cloudcamp chicago - june 17, 2015 the internet of things

66
CloudCamp Chicago “The Internet of Things” #cloudcamp @CloudCamp_CHI Sponsored by Hosted by

Upload: cloudcamp-chicago

Post on 28-Jul-2015

419 views

Category:

Technology


1 download

TRANSCRIPT

Page 1: CloudCamp Chicago - June 17, 2015 The Internet of Things

CloudCamp Chicago

“The Internet of Things”

#cloudcamp @CloudCamp_CHI

Sponsored by

Hosted by

Page 2: CloudCamp Chicago - June 17, 2015 The Internet of Things

Emcee

Margaret Walker Cohesive Networks

Tweet: @CloudCamp_Chi #cloudcamp

#cloudcamp @CloudCamp_CHI

Sponsored by

Hosted by

Page 3: CloudCamp Chicago - June 17, 2015 The Internet of Things

… sponsored by you!

William Knowles - Evident.io Chuck Mackie - Maven Wave Partners Chacko Kurian - Complete Health Systems, LC Danai Samuriwo - tenniswithd Charlie Havens - Global Tech & Resources Jessica Hitch - Pariveda Solutions

Page 4: CloudCamp Chicago - June 17, 2015 The Internet of Things

6:00 pm Introductions 6:05 pm: Lightning Talks

The Internet of (Insecure) Things - Chandler Howell, Engineering Manager at Nexum @chandlerhowell CPL MakerLab: Intriging the General Public - Jorge Garcia, Maker Navigator for the CPL MakerLab @yorickgarcia "Connecting Vehicles on Google Cloud Platform" - David Patterson, Senior Principal at Maven Wave Partners IoT in Healthcare - Harold Clampitt, CEO & Founder at American RFID Solutions, LLC @haroldclampitt "IoT Perspectives from the Trenches" - Steven Loving, Director of Business Development at Infobrite

7:00 pm: Unpanel 7:45 pm: Networking, drinks and pizza

Agenda

#cloudcamp @CloudCamp_CHI

Sponsored by

Hosted by

Page 5: CloudCamp Chicago - June 17, 2015 The Internet of Things

"The Internet of (Insecure) Things"

Chandler Howell, Engineering Manager at Nexum

Tweet: @chandlerhowell #cloudcamp

#cloudcamp @CloudCamp_CHI

Sponsored by

Hosted by

Page 6: CloudCamp Chicago - June 17, 2015 The Internet of Things

The Internet of(Insecure)

Things

Chandler HowellJune 2015

Page 7: CloudCamp Chicago - June 17, 2015 The Internet of Things

The Internet of (Insecure) Things

1. Smart is the New Dumb2. When Worlds Collide3. Failure Modes4. A Parade of Horrors5. So What Should I do Now?

Page 8: CloudCamp Chicago - June 17, 2015 The Internet of Things

SMART IS THE NEW DUMBIronic, really

Page 9: CloudCamp Chicago - June 17, 2015 The Internet of Things

Smart is the New Dumb

Smart, but VulnerableSecurity is not a priority of IoT (yet)

Focus is on Time to marketFeatures & Functionality

Focus is NOT onSecurityMaintainabilityLongevity

Page 10: CloudCamp Chicago - June 17, 2015 The Internet of Things

WHEN WORLDS COLLIDEWe ain’t seen nothing yet

Page 11: CloudCamp Chicago - June 17, 2015 The Internet of Things

When Worlds Collide

Lifecycles are mismatchedTechnology lifecycles are very short

Devices go EOL in 3-5 years or less

Consumer lifecycles are longerRefrigerators, coffee makers, etc. can last 10 years

Industrial Equipment may outlive youHeavy Equipment can have service lives >50 years

Page 12: CloudCamp Chicago - June 17, 2015 The Internet of Things

FAILURE MODESHow can I fail thee? Let me count the ways…

Page 13: CloudCamp Chicago - June 17, 2015 The Internet of Things

Failure Modes

1. Get Broken

2. Get Leveraged

3. Get Exploited

Page 14: CloudCamp Chicago - June 17, 2015 The Internet of Things

Failure Modes

Get BrokenDamage or destroy the device or attached devices

For example…Plant Control SystemsPeople with Pacemakers

Page 15: CloudCamp Chicago - June 17, 2015 The Internet of Things

Failure Modes

Get LeveragedCompromised Device is used as a vector for

other Badness

For Example…Unlock a Smart HomeJoin a botnetProvide a beachhead for APT

Page 16: CloudCamp Chicago - June 17, 2015 The Internet of Things

Failure Modes

Get ExploitedThe device can be used to spy on people, either

directly or indirectly

Yes, even more examples…Smart TV’sData & MetaData Collection

Page 17: CloudCamp Chicago - June 17, 2015 The Internet of Things

A PARADE OF HORRORSIt’s spelled “IoT” but it’s pronounced “Fail”

