iot & byod – the new security risks (v1.1)

43
Delivering the best in z services, so2ware, hardware and training. Delivering the best in z services, so2ware, hardware and training. World Class z Specialists IoT & BYOD - The New Security Risks Rui Miguel Feio – Security Lead

Upload: rui-miguel-feio

Post on 15-Apr-2017

191 views

Category:

Internet


0 download

TRANSCRIPT

Page 1: IOT & BYOD – The New Security Risks (v1.1)

Deliveringthebestinzservices,so2ware,hardwareandtraining.Deliveringthebestinzservices,so2ware,hardwareandtraining.

WorldClasszSpecialists

IoT&BYOD-TheNewSecurityRisks

RuiMiguelFeio–SecurityLead

Page 2: IOT & BYOD – The New Security Risks (v1.1)

Agenda•  Introduc:on•  TheInternetOfThings(IoT)•  BringYourOwnDevice(BYOD)•  ExposingtheMainframe•  OnaniceSundaymorning…•  WhattoDo?•  ReferencesandResources•  Ques:ons?

Page 3: IOT & BYOD – The New Security Risks (v1.1)

Introduc:on-RuiFeio–  SecurityleadatRSMPartners

–  Beenworkingwithmainframesforthepast17years

–  StartedasanMVSSystemsProgrammerwithIBM

–  Specialisesinmainframesecurity

–  Experienceinnon-mainframeplaUormsaswell

–  Beengivenpresenta:onsallovertheworld

Page 4: IOT & BYOD – The New Security Risks (v1.1)

TheInternetofThings

Page 5: IOT & BYOD – The New Security Risks (v1.1)

IoT–Whatisit?–  IoTstandsforInternetofThings

–  Termusedtodescribephysicalobjectsthatcancommunicatewitheachotherandcompletetaskswithoutanyhumaninvolvementhavingtotakeplace.

–  Examples:•  Vehicles,appliances,buildings,…•  Anyitemembeddedwithelectronics,so2ware,sensors,andnetworkconnec:vity

Page 6: IOT & BYOD – The New Security Risks (v1.1)

IoT–Somenumbers•  AstudyconductbytheGartnersays:

–  Morethan4.9billionIoTconnecteddevicesin2015

–  6.4billionIoTconnecteddevicesin2016

–  Morethan20billionIoTconnecteddevicesin2020

•  ACISCOreportpredictstherewillbe50billionIoTconnecteddevicesin2020!

Page 7: IOT & BYOD – The New Security Risks (v1.1)

IoT–It’sheretostay

Page 8: IOT & BYOD – The New Security Risks (v1.1)

IoT–Theproblem•  Trendyfashionabledevicesareproducedtoappealtothetechnical

savvyconsumers

•  ButthemanufacturersofIoTdevicestendnottohavesecurityinmind

•  Somedeviceslikerouters,havethefirmwarecustomisedbytheInternetServiceProviders(ISP):–  Don’tallowfirmwareupdatesdirectlyfromthemanufacturer–  Don’tprovidecustomisedupdatedversionsofthefirmware

Page 9: IOT & BYOD – The New Security Risks (v1.1)

IoT–Thisleadsto…

Page 10: IOT & BYOD – The New Security Risks (v1.1)

IoT–Andto…

Page 11: IOT & BYOD – The New Security Risks (v1.1)

IoT–Andevento…

Page 12: IOT & BYOD – The New Security Risks (v1.1)

IoTandCyberCrime•  HPstudyreveals70%ofIoTdevicesarevulnerabletoafacks

•  Cybercriminalsareworkingonnewtechniquesforgehngthroughthesecurityofestablishedorganisa:onsfocusingonIoT:–  Homeappliances–  Officeequipment–  Smartdevices

•  IoTdevicesareeasiertohackastheydon’thaverobustsecuritymeasures

Page 13: IOT & BYOD – The New Security Risks (v1.1)

IoT–Howtohack?•  Thereareseveralresourcesavailableintheinternetanddarkweb:

–  Websites–  Blogs–  Forums–  So2waretools–  Scripts–  Vulnerabili:es–  Specialisedsearchengines

Page 14: IOT & BYOD – The New Security Risks (v1.1)

Shodan–TheIoTSearchEngine

hAps://www.shodan.io/

Page 15: IOT & BYOD – The New Security Risks (v1.1)

