Tuesday, September 27, 2016

The Fruit of Insecurity

I was planning on writing about how IoT in the business world affects auditing and compliance, but something rather significant happened last week that I think deserves mentioning.

Brian Krebs is a relatively well-known reporter on information security; his website is https://krebsonsecurity.com/, and he covers a broad range of topics (with an emphasis on ATM skimming). However, he recently posted several articles related to a DDoS-for-service group in Israel--during which time they were arrested and purportedly released on bail. Soon afterwards, his site was hit by a significant DDoS attack--over 600 Gbps in size. This is a huge amount of data, and the size of this attack forced his DDoS protection service (who volunteered their services to him) to stop protecting him. As a result, his website was taken offline for several days. It's currently up and running, and the site is now protected by Google's Project Shield.

There is something significant about this DDoS attack, though: it appears to have been the work of a botnet of IoT devices.

I've discussed through this blog how insecurity is a major problem in the IoT, and this massive DDoS attack is a direct result of this. Botnets are cheap for the attacker--aside from the communications needed to control the hacked devices, the attacker spends little on bandwidth or Internet connection, and they pay nothing for the processing power or electricity needed to run these devices. In addition, botnets don't require a large amount of criminals in order to work well (if "well" is the appropriate term here); literally a handful of masterminds can set up a botnet and run it. Finally, it doesn't take a lot of computing resources to send lots of network packets to a target; even a small (read: IoT) device could be used for such a purpose. And what is the result?

600 Gbps DDoS attacks. And anything else botnets of this size could do.

This is a big deal, and it wouldn't be possible without the baked-in insecurity of the IoT. Sure, one reporter's website isn't a big deal, but a DDoS weapon of this size could knock out most websites or other network-connected services. It would take a toll on small ISPs and some network links if weaponized against them.

Is the solution to this problem churning out millions of more IoT devices in the next decade?

Probably not. As has already been stated here, the best solution is for security to be implemented at the device level. True, there will always be vulnerable devices, even with the best of intentions. However, raising the bar of IoT security will also raise the bar of botnet creation--a bar that is abysmally low right now.

No comments:

Post a Comment