Page 18: CloudCamp Chicago - June 17, 2015 The Internet of Things

A Parade of Horrors

Welcome to the Future

Page 19: CloudCamp Chicago - June 17, 2015 The Internet of Things

A Parade of Horrors

Consumer Goods

RefrigeratorsSmart Fridges found in a botnet (2014)25% of devices in that large botnet were IoT

Televisions & ElectronicsSamsung “Smart TV” SpyingNumerous XSS, local exploits

Light BulbsLIFX “Smart” Bulbs authentication flawsDisclosed credentials for attached wi-fi

Page 20: CloudCamp Chicago - June 17, 2015 The Internet of Things

A Parade of Horrors

Medical DevicesSurgical and anesthesia devicesVentilatorsDrug infusion pumpsPacemakersExternal defibrillatorsPatient monitorsLaboratory and analysis equipment

Pretty much every type of failure you can imagine

Page 21: CloudCamp Chicago - June 17, 2015 The Internet of Things

A Parade of Horrors

CarsBlack Boxes

Data stolen or alteredRemote Lock/Unlock and starters

Key fobs and alarm protocols brokenON*Star

Hacked & Abused by Law EnforcementBraking & steering controls

Integration with entertainment/dash allowed access and compromise

Page 22: CloudCamp Chicago - June 17, 2015 The Internet of Things

A Parade of Horrors

Airplanes

DronesDefinitely

In-Flight EntertainmentDefinitely

Passenger Flight ControlMaybe

Page 23: CloudCamp Chicago - June 17, 2015 The Internet of Things

A Parade of Horrors

Infrastructure

Traffic LightsPlaintext wirelessWeak/No Authentication

Industrial Control Systems2008: Turkish Gas Pipeline Destroyed2010: Iranian Gas Centrifuges (Stuxnet)2014: Steel Mill’s Blast Furnace ($17mm in damage)

Utility MetersWeak AuthenticationInaccurate readings == Fraud

Tampered or otherwise

Page 24: CloudCamp Chicago - June 17, 2015 The Internet of Things

SO WHAT SHOULD I DO?Can I have a hint?

Page 25: CloudCamp Chicago - June 17, 2015 The Internet of Things

Fortunately, not this.

So what should I do?

Page 26: CloudCamp Chicago - June 17, 2015 The Internet of Things

So what should I do?

Realize these are not new problemsInsecure computers are nothing new

Think in terms of Failure ModesUse these to understand your threats

Expect Novel attack typesInference AttacksSide-Channel Attacks

Page 27: CloudCamp Chicago - June 17, 2015 The Internet of Things

So what should I do?

Architect for Insecure ThingsAssume devices are insecure by defaultIf not today, they will be some day

Leverage Security Tools & ProcessesDefense-in-DepthThreat ModelingIncident Response

Page 28: CloudCamp Chicago - June 17, 2015 The Internet of Things

So what should I do?

Assess whether the Smart is worth the Risk

Don’t forget how to live without IoT

Think of it in Business Continuity Planning (BCP) or Disaster Recovery (DR) termsSmart Devices are just another system to fail

Page 29: CloudCamp Chicago - June 17, 2015 The Internet of Things

Get Dumb Again

Like Power Over Ethernet (PoE) light bulbs…THANK YOU!

Well, that was fun.

Page 30: CloudCamp Chicago - June 17, 2015 The Internet of Things

"Chicago Public Library MakerLab: Intriging the General Public "

Jorge Garcia, Maker Navigator for the CPL MakerLab

Tweet: @yorickgarcia #cloudcamp

#cloudcamp @CloudCamp_CHI

Sponsored by

Hosted by

Page 31: CloudCamp Chicago - June 17, 2015 The Internet of Things

"Connecting Vehicles on Google Cloud Platform"

David Patterson, Senior Principal at Maven Wave Partners

Tweet: @CloudCamp_Chi #cloudcamp

#cloudcamp @CloudCamp_CHI

Sponsored by

Hosted by

Page 32: CloudCamp Chicago - June 17, 2015 The Internet of Things

Connected Bike on Google Cloud Platform

David Patterson - Senior [email protected]

Page 33: CloudCamp Chicago - June 17, 2015 The Internet of Things

Client Vision

Allow riders to “plug-in” their devices to receive information about their planned ride. Create a community to share ride experiences - popular rides, scenic roads, and POI’s

