Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
7/16/2020
10:00 AM
Natali Tshuva
Natali Tshuva
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
100%
0%

Third-Party IoT Vulnerabilities: We Need a Cybersecurity Paradigm Shift

The only entities equipped to safeguard Internet of Things devices against risks are the IoT device manufacturers themselves.

The discovery of the Ripple20 vulnerabilities, affecting hundreds of millions of Internet of Things (IoT) devices, is the latest reminder of the dangers that third-party bugs pose to connected devices.

Although the estimated 31 billion IoT devices in the world perform a vast array of crucial functions — powering lifesaving medical tools, facilitating efficient transportation, and transforming critical business processes — these devices are alarmingly vulnerable to attack. In large part, that's because OEMs rely on third-party vendors — like the Ohio software company at the center of the Ripple20 firestorm — that sell code riddled with potential entry points for malicious hackers.

Nevertheless, a recent Ponemon Institute study found that six in 10 organizations do not monitor the cyber-risks of IoT devices developed by third parties, leaving thousands of businesses and institutions accountable for supplying vulnerable products and exposed to heavy financial losses and reputational damage.

The only entities equipped to safeguard IoT devices against these risks are the IoT device manufacturers themselves, given that end users typically lack adequate security mechanisms for protecting their connected devices. Because new cyber vulnerabilities will continuously pop up, there's no magic bullet— but by assuming accountability and protecting each individual device, manufacturers can prevent attacks and secure IoT innovation.

Proliferating Vulnerabilities
Who's most at risk from inadequate IoT cybersecurity? Just about everyone. Take the Ripple20 case, which centers around 19 bugs found in code sold by the software company Treck. The company's code is found in devices used by everyone from mom and pop shopkeepers to Fortune 500 companies, as researchers at JSOF, who discovered the vulnerabilities, noted. Affected industries spanned the gamut, including medical, transportation, energy, retail, and more.

News of the Ripple20 bugs came on the heels of the revelation that 26 new vulnerabilities had been discovered in the Zephyr Real Time Operating System (RTOS), which powers IoT devices and is supported by vendors including Intel, Nordic, and Texas Instruments.

In another case, the US Food and Drug and Administration announced in March the discovery of 12 additional third-party vulnerabilities known as "SweynTooth" affecting IoT medical devices — underscoring that the risk posed by cybersecurity vulnerabilities could extend beyond property and reputation to life itself, with hackers potentially able to steal sensitive medical data or stop devices such as heart monitors from working.

The takeaway from these cases: vulnerabilities within IoT devices are proliferating. So how can manufacturers meet the scale of the threat?

New Pressure on OEMs
Fortunately, the latest revelations of IoT bugs haven't caught policymakers unaware. Regulatory measures are shifting the burden of responsibility onto device manufacturers. Case in point: a new California law took effect in January requiring IoT OEMs to equip devices with cybersecurity features that are appropriate to the specific nature of the device itself and the information it collects and transmits, while preventing unauthorized access or manipulation. The law made California the second state, after Oregon, to adopt such a law.

Meanwhile, the UK Department for Digital, Culture, Media and Sport unveiled similar regulations earlier this year, requiring manufacturers to provide a public point of contact for reporting and responding to vulnerabilities and to explicitly state the minimum duration for device security updates.

Governments across the globe should join this regulatory effort, putting pressure on OEMs to act swiftly to safeguard the devices critical to both our lives and our livelihoods. The bottom line: No IoT device should be allowed on the market if proper security isn't installed on the device itself.

A Paradigm Shift
The goal of IoT cybersecurity shouldn't be eradicating all vulnerabilities; that would be setting manufacturers up for failure. Vulnerabilities will always exist — so what's needed instead is a paradigm shift in how manufacturers think about securing connected devices.

Device manufacturers cannot rely on the security of third-party vendors. As gatekeepers, OEMs themselves must implement controls to protect their clients. Effective design protection should include not only protecting the manufacturer's code, but also securing all third-party components. This is why secure-by-design, static analysis, and even hardware security don't fully answer IoT protection needs, as IoT network security is only one piece of the puzzle and cannot protect distributed devices.

When manufacturers do ultimately discover vulnerabilities, they should patch them — but patching shouldn't be the focal point of their cybersecurity strategy. Instead, OEMs should seek innovative solutions that focus on preventing attacks, regardless of vulnerabilities. New techniques in cybersecurity for IoT devices make this possible. OEMs can then spend less time and money looking for vulnerabilities as they will be better equipped to stop exploitation attempts and respond immediately to incidents.

In the IoT age, each individual device serves as a potential point of entry for attackers — which is why manufacturers should ensure that cyber protection is embedded onto each device. Such solutions will be critical as IoT on 5G networks is poised to drive $8 billion in revenue for operators by 2024.

Related Content:

 

 

Register now for this year's fully virtual Black Hat USA, scheduled to take place August 1–6, and get more information about the event on the Black Hat website. Click for detail on conference information and to register.

Natali brings over 10 years of experience, both as a researcher and a team leader, in the field of offensive cybersecurity and software development. After graduating magna cum laude B.Sc. in Computer Science at the age of 19, as part of a special program for gifted and ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/25/2020
Hacking Yourself: Marie Moe and Pacemaker Security
Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
Startup Aims to Map and Track All the IT and Security Things
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25137
PUBLISHED: 2020-09-25
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur via the alert_name or alert_message parameter to the /a...
CVE-2020-25138
PUBLISHED: 2020-09-25
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur via /alert_check/action=delete_alert_checker/alert_test...
CVE-2020-25139
PUBLISHED: 2020-09-25
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur via la_id to the /syslog_rules URI for delete_syslog_ru...
CVE-2020-25140
PUBLISHED: 2020-09-25
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur in pages/contacts.inc.php.
CVE-2020-4531
PUBLISHED: 2020-09-25
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the sy...