From Physical To Cyber - Locking down network video surveillance

From Physical To Cyber

Locking down network video surveillance

Both physical security and IT professionals place great importance on cyber security. When it comes to protecting people and assets in 2012—as PhySec systems are increasingly moving into the all-digital realm—the data created by video and access control communications falls under the cyber umbrella, and both camps must be well-versed in the threats of the other.

From Physical To CyberIn fact, ASIS International President Eduard Emde, CPP, stated in a recent interview that he was “convinced that 2012 will continue to be dominated by all facets of cyber-related security risks.” In another recent piece of news, the ASIS International 58th Annual Seminar and Exhibits and (ISC)2, the world’s largest not-for-profit membership body of certified information security professionals, announced that the second annual (ISC)2 Security Congress will be collocated with ASIS in Philadelphia in 2012. This places greater emphasis on the increasing importance and interdependence of both physical and Information Systems Security in the network ecosystem.

But why now? Why the seemingly sudden need to educate the respective security owners—logical and physical—on what the other hand is doing? It’s simple: physical security is moving toward intelligent devices. Intelligence devices produce data and provide a portal into the enterprise infrastructure. Both the data and the portal must be protected.

Network video surveillance systems are composed of “edge” devices, such as network cameras and encoders that produce video content, and metadata, control, analysis, media search and content management, storage and display components. Physical and logical infrastructure provides connectivity between categories and also conforms to useful standards (e.g., 802.1x and port-based network access control). This ensures a user or device cannot make a full network connection until he or it is properly authenticated.

To the IT-focused world, the cameras, encoders and readers will be just another node on the network (when it comes to securing their infrastructure, that is). Thus, the physical security practitioner must be able to relate to the need for proper authentication.

Authenticate for a Secure State

Aside from making their IT counterparts happy, physical security practitioners, too, need to understand the importance of protecting their data—namely the video and its quality.

An important trend in IP video development is the increase in the power and sophistication of today’s network video cameras, making them small computers, complete with solid-state storage, room for on-board security, video content analysis apps, and enhanced image processing. Improving the fidelity of the video content right at the source provides the physical security industry with problem-solving technologies like wide dynamic range and improved ultra-low-light performance. With more important processes at these “non-person entities” and edge devices, it is vital that they be resistant to intrusion exploits and they achieve a trusted identity.

To date, most physical security practitioners and integrators practice some form of logical security with password protection and user-assigned permissions. Best practice dictates that the default passwords for network-connected physical security devices (cameras, encoders, etc.) be changed upon installation. However, as the industry moves to all-IP and the IT world becomes increasingly more influential in the installation and maintenance of surveillance systems, the physical world must abide by IT security best practices: namely, authentication and standards acceptance.

The National Institute of Standards (NIST) recently published an education video illustrating how the National Strategy for Trusted Identities in Cyberspace will work. The goal is to establish identity solutions and privacy-enhancing technologies that will improve security by authenticating individuals and infrastructure. In this structure, the selection of secure and independent identity providers is followed by users proving their identity and the provider issuing a trusted credential.

Users, especially in the government arena, have started to apply this structure to network video. Cameras and encoders will be expected to run a cryptographic application that communicates to a digital certificate authority that registers, validates and, in some cases, revokes the network device’s access to core digital video services.

Just like the mobile banking customer who must answer security questions and validate site keys, the network video camera will “prove” its identity through this validation process. The world of “non-person entities” can also include Voice over IP (VoIP) communications, electronic access control readers, intelligent perimeter sensors and mobile devices. A secure application on a smartphone can initiate a payment of funds to a quickserve establishment’s owner/operator while decoding video and statistical content such as customer volume from the “meta” or “feature” data.

For the world of video, not only does this methodology protect camera streams from being accessed and the cameras themselves from being controlled, but recordings that reside on the server are safe. If unauthorized access does occur, steps can be taken to corrupt the video file so it is unplayable for the hacker.

Permission to Come Aboard: How it Works

The specification of a network video surveillance system architecture and function, together with the authentication requirements, can enhance the definition of use cases—which in the IT/ software/engineering realm means a list of steps that define interactions between a “role” (a human, camera, etc.) and the system as a whole.

