12. mobile devices and the internet of things · 1 12. mobile devices and the internet of things...

31
1 12. Mobile Devices and the Internet of Things Blase Ur, May 3 rd , 2017 CMSC 23210 / 33210

Upload: others

Post on 07-Sep-2019

7 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

1

12. Mobile Devices and

the Internet of Things

Blase Ur, May 3rd, 2017

CMSC 23210 / 33210

Page 2: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

2

Today’s class

• Security and privacy for:

– mobile devices

– the IoT

– safety-critical devices

• Discuss midterm

Page 3: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

3

Mobile Devices

Page 4: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

4

Authentication

Page 5: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

5

Permissions Model for Apps

Page 6: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

6

Phones in the Legal System

• Riley v. California

– SCOTUS 2014

• Unanimous ruling that warrantless search

of a phone during an arrest is

unconstitutional

Page 7: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

7

Mobile Devices

• What are some other key security and

privacy challenges for mobile devices?

– Tracking for advertising

– Tracking using MAC address

– Tracking using accelerometer

– Lack of desktop-based tools

– Authentication of telephone networks

Page 8: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

8

Mobile Devices

• Stingrays (cell site simulator)

Page 9: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

9

Internet of Things

Page 10: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

10

What is the IoT?

Page 11: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

11

What is the IoT?

Page 12: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

12

What is the IoT?

Page 13: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

13

Security Issues in Homes

• Sharing data

– Many users

– Many devices

– Sensitive data

• Access to networks (e.g., wifi)

• Device pairing

Page 14: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

14

Considerations in the Home

• Home as “castle”

• Occupants with social relationships

• Visitors; guests

• Surveillance

• Patching devices

• Side channels

Page 15: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

15

Safety-critical devices

Page 16: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

16

Cars

https://www.youtube.com/watch?v=oqe6S6m73Zw

https://www.youtube.com/watch?v=3jstaBeXgAs

Page 17: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

17

Meta-issues with car privacy/security

• Why are our cars run by computers?

• Why are we connecting our cars to the

Internet?

– Rich media content

– Real-time traffic and safety info

– OTA updates

– Self-driving cars

– (Surveillance)

• Are privacy/security issues the same?

Page 18: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

18

Meta-issues with privacy/security

• Let’s answer the same questions for

medical devices

Page 19: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

19

Implantable Medical Devices (IMD)

Usable Privacy and Security

healthcareitsystems.com

• Embedded computers

• 350K Pacemakers & 173K Cardiac Defibrillators in 2006

Page 20: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

20

Operational Requirements

• Possible goals

– Collect information (diagnostics)

– Provide information (medical history)

– Perform medical function

• Disable IMD before conducting surgeries

• Access in emergency situations

• Constraints

• Limited capacity of battery (replacement = surgery)

Page 21: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

21

Risks in Medical Devices

• Vulnerabilities

– Authentication

• Attack Vectors

– Passive

– Active

• Risks / threats

– DoS

– Changes in configuration

– Replace medical records -- someone having a different operation

– Injuries, death

Page 22: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

22

Hacking Tests (1)

• 2008: wireless access to a combination

heart defibrillator and pacemaker (within

two inches of the test gear)

• Disclose personal patient data

• Reprogram IMD to shut down and to

deliver jolts of electricity that would

potentially be fatal

Page 23: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

23

Hacking Tests (2)2011-2012-2013

• Hacking Insulin Pumps

2013 -- Black Hat /Defcon:

• “Implantable medical devices: hacking humans”

– At 30 feet by compromising their pacemaker

– Transmitter to scan for and interrogate individual medical implants

– Security techniques for manufacturers

-- ioactive.com

-- insulinpump.com

Page 24: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

24

Defense Approaches

• How do we achieve resistance to attacks?

– What are the classes of attacks?

• What can go wrong?

• How do we balance utility and

security/privacy?

Page 25: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

25

Authentication Methods

• Passwords: how to make them available?

– Tattooed passwords (visible, UV visible)

– Bracelet

• Biometrics (face recognition)

• Smart Cards

• Touch-to-access policy

• Key-based systems

• Shields

– Necklace

– Computational wristband

-- Figures from Denning et al.

Page 26: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

26

IMD Shield

- IMDShield -mit.edu

• Proxy (messages exchanges)

• Authentication + encryption (channel)

Page 27: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

27

IMD Shield - Implementation

• Jammer design (full

duplex radio)

- S. Gollakota et al. MIT

Page 28: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

28

Wristbands / Alert Bracelets

• Safety in emergencies

• Security & Privacy under adversarial

conditions

• Battery life

Page 29: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

29

Wristbands / Alert Bracelets

• Protection is granted while wearing the bracelet.

• Remove to gain access to the IMD

• Inform patients about malicious actions – But not preventive

• Authentication + symmetric encryption

• Disadvantages

– Relies on the patient wearing the bracelet

– Reactive

– Cognitive effects on patients

--Denning et al.

Page 30: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

30

Usability Considerations

• Hospitals not having correct equipment

• Visual indicator of patients condition (something is wrong). Personal dignity.

• Carrying one more device

• Aesthetics

– Wristbands (especially). “Mockups are unaesthetic”

– Tattoos

• Mental and physical inconvenience

• Cultural and historical associations

Page 31: 12. Mobile Devices and the Internet of Things · 1 12. Mobile Devices and the Internet of Things Blase Ur, May 3rd, 2017 CMSC 23210 / 33210

31

Electronic Medical Records

• Why do we want electronic medical

records?

• What are privacy/security concerns about

electronic medical records?

• How do we mitigate those concerns?