In a survey published this month by Black Hat, 60% of respondents believe that cyber criminals will successfully attack U.S. critical infrastructure in the next two years. The majority of respondents also feel that in the next year a successful attack is likely in the corporations where they work.
This general mood of caution also bleeds into the IoT space. The majority of respondents to the survey believe that their priorities concerning IoT will need to shift soon. While attacks on IoT devices currently ranks #10 among their chief concerns, when asked what they will most likely be concerned about in two years, 34% responded that IoT security will rank #1. This makes sense as Gartner estimates that over 20 billion IoT devices will be connected by 2020, up from 8.4 billion in 2017.
As we prepare for the exponential growth of IoT, it is good to note the major vulnerabilities of IoT security and what must be done to better secure this connected environment:
DDoS Botnet Attacks
Few can forget the massive attack against Dyn last year in which legions of IoT devices were infected with the Mirai malware and were then used to launch the DDoS attack against the DNS provider. The unfortunate reality is that the malware simply searched for IoT devices still using default passwords. It’s search was not in vain. Some estimate that over 500,000 devices were infected using this technique. With such an army of infected devices, it is no wonder why the DDos attack was so devastating.
MQTT Attacks
On July 10th, Kelly Jackson Higgins, of Dark Reading, broke a story that may send shockwaves as it continues to unfold. Last year, at DEF CON, Lucas Lundgren showed how he found over 65,000 IoT servers using the Message Queuing Telemetry Transport (MQTT) on the Internet that were not using any authentication or encrypted communication. MQTT, designed as a lightweight publish/subscribe messaging transport, is currently being used for connections with remote locations where a small code footprint is required and/or network bandwidth is at a premium.
Now, this month at Black Hat USA, Lundgren plans to unveil a tool that could attack MQTT-based servers and not only see the data being sent and received but could actually control the devices. In his initial Penn Testing, he was able to view and access prison doors, airplane coordinates, oil pipelines, and more. The vulnerability to our infrastructure could be massive.
Remote Access Device Attacks
The Target data breach of 2013 in which over 40 million customer debit and credit card information was stolen is still fresh in many minds. What many forget, however, is that Target’s network was initially breached when the hackers stole the login credentials for Target’s Internet-enabled HVAC system. Since the HVAC system had remote access rights to Target’s network, the hackers embedded themselves inside the network and waited for an opportunity to gain access to company’s payment systems.
The truth is, with every IoT device that is enabled, it becomes a new threat vector for the network. If they are not properly secured, it potentially opens your entire system for attack.
A Path Forward
The good news is, following the data security best practices already in place could greatly decrease the chances of your IoT devices being used in similar attacks. Things like:
- Robust password management
- Multi-factor authentication
- Secure communication like TLS or SSH
- Strong encryption, like AES, for data-at-rest
- Enterprise level key management by utilizing interfaces like SQL Server EKM or MongoDB’s KMIP functionality.
- Real-time monitoring of the system for unusual activity
The bad news, since we saw that over 500,000 devices were infected in the Dyn DDoS attack by simply exploiting default passwords, I think we have a ways to go to even be in compliance with basic best practices. And the truth is, securing your IoT devices could protect more than just your organization. You could help prevent the next massive DDoS attack.