andy thurai iot security

19
IoT Security Andy Thurai/ (@andythurai) SaneIoT.com "Bringing sanity to the IoT/API chaos"

Upload: masstlc

Post on 09-May-2015

415 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Andy thurai iot security

IoT Security

Andy Thurai/ (@andythurai)SaneIoT.com

"Bringing sanity to the IoT/API chaos"

Page 2: Andy thurai iot security

"Smaht" Things...Ya Baby!

We will Internet ("IP") enable our sensitive devices and call them "Wicked Smaht"

Page 3: Andy thurai iot security

IoT infestation...

Photo courtsety Intel

SmartTraffic, SmartCity, SmartGrid, SmartHome, SmartToilet,SmartEnergy .....SmarterPlanet

Page 4: Andy thurai iot security

IoT in the news lately...

Page 5: Andy thurai iot security

Are you worried?

Page 6: Andy thurai iot security

Pure Numbers

• Billions of devices. – Currently we are about 10 B devices*– Expected to grow to 50 B devices in 2020*

• Trillions of dollars.– Revenue by IoT is expected to be $9 T**– That doesn't include the monetization of the

data that these IoTs help collect

* Cisco estimation** IDC estimation - Cisco estimation is $19 T

Page 7: Andy thurai iot security

Data Economy

Data is the new commodity

Page 8: Andy thurai iot security

End to End Data Economy

• Data need to be collected (IoT, Devices, Sensors)

• Data need to be securely transported• Data needs to be sanitized• Data needs to be processed (Big Data)• Data needs to be stored• Data needs to be exposed (API)• Actionable results from Data (Analytics)

Page 9: Andy thurai iot security

Pain or Gain?

• Monetization attack - Gain– Disrupt the supply chain– Disrupt the food/water supply chain– Disrupt the manufacturing chain

• Cause disruption and Chaos - Pain– (Cyber) terrorism

Page 10: Andy thurai iot security

Maginot Line

Page 11: Andy thurai iot security

Strategy or Execution?

Page 12: Andy thurai iot security

Smart Energy/ Smart Grid

Page 13: Andy thurai iot security

Control Freak!!!

photo courtesy of rtcmagazine

Page 14: Andy thurai iot security

Stuxnet

Page 15: Andy thurai iot security

So what now?

• With Billions of devices end point protection is not easy.

• Доверяй, но проверяй doveryai no proveryai (russian) - Trust, but Verify.

• Dont trust always verify.

Page 16: Andy thurai iot security

Defense in Depth

Page 17: Andy thurai iot security

Advise• Design with failure and vulnerability in mind• Data quality matters, not just quantity. • Clean, Trusted data should be weighted more.• Digitally sign device firmware. • Dont run anything from untrusted source,

especially firmware updates.• New generation of nano scanners.• Vouch for data integrity.

Page 18: Andy thurai iot security

Different planes

Page 19: Andy thurai iot security

IoT Security

Andy Thurai/ (@andythurai)SaneIoT.com

"Bringing sanity to the IoT/API chaos"