Stop An IP Camera Hack

How’s this for a nightmare scenario? Stealthy bad hats sneak up on an IP video camera attached to a remote fence and unplug it from its Ethernet cable. In its place, they jack in a laptop computer and -- voila! -- they’re now inside that surveillance network where they can manipulate other cameras, reprogram door locks, fiddle with access credentials and perhaps wreak havoc all over the target organization’s intranet.

Or maybe not. If that branch of the network is secured by a new appliance developed by Waterfall Solutions Ltd., a Tel Aviv-based startup, these intruders might find themselves staring at what amounts to a virtual wall situated just a few meters down the network.

Waterfall claims its appliance, employing a clever combination of hardware and software, can isolate network segments in a way that’s completely impenetrable.

“I can give you full control -- password, administration rights, and more,” says Lior Frenkel, chief technology officer and co-founder of Waterfall. There’s no way through, he adds. “Standard firewalls and gateways are vulnerable to hacking or misconfiguration. Our appliance is not.”

Waterfall’s IP Surveillance Enabler exploits the fact that IP networks rely on a constant two-way flow of information.

Data packets, containing images from a camera, for instance, flow one way. Traffic control signals -- short data bursts that acknowledge that the originating data packets have been received or, if not, request a resend -- flow the other way. By blocking all of that downstream traffic control data and passing only upstream data packets,Waterfall’s box makes sure that any device located on the other side of the box will be unable to acknowledge packets sent to it by the intruders’ laptop. As a result, the laptop will be unable to engage with, much less manipulate, any device beyond the local network segment.

What stops hackers from receiving a single bit of downstream data? Within Waterfall’s box, inbound packets get turned into pulses of light, sent down a short piece of optical fiber, and then turned back into electronic pulses to continue their journey as usual. And it’s absolutely impossible, says Frenkel, for any data to travel the opposite direction across this electro-optical divide.

Waterfall says it also has worked out methods, based on a proprietary protocol, to keep the camera none the wiser about its isolation from the broader network. The camera will still be addressable from the management system, remote polling and control will continue to work and managers can even upgrade the device, all with no sacrifice in security.

Frenkel declines to quote specific prices, but says the company’s goal is to make sure its device costs no more than 10 percent of the overall investment a customer is making in surveillance, including cameras, software and networking. For now, the Waterfall device will likely be deployed only to protect certain cameras and other devices that are remotely located and therefore particularly vulnerable to physical attack. Waterfall has begun shipments, has several pilot projects in the works and has signed one customer, in Israel.

Privately financed, the firm is now scrambling to make its product smaller and less costly to produce, qualities that enabled once-costly and arcane network firewall products to take off a decade ago. Says Frenkel: “Today’s highend solutions always become tomorrow’s common solutions.”

About the Author

John W. Verity is a freelance writer based in South Orange, N.J.

Featured

  • 2025 Gun Violence Statistics Show Signs of Progress

    Omnilert, a national leader in AI-powered safety and emergency communications, has released its 2025 Gun Violence Statistics, along with a new interactive infographic examining national and school-related gun violence trends. In 2025, the U.S. recorded 38,762 gun-violence deaths, highlighting the continued importance of prevention, early detection, and coordinated response. Read Now

  • Big Brand Tire & Service Rolls Out Interface Virtual Perimeter Guard

    Interface Systems, a managed service provider delivering remote video monitoring, commercial security systems, business intelligence, and network services for multi-location enterprises, today announced that Big Brand Tire & Service, one of the nation’s fastest-growing independent tire and automotive service providers, has eliminated costly overnight break-ins and significantly reduced trespassing and vandalism at a high-risk location. The company achieved these results by deploying Interface Virtual Perimeter Guard, an AI-powered perimeter security solution designed to deter incidents before they occur. Read Now

  • The Evolution of ID Card Printing: Customer Challenges and Solutions

    The landscape of ID card printing is evolving to meet changing customer needs, transitioning from slow, manual processes to smart, on-demand printing solutions that address increasingly complex enrollment workflows. Read Now

  • TSA Awards Rohde & Schwarz Contract for Advanced Airport Screening Ahead of Soccer World Cup 2026

    Rohde & Schwarz, a provider of AI-based millimeter wave screening technology, announced today it has won a multi-million dollar award from TSA to supply its QPS201 AIT security scanners to passenger security screening checkpoints at selected Soccer World Cup 2026 host city airports. Read Now

  • Brivo, Eagle Eye Networks Merge

    Dean Drako, Chairman of Brivo, the leading global provider of cloud-native access control and smart space technologies, and Founder of Eagle Eye Networks, the global leader in cloud AI video surveillance, today announced the two companies will merge, creating the world’s largest AI cloud-native physical security company. The merged company will operate under the Brivo name and deliver a truly unified cloud-native security platform. Read Now

New Products

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction.