Showing posts with label IoT. Show all posts
Showing posts with label IoT. Show all posts

By: Akanksha Kumari, BCA 4th Sem, 1st Shift

Before we jump into the security challenges of IOT, let us know that what exactly IoT, i.e. Internet of Thing is. Internet which means several networks connected and thing simply mean anything like various devices, human beings, animals, plants, etc.

Simply, IoT includes the things which are connected to the internet. It means several interrelated devices which are somehow connected with each other. It is the way that how all the things in the universe are connecting and exchanging information.

They all are provided with their unique identifiers; and are given their own IP addresses and helps to transfer data over the network.

IoT is making the cities and devices smarter. Like your car will give you alert to take different route or path due to traffic possibilities ahead, the wireless connectivity or the heart transplantation.
This is because of sensors, electronics, software and network connectivity whicenablees these devices to exchange information. It also imposes few standards and protocols while exchanging information.

In the smooth run of the IoT department, there also come few hurdles in the path. Everything has its pros and cons, so does IOT because of which people have started calling it as “internet of insecure things”. The main challenge that it would deal with is “security”. Many questions have been raised regarding the security concern of this department.

Security issues regarding IOT

  • As all the devices are interconnected over the network then there is a possibility that someone can hack into your security systems.
  • One more problem that comes into play is what to do with the huge amount of data that is been produced by millions of devices, answer for this is encryption and retrieval of the data, companies need to figure out the way to store, track and analyse the data.
  • But after encryption too, there is a possibility that any outsider can create a false data and change the settings of your system. So, foremost step to be taken for this is providing data authenticity.
  • Hardware chips are used in the wearable devices but these chips are very complex and difficult to cope up with the battery backup problem. Just because of their increased amount they are not used by the wearable devices which is the primary problem and make these devices insecure. There is no silver bullet for any problem but still, we can opt for few ways to get rid of this.
  • Few companies deploy the IOT devices.
There is no silver bullet for any problem that is the reason there is no specific way to get out of these problems. Many companies simply deny for developing new software, only 20% be confident to deal with the security issues. They simply use to deploy the IoT devices. Money factor is also there as lots of money is getting into use and no full assurance is there that the developed software will cope up with the security. Hacking into your private systems and changing the settings of it is the biggest fear of every human.

Despite of problems associated with IoT, it is helping people to take advantage of the services that it is providing. As it is the hot topic of present day so developers are also working on the idea for getting out of this security issue and providing a fearless and secure environment.
By: Shubhangi Negi, BCA 6th Sem, 1st Shift
Internet of things is basically the term given to the various everyday machines, vehicles and other objects to communicate over the internet with the use of sensors or actuators embedded in them. These objects together make up the Internet of Things (IoT). One of the main features of IOT is that it allowed us to sense/control objects remotely.

IoT received a lot of initial hype and it has also been a ‘buzzword’ in the IT sector for years now. Some experts also went to the length of estimating that but the year 2020, IoT will have connected over 50 billion objects. This was back in 2011. Why has a prospect so promising succumbed to sluggish development and limited commercialization? While IoT is a great step towards a better-connected world, it also comes with a number of challenges.

Challenges:

1. Data Encryption: Is my data secure?
Data encryption is extremely important as it allows us to exchange protected data or protect our data if we do not wish to anyone without a key to be able to access it. IoT environment works on the collection and processing of data. A standard IoT application collects tones of data. Most of which is personal and in need of protection. This is very crucial to major companies and firms. But it is very difficult for big businesses to maintain effective security when it comes to IoT. According to SC Magazine, a team of researchers has just defeated one of the most widely used encryption solutions for IoT, The Algebraic Eraser. What’s more, they’ve done it using parameters provided by the creators of the key itself. Which raises the question: Can effective protection ever be achieved through encryption?
2. Data Authentication: An important security measure.
New technologies mean new threats to data. The challenge of the IoT is that of trust. Authentication means making sure that the user of a device is who he/she says he/she is. It is critical for the software to know who all are authorised to access/send the data because if the information gets to the wrong users, the integrity of the data gets compromised. Having a single user also is not safe in the chance that a defect is detected in the connected device making data authentication a big security challenge of IoT.
3. Side-channel Attacks: What are those?
The focus in this kind of attacks is on information gained from ‘physical implementation of a cryptosystem’ rather than ‘brute force’ or ‘theoretical weaknesses in the algorithms’. Which means that these types of attacks focus more on how that information is being presented and less on the information itself.
4. Hardware: Yes, it is important.
Experts say that the Key to IoT Security Is a Strong Hardware Foundation. IP thefts of a network device can occur when it doesn’t have sufficient hardware security. Most of the industrial equipment have low lifetimes and relying on software alone isn’t the best idea. Hardware security chips like the ones found in credit cards and Aadhaar cards are extremely helpful in maintaining security.

Overcoming all these challenges is an ongoing process and it could take years still, to achieve our ideal goal. While the top of this staircase may not be near, each invention takes us a step upward.


Internet of Things

By: Vishesh Berera, BCA 2nd Semester, 2nd Shift

IoT comprises of devices and sensors interacting and communicating with other machines, objects and environments. There will be 26 billion devices connected to each other by 2020. There are still other predictions that put this number at 50 billion devices by 2020. As a result of this exploding growth in the interaction between devices and systems, huge volumes of data are expected to be generated and moved across information processing systems. These raw data will be processed and analysed to generate meaningful information and to perform actionable decision making. The Internet of Things (IoT) is captivating organisations because of its potential to rapidly transform businesses and people’s lives. It is widely believed that IoT will precipitate a major shift in people’s lives similar to how the Internet transformed the way people communicate and share information.

