The Cyber Security Review | Wednesday, November 09, 2022
As attackers target the ever-growing IoT attack surface, companies can reduce their risks with these six security best practices.
FREMONT, CA: There is a significant attack surface on the internet of things, and it is expanding rapidly. These gadgets are increasingly targeted by skilled hackers, including nation-states and cybercriminals, as they frequently have security flaws and high-risk vulnerabilities.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
IoT assaults have long been linked to lower-level dangers like botnets that mine cryptocurrency and distributed denial of service attacks. However, a rising number of ransomware attacks, espionage, and data theft operations are using IoT as the initial access point into a wider IT network, including the cloud. As recently demonstrated by the QuietExit backdoor, advanced threat actors utilise IoT devices to maintain persistence inside these networks and avoid discovery.
Creating a Holistic and Up-to-date Asset Inventory
80 per cent of corporate security teams cannot even recognise the vast majority of IoT devices connected to their networks. That is a startling number that demonstrates the magnitude of the issue. However, IoT inventorying is challenging. Systems for detecting network behaviour anomalies listen for traffic on span ports. Still, most IoT traffic is encrypted; even if it isn't, the data provided needs more identification information.
Knowing something is an HP printer without any further information is not sufficient, especially if it has security flaws that need to be corrected. However, because they work by delivering distorted packets, legacy vulnerability scanners aren't suitable for IoT identification and may potentially take an IoT device offline.
Discovering IoT devices through native-language interrogation of the devices is a preferable method. In-depth information on IoT devices, such as device version, model number, firmware version, serial number, active services, certificates, and credentials, can be created by an organisation using this. This enables the company to address these risks rather than just find them.
Password Security is Essential
As many IoT devices still utilise default passwords, attacks on these devices are simple to execute. This is the case for about 50 per cent of all IoT devices, and the percentage is considerably greater for particular device types. For instance, 95 per cent of IoT devices for audio and video equipment use default passwords. Even when devices don't use default passwords, most only change their password once every ten years, according to our research.
IoT devices must have special, challenging passwords that are changed routinely. Complex passwords are only supported by some devices, though. Older IoT devices may only support PINs with four digits, while others may only support 10 characters, and some may not even support special characters.
It's crucial to become familiar with all of the features and specifications of an IoT device to create secure passwords and make changes. Consider replacing legacy devices with more contemporary ones that will enable improved security procedures if they have weak password settings or cannot provide authentication.
Managing Device Firmware
As a result of the widespread use of obsolete firmware, most IoT devices present serious security threats. Devices are vulnerable to assaults such as common malware, complex implants and backdoors, remote access attacks, data theft, ransomware, espionage, and even physical destruction due to firmware flaws. The average device's firmware is six years old, and their manufacturers no longer support about one-fourth of them (25 to 30 per cent).
IoT devices should always have the most recent firmware and security fixes available from the suppliers. This can be difficult, especially in large enterprises with millions or hundreds of thousands of these devices. However, it must be done in some manner to maintain the network's security. There are enterprise IoT security platforms that can scale up the automation of this and other security procedures.
The firmware of a device should occasionally be degraded rather than upgraded. Since IoT suppliers frequently take longer to release patches than traditional IT device makers, it can be advisable to temporarily downgrade the device to an earlier firmware version that does not contain the vulnerability when it is being widely abused, and there is no accessible patch.
TurnING off Extraneous Connections, and Limit Network Access
IoT devices frequently have many connectivity features enabled by default, including Bluetooth, wired and wireless connections, Secure Shell, telnet, and other protocols. They are an accessible target for an outside attacker due to their promiscuous access.
Businesses must implement system hardening for IoT in the same way they did for their IT networks. IoT device hardening entails disabling these superfluous ports and pointless features. Examples include using SSH instead of telnet, wired ethernet instead of WiFi, and deactivating Bluetooth.
Additionally, businesses should restrict their ability to communicate across non-network channels. Network firewalls, unidirectional diodes, access control lists, and virtual local area networks can all be used at the Layer 2 and 3 levels. Limiting IoT device internet connectivity will prevent attacks like ransomware and data theft that rely on installing command-and-control software.
Ensuring Certificates are Effective
IoT digital certificates guarantee secure authorisation, encryption, and data integrity and are commonly out of date and ineffectively managed. Even the initial access point to the network is not properly secured because this issue affects crucial network components like wireless access points. To address potential issues, including TLS versions, expiration dates, and self-signing, it is crucial to evaluate the status of these certificates and connect them with a certificate management solution.
More in News