a way that’s completely impenetrable.

“I can give you full control -- password, administration rights, and more,” says Lior Frenkel, chief technology officer and co-founder of Waterfall. There’s no way through, he adds. “Standard firewalls and gateways are vulnerable to hacking or misconfiguration. Our appliance is not.”

Waterfall’s IP Surveillance Enabler exploits the fact that IP networks rely on a constant two-way flow of information.

Data packets, containing images from a camera, for instance, flow one way. Traffic control signals -- short data bursts that acknowledge that the originating data packets have been received or, if not, request a resend -- flow the other way. By blocking all of that downstream traffic control data and passing only upstream data packets,Waterfall’s box makes sure that any device located on the other side of the box will be unable to acknowledge packets sent to it by the intruders’ laptop. As a result, the laptop will be unable to engage with, much less manipulate, any device beyond the local network segment.

What stops hackers from receiving a single bit of downstream data? Within Waterfall’s box, inbound packets get turned into pulses of light, sent down a short piece of optical fiber, and then turned back into electronic pulses to continue their journey as usual. And it’s absolutely impossible, says Frenkel, for any data to travel the opposite direction across this electro-optical divide.

Waterfall says it also has worked out methods, based on a proprietary protocol, to keep the camera none the wiser about its isolation from the broader network. The camera will still be addressable from the management system, remote polling and control will continue to work and managers can even upgrade the device, all with no sacrifice in security.

Frenkel declines to quote specific prices, but says the company’s goal is to make sure its device costs no more than 10 percent of the overall investment a customer is making in surveillance, including cameras, software and networking. For now, the Waterfall device will likely be deployed only to protect certain cameras and other devices that are remotely located and therefore particularly vulnerable to physical attack. Waterfall has begun shipments, has several pilot projects in the works and has signed one customer, in Israel.

Privately financed, the firm is now scrambling to make its product smaller and less costly to produce, qualities that enabled once-costly and arcane network firewall products to take off a decade ago. Says Frenkel: “Today’s highend solutions always become tomorrow’s common solutions.”

About the Author

John W. Verity is a freelance writer based in South Orange, N.J.

Featured

  • New Report Reveals Top Security Risks for U.S. Retail Chains

    Interface Systems, a provider of security, actionable insights, and purpose-built networks for multi-location businesses, has released its 2024 State of Remote Video Monitoring in Retail Chains report. The detailed study analyzed over 2 million monitoring requests across 4,156 retail locations in the United States from September 2023 to August 2024. Read Now

  • Gaining a Competitive Edge

    Ask most companies about their future technology plans and the answers will most likely include AI. Then ask how they plan to deploy it, and that is where the responses may start to vary. Every company has unique surveillance requirements that are based on market focus, scale, scope, risk tolerance, geographic area and, of course, budget. Those factors all play a role in deciding how to configure a surveillance system, and how to effectively implement technologies like AI. Read Now

  • 6 Ways Security Awareness Training Empowers Human Risk Management

    Organizations are realizing that their greatest vulnerability often comes from within – their own people. Human error remains a significant factor in cybersecurity breaches, making it imperative for organizations to address human risk effectively. As a result, security awareness training (SAT) has emerged as a cornerstone in this endeavor because it offers a multifaceted approach to managing human risk. Read Now

  • The Stage is Set

    The security industry spans the entire globe, with manufacturers, developers and suppliers on every continent (well, almost—sorry, Antarctica). That means when regulations pop up in one area, they often have a ripple effect that impacts the entire supply chain. Recent data privacy regulations like GDPR in Europe and CPRA in California made waves when they first went into effect, forcing businesses to change the way they approach data collection and storage to continue operating in those markets. Even highly specific regulations like the U.S.’s National Defense Authorization Act (NDAA) can have international reverberations – and this growing volume of legislation has continued to affect global supply chains in a variety of different ways. Read Now

Featured Cybersecurity

Webinars

New Products

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame. 3

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3