Showing posts with label IoT security. Show all posts
Showing posts with label IoT security. Show all posts

Monday, March 13, 2017

96 Percent of IT Security Professionals Expect an Increase in Cybersecurity Attacks on Industrial Internet of Things



Study reveals most organizations take additional precautions to secure IIoT

Portland, Ore. – March 13, 2017 – Tripwire, Inc. today announced the results of a study conducted in partnership with Dimensional Research. The study looked at the rise of Industrial Internet of Things (IIoT) deployment in organizations, and to what extent it is expected to cause security problems in 2017.  

IIoT are the connected devices in critical infrastructure segments such as energy, utilities, government, healthcare and finance. Tripwire’s study revealed that:
  • Ninety-six percent of those surveyed expect to see an increase in security attacks on IIoT in 2017.
  • Fifty-one percent said they do not feel prepared for security attacks that abuse, exploit or maliciously leverage insecure IIoT devices.
  • Sixty-four percent said they already recognize the need to protect against IIoT attacks, as they continue to gain popularity among hackers.

“Industry professionals know that the Industrial Internet of Things security is a problem today. More than half of the respondents said they don’t feel prepared to detect and stop cyber attacks against IIoT,” said said David Meltzer, chief technology officer at Tripwire. “There are only two ways this scenario plays out: Either we change our level of preparation or we experience the realization of these risks. The reality is that cyber attacks in the industrial space can have significant consequences in terms of safety and the availability of critical operations.” 

“As Industrial companies pursue IIoT, it’s important to understand the new threats that can impact critical operations. Greater connectivity with operational technology (OT) exposes operational teams to the types of attacks that IT teams are used to seeing, but with even higher stakes,” said Robert Westervelt, security research manager at IDC.  “The concern for a cyber attack is no longer focused on loss of data, but safety and availability. Consider an energy utility as an example - cyber attacks could disrupt power supply for communities and potentially have impact to life and safety.”

The study’s respondents were also asked how they expect their organizations’ deployment of IIoT devices to change, and how it will affect their level of vulnerability. Tripwire found that: 

  • Ninety percent expect IIoT deployment to increase.
  • Ninety-four percent expect IIoT to increase risk and vulnerability in their organizations.
  • When respondents were broken down by company size, both larger companies (96 percent) and smaller companies (93 percent) expect a significant increase in risk caused by the use of IIoT.

Meltzer continued, “The Industrial Internet of Things ultimately delivers value to organizations, and that’s why we’re seeing an increase in deployments. Security can’t be an industry of ‘no’ in the face of innovation, and businesses can’t be effective without addressing risks. The apparent contradiction of known risks and continued deployment demonstrates that security and operations need to coordinate on these issues. While IIoT may bring new challenges and risks, the fundamentals of security still apply. Organizations don’t need to find new security controls, rather they need to figure out how to apply security best practices in new environments.”

Tuesday, December 20, 2016

Hackers Can Access Flight Controls through Entertainment System

Just in time for your Christmas and holiday travel!

12/20/2016 - Eskenzi PR Ltd. - IOActive recently did some research into a flaw in an in-flight entertainment system used by major airlines including Emirates, Virgin and Qatar that could let hackers access a planes' controls.

Commenting on this, Art Swift, president of the not-for-profit prpl Foundation that aims to make the IoT more open, interoperable and secure, said, "Travellers this holiday season will be horrified to hear that in-flight entertainment systems could be used to help hackers gain access to their favourite airline’s flight control system, but the truth is it’s something which prpl has been talking about publicly since the flaw was first disclosed - and it’s not just airplanes that are at risk. Technology plays an important role in getting us from here to there, but without separation of critical aspects within the systems that keep things like critical controls such as steering, braking or heating and cooling that could potentially cause damage apart from less critical aspects like entertainment. Hackers can worm their way around systems and potentially cause real devastation. For this reason, the prpl Foundation has come up with its free "Security Guidance for Critical Areas of Embedded Computing" for developers, manufacturers and engineers that outlines exactly how this security separation is possible."

