disclosing vulnerabilities and breaches in the …...•the “internet of things” puts computers...

19
Disclosing Vulnerabilities and Breaches in the ‘Internet of Things’ Ross Anderson Cambridge CEPS, Sep 27 2017

Upload: others

Post on 15-Aug-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

DisclosingVulnerabilitiesandBreachesinthe‘InternetofThings’

RossAndersonCambridge

CEPS,Sep272017

Page 2: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

WhatwilltheIoT change?

• PrivacymadetheearlyrunningwiththesmartTVandtheCayla doll– butyourphonealreadyhearseverythingandisfullofadware

• Denial-of-servicewasnextwiththeMiraibotnet– butwealreadyhavebotnets

• Butsafetylooksliketherealpressurepoint• Phonesandlaptopsdon’tkillmanypeopledirectly;carsandmedicaldevicesdo…

CEPS,Sep272017

Page 3: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

HowdoesIoT changesafety?

• Eireann Leverett,RichardClaytonandIdidaprojectfortheEuropeanCommission

• TheEUhascomplexregulatoryregimesforthesafetyofallsortsofdevices

• Howwillthesehavetochangeoncethere’ssoftwareeverywhere?

• Welookedspecificallyatvehicles,medicaldevices,andelectrotechnical equipment

• Butthelessonsaremorewidelyapplicable!

CEPS,Sep272017

Page 4: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

EUproblemstatement• Weregulatesafetyinmanyindustries• The“InternetofThings”putscomputersandcommunicationseverywhere

• Thiscreatesnewsafetyrisksaroundsecurity• Indeed,thetwoarethesameinthelanguagesspokenbymostEUcitizens(sicurezza,seguridad,sûreté,Sicherheit,trygghet…)

• Howdoweupdatesafetyregulation(andsafetyregulators)tocope?

CEPS,Sep272017

Page 5: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Background

• Marketsdosafetyinsomeindustries(aviation)waybetterthanothers

• CarsweredreadfuluntilNader’s‘UnsafeatAnySpeed’firedupthepublic,gotinsuranceindustryinvolvementandledtotheNHTSA

• IntheEU,wegottheProductLiabilityDirective85/374/EES,FrameworkDirective2007/43/EContypeapproval,andmuchmuchelse

• Broadprinciples,plusmanydetailedrules

CEPS,Sep272017

Page 6: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Background(2)

• Traditionalcarmakersmovingtoautonomyinsteps(adaptivecruisecontrol,automaticemergencybraking,automaticlanekeeping…)

• TeslahasalreadymovedtoregularupgradesandthelegacyOEMsareracingtofollow

• Butmanagingvulnerabilitiesishard,andexpensive:Androidispatchedfor3years,Windowsfor5

• Sohowwillwepatcha2017carin2037?

CEPS,Sep272017

Page 7: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

CEPS,Sep272017

Page 8: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

CEPS,Sep272017

Page 9: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Background(3)• TheMedicalDeviceDirectives(90/385EEC,93/42/EEC,98/79/EU)arenowbeingrevised

• ResearchbyHaroldThimbleby:intheUK,hospitalsafetyusabilityfailureskillabout2000p.a.(aboutthesameasroadaccidents)

• Priority:getregulatorstodopost-approvalstudiesandadverseeventreporting

• Atpresentdevicesaretypicallyapprovedonpaperworkalone

• Evenlesspost-marketfeedbackthaninpharma…CEPS,Sep272017

Page 10: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Background(4)

• Usabilityfailuresthatkillaretypicallyblamedonthenurse(ifnoticedatall)

• Butattacksaremuchhardertoignore– a2015wifi tamperingdemoledtheFDAtoblacklisttheHospira Symbiq infusionpump

• 2017:recallof450,000StJudepacemakers• Butsoftwareupgradescanbreakcertification!• Propersafety/securitylifecycleisneeded

CEPS,Sep272017

Page 11: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

TheBigChallenge

• Establishednon-ITindustriesusuallyhaveastaticapproach– pre-markettestingwithstandardsthatchangeslowlyifatall

• Thetimeconstantistypicallyadecade• Whenmaliciousadversariescanscalebugsintoattacks,industrieswillneedadynamicapproachwithpatching,asinIT

• Thetimeconstantisthentypicallyamonth

CEPS,Sep272017

Page 12: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Broadquestionsinclude…

• Whowillinvestigateincidents,andtowhomwilltheybereported?

• Howdoweembedresponsibledisclosure?• Howdowebringsafetyengineersandsecurityengineerstogether?

• Willregulatorsallneedsecurityengineers?• Howdowepreventabusivelock-in?NotetheUSDMCAexemptiontorepairtractors…

CEPS,Sep272017

Page 13: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

InstitutionalPlayers• DozensofEuropeanregulators(+hundredsinMemberStates)

• Standardsbodies(UNECE,ETSI,CEN,CENELEC)• Safetylabs(KEMA,EuroNCAP,…)• Securitylabs(CLEFs,Underwriters’Labs,commercialpentesters,ENCS,academics…)

• OthercustodiansofthemanysafetyandsecuritystandardsincludingNIST,IEEE,IEC

• Otherprincipals,e.g.insuranceindustry

CEPS,Sep272017

Page 14: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Policyrecommendationsincluded• Requirevendorstoself-certify,fortheirCEmark,thatproductscanbepatchedifneedbe

• Requireasecuredevelopmentlifecyclewithvulnerabilitymanagement(ISO29174,30111)

• CreateaEuropeanSecurityEngineeringAgencytosupportpolicymakers(now:ENISA)

• ExtendProductLiabilityDirectivetoservices• UpdateNISDirectivetoreportbreachesandvulnerabilitiestosafetyregulatorsandusers

CEPS,Sep272017

Page 15: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Translatingthistoengineering• Theproblemasalwayswillbescale• Europehas50,000fatalaccidentsayearandtentimesthatmanycausingseriousinjury

• Futurecarswillgeneratevastamountsofdata• Howdotherightdatagettotrafficcops,insurers,safetyregulatorsandothers?

• Wecan’tjustreportvulnerabilitiesandbreachestoENISA/SIAs/DPagencies!

• Culturechangetoo(e.g.VWvBirmingham)CEPS,Sep272017

Page 16: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Implicationsforcomputerscience• Computersciencehasalwaysbeenaboutmanagingcomplexity

• Safety-criticaldurablegoods,online,andcomposedofheterogeneouscomponentsfrommutuallymistrustfulsuppliers,arethenewgrandchallenge

• SincedoingthisprojectI’vestartedteachingsafetyandsecuritytogetherinthesamecoursetofirst-yearundergraduates

CEPS,Sep272017

Page 17: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Conclusions• TheEUregulatessafetyindozensofindustries• Oncesafety-criticalgoodscanbeattackedonline,it’spatchorscrap

• Fordurablegoodslikecarsandmedicaldevices,thiswillbeareallyreallybigdeal

• Tomanagetheecosystem,avastamountofdataonvulnerabilities,breachesandaccidentswillhavetobemanaged

• Manypolicychallengeslieahead!CEPS,Sep272017

Page 18: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

More…

• Ourpaper“Standardisation andCertificationintheInternetofThings”isonmywebpagehttp://www.cl.cam.ac.uk/~rja14/

• Orsee“WhenSafetyandSecurityBecomeOne”onourblog

https://www.lightbluetouchpaper.orgwhichalsohasacoupleofvideos

Cambridge,Sep2017

Page 19: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

CEPS,Sep272017