Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

2/24/2015
08:45 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

5 Ways To Prepare For IoT Security Risks

As the Internet of Things begins to take shape, IT organizations must prepare for change.

Enterprises can expect to see some fundamental changes in the information security and data privacy landscape as the Internet of Things (IoT) begins to take shape over the next several years.

The sheer diversity of IoT assets and the myriad ways in which they connect with each other and the enterprise network will raise new IT governance and cybersecurity challenges, Verizon said in a status report on the IoT market this week. Dealing with the changes will require a new way of thinking about IT security and management, the report noted.

“Because IoT is all about physical “things,” hackers that gain access can not just perform the usual digital attacks like stealing data, moving money, or shutting down websites,” Verizon said. They can also cause physical havoc by tampering with critical infrastructure like electric grids, SCADA systems, healthcare devices, and aviation systems.

For the most part, the Verizon report offers a review of how organizations in different industries have already begun deriving measurable business value from IoT projects. As examples, it points to transportation companies that are saving millions of dollars on fuel consumption by using IP-enabled devices to track and manage fleets, local governments stretching their budget dollars via smart street lighting projects and utilities improving operations via smart meters.

Organizations across sectors are harnessing IoT technologies to increase revenues, improve operational efficiencies and find new ways to do thing, Verizon noted.

But the trend also presents new challenges, Verizon noted. Every Internet-enabled sensor and device in an IT environment presents a potential security risk. Verizon pointed to a 2014 report by Hewlett-Packard showing 70 percent of the most commonly used IoT devices, such as smart thermostats and home security systems, contain serious security vulnerabilities.

Even the most security-conscious organizations may be unprepared for the full security impact of a world in which tens of billons of devices and things are connected to the Internet, the report noted.

Johan Sys, managing principal of identity and access management at Verizon Enterprise Solutions, says as more things join the established Internet, they are likely to present the same kind of attack opportunities as the devices that first made up the Internet. “As long as there is value in the information exchanged by connected devices, there will be malicious actors who will attack the applications running on the network,” Sys said in emailed comments to Dark Reading. There are several measures that organizations can take to prepare for the risks, he said.

1. Bake security into IoT applications from the start

Because of its highly interconnected nature, the IoT amplifies the impact of security vulnerabilities, says Daniel Miessler, an HP security researcher involved in the 2014 IoT report. “We have broken network security, broken web security, broken cloud security,” he says. “What the IoT does is take all of these vulnerabilities and smash them together into one product. We should not be surprised there are issues,” Miessler says.

One of the first things developers of IoT applications should focus on, according to Sys, is building in security from the start. “This needs to include ways of updating the system in a secure manner,” he said.

2. Identify Risks

Know the specific threats you are facing: “The risks associated with connected vehicles are different to those facing a smart grid," Sys said. Know what your organization’s risk exposure is, plan for compromises, and have a clear idea of what to do when that happens.

The most common IoT vulnerabilities include web interface authentication and authorization, lack of transport encryption security, insufficient security configurability, and poor physical controls, Miessler says. Enterprises need to be aware of such risks and review the components of their IoT environment to identify and eliminate them, he notes.

3. Segment Networks

Because security errors tend to get magnified in an IoT environment, organizations need to keep their IT networks properly segmented from the IoT to prevent a security issue in one part of the network enabling or leading to problems in other parts of the network, Miessler said.

An organization that deploys an enterprise system to manage an industrial control system for instance has to manage two separate sets of security issues while keeping the two environments properly segmented.

4. Have a layered security system

Traditional IT security controls such as firewalls, intrusion detection systems, and anti-virus tools, will not be enough to protect IoT assets, Sys said. Even the user experience may not be a human experience. “If security measures such as passwords require human involvement, the system will either be inefficient or avoided entirely,” he said.

In addition, many IoT components are not equipped to deal with security issues and have minimal support for security patches and software updates, Miessler said. Often the patches themselves are easily compromised and can be used to deliver malware instead.

Dealing with such issues will require companies to deploy multi-layered controls for mitigating threats.

5. Be prepared to share security responsibility

Miessler expects IoT security to “absolutely be a shared jurisdiction” in which IT groups will need to coordinate security efforts with physical security teams and device manufacturers. Where manufactures are reluctant to take on the responsibility for integrating better security, organizations will need to put pressure on them to do so, he said.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Zero-Factor Authentication: Owning Our Data
Nick Selby, Chief Security Officer at Paxos Trust Company,  2/19/2020
44% of Security Threats Start in the Cloud
Kelly Sheridan, Staff Editor, Dark Reading,  2/19/2020
Ransomware Damage Hit $11.5B in 2019
Dark Reading Staff 2/20/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-0063
PUBLISHED: 2020-02-21
Insecure plugin update mechanism in tucan through 0.3.10 could allow remote attackers to perform man-in-the-middle attacks and execute arbitrary code ith the permissions of the user running tucan.
CVE-2013-3551
PUBLISHED: 2020-02-21
Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS ITSM 3.0.x before 3.0.8, 3.1.x before 3.1.9, and 3.2.x before 3.2.5 does not properly restrict tickets, which allows remote attackers with a valid agent ...
CVE-2013-4088
PUBLISHED: 2020-02-21
Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket spli...
CVE-2019-19865
PUBLISHED: 2020-02-21
Atos Unify OpenScape UC Web Client 1.0 allows XSS. An attacker could exploit this by convincing an authenticated user to inject arbitrary JavaScript code in the Profile Name field. A browser would execute this stored XSS payload.
CVE-2019-19866
PUBLISHED: 2020-02-21
Atos Unify OpenScape UC Web Client 1.0 allows remote attackers to obtain sensitive information. By iterating the value of conferenceId to getMailFunction in the JSON API, one can enumerate all conferences scheduled on the platform, with their numbers and access PINs.