Data Secure

Keep IoT devices and data safe from threats

The risk posed by hackers to the Internet of Things (IoT) is a hot topic and there have already been some serious real-world attacks. Any organization deploying network-connected devices would be well advised to take a deeper look at the risks posed and take steps to protect themselves.

When we talk about any risk we must consider the frequency with which incidents may occur and the impact that an incident would have on the organization. Some events may be fairly common but carry a low impact while others are rarer but carry tremendous consequences. Determining what we realistically should be worried about will help decide the measures that are appropriate to defend an IoT installation against attacks.

We must consider what the IoT device itself is being used for. Many IoT devices are used for physical security, such as cameras and door access control, and if they were compromised could be expected to lead to a compromise of physical security, which may be severe depending on the type of facility. Moving to the higher impact end of the spectrum, most hospitals now use medical devices that are connected to the network and a breach of those devices could potentially be a matter of life and death for the patients relying on them. On a broader scale, utilities are using more IoT devices for monitoring and management of infrastructure. A successful attack could impact many thousands or even millions of people.

The direct risk posed by the devices themselves may be serious but it is only one aspect of their risk. As modern IoT devices contain as much computing power as personal computers from only a few years ago and are often based on the same underlying architectures and software, they can also be leveraged to attack other network resources. A poorly protected IoT device could be used to attack a sensitive server or database and then exfiltrate the resulting data.

Many organizations may believe they have nothing of value on their network that an attacker would want (I would disagree, attackers always want bank login credentials), but even in this case an attacker can leverage compromised IoT devices to attack other organizations. We saw this in 2016 with the Mirai botnet, which was primarily based on IP cameras that had default or backdoor passwords; the resulting attacks knocked many of the largest websites offline.

Protecting IoT devices requires efforts from both the vendors that create and sell these devices and the users who install them. If a device isn’t designed properly there will be no way to secure it regardless of what steps the user takes, while even products with the best builtin security will require some effort on the part of users during the deployment process.

Vendors

IoT devices need to be designed with security “baked in”. This means using proper authentication and encryption for both data transmission and administration. Other common traps need to be avoided as well, like using the same default password for every device (users are unlikely to change them) or, even worse, creating a backdoor account with a hardcoded password (these are fairly easy for attackers to find and extremely easy to exploit once found).

Vendors also have to consider the lifespan of their products. Many consumer product companies have had a “sell it and forget it approach,” which presents an enormous risk when software and network connectivity is in play. A vulnerability in a 10-year-old product is potentially more valuable to an attacker than a vulnerability in a just-released product, as the installed base of the older product is likely to be much larger. Vendors must take reports of security vulnerabilities seriously and release patches, even for long-discontinued products.

Users

The devices themselves will require some security configuration. Removing default passwords and replacing them with strong passwords is one of the most important steps, but other settings should be reviewed as well. Depending on the device these could include encryption settings, lists of IP addresses that are allowed to administer the device, and authorizations for interactions with other devices.

The devices themselves will also require maintenance and monitoring just like a PC. Patches should be applied quickly in order to address security vulnerabilities and the network traffic generated by the devices should be monitored to make sure that they have not been co-opted for use by an attacker.

The devices themselves should also be protected, just like any other computer. This means firewalling them off from the Internet. Search engines, like the one available at shodan.io, make it easy for attackers to search for vulnerable devices that are exposed.

Cloud

Many IoT devices leverage cloud resources. This may be for remote storage of data or to enable easy administration via a web frontend. It’s important to remember that “cloud” resources are just another set of computers in a datacenter with all of the same security concerns of a regular computer, only in this case the user is relying on the cloud provider to handle the security.

Users of cloud services should once again consider the risk posed by the compromise or loss of any data that they are about to place in the cloud and make sure that contracts with cloud providers include provisions for an appropriate level of security. If vendors aren’t willing to commit to securing the data then cloud services may not be the right fit.

This article originally appeared in the June 2017 issue of Security Today.

Featured

  • 91 Percent of Security Leaders Believe AI Set to Outpace Security Teams

    Bugcrowd recently released its “Inside the Mind of a CISO” report, which surveyed hundreds of security leaders around the globe to uncover their perception on AI threats, their top priorities and evolving roles, and common myths directed towards the CISO. Among the findings, 1 in 3 respondents (33%) believed that at least half of companies are willing to sacrifice their customers’ long-term privacy or security to save money. Read Now

  • Milestone Announces Merger With Arcules

    Global video technology company Milestone Systems is pleased to announce that effective July 1, 2024, it will merge with the cloud-based video surveillance solutions provider, Arcules. Read Now

  • Organizations Struggle with Outdated Security Approaches, While Online Threats Increase

    Cloudflare Inc, recently published its State of Application Security 2024 Report. Findings from this year's report reveal that security teams are struggling to keep pace with the risks posed by organizations’ dependency on modern applications—the technology that underpins all of today’s most used sites. The report underscores that the volume of threats stemming from issues in the software supply chain, increasing number of distributed denial of service (DDoS) attacks and malicious bots, often exceed the resources of dedicated application security teams. Read Now

  • Cloud Resources Have Become Biggest Targets for Cyberattacks According to New Research

    Thales recently announced the release of the 2024 Thales Cloud Security Study, its annual assessment on the latest cloud security threats, trends and emerging risks based on a survey of nearly 3000 IT and security professionals across 18 countries in 37 industries. As the use of the cloud continues to be strategically vital to many organizations, cloud resources have become the biggest targets for cyber-attacks, with SaaS applications (31%), Cloud Storage (30%) and Cloud Management Infrastructure (26%) cited as the leading categories of attack. As a result, protecting cloud environments has risen as the top security priority ahead of all other security disciplines. Read Now

Featured Cybersecurity

Webinars

Whitepapers

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file. 3

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3