The network video authentication requirements can be looked at on a step-by-step basis:

  • Verify the network video plus metadata or “Digital Multimedia Content” (DMC) source(s) with Network Intrusion Detection Systems (IDS) and Network Management Systems (NMS) for authorized consumption of network resources.
  • Provision the appropriate DMC-source(s) network resources in accordance with NMS and Quality of Service (QoS) definitions, as defined by the user/integrator.
  • Verify the DMC user/consumer(s) (such as smartphones and workstations) with IDS and NMS for authorized consumption of network resources (bandwidth, etc.) and access to DMC source(s).
  • Process DMC-source(s) Public Key Infrastructure (PKI) certificate(s) and validate or reject, as required.
  • Provision appropriate DMC user/consumer(s) network resources and DMC source(s) access in accordance with NMS, QoS definitions, local and global rules, and credential authorities. Establish the validity of the identity credential presented as part of the authentication transaction. Process DMC user PKI certificate(s) and validate or reject, as required using revocation status checking and certificate path validation.
  • The DMC user/consumer(s) then can access DMC-source live or recorded content.

Growing Need for Authentication

Network video allows police officers to be more operationally effective in fighting crime. Video and Physical Security Information Management (PSIM) applications are designed to give authorities minute-by-minute situational awareness about public safety and crime, as well as to a number of medical emergencies to which officers respond on any given day. The flexibility and performance of network security solutions are equally important to the valuable content and intelligence these systems provide.

Therefore, the necessity of improved authentication in public safety applications is becoming of greater importance. The Department of Homeland Security’s “Hot Spots of Terrorism and Other Crimes in the United States, 1970 to 2008” report, January 2012, illustrates the need for enhanced public safety through tools like video surveillance in major cities such as New York, Miami, Washington, D.C., Chicago, Los Angeles and San Francisco. Nearly 30 percent of all attacks took place in just five counties in the United States, permitting focused efforts of video surveillance as forensic and observation tools.

Should a pen tester or hacker gain access to a law enforcement vehicle or command center’s video content and surveillance device, movements in real time can be tracked and security in these areas of high risk become compromised. Video could also be potentially altered, destroyed or lose the proper chain of custody.

This, of course, isn’t a new problem—and network cameras and encoders today have the same IT security protocols and certificates in place as any other network-connected device—but as more physical security devices connect to the network and practitioners increase their use of critical digital surveillance, increased digital security must be considered.

Even at the Consumer Electronics Show in January 2012, a “Digital Health Summit” showed how doctors are using technology to eliminate distance and borders and be preventative in their treatment approach. Network video will enhance this style of treatment and require proven security. Of course, this type of sensitive data must be protected not only for peace of mind but also, in some cases, for compliance requirements.

And while authentication of devices provides an extra layer to the system, it’s comforting to know that the validation of trusted network devices also makes bandwidth management easier for the IT administrators. It’s a logical companion to network management systems, which is another point that will gain favor in the growing IT/physical security management relationship.

Hackers will forever search for ways to compromise a system— and unfortunately no network-connected system has proven unhackable. Even today we see hackers targeting teleconferencing systems. So as the inevitable use of IP-based surveillance systems grows and becomes more public, we can close the window of opportunity on hacking threats through authentication before it opens.

This article originally appeared in the April 2012 issue of Security Today.

About the Author

Steve Surfaro is an industry liaison at Axis Communications.

Featured

  • ESX 2025 Announces Expanded Schedule of Events

    ESX has announced its dynamic 2025 schedule, set to provide an unparalleled experience for professionals in the electronic security and life safety industry. Taking place June 16-19 at the Cobb Galleria Centre, this year’s event features an expanded lineup of educational sessions, hands-on workshops, inspiring main stage speakers, networking opportunities, and an engaging expo floor showcasing the latest technology. Read Now

  • City of New Orleans Launches NOLA Ready Public Safety App Before Super Bowl

    The City of New Orleans Office of Homeland Security and Emergency Preparedness (NOHSEP) is pleased to announce the official launch of the NOLA Ready Public Safety App, powered by Motorola Solutions. This new mobile application is designed to enhance public safety and emergency preparedness for both residents and visitors. All individuals planning to attend major events in New Orleans, including the Super Bowl, Mardi Gras, and other large gatherings, are encouraged to download the app. Read Now

  • 5 Tips to Improve Your Password Security

    Change Your Password Day is right around the corner. Observed every year on February 1, the day aims to raise awareness about cybersecurity and underscores the importance of keeping passwords strong and up to date. Read Now

  • Enhancing Port Security

    DP World Yarimca, one of the largest container terminals of the Gulf of İzmit and Turkey, is a strong proponent of using industry-leading technology to deliver unrivaled value to its customers and partners. As the port is growing, DP World Yarimca needs to continue to provide uninterrupted operations and a high level of security.To address these challenges, DP World Yarimca has embraced innovative technological products, including FLIR's comprehensive portfolio of security monitoring solutions. Read Now

New Products

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.