Tuesday, June 28, 2016

IoT Botnet: 25,513 CCTV Cameras Used in Crushing DDoS Attacks

It's only a matter of time before these types of attacks proliferate.

June 28, 2016 -- Eskenzi PR -- Researchers from security firm Sucuri have encountered a denial-of-service botnet that's made up of more than 25,000 internet-connected closed circuit TV devices. The malicious network was discovered whilst Sucuri was defending a small brick-and-mortar jewellery shop against a distributed denial-of-service attack. After the DDoS continued for several days, Sucuri researchers soon discovered the individual devices carrying out the attack were CCTV boxes that were connected to more than 25,500 different IP addresses, located in no fewer than 105 countries around the world.

"For over a decade, security professionals have been evangelizing that anything with an IP address can become the victim of a cyber-attack, and anything with an IP address can be used in a cyber-attack," notes Stephen Gates, Chief Research Intelligence Analyst at NSFOCUS IB. "Here is another case in point whereby a vulnerability has been exploited, remote code execution has been successful, and a botnet has been constructed from devices that rarely, if ever get updated. This problem is going to continue to grow as more and more devices get connected.  IPv6 will serve to increase this problem even further.

"In the world of IPv4, network address translation (NAT) has helped hide devices from attackers on the Internet.  Devices sitting behind a firewall using NAT, are often not visible from the Internet itself.  Although NAT was designed to solve the fossil fuel effect of IPv4, it was never intended to be a security feature - but has helped.  However, in IPv6 the concept of NAT isn’t needed.  Every device can have a publicly visible IP address.  As a result, hacking will grow exponentially."

The Internet of Things (IoT) has attracted strong interest from both academia and industry. Unfortunately, it has also attracted the attention of hackers. Security and Privacy in Internet of Things (IoTs): Models, Algorithms, and Implementations brings together some of the top IoT security experts from around the world who contribute their knowledge regarding different IoT security aspects. It answers the question "How do we use efficient algorithms, models, and implementations to cover the four important aspects of IoT security, i.e., confidentiality, authentication, integrity, and availability?"

Thursday, April 7, 2016

Energy Sector Sees Dramatic Rise in Successful Cyber Attacks


Portland, OR – April 7, 2016 – Tripwire, Inc. today announced the results of a study conducted for Tripwire by Dimensional Research. The study, which was carried out in November 2015, assessed cyber security challenges faced by organizations in the energy sector. Study respondents included over 150 IT professionals in the energy, utilities, and oil and gas industries.

When asked if their organization had experienced a rise in successful cyber attacks in the last 12 months, seventy-seven percent of the respondents in Tripwire’s study replied, “yes.” In addition, more than two-thirds of the respondents (sixty-eight percent) said the rate of successful cyber attacks had increased by over twenty percent in the last month.

“It’s tempting to believe that this increase in attacks is horizontal across industries, but the data shows that energy organizations are experiencing a disproportionately large increase when compared to other industries,” said Tim Erlin, director of IT security and risk strategy for Tripwire. “At the same time, energy organizations face unique challenges in protecting industrial control systems and SCADA assets.”

Additional findings from the study include:

• Energy executives were more than twice as likely to believe their organization detected every cyber attack (forty-three percent) than nonexecutives (seventeen percent).

• In the last 12 months, seventy-eight percent of the respondents said they experienced a cyber attack from an external source, and thirty percent have seen an attack from an inside employee.

• Forty-four percent of the respondents indicated they have not gathered enough information to identify the sources of cyber attacks on their organizations.

• Nearly one-fourth (twenty-two percent) of the respondents admitted their organizations do not have business processes to identify sensitive and confidential information.

“ Detecting attacks successfully is the midpoint of the overall process,” Erlin continued. “Energy organizations need to invest in greater prevention and forensic tools to decrease the rate of successful attacks and fully investigate those they can’t prevent.”