Concerns have been raised that the Internet of Things is being developed rapidly without appropriate consideration of the profound security challenges involved and the regulatory changes that might be necessary. IoT suffers from platform fragmentation and lack of technical standards, a situation where the variety of IoT devices, in terms of both hardware variations and differences in the software running on them, makes the task of developing applications that work consistently between different inconsistent technology ecosystems hard. Customers may be hesitant to bet their IoT future on a proprietary software or hardware devices that use proprietary protocols that may fade or become difficult to customise and interconnect.

IoT's amorphous computing nature is also a problem for security since patches to bugs found in the core operating system often do not reach users of older and lower-price devices. One set of researchers says that the failure of vendors to support older devices with patches and updates leaves more than 87% of active devices vulnerable.

According to the Business Insider Intelligence Survey conducted in the last quarter of 2014, 39% of the respondents said that security is the biggest concern in adopting Internet of Things technology. In particular, as the Internet of Things spreads widely, cyber attacks are likely to become an increasingly physical (rather than simply virtual) threat. In a January 2014 article in Forbes, cybersecurity columnist Joseph Steinberg listed many Internet-connected appliances that can already "spy on people in their own homes" including televisions, kitchen appliances, cameras, and thermostats. Computer-controlled devices in automobiles such as brakes, engine, locks, hood and truck releases, horn, heat, and dashboard have been shown to be vulnerable to attackers who have access to the onboard network. In some cases, vehicle computer systems are Internet-connected, allowing them to be exploited remotely. Later hackers demonstrated remote control of insulin pumps and implantable cardioverter defibrillators.

As a response to increasing concerns over security, the Internet of Things Security Foundation (IoTSF) was launched on 23 September 2015. IoTSF has a mission to secure the Internet of Things by promoting knowledge and best practice. Its founding board is made from technology providers and telecommunications companies including BT, Vodafone, Imagination Technologies and Pen Test Partners. A study by HP’s security unit Fortify found that 70 percent of popular consumer IoT devices are easily hackable. When Kaspersky Lab examined industrial controls systems exposed to the Shodan search engine it found seven percent of 172,982 ICS components vulnerable to attack had “critical” issues.

Some of the simplest IoT devices (or machine-to-machine) devices lack adequate processing power and storage to host endpoint security software. They are real-time OS’s which do not offer support for a wide variety of endpoint protection products. The list of IoT products without the ability to have the firmware updated with security protection is long. In the rush to connect everything to the internet, no one has stopped to think if it should be connected to the internet. Security is taking a backseat to convenience and ease of access. Does it make sense to be able to check your Gmail account on your fridge? Or does a building’s HVAC system really need to be linked to the internet?

Without proper investment in secure protocols, website interfaces, and APIs, the risks associated with IoT seldom outweigh the benefits Internet of Things applications collect tonnes of data. Data retrieval and processing is an integral part of the whole IoT environment. Most of this data is personal and needs to be protected through encryption.

To address this IoT security issue you can use Secure Sockets Layer protocol or SSL wherever your data is present online. Websites already use SSL certification to encrypt and protect the user’s data online. This is only half part of the equation other half is to protect the wireless protocol side. While data is being transferred wirelessly it needs encryption as well. Sensitive data like locations need to be available to be concerned user and no one else. Therefore, make sure you use a wireless protocol with inbuilt encryption.

"Hackers are beginning to realise that the value of protected health information (PHI) is far more valuable than personally identifiable information (PII) and the weakness in the hospital network makes them a greater target than in the past. What makes this extremely dangerous for the patient is that the hacker is tampering with biomedical devices like infusion pumps, which can then become a life-threatening situation," he said.

Among the recent examples, one involves researchers who hacked into two cars and wirelessly disabled the brakes, turned the lights off and switched the brakes full on—all beyond the control of the driver. In another case, a luxury yacht was lured off course by researchers hacking the GPS signal that it was using for navigation.

Home control hubs have been found to be vulnerable, allowing attackers to tamper with heating, lighting, power and door locks, other cases involve industrial control systems being hacked via their wireless network and sensors.

We are already seeing hacked TV sets and video cameras [and] child monitors that have raised privacy concerns, and even hacked power meters which to date have been used to steal electric power, adds Paul Henry, a principal at security consulting firm VNet Security LLC in Boynton Beach, Fla., and a senior instructor at the SANS Institute, a cooperative research and education organization in Bethesda, MD."A recent article spoke of a 'hacked light bulb,'" Henry says. "I can imagine a worm that would compromise large numbers of these Internet-connected devices and amass them into a botnet of some kind. Remember it is not just the value or power of the device that the bad guy wants; it is the bandwidth it can access and use in a DDoS (distributed denial-of-service) attack.

What Can We Do?


While threats will always exist with the IoT as they do with other technology endeavours, it is possible to bolster the security of IoT environments using security tools such as data encryption, strong user authentication, resilient coding and standardised and tested APIs that react in a predictable manner.


Security needs to be built in as the foundation of IoT systems, with rigorous validity checks, authentication, data verification, and all the data needs to be encrypted. At the application level, software development organisations need to be better at writing code that is stable, resilient and trustworthy, with better code development standards, training, threat analysis and testing. As systems interact with each other, it's essential to have an agreed interoperability standard, which safe and valid. Without a solid bottom-top structure we will create more threats with every device added to the IoT. What we need is a secure and safe IoT with privacy protected with the tough trade off but not impossible.

For organisations to realise the full value of IoT, they must address security holistically. First, they need to physically secure IoT, especially sensors and smart meters that are out in the field. Second, they need to secure IoT connections. IoT connection security should provide the ability to easily identify, authenticate, onboard, segment, and monitor connected devices and then enforce access policies consistently and continuously. Finally, they need to secure data collected by IoT devices.