Motorcycle Manufacturer: Connected Bike POC

1

Bike Performance

Page 34: CloudCamp Chicago - June 17, 2015 The Internet of Things

Project Goals

1

2

3

Bike and location data collection

Location-based alerts

Scalable data collection

4Post-ride services and analytics

Motorcycle Manufacturer: Connected Bike POC

Page 35: CloudCamp Chicago - June 17, 2015 The Internet of Things

Motorcycle Manufacturer: Connected Bike POC

Product Inspiration Competitive Advantage

Third-party aftermarket products

Other vehicle apps - e.g. Tesla

● Tremendous brand loyalty

● Strong sense of community among

customers

● Proprietary engine codes / engineering

knowledge

Page 36: CloudCamp Chicago - June 17, 2015 The Internet of Things

Motorcycle Manufacturer: Connected Bike POC

Engine byte stream Onboard Location

Data Acquisition

Page 37: CloudCamp Chicago - June 17, 2015 The Internet of Things

LOCATION

ALERTPRECIPITATION FORECAST

Alerts pushed to preferred rider and/or passenger devices

Motorcycle Manufacturer: Connected Bike POC

Google App Engine

Backend

Precipitation Alerts

Page 38: CloudCamp Chicago - June 17, 2015 The Internet of Things

Dashboards showing real-time positioning and engine metrics

Motorcycle Manufacturer: Connected Bike POC

Page 39: CloudCamp Chicago - June 17, 2015 The Internet of Things

Motorcycle Manufacturer: Connected Bike POC

Android

App Engine

Datastore

BigQuery

Google Cloud Messaging

Guaranteed push notifications to mobile devices

Fully managed application platform. Cost scales with application adoption

Fully managed NoSQL data storage. Extremely scalable random I/O

Big Data Service to perform interactive analysis on massive amounts of data

Native client application

Page 40: CloudCamp Chicago - June 17, 2015 The Internet of Things

Clients & Frontends

Backend Services

Storage

Motorcycle Manufacturer: Connected Bike POC

Data Providers

Ride Data

2

6

4

3

5

7

1

Page 41: CloudCamp Chicago - June 17, 2015 The Internet of Things

Thank You

Page 42: CloudCamp Chicago - June 17, 2015 The Internet of Things

"IoT in Healthcare" Harold Clampitt, CEO & Founder at American RFID Solutions, LLC

Tweet: @haroldclampitt #cloudcamp

#cloudcamp @CloudCamp_CHI

Sponsored by

Hosted by

Page 43: CloudCamp Chicago - June 17, 2015 The Internet of Things

American RFID Solutions, LLC © 2015

Page 44: CloudCamp Chicago - June 17, 2015 The Internet of Things

American RFID Solutions, LLC © 2015

Page 45: CloudCamp Chicago - June 17, 2015 The Internet of Things

American RFID Solutions, LLC © 2015

• ‘things’ have an aperture and become active participants:

in business

in vacations

In hobbies

• information and processes offer real time situation awareness

interact and communicate:

among themselves

with the environment by exchanging data and information

‘sensed’ about the environment

• running processes:

trigger actions

create services

autonomously with or without direct human intervention

Page 46: CloudCamp Chicago - June 17, 2015 The Internet of Things

American RFID Solutions, LLC © 2015

Page 47: CloudCamp Chicago - June 17, 2015 The Internet of Things

"IoT Perspectives from the Trenches"

Steven Loving, Director of Business Development at Infobrite

Tweet: @ Infobrite #cloudcamp

#cloudcamp @CloudCamp_CHI

Sponsored by

Hosted by

Page 48: CloudCamp Chicago - June 17, 2015 The Internet of Things

Internet  of  Things  

“Lightning”  Talk  

Cloud  Camp  Chicago  

Steven  Loving  (IoT  Chicago  Meet-­‐up)  

2015  

Page 49: CloudCamp Chicago - June 17, 2015 The Internet of Things

2  

Page 50: CloudCamp Chicago - June 17, 2015 The Internet of Things

3  

Page 51: CloudCamp Chicago - June 17, 2015 The Internet of Things

4  

Page 52: CloudCamp Chicago - June 17, 2015 The Internet of Things

Consumer Safety. Protect home investments with affordable remote monitoring.

Savings. Save money by decreasing energy usage from home products.

Comfort. Maximize time with remote home product and appliance management.

Smart Service. Take advantage of remote diagnostic testing and advanced customer service programs.

Green. Reduce energy consumption and protect the environment.

Value, Growth, Savings Driving Business and Consumer Benefits

Business Diversify. Diversify revenue strategies and earn income from new sources.

New Markets. Engage current and high potential mobile customers.

Efficient Diagnostics. Save money with remote product diagnostic testing and monitoring.

Quality Customer Service. Provide best-in-class customer service with new product information and advice.

Brand Reputation. Build brand reputation for product innovation and leadership.