According to the Department of Homeland Security, the energy sector faces more cyber attacks than any other industry. Despite these escalating risks, the energy sector faces serious challenges responding to security threats effectively. For example, the results of the North American Electric Reliability Corporation’s (NERC) GridEx III "cyberwar games" revealed significant challenges with the cyber threat intelligence practices of grid operators.

In addition to this study, Tripwire conducted a survey of 200 security professionals attending RSA Conference 2016. When asked if a cyber attack would cause physical damage to critical infrastructure in 2016, eighty-three percent of the respondents replied, “yes.” In addition, seventy-three percent of respondents to this second survey said critical infrastructure providers are more vulnerable to ransomware attacks than other organizations.

For more information about the survey please visit Tripwire.

Related Books

NEW! Cyber Security for Industrial Control Systems: From the Viewpoint of Close-Loop

Cybersecurity for Industrial Control Systems: SCADA, DCS, PLC, HMI, and SIS

Security and Privacy in Smart Grids

Data Privacy for the Smart Grid

Security and Privacy in Internet of Things (IoTs): Models, Algorithms, and Implementations

Monday, March 14, 2016

Free IoT Security e-book


IoT Security has been identified by Gartner as one of the Top 10 technology areas that should be on every organization's radar in 2017 and 2018. Billions of devices are expected to generate more than 40 zeta bytes of data annually by the year 2020. While the Internet of Things promises many benefits to individuals and enterprises, the unprecedented growth in devices, data and connections leads to bigger security threats. Gemalto's IoT Security e-book discusses the impact of security breaches in a connected world. Learn about the key pillars that form the foundation of a secure IoT infrastructure: securing the device, securing the cloud and security lifecycle management.

When you're ready to learn more or doing something about it, see "Security and Privacy in Internet of Things (IoTs): Models, Algorithms, and Implementations."

Tuesday, February 9, 2016

GSMA Announces Security Guidelines to Support Growth of the Internet of Things


Backed by the Mobile Industry, New Guidelines Outline Common Approach to Security for IoT Services

LONDON--(BUSINESS WIRE)--The GSMA today announced the availability of new guidelines designed to promote the secure development and deployment of services in the growing Internet of Things (IoT) market. The document, ‘The GSMA IoT Security Guidelines,' has been developed in consultation with the mobile industry and offers IoT service providers and the wider IoT ecosystem practical advice on tackling common cybersecurity threats, as well as data privacy issues associated with IoT services.

The project has received the backing and support of the mobile industry including mobile operators AT&T, China Telecom, Etisalat, KDDI, NTT DOCOMO, Orange, Telefónica, Telenor and Verizon and vendor and infrastructure partners 7Layers, Ericsson, Gemalto, Morpho, Telit and u-blox.

“As billions of devices become connected in the Internet of Things, offering innovative and interconnected new services, the possibility of potential vulnerabilities increases,” said Alex Sinclair, Chief Technology Officer, GSMA. “These can be overcome if the end-to-end security of an IoT service is carefully considered by the service provider when designing their service and an appropriate mitigating technology is deployed. A proven and robust approach to security will create trusted, reliable services that scale as the market grows.”

The GSMA’s IoT Security Guidelines have been designed for all players in the IoT ecosystem including IoT service providers, IoT device manufacturers and developers. They will help service providers build secure services by outlining technologies and methods to address potential threats, as well as how to implement them. They also establish the need for risk assessment of all components of an IoT service to ensure they are designed to securely collect, store and exchange data and successfully mitigate cybersecurity attacks. The Guidelines recently completed a thorough industry consultation with academics, analysts and other industry experts to ensure that they are as robust as possible.

