The rise of IoT and what it means for security
From the voice assistant to the connected coffee machine: what connected devices do to the attack surface at home and at work, and where their security falls down.
Vom Sprachassistenten bis zur vernetzten Kaffeemaschine: was vernetzte Geräte für die Angriffsfläche im Haushalt und im Unternehmen bedeuten und woran ihre Sicherheit scheitert.
The Internet of Things (IoT) covers every smart device that is connected to the internet and behaves like a small computer. Voice assistants such as Amazon Echo or Google Home let us control our homes by speaking. There are smart fridges, door locks and coffee machines; a great many household appliances now carry IoT capability and have become part of daily life.
The technology brings problems with it too, above all in security. This article looks at the rise of the Internet of Things and what it means for security in practice.
How fast IoT has spread
Number of devices connected to the Internet of Things worldwide to 2030. Published by Statista Research Department, 3 January 2024
The number of IoT devices worldwide has risen from 8.6 billion in 2019 to 15.14 billion. By 2030 it is expected to almost double again, to 29 billion devices.
That raises questions about security management, data protection and the long-term sustainability of this infrastructure, because these devices are targets.
Why securing IoT is hard
The Internet of Things has opened up a great deal and made a lot of everyday things easier.
It also brings a set of problems that come with adopting these devices at this scale.
The largest of them is security. Many IoT devices were built with inadequate security, and those weaknesses leave them open to several kinds of attack.
The most common attacks on IoT devices
-
Denial-of-service attacks: a DoS attack tries to affect the availability of a service or resource by overloading the target device or network resource, for instance by sending a large number of requests from compromised IoT devices until the target fails.
-
Botnet attacks: attackers can infect a large number of IoT devices and combine them into a botnet. Those botnets are then used for DDoS attacks, sending spam, cryptocurrency mining or other purposes.
-
Physical attacks: attackers can also gain physical access to IoT devices to manipulate, damage or steal them, which can compromise confidential data or stop the devices working properly.
-
Man-in-the-middle attacks: an attacker listens to the traffic between an IoT device and its destination and can manipulate or intercept the data in order to take or alter confidential information.
-
Firmware hacking: attackers try to alter the firmware of IoT devices to place malicious code or exploit weaknesses and take control of the device.
-
Password and authentication attacks: some IoT devices can be compromised through brute force or weaknesses in authentication, which gives attackers access to sensitive data or functions.
These are only some of the possibilities. Manufacturers and users need to know what the threats are and take appropriate measures.
Why security matters here
Security is a continuous process that takes ongoing effort to keep up with how the threats develop.
Some of the reasons it matters in this field:
-
Protecting privacy: many IoT devices collect personal and sensitive data about their users. Without adequate security that information can end up in the wrong hands and be misused.
-
Keeping systems intact: IoT devices often control critical systems and processes, from smart home devices through to industrial control systems. Compromising them can have serious consequences for the integrity and function of those systems.
-
Preventing outages: attacks on IoT devices can disrupt services and infrastructure, with outages, interruptions and lost productivity. That affects individuals, companies and operators of critical infrastructure alike.
-
Avoiding financial loss: IoT attacks cause financial damage too, through theft, failed services or lost business after damage to a reputation.
-
National security: in some cases IoT attacks can affect national security, in particular where they reach critical infrastructure such as power grids, water supply or transport.
Meeting those threats takes a complete and proactive approach: solid security measures at device level, encrypted data transmission, regular review and updating of security policy, and training for users and developers on security practice.
What helps
A survey asked organisations about their main security concerns when adopting IoT. The figure below shows those concerns, from the IoT Signals report published in October 2021.
- Ensuring data protection (46%).
-
Ensuring security at network level (40%).
-
Security endpoints for each IoT device (39%).
-
Tracking and managing each IoT device (36%).
-
Making sure all existing software is updated (35%).
-
Updating firmware and other software on devices (34%).
-
Hardware and software testing and device evaluation (34%).
-
Updating encryption protocols (34%).
-
Training programmes for staff working in the IoT environment (33%).
-
Secure provisioning of devices (33%).
-
Moving from device-level control to identity-level control (29%).
-
Changing default passwords and credentials (29%).
The steps below let people without a security background protect their own IoT devices and reduce the risk of an attack or a data breach.
-
Password management: use strong and unique passwords for your IoT devices and accounts. Avoid default passwords and change them regularly. Use a separate password for every device and application.
-
Regular updates: make sure your IoT devices are updated regularly. Check the settings to enable automatic updates where possible, and look for available updates yourself.
-
Check the security settings: go through the security settings of your IoT devices and enable the security functions such as firewalls and encryption options where they exist.
-
Secure the network: protect your home network with a strong password and use a firewall to keep unwanted access out. Use separate networks for IoT devices and personal devices to reduce the risk.
-
Use devices and applications you can trust: buy IoT devices from manufacturers you trust and read the privacy policy and the security functions before you buy. Download applications for your devices from official app stores only.
-
Watch the data: pay attention to what data your IoT devices collect and how it is used. Read the privacy policy and check the settings to limit collection where you can.
-
Stay alert: watch for suspicious activity or unusual behaviour from your IoT devices. Report suspicious incidents or security problems to the manufacturer or your internet provider.
In short
The Internet of Things puts connected devices into everyday life, and it brings new security risk with it. Meeting that risk takes a strategy rather than a single measure: strong passwords, regular updates, network segmentation and user training. That is what lets the technology be used without giving away the data and systems behind it.