5  

Page 53: CloudCamp Chicago - June 17, 2015 The Internet of Things

Industrial  Automa3on   Smart  Health  

Smart  Home   Smart  City  

“Things  having  iden33es  and  virtual  personali3es  opera3ng  in  smart  spaces  using  intelligent  interfaces  to  connect  and  communicate  within  social,  environmental,  and  user  

contexts”  

6  

Page 54: CloudCamp Chicago - June 17, 2015 The Internet of Things

7  

Devices,  Products,  Assets  On-­‐premise,  In  the  field  

M2M  Enabled  Devices  

Device  PlaOorm   Applica3on  PlaOorm  

Smart  Enterprise  Infrastructure  

Smart  Product  Developm

ent  

Network  

M2M    Sensors  Actuators  

LAN,  WIFI  Cellular  

M2M

 Gateway  

WAN  

Device  Mgmt.  Enablement  Cer3fica3on  Provisioning  Security  Data  Rules  Alerts  Real  Time  Analy3cs  

Data  Collec3on  Applica3on  Integra3on  Analy3cs  Dashboards  Data  Models  Applica3on  Dev.  Applica3on  Sec.  Enterprise  Systems  

1+N  

Page 55: CloudCamp Chicago - June 17, 2015 The Internet of Things

8  

Page 56: CloudCamp Chicago - June 17, 2015 The Internet of Things

9  

Page 57: CloudCamp Chicago - June 17, 2015 The Internet of Things

10  

Devices  speak  wirelessly  to    Home  hub  

Hub  plugs  into  home  router  to  access  Internet  

Cloud  links  devices,  applica3ons  and  analy3cs  

Consumer  controls  Home  from  phone  

Page 58: CloudCamp Chicago - June 17, 2015 The Internet of Things

11  

Whirlpool  6th  Sense  

“20  %  of  your  day  is  used    For  meal  /  clothes  mgmt”    

IoT  Use  Cases:  •  Home  AutomaNon  •  Energy  Savings  

MSRP     Various  (washer,  dryer,  dish,  frig.)  

EsNmated  Volume   50,000+  

ConnecNvity   Wi-­‐Fi  

Channels  

11  

Page 59: CloudCamp Chicago - June 17, 2015 The Internet of Things

“Never  worry  if  your  garage  door  is  open  again”    

IoT  Use  Cases:  •  Awareness  &  ProtecNon  •  Home  AutomaNon  

Product  Use  Cases  •  Control  your  garage  door  and  your  

house  lights  through  your  smart  phone  •  Get  noNfied  if  your  garage  door  opens  or  

if  you  forgot  to  close  your  garage  door  •  Know  if  your  garage  door  opened  while  

you  were  away  

MSRP     $129.99  

EsNmated  Volume   250,000+  

ConnecNvity   Wi-­‐Fi  

Channels  

Chamberlain  MyQ  

12  

Page 60: CloudCamp Chicago - June 17, 2015 The Internet of Things

13  

A  Connect  Cloud  Pla`orm  -­‐  Sample  

AES  128  Encryp3on  and  key  management  from  the  device.  SSL  and  two  factor  authen3ca3on  for  data  transfer  and  storage  in  the  cloud.  

Normalize  Data  to  your  exis3ng    ERP,  CRM  and  BI  systems  

Both  backup  &  recovery  and  3me  series  storage  available  using  dedicated  virtual  machines  running  Cassandra  DB   Android,  iOS,  and  

Windows  Push  no3fica3ons,  SMS,  and  email  

Real  3me  weather  and  3me  of  day  energy  pricing  

SLA:  -­‐ 99.9%  up3me      -­‐ Sub-­‐second  latency    

Mobile  appp  development  plaOorm  to  speed  app  development.  

Page 61: CloudCamp Chicago - June 17, 2015 The Internet of Things

•  Technology is Fragmented – Lack of Common Standards (fragmented) – Closed Systems

•  Users are Concerned – Security / Privacy Challenges – Complexity

•  Business Challenges

14  

Page 62: CloudCamp Chicago - June 17, 2015 The Internet of Things

Actor

Cloud (s)

Device

Actor

Devices / Data

Sensors

Actor

Interface

Devices

Device

Interface

Device

Interface

Systems, Products Services

Other Service Users

Mac/PC

Smartphone

Smartphone Screen

Smartphone

Accelerometer

Products (1+N)

15  

Page 63: CloudCamp Chicago - June 17, 2015 The Internet of Things

16  

Page 64: CloudCamp Chicago - June 17, 2015 The Internet of Things

Thank You

17  

Page 65: CloudCamp Chicago - June 17, 2015 The Internet of Things

Un-panel Discussion

volunteer to join the panel & ask questions from the floor!

#cloudcamp @CloudCamp_CHI

Sponsored by

Hosted by

Page 66: CloudCamp Chicago - June 17, 2015 The Internet of Things

Unconference

Small groups & discussions, network

Pizza’s almost here!

#cloudcamp @CloudCamp_CHI

Sponsored by

Hosted by