iot security and privacy challenges · 2019-10-24 · definition of iot [wikipedia ] the internet...

59
Adel Abdel Moneim, MBA ITU-ARCC Cyber Security Expert SCCISP ,CISSP, CISM, CRISC, CISA, CGEIT, CCISO,SABSA-SCF, CEH, CCSK,CHFI, EDRP,CSA ,ECSA, LPT,CND, ECES, CCFP-EU,PECB MS Auditor, SMSP, ECIH, Master ISO27001, ISO27005LRM , ISO31000, ISO27032 Lead Cybersecurity Manager, ISO27035 LIM, ISO38500 Lead IT Corporate Governance Manager,ISO24762 LDRM, CLSSP, ISO 29100 Lead Privacy Implementer, Lead Forensic Examiner, Certified Cyber Intelligence Professional (CCIP) IoT Security and privacy challenges

Upload: others

Post on 13-Mar-2020

4 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Adel Abdel Moneim, MBAITU-ARCC Cyber Security Expert SCCISP ,CISSP, CISM, CRISC, CISA, CGEIT, CCISO,SABSA-SCF, CEH, CCSK,CHFI, EDRP,CSA ,ECSA, LPT,CND, ECES, CCFP-EU,PECB MS Auditor, SMSP, ECIH, Master ISO27001, ISO27005LRM , ISO31000, ISO27032 Lead Cybersecurity Manager, ISO27035 LIM, ISO38500 Lead IT Corporate Governance Manager,ISO24762 LDRM, CLSSP, ISO 29100 Lead Privacy Implementer, Lead Forensic Examiner, Certified Cyber Intelligence Professional (CCIP)

IoT Security and privacy challenges

Page 2: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Definition of IoT[WIKIPEDIA ] The Internet of Things (IoT) is the

network of physical objects or "things" embedded with

electronics, software, sensors

and connectivity to enable it to achieve greater value

and service by exchanging data with the manufacturer,

operator and/or other connected devices.

[ OXFORD ] A proposed development of the Internet in which everyday objects have network connectivity, allowing them to send and receive data.

Page 3: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

The internet of Things moves in

Page 4: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

ADEL ABDEL MONEIM [ [email protected] ] 4

IOT Attack news

Page 5: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

5

https://gdpr.report/news/2019/05/24/iot-cyber-attacks-cost-the-uk-economy-1-billion/

IOT Attack news

Page 6: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

6

IOT Attack news

Page 7: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

7

IOT Attack news

Page 8: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

8

IOT Attack news

Page 9: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

9

IOT Attack news

Page 10: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

10

Page 11: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Smart Home &Wearable devices

Page 12: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

IoT in Health

Page 13: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

IoTin Agriculture

Page 14: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

IoTin Education

Page 15: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

IoTin Traffic

Page 16: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

IoT in Retail

Page 17: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

IoT in Smart City

Page 18: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

IoTBasedWasteCollection

Page 19: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

IoT Based Pollution Control

Page 20: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Smart Dust Bin in London

Page 21: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Smart Dust Bin in London (Cont.)

Page 22: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Smart Dust Bin in London (Cont.)

Page 23: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

IoT Application Areas and Devices

Page 24: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

IoT Application Areas and Devices

Page 25: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,
Page 26: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,
Page 27: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

IoTAttackSurfaceAreasDevice Memory

• Cleartextcredentials

• Third-party credentials

• Encryption keys

Ecosystem (general)

• Implicit trust between components

• Enrollment security

• Decommissioning system

• Lost access procedures

Device Physical Interfaces

• Firmware extraction

• User CLI

• Admin CLI

• Privilege escalation

• Reset to insecure state

• Removal of storage media

• Tamper resistance

Device Web Interface

• SQL injection

• Cross-site scripting

• Cross-site Request Forgery

• Username enumeration

• Weak passwords

• Account lockout

• Known default credentials

Device Firmware

• Hardcoded credentials

• Encryption keys

• Encryption (Symmetric, Asymmetric)

• Sensitive information

• Sensitive URL disclosure

• Firmware version display and/or last update date

Page 28: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

IoTAttackSurfaceAreasDevice Network

Services

• Information disclosure

• User CLI

• Administrative CLI

• Injection and Denial of Service

• Unencrypted Services

• Poorly implemented encryption

• UPnP

• Vulnerable UDP Services

Administrative Interface

• SQL injection

• Cross-site scripting

• Security/encryption options

• Logging options

• Two-factor authentication

• Inability to wipe device

Local Data Storage

• Unencrypted data

• Data encrypted with discovered keys

• Lack of data integrity checks

Cloud Web Interface

• SQL injection

• Cross-site scripting

• Transport encryption

• Insecure password recovery mechanism

• Two-factor authentication

Third-party Backend APIs

• Unencrypted PII sent

• Encrypted PII sent

• Device information leaked

• Location leaked

Page 29: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

IoTAttackSurfaceAreasUpdate

Mechanism

•Update is not encrypted

•Updates not signed

•Update location writable

•Update verification & authentication

•Missing update mechanism

•No manual update mechanism

Mobile Application

• Implicitly trusted by device or cloud

•Username enumeration

•Account lockout

•Known default credentials

•Weak pass

•Transport encryption

• Insecure recovery mechanism

Vendor Backend APIs

• Inherent trust of cloud or mobile application

•Weak authentication

•Weak access controls

• Injection attacks

•Hidden services

Ecosystem Communication

•Health checks

•Heartbeats

•Ecosystem commands

•Deprovisioning

•Pushing updates

Network Traffic

•LAN

•LAN to Internet

•Short range

•Non-standard

Page 30: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

IoT Security is the Worst-of-All-WorldsNetwork

Application

Mobile

Cloud

IoT

• services, encryption, firewall, input…

• authN, authZ, input validation, etc.

• insecure APIs, lack of encryption, etc.

• AuthSessionAccess

• net + app + mobile + cloud = IoT

Page 31: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

IoT Technologies and Protocols

Page 32: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

IoT Communication Models

Page 33: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

IoT : How IoT Works

Page 34: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Data Leakage & Users Privacy Issues

Page 35: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Data Leakage & Users Privacy Issues

Page 36: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Data Leakage & Users Privacy Issues

Page 37: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Google Services

Page 38: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Google Services (Cont.)

Page 39: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Google Services (Cont.)

Page 40: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Google Services (Cont.)

Page 41: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Google Services (Cont.)

Page 42: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Google Services (Cont.)

Page 43: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Google Services (Cont.)

Page 44: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Google Services (Cont.)

Page 45: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Google Services (Cont.)

Page 46: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,
Page 47: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Google Services (Cont.)

Page 48: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Samsung Health App

Page 49: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Samsung Health App

Page 50: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Samsung Health App (Cont.)

Page 51: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Samsung Health App (Cont.)

Page 52: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Samsung Health App (Cont.)

Page 53: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,
Page 54: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

NIST Cyber Security Framework

Page 55: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,
Page 56: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

56

Page 57: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Contact [email protected]

@adelnet2k

www.facebook.com/adelnet2k

www.linkedin.com/in/Adel-Abdel-Moneim

Page 58: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,

Questions?

Page 59: IoT Security and privacy challenges · 2019-10-24 · Definition of IoT [WIKIPEDIA ] The Internet of Things (IoT) is the network of physical objects or "things" embedded with electronics,