“There is a significant amount of evidence to suggest that cyberattacks are already happening in the burgeoning IoT space. If not handled appropriately, these attacks are likely to inhibit the growth and stability of the Internet of Things,” commented Don A. Bailey, Founder and CEO, Lab Mouse Security. “It is imperative that the industry adopts a standard approach for dealing with security risks and mitigations, helping to ensure that the entire IoT ecosystem will not be subject to fraud, exposures of privacy, or attacks that affect human life."

The GSMA IoT Security Guidelines have been developed through the GSMA Connected Living program. The program is designed to help operators accelerate the delivery of new connected devices and services in the M2M market. It focuses on driving industry collaboration, promoting appropriate regulation and optimizing networks to support the growth of M2M in the immediate future and the IoT in the longer term.

The IoT Security Guidelines are available to download here.

For more on securing the IoT, get a copy of "Security and Privacy in Internet of Things (IoTs): Models, Algorithms, and Implementations." The book consists of five parts covering attacks and threats, privacy preservation, trust and authentication, IoT data security, and social awareness.

Thursday, January 28, 2016

IoT Scale Is Outpacing Its Security – Telefonica

You knew this would happen. The pace of technological changes far outruns our ability to manage them. IoT is no different. Companies roll out new products and services and worry about securing them later. Infoworld recently ran a story about home automation horror stories. It's just the beginning. And while Scientific American debunked the Wired story of hacking a car, one has to ask, why not? These tales grab us because they strike close to home. But the industrial scale, and threats, are so much greater.

So, better late than never.

Get a handle on securing the IoT with Security and Privacy in Internet of Things (IoTs): Models, Algorithms, and Implementations. The book brings together some of the top IoT security experts from around the world who contribute their knowledge regarding different IoT security aspects. It answers the question "How do we use efficient algorithms, models, and implementations to cover the four important aspects of IoT security; i.e., confidentiality, authentication, integrity, and availability?"

Order your copy today!

Monday, October 5, 2015

Top 3 Trends in Today's Threat Landscape

Top 3 Trends in Today's Threat Landscape
Benny Czarny, Founder and CEO of OPSWAT

Every day there seems to be a new malware threat that we hear about, from remotely controlling cars and medical equipment, to attacks on well-known security vendors such as Kaspersky Lab and Bitdefender. Each threat seems to be bigger and more dangerous than the last. Among this never ending stream of publicized cyber threats and attacks, here are three trends to keep an eye on:

Trend 1. Cyber Security Companies Are Targets
Recently we have seen a number of sophisticated attacks specifically directed towards cyber security companies and their products. Kaspersky’s network was recently hacked and valuable R&D data was accessed, including source code and intellectual property. The attack was apparently very sophisticated and it is thought that millions of dollars went into its development. The data breach at Bitdefender and subsequent ransom demand is another example of a cyber security company being targeted by hackers. In addition, we are seeing a rise in malware that is capable of evading cyber security products. For instance, the Duke malware family includes anti-AV detection capabilities and searches for several security products to evade, including Kaspersky Lab, Sophos, DrWeb, Avira, Crystal, Comodo Dragon, AVG and K7.

Trend 2. Internet of Things Is Under Attack
The vulnerability of the Internet of Things (IoT) is currently a hot topic that receives a lot of attention in the press. Devices are increasingly being connected to the Internet such as cars, medical equipment, thermostats, and watches, to name but a few. Our society is becoming more and more connected, with endless possibilities. In the future, we will be able to switch on our oven remotely, start the vacuum cleaner and feed the cat. All these possibilities appeal to our imagination and need for convenience, but also reminds us of big brother and how, if these devices were hacked, attackers would have access to our private lives. Since each device that is connected to the Internet can theoretically be hacked, the ubiquity of these devices inherently means that we are exposing ourselves to more threats.

