Physical AI HBM Smart Factory SDV AIoT Power Semicon 특수 가스 정정·반론보도 모음 e4ds plus

How to deal with growing IoT security threats?

Google 우선 소스 기사입력2019.09.30 17:11

| 14.6 billion IoT devices will be connected by 2022
| There are no IoT security component technology standards or specifications yet
| Most of the overseas IoT-related security guides are in early versions



Cisco predicted in its Visual Networking Index report that the number of connected devices worldwide will reach approximately 28.5 billion by 2022. More than half of those, or 14.6 billion, will be IoT devices that connect machines to machines.
It is expected that approximately 14.6 billion IoT devices will be in operation in 2022.

IoT devices that are based on the Internet from the beginning are all bound to be targets of hacking. IoT devices have various types and functions and must operate with minimum processing performance and memory, so it is not easy to install security solutions. Although interest and demand are increasing, security awareness is low, so there are more diverse security threats than before.

Domestic companies' spending on IoT security is increasing. However, LG Uplus' Choi Dong-jin points out that the company is still vulnerable to security issues as it selects products and services as stopgap measures rather than strategically establishing IoT security policies and implementing security architectures accordingly.

The absence of specific regulations creates a security vacuum. Compliance is the most important factor in IoT security. IoT security requires an IoT management platform that covers device management, connection management, application management, reporting, and analytics.

However, since there are no technical standards or specifications for security components of IoT yet, the government or standardization organizations must implement these to institutionalize IoT security.


IoT vulnerability defense failure case
The following are examples of IoT vulnerabilities that were attacked by attempting to access devices using automated attack tools, stealing power and video information, and hacking IP cameras.

Russia's Insecam hacked and live-streamed about 73,000 IP cameras around the world, and about 6,000 IP cameras in Korea were hacked as well. Hackers hacked IP cameras that had not changed their default settings when they were released, and they also used Google Maps, which can show latitude and longitude, to steal video information from various places such as homes and offices. Even when IoT vulnerabilities are discovered and patched, there are many cases where users do not update the patches, leaving them defenseless.

Attackers at DNS hosting company Dyn took advantage of known vulnerabilities and default password settings in IoT devices, using malware called Mirai to hijack IoT devices and launch a Denial of Service (DOS) attack on Dyn. This caused major websites managed by Dyn to become crippled, including Twitter, Netflix, PayPal, and major media outlets. Mirai developers have released their source code, which has led to continued emergence of variant malware.

The Korea Internet & Security Agency (KISA) is implementing an IoT vulnerability reporting reward system, and the number of reports is continuously increasing. The diversity of IoT security threat scenarios is also increasing.
CCTV vulnerable to hacking causes invasion of privacy

Hacking into CCTV or cameras mounted on robot vacuum cleaners to leak private footage, hacking into home IoT to turn the house into a mess, and hacking into the shared key of a router to insert malware and use it as a DDoS attack point are just a few examples.

There are cases where they hack into the control systems of factories or public facilities, causing fatal accidents, and even medical devices such as insulin pumps, causing death by injecting patients with lethal doses.


IoT Security, Security Internalization is Essential
While PCs and mobile devices can provide a secure environment in high-power, high-performance environments, IoT devices must implement security functions with low-power, low-performance resources, so it is essential to incorporate security from the design stage.

In June 2016, the government launched the 'IoT Security Alliance' and announced a security guide for internalizing IoT security, thereby responding to IoT security threats. The medical sector, the Ministry of Food and Drug Safety, and the Korea Internet & Security Agency are proposing IoT common security principles, IoT common security guide, and home appliance IoT security guide. The seven IoT common security principles established here are as follows.

▲Design of IoT products and services considering information protection and privacy enhancement ▲Application and verification of safe software and hardware development technology ▲Provision of safe initial security settings ▲Compliance with security protocols and safe parameter settings ▲Continuous implementation of security patches and updates for vulnerabilities in IoT products and services ▲Establishment of information protection and privacy management system for safe operation and management ▲Establishment of IoT breach response system and accountability traceability measures


IoT Security Guide Status
Due to security issues in IoT products and services, various types of IoT security guides are also being presented. Compared to the existing fragmentary issues and countermeasures, the Information-technology Promotion Agency (IPA) of Japan, the Global System for Mobile Communications Association (GSMA), the international web security standards organization OWASP (The Open Web Application Security Project), and the international cloud security association CSA (Cloud Security Alliance) have announced various types of security guides, including security requirements and countermeasures for secure design and development of IoT devices and safe service operation.
Current status of overseas IoT security guides
(Table = Next-generation IoT security in the 5G era, Dongjin Choi)

On June 27, 2018, global mobile operators announced that they would adopt and implement the GSMA IoT Security Guidelines. These guidelines describe a comprehensive security assessment system to determine whether IoT services in the IoT ecosystem have sufficient security measures in place to address security risks.

The GSMA’s IoT Security Guidelines are aimed at IoT service providers, device manufacturers, developers and mobile operators, and provide industry-wide best practices for designing, developing and deploying highly secure IoT solutions.

These guidelines also address common cybersecurity and data privacy issues associated with IoT services and are supported by an IoT Security Assessment scheme that provides a checklist to support the launch of IoT solutions and aims to create an IoT ecosystem that maintains high security across services.

GSMA's IoT Security Guidelines and IoT Security Assessments target rapidly growing mobile IoT technologies, including LPWA and LTE-M and NB-IoT.

Although the security guides are presented from different perspectives based on different criteria such as security vulnerabilities, the life cycle of IoT devices, and components of IoT services (terminals, networks, and services) depending on the characteristics of the institutions and organizations developing the security guides, most of the guide contents are similar, including many general security requirements for terminals, networks, and services that make up IoT.

GSMA presents IoT security guidelines

Most of the overseas IoT security guides released so far are in their early versions and do not present specific technologies or detailed security measures as countermeasures for security requirements that vary by industry sector for IoT services. For this reason, overseas IoT security guides present general security measures based on the current state of IoT technology and status, and the contents of IoT security guides are expected to be updated in the future according to the development and advancement direction of IoT technology.


To improve IoT security level
It is realistically difficult for individuals to handle security issues regarding IoT, which is already widely distributed and is becoming widespread.

Security threats to IoT products and services can be addressed almost entirely with a well-defined architecture, the ability to identify risks before and after a security incident, and well-established policies and procedures for handling incidents.

If you ask IoT service providers what security concepts are important, you can get help solving the most urgent vulnerabilities. If security questions and concerns are revealed at the time of implementation, shared from an organizational perspective, countermeasure strategies are developed, and the skills and knowledge of various people are built into a database, you can prepare for IoT security.

LG Uplus’s Dongjin Choi emphasized that “fostering a security ecosystem through a platform hub for government and industry-academia-research collaboration” is important for the IoT security ecosystem.
이수민 기자
기사 전체보기