Internet of Things

The Internet of Things connects everyday devices to networks, enabling data exchange and automation while raising new security, privacy, and management challenges.

3 slides · 2 min read · Domain 3

Slide 1

The increasing miniaturization of embedded systems and the ubiquity of wireless networks to provide connectivity to previously discrete infrastructures have created tremendous opportunities for monitoring and interacting with the physical environment. Refrigerators, road condition monitors, smartwatches, and myriad other devices can now communicate and provide inputs to other systems for decision-making.

The complexity and capability of Internet of Things (loT) devices start with simple status monitoring tools using relatively small operating systems and input sensors and go on to include highly complex, calibrated devices with safety-of-life implications.

They may be built using general-purpose operating systems that support a rich, complex application suite. They may also include standard communications protocols and employ secure cryptographic algorithms to protect their communications. As a result, this new class of devices, no longer isolated on their own separate networks, presents an expanded attack surface relative to the legacy embedded systems.

Vulnerabilities associated with the loT include:

  • Denial of service (DoS). While many of the vulnerabilities applicable to industrial control systems (ICSs) and embedded systems can be found in loT environments, the increased reliance on wireless communications protocols presents additional weaknesses. Where the target loT device uses standard communications protocols, the weakness of those protocols comes into play. The use of proprietary or nonstandard protocols brings with it the potentially exploitable vulnerabilities within those implementations. lot communications may also transit multiple infrastructures as they establish connections and share data. As a result, DoS attacks can significantly degrade the quality of service between the devices. Latency costs imposed by retransmission reconnection or encryption must be considered in system design.
  • Device security. The remote location of the loT devices may open them to physical attack, including theft. This exposes the loT system to data remanence exploitation or reverseengineering attacks; the stolen device may also be repurposed to be part of a subsequent attack. Furthermore, if the device is monitoring a process or environment (e.g., a wireless camera or temperature sensor), manipulating the environment may be a productive avenue to compromise the device.
  • Cryptographic security. Not all loT devices have the computational horsepower to perform complex cryptographic operations on communications and stored data.
Test this domain