Iot security issues caused by Honeypot
In recent years, the Internet of Things (IOT) has been around in a fast and secure manner. The evil names of "anything connected to the Internet can be hacked" are also like shadows. In 2015 alone, security researchers discovered vulnerabilities in Iot devices such as baby monitors, skateboards, rifle guns, and jeeps, A investigator controlled a plane for a short time during its flight.
The New York Times commented:
"Relying on convenient and safer selling points, Iot products are widely favored. On the contrary, this is a high-speed train that frequently fails on a private and secure track ."
Concerns about Iot devices are not just beginning. Security researchers have been warning millions of Iot devices that are vulnerable to security risks and attacks. According to statistics from the U.S. Department of Homeland Security's network attack defense branch, nearly 245 security incidents were reported last year.
How are those devices hacked?
For in-depth research, researchers have established the "Iot honeypot", which is used to find hackers who launch attacks against online gas stations and medical devices and to study their attack behavior.
Within six months, TrendMicro has established a number of online gas stations with poor protection measures in seven countries to see what will happen? Earlier this year, researchers HD Moore revealed that more than 5000 gas stations connected to the network do not have password settings, which means attackers can directly access and destroy them, by changing the settings, the original full pump is displayed as null, which eventually leads to overflow.
This project eventually found a total of 20 attacks:
Trend Micro: Some attacks are just simple detection of gas station locations. American gas stations are the "most popular" target.
Two denial-of-service attacks targeting U. S. gas stations are considered to be related to the Syrian electronic army, a Syrian hacker group, although the researchers cannot say for sure that the attack is absolutely what they did.
In Jordan, the gas stations of the American Oil Company and the American oil company appeared to have been visited by hackers related to the "Iran hacker group, they just changed the pump name from "lead-free" and "diesel" to "IDC organization to this tour" and "Ahaad here. Of course, this is also an attack type, but most of them are not actually aggressive.
Although the researchers are not sure, no attackers have attempted to change the energy level settings, and such behavior can cause very serious damage.
"More serious attacks will appear soon"
Said Kyle Wilhoit at the 55blackhat Black Hat conference.
Coincidentally, at Defcon, another hackers' conference, the researchers said they have studied the Internet of Things including insulin pumps, pacemakers, MRI machines, and other medical control device systems. In a honeypot test, you can obtain control of these devices only by using the common user name and password from the manufacturer's website. Of course, some vendors put passwords and user names in a Pastebin file, which is essentially "there are user names and passwords for some medical devices. If someone wants to attack them, ".
These "honeypot" medical devices have been logged on more than 55000 times and installed with malware more than 300 times. There are 24 instructions and 8 logon creden with special creden---that is, someone can open the Pastebin file to abuse the information in it.
Attackers can access the honeypot of medical devices.
According to the data above, most of the attacks originated from the Netherlands, China, and South Korea, said Scott Erven, Chief Research Institute of Protibiti, "these attacks are basically not targeted attacks ."
Most attackers are only doing simple "exploration" to map the IOT layout. However, Erven said that they can easily access the hospital's drug devices, and attackers can also obtain information from these devices. As long as you enter a ECG machine, in theory, you can get information about patients using this device, such as their names, social security numbers, and dates of birth.
In real life, malware can also interfere with the operation of medical devices. "If a large-scale attack causes a device failure, we cannot immediately know this ."
However, with these "honeypot", medical device security researchers have not discovered any obvious malicious attacks, such as making pacemakers abnormal or injecting patients with excessive insulin.
"They (hackers) have System Management permissions, but they do not send commands. They may not realize that they have obtained root permissions for an MRI machine ."
Therefore, should we pay attention to this situation? Attackers can access these systems only once. They seem to be not interested in attacking these devices or harming people.
Iot security: a time bomb?
Andy Thurai from IBM said that the development of technology is far beyond the improvement of the enterprise's own security maintenance capabilities, and the IOT brings together a variety of sensors and components in the network. The company has not paid the appropriate fees for its security business. Although it has started to grow, it is far from enough, while Iot makes everything worse. Therefore, Iot is a time bomb.
According to the IOT report, as one OF the important wireless interconnection standards widely used to connect the above devices, ZigBee technology was also revealed to have serious security vulnerabilities at the recently held 2015 Black Hat conference, this has aroused widespread attention in the industry.
FreeBuf has previously discussed the blue ocean strategy of Iot security. ZigBee is a low-cost, low-power, and close-range wireless networking communication technology. It is widely used in a large number of emerging Iot devices, such as smart bulbs, smart door locks, motion sensors, and temperature sensors. However, researchers have found that there is a serious defect in the implementation method of ZigBee technology. hackers may harm the ZigBee network by involving multiple types of devices, and "take control of all connected devices in the network ". As a result, it may bring security risks to a large number of Iot products.
A recent research report shows that the market for small-scale technical solutions and services for Iot security will surge, and the market for Iot security will grow to $2020 in 28.9 billion.
Of course, not everyone is right about the endless Iot security incidents.
Security researcher Dan Tentler believes that,
"It is very difficult to study Iot device vulnerabilities. To attack the jeep, the investigator had to buy one and spend a year studying the code. When attackers enter these 'honeypot, they may still have no idea what to do ."