Shodan–AnExample

Page 16: IOT & BYOD – The New Security Risks (v1.1)

IoT-TheHeadofUSintelligence

Page 17: IOT & BYOD – The New Security Risks (v1.1)

IoT–TheNSAChiefofTAO

Page 18: IOT & BYOD – The New Security Risks (v1.1)

IoT–TheRisk•  YourhomenetworkcanbecompromisedbyoneofyourownIoT

devices•  HowsecureareyourIoTdevices?•  Howfrequentlydoyouupdatethefirmwareandso2wareofthe

devices?•  AretheIoTdevicess:llsupportedbythemanufacturer?•  Youconnectfromhometoyourcompany’snetwork•  Whatwillithappenifyourhomenetworkiscompromised?•  Howlongwillittakeforahackertoexploitthissecurityflaw?

Page 19: IOT & BYOD – The New Security Risks (v1.1)

IoT–TheRisk@Home

Page 20: IOT & BYOD – The New Security Risks (v1.1)

BringYourOwnDevice

Page 21: IOT & BYOD – The New Security Risks (v1.1)

BYOD–Whatisit?•  BYODstandsforBringYourOwn

Device•  It’sbecomingthestandardwhich

allowsemployeestousetheirownpersonaldevicestoaccessthecompany’snetworkremotely,eitherfromtheirhomeloca:onorfromtheworkplace

•  Seenbycompaniesasawaytoreducecosts

Page 22: IOT & BYOD – The New Security Risks (v1.1)

BYOD–SomenumbersAstudyfromGartner:

•  38%ofUSCIOswereexpectedtosupportBYODbytheendof2012

•  82%ofsurveyedcompaniesin2013allowedsomeorallworkerstouseemployee-owneddevices

•  By2017halfofallemployerswillu:liseBYODdevicestoreducecostsandincreaseusabilityintheworkplace.

Page 23: IOT & BYOD – The New Security Risks (v1.1)

BYOD–Theproblem•  Therearealargenumberofsecurityrisks:

–  Asthedeviceisownedbytheemployee,itisalsousedfortheirownpersonaluse

–  Theorganisa:onhaslimitedcontrolovertheBYODdevicesandhowtheyareused

–  IftheBYODdevicebecomesinfectedorcompromised,theafackercouldusethisasaplaUormtoafackthecompany’snetwork

Page 24: IOT & BYOD – The New Security Risks (v1.1)

BYOD–Thisleadsto…

Page 25: IOT & BYOD – The New Security Risks (v1.1)

BYOD–Andto…

Page 26: IOT & BYOD – The New Security Risks (v1.1)

BYODandCyberCrime•  IntheUKinadocumenten:tled”10StepstoCyberSecurity”the

GCHQhasadvisedbusinessestoconsiderbanningbringyourowndevice(BYOD)becausestaffrepresentthe"weakestlinkinthesecuritychain”

•  Approximately22%ofthetotalnumberofmobiledevicesproducedwillbelostorstolenduringtheirlife:me,andover50%ofthesewillneverberecovered

•  AccordingtoKaspersky,98%ofiden:fiedmobilemalwaretargettheAndroidplaUorm,andthenumberofvariantsofmalwareforAndroidsgrew163%in2012comparedwith2011.

Page 27: IOT & BYOD – The New Security Risks (v1.1)

BYOD–TheRisk•  A2015PonemonIns:tutestudyreports:

–  Negligentemployeesareseenasthegreatestsourceofendpointrisk•  IncreasednumberofBYODdevicesconnectedtothenetwork(includingmobiledevices)

•  Useofcommercialcloudapplica:onsintheworkplace

•  Securitymanagementcontroltasksbecomelessefficientandmoredifficulttoimplement,‘crea:ngholes’thatcanbeexploitedbyhackers

Page 28: IOT & BYOD – The New Security Risks (v1.1)

BYOD–TheRiskofMobiledevices

Page 29: IOT & BYOD – The New Security Risks (v1.1)

ExposingtheMainframe

Page 30: IOT & BYOD – The New Security Risks (v1.1)

IoT&BYODvsTheMainframe•  Remember:themainframeisjustanotherplaUormresidinginthe

company’snetwork

•  Ifthenetworkiscompromisedthemainframecanbedirectlyorindirectlyaffected

•  UsingBYODcreateschallengestothecompany’ssecurityteamthatcanbedifficulttotackle

•  Youmaythinkthatyourhomenetworkissecure;youupdateyourlaptopwiththelatestsecuritypatches,an:virusandfirewalldefini:ons,but…haveyoueverconsideredtheIoTdevices?

