{"id":17686,"date":"2018-03-27T10:51:41","date_gmt":"2018-03-27T09:51:41","guid":{"rendered":"http:\/\/www.intelligentcio.com\/africa\/?p=17686"},"modified":"2018-03-27T10:51:41","modified_gmt":"2018-03-27T09:51:41","slug":"opinion-how-an-iot-hack-could-be-a-line-from-a-modern-day-cartoon","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2018\/03\/27\/opinion-how-an-iot-hack-could-be-a-line-from-a-modern-day-cartoon\/","title":{"rendered":"Opinion: How an IoT hack could be a line from a modern-day cartoon"},"content":{"rendered":"<p>Bryan Hamman, Arbor Networks&#8217; territory manager for Sub-Saharan Africa, says hackers go after data because it\u2019s valuable and can be used for gain.<\/p>\n<p>For movie buffs and television fans, some lines are enduring classics. For example, how many times have you heard the phrase: \u201cStep away from the vehicle?\u201d in one form or another? From movies like <em>The Saint<\/em> (1997) and <em>Herbie Fully Loaded<\/em> (2005), to television classics like <em>Law &amp; Order: Special Victims Unit, That 70s Show, Blue Bloods<\/em> and <em>JAG<\/em>, this is a phrase that has endured. The fun part is that the audience usually knows what\u2019s coming next \u2013 common responses include someone running away, driving away or pulling a gun on the police officer issuing the command.<\/p>\n<p>In contrast, there is not a standard response to this command: \u201cStep away from the fish tank \u2013 it\u2019s locked and loaded!\u201d &#8211; which is perhaps why it\u2019s not yet become part of movie and television history. However, as per a recent incident in which 10 gigabytes of data was stolen from a casino, there might in fact be a very good reason to step away from the fish tank and towards the relevant threat intelligence experts instead. So how did the phrase \u201cStep away from the fish tank!\u201d come to enter this narrative?<\/p>\n<p>Well, as they say in some movies (usually the animated ones), \u201cOnce upon a time, there was a casino somewhere in the US and this casino had, as one of its soothing background features, a rather impressive fish tank, which was linked to the Internet for remote monitoring, temperature and salinity adjustment and feeding schedules for the fish. It was a very lovely and unusual example of the Internet of Things (IoT). One day, the beautiful, smart IoT fish tank was attacked by hackers, who used the internet to infiltrate the fish tank system and thereby the bigger network of the casino, from which they stole 10Gb of data before, finally, the intelligence experts managed to establish that the \u2018smart\u2019 fish tank installed in the casino was being used as a conduit to hack data.\u201d<\/p>\n<p>Doesn\u2019t that sound like the most remarkable type of modern fairy tale? You can almost see the animation studios jumping up and down to get their hands on the script. But the thing is, it\u2019s simply not a story, however modern it might sound \u2013 it\u2019s based in reality, albeit of the most far-fetched kind.<\/p>\n<p>\u201cThis interesting story showcases some points about data that are good to remember,\u201d said Hamman.<\/p>\n<p>\u201cFirstly, we are reminded about the value of data \u2013 hackers go after data because it\u2019s valuable and can be used for gain. In this case, there were the casino patrons\u2019 personal and financial details potentially at stake. Secondly, we remember that hackers today are resourceful and IoT only adds to their possible exploitation points. Thirdly, once they\u2019re into the system, they\u2019ll find a way to get the data out.<\/p>\n<p>\u201cIn the case of the fish tank, its internet communications with the casino\u2019s network seemed to continue as normal. However, in addition to the normal operations, the fish tank system was also sending data to a remote server in Finland. It was a clear case of data exfiltration, and a very clever one at that.\u201d<\/p>\n<p>Hamman added that the ongoing growth in the number of online devices will lead to potential system compromises and security risks in the most unusual ways, as outlined above.<\/p>\n<p>\u201cThe greater the expansion of the Internet, the more scope there is for hackers to infiltrate Internet-connected devices, which may include PCs, servers, mobile devices and IoT devices and then infect and control them through <a href=\"http:\/\/searchsecurity.techtarget.com\/definition\/malware\">malware<\/a>,\u201d he said.<\/p>\n<p>\u201cThe fish tank example is obviously a very unusual case \u2013 more \u2018routine\u2019 IoT devices which can be hacked generally include webcams, digital video recorders (DVRs) and cable and satellite television set-top boxes. The lesson to learn is that, while the IoT brings the promise of efficiency and innovation to the enterprise, it also profoundly expands the threat surface for your organisation.\u201d<\/p>\n<p>IoT devices are attractive to attackers because so many are shipped with insecure defaults, including default administrative credentials, open access to management systems via the Internet-facing interfaces on these devices and shipping with insecure, remotely exploitable code. A large proportion of embedded systems are rarely if ever updated to patch against security vulnerabilities \u2013 indeed, many vendors of such devices do not provide security updates at all. Embedded IoT devices are often low-interaction \u2013 end-users don\u2019t spend much time directly interfacing with them, and so aren\u2019t given any clues that they\u2019re being exploited by threat actors to launch attacks.<\/p>\n<p>\u201cIn these times of expanding IoT surfaces, organisations are advised to defend against malware attacks, including Distributed Denial of Service (DDoS) attacks, by implementing best current practices for DDoS defence and making sure that they have complete visibility into all traffic entering and leaving from their networks,\u201d said Hamman.<\/p>\n<p>\u201cOther advice includes practical suggestions like changing the default password of your IoT device once it\u2019s been installed and placing IoT devices onto separate networks to limit the number of routes into your network. Nobody wants their company to enter digital history under the title of \u2018World\u2019s Weirdest IoT Hacks\u2019, but this day could well be coming &#8211; I don\u2019t think that the fish tank hack is going to remain an unusual incident for too much longer.\u201d<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Bryan Hamman, Arbor Networks&#8217; territory manager for Sub-Saharan Africa, says hackers go after data because it\u2019s valuable and can be used for gain. For movie buffs and television fans, some lines are enduring classics. For example, how many times have you heard the phrase: \u201cStep away from the vehicle?\u201d in one form or another? From [&hellip;]<\/p>\n","protected":false},"author":25,"featured_media":17687,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,136,6,399],"tags":[560,561,563,155,101],"class_list":["post-17686","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-industry-expert","category-insights","category-more-news","tag-arbor-networks","tag-bryan-hamman","tag-distributed-denial-of-service","tag-internet-of-things","tag-malware"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/17686","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=17686"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/17686\/revisions"}],"predecessor-version":[{"id":17688,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/17686\/revisions\/17688"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/17687"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=17686"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=17686"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=17686"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}