+ All Categories
Home > Documents > Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is...

Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is...

Date post: 26-May-2020
Category:
Upload: others
View: 0 times
Download: 0 times
Share this document with a friend
32
Welcome to The Internet of (Insecure) Things
Transcript
Page 1: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

Welcome toThe Internet of

(Insecure) Things

Page 2: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

Who am I? Who is Nexum?

I’m Chandler HowellDirector of Engineering at [email protected]@chandlerhowell on Twitter

Nexum is a Network & Security Reseller & Consultancy

Headquartered in ChicagoPresence East of the Mississippi Riverhttp://nexuminc.com

Page 3: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

The Internet of (Insecure) Things

1. The Internet of What?

2. Smart is the New Dumb

3. When Worlds Collide

4. Failure Modes

5. A Parade of Horrors

6. So What Now?

Page 4: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

THE INTERNET OF WHAT?A few definitions might be handy

Page 5: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

The Internet of What?

“The Internet of Things is the network of physical objects that contain embedded technology to communicate and sense or interact with their internal states or the external environment, “ – Gartner

“Spime is a neologism for a futuristic object…that can be tracked through space and time throughout its lifetime” – Wikipedia/Bruce Sterling

Page 6: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

The Internet of What?

IoT is massive and getting massiver

'14 '15 '16 '17 '18 '19 '2005

10152025

# of Devices (Billions)

Residential (78%)

Commecial (22%)

Sources: Gartner; Praetorian Security (@praetorianlabs)

Page 7: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

SMART IS THE NEW DUMBIronic, really

Page 8: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

Smart is the New Dumb

Smart, but Vulnerable Security is not a priority of IoT (yet)

Focus is on Cost Time to market Features & Functionality

Focus is NOT on Security Maintainability Longevity

Page 9: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

WHEN WORLDS COLLIDEIs your Internet in my Thing or my Thing in your Internet?

Page 10: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

When Worlds Collide

Lifecycles are mismatched

Technology lifecycles are short (18-48 months)

Consumer lifecycles are longer (12-15 years)

Industrial Equipment is supposed to outlive you

Page 11: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

When Worlds Collide

IT is not IoT Scale

Network Connectivity

Inventory

Logging & Monitoring

Incident Response

Page 12: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

When Worlds Collide

Compliance What IoT data needs a Privacy Policy? What about Data Retention policies? What about standards in general?

Insurance Do you have the right coverage? Are you sure?

Lawsuits Software Liability is coming through IoT

Page 13: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

FAILURE MODESHow can I fail thee? Let me count the ways…

Page 14: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

Failure Modes

1.Get BrokenDamage or destroy the device or attached devices

2.Get LeveragedUse the device as a vector for Other Badness

3.Get ExploitedUse the device to spy on or steal from the target

Page 15: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

A PARADE OF HORRORSIt’s spelled “IoT” but it’s pronounced “Fail”

Page 16: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

A Parade of Horrors

Welcome to the Future

Page 17: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

A Parade of Horrors

Numerous, Recurring Poor Security Decisions Weak/No Crypto Weak/No transport security Insecure/Default Authentication Root-only devices Security-by-Obscurity Insecure /unsigned images Fail-Open designs Credential Leaks Key & Credential Replay Insecure User Interfaces (XSS, CSRF) Cloud Insecurity Privacy Violations

Page 18: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

A Parade of Horrors

Consumer Goods Refrigerators Light Bulbs Televisions & Electronics Smart Watches Home Automation

Page 19: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

A Parade of Horrors

Medical Devices Surgical and anesthesia devices Ventilators Drug infusion pumps Pacemakers External defibrillators Patient monitors Laboratory and analysis equipment

Pretty much every type of failure you can imagine

Page 20: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

A Parade of Horrors

Cars Miller & Valasek Jeep Hacking Samy’s OwnStar > ON*Star Samy’s RollCode just re-hacked car keyless entry Black Boxes & Telematics Volkswagen hacked themselves

Page 21: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

A Parade of Horrors

Airplanes Drones

Definitely (Iranian Gov't, Samy's SkyJack)

In-Flight Entertainment (IFE) Definitely (Ruben Santamarta)

Telemetry, Internet uplinks & SATCOM Probably (Ruben Santamarta)

Page 22: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

A Parade of Horrors

Infrastructure NFC & Prox Cards Traffic Lights Industrial Control Systems Utility Meters

Page 23: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

SO WHAT NOW?Can I have a hint?

Page 24: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

Fortunately, not this.

So what now?

Page 25: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

So what now?

Don’t Panic

Think in terms of Failure Modes

Realize these are not new problems

Expect Novel attacks

Page 26: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

So what now?

Ashley Madison + Smart TV’s =

Page 27: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

So what now?

Know your Key Controls Preventative: Onboarding & Inventory Detective: Monitoring Reactive: Incident Response

Ensure proper Risk Ownership

Have a robust Exceptions Process

Page 28: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

So what now?

Assess whether the Smart is worth the Risk

Align Trust & Risk Boundaries

Architect for Insecure Things Assume devices are insecure by default If not today, they will be some day

Avoid proprietary standards & protocols (where possible)

Don't forget how to operate without IoT

Page 29: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

So what now?

Leverage Existing Security Tools & Processes

Defense-in-Depth

Threat Modeling

Incident Response

Implement Compensating Controls

Page 30: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

So what can I do?

Support/Leverage Emerging IoT Security Groups and Standards, e.g. Online Trust Alliance

Hold the line on security standards for IoT They are not special!

Include the cost of IoIT security in their TCO

Page 31: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

Thank You for your time!

Fun Fact: John Bender invented Power-Over-Ethernet (PoE) light bulbs

Well, that was fun.

Page 32: Welcome to The Internet of (Insecure) Things · The Internet of What? “The Internet of Things is the network of physical objects that contain embedded technology to communicate

I try to behave,

but sometimes these things happen...


Recommended