Page 31: IOT & BYOD – The New Security Risks (v1.1)

OnaniceSundayMorning…

Page 32: IOT & BYOD – The New Security Risks (v1.1)

OnaniceSundaymorning…

Page 33: IOT & BYOD – The New Security Risks (v1.1)

OnitsTVscreenfacingthestreet

Page 34: IOT & BYOD – The New Security Risks (v1.1)

Whattodo?

Page 35: IOT & BYOD – The New Security Risks (v1.1)

Whatcanbedone?•  ManufacturersofIoTdevicesneedtostartfocusingmoreon

security

•  GovernmentsmusttakeleadinIoTsecurity

•  IsanIoTwatchdogneeded?

•  Companiesandindividualsneedtobemoresecurityconsciousandconsidertheimplica:onsofBYODandIoT

•  Reducingcostsontheshorttermcanleadtogreatfinanciallossesinthemediumandlongtermforeveryone

Page 36: IOT & BYOD – The New Security Risks (v1.1)

Whatcanbedone?•  Strongsecuritypoliciesandrulesneedtobeinplacetoensurethat

anyBYODdeviceissecuritycompliant

•  EmployeesneedtobeeducatedabouttherisksandchallengesofbothIoTandBYOD

•  Managersanddirectorsalsoneedtobeeducated!!Moneysavingnow,canbeaverycostlythinginthefuture

•  Haveyoueverimaginedhowacompany’simagewouldbeaffectedifit’sITsecurityhadbeenbreachedusinga…....

Page 37: IOT & BYOD – The New Security Risks (v1.1)
Page 38: IOT & BYOD – The New Security Risks (v1.1)

Whatif…..•  AhackercompromisesyourIOTdevice….•  YourFridge!!•  TheyhaveaccesstoyourWiFinetwork•  Thearescanningyournetworkandseeyourworklaptopconnected•  Theymanagetocompromiseyourlaptop•  YouVPNintoyourcoporatenetwork•  Theyportscanandfindtelnetlisteningonport23foraDNSentrycalled

zOSProd•  Andtheyjusthappentoknowwhatz/OSisortheygooglezOSProdorzOS

TELNET•  Startreadingandenjoy!!!•  Idontbelieveinscaringpeople,butthiscouldhappen!

Page 39: IOT & BYOD – The New Security Risks (v1.1)

Beingmorespecific•  Evaluatedeviceusagescenariosandinves:gateleadingprac:cesto

mi:gateeachriskscenario.•  Investinamobiledevicemanagement(MDM)solu:ontoenforce

policiesandmonitorusageandaccess.•  Enforceindustrystandardsecuritypoliciesasaminimum•  Setasecuritybaseline•  Differen:atetrustedanduntrusteddeviseaccess•  Introducemorestringentauthen:ca:onandaccesscontrolsfor

cri:calbusinessapps.•  Addmobiledevicerisktotheorganisa:on’sawarenessprogram.

Page 40: IOT & BYOD – The New Security Risks (v1.1)

References&Resources

Page 41: IOT & BYOD – The New Security Risks (v1.1)

References&Resources

•  “SixthingsyoushouldknowabouttheInternetofThings”,TechRadar•  Gartner:hfp://www.gartner.com•  ArsTechnica:hfp://arstechnica.com•  MITTechnologyReview:hfps://www.technologyreview.com•  Alphr:hfp://www.alphr.com/•  HPCommunityEnterprise:hfp://community.hpe.com/•  CIO:hfp://www.cio.co.uk•  EETimes:hfp://www.ee:mes.com•  ComputerWeekly:hfp://www.computerweekly.com•  CISCO:hfp://www.cisco.com•  ExactTrak:hfp://www.exacfrak.com•  PonemonIns:tute:hfp://www.ponemon.org

Page 42: IOT & BYOD – The New Security Risks (v1.1)

Ques:ons?

Page 43: IOT & BYOD – The New Security Risks (v1.1)

RuiMiguelFeio,[email protected]:+44(0)7570911459linkedin:www.linkedin.com/in/rfeiowww.rsmpartners.com

Contact