Trend 3. Increasing Firmware Hacks
Another trend that we are seeing is firmware hacking: the process of installing rogue firmware on embedded devices. Cisco recently warned customers that hackers are replacing the boot firmware on devices running Cisco’s IOS operating system with a malicious version. The attackers install the malicious version to prevent reboots from wiping IOS infections. Now that Point of Sale systems (POS) have gone mobile, these too have become a target for hackers. Although the possibility of firmware hacking has been known for some time, actual real-world attacks have been rare until now.

So what can you do to protect yourself against these threats? Unfortunately the effectiveness of using a single anti-virus engine is decreasing. With over 450,000 new threats emerging daily, it is impossible for any single engine to provide guaranteed protection 100% of the time. The solution is to use multiple anti-malware engines. By combining multiple anti-malware engines, you can leverage the power of the different detection algorithms and heuristics of each engine and detect significantly more threats. Other technologies such as data sanitization and file type verification can provide additional protection against threats that are missed by anti-virus engines. Finally, we will be seeing a lot of IoT security improvements as vendors address vulnerabilities using techniques such as white listing connections, and performing packet inspections and anti-malware scanning in the cloud.

Benny Czarny is the Founder and Chief Executive Officer at OPSWAT. Benny has over 20 years of experience in the Computer and Network Security field. From the early days of computer viruses he was interested and involved in the fields of encryption, network operations, security vulnerabilities detection, and research.

Thursday, January 29, 2015

Nine Questions to Ask to Improve IoT Risk Management

(BUSINESS WIRE)--As connected devices infiltrate the workplace—some with IT’s knowledge and some without—both value and risk can increase significantly. Global IT association ISACA has released new guidance urging companies to ask nine critical questions as they grapple with the Internet of Things (IoT).

ISACA recommends companies address:
1. How will the device be used from a business perspective, and what business value is expected?
2. What threats are anticipated, and how will they be mitigated?
3. Who will have access to the device, and how will their identities be established and proven?
4. What is the process for updating the device in the event of an attack or vulnerability?
5. Who is responsible for monitoring new attacks or vulnerabilities pertaining to the device?
6. Have risk scenarios been evaluated and compared to anticipated business value?
7. What personal information is collected, stored or processed by the IoT device?
8. Do the individuals whose information is being collected know that it is being collected and used, and have they given consent?
9. With whom will the data be shared?

These questions are particularly critical given that 43 percent of enterprises are leveraging IoT already, or have plans to do so in 2015, according to ISACA’s IT Risk/Reward Barometer survey.
“Connected devices are everywhere—from obvious ones, like smart watches and Internet-enabled cars, to ones most people may not even be aware of, such as smoke detectors,” said Robert Stroud, CGEIT, CRISC, international president of ISACA and vice president of strategy and innovation at CA Technologies. “Often, organizations can be using IoT without even realizing it—which means their risk management stakeholders are not involved and potential attack vectors are going unmonitored.”

ISACA’s free (after registration) “Internet of Things: Risk and Value Considerations” guide was released today as a free download at www.isaca.org/internet-of-things. The paper includes dos and don’ts for the IoT, and outlines the types of risks organizations must consider.

Related Books

Unit and Ubiquitous Internet of Things

Smart Grid Security: An End-to-End View of Security in the New Electrical Grid

Data Privacy for the Smart Grid

Security and Privacy in Smart Grids

Monday, January 26, 2015

Critical Infrastructure Executives Complacent about Internet of Things Security


Surveys aren't as bad as listicles for clickbait, but there so seem to be a lot of them, most requiring surrender of sufficient information to quality as a sales lead. Still, they do generate some thought, and the summaries are sufficient to get the key points. Here's a  survey summary on attitudes of critical infrastructure execs on IoT dangers.

Friday, November 14, 2014

Call for Chapters: Security and Privacy in Internet of Things (IoTs): Models, Algorithms, and Implementations

We have a new book underway, Security and Privacy in Internet of Things (IoTs): Models, Algorithms, and Implementations, edited by Dr. Fei Hu from the University of Alabama. If you're interested in participating, here's a link to the Call for Chapters.