Wednesday, 27 April 2016

IoT Data security – the core mission of risk assessment for connected devices


Investing in an IoT system is a risk that needs to be bolstered by a systemic readiness review and attack-based status monitoring strategy.

The Internet of Things is driving transformations in major operational models by connecting assets, people, products and services, creating the possibility to make real-time decisions and deliver personalized outcomes.

The technology holds much promise in machine-to-machine frameworks that are increasingly used in critical industries like oil and gas, transportation, healthcare and the manufacturing sector. By the year 2020, machine sensors are expected to dominate the IoT ecosystem, contributing up to 40% of the total data generated. The industrial sector is exploring ways to integrate plant floors with control systems for capabilities in automation and data handling. Wearable smartbands and trackers that monitor fitness and health are piquing the interest of healthcare providers and researchers. Ingestible pill sensors and other devices are under experimentation for the remote access they offer to real time data throughout an ordinary day in the life of a patient. Undeniably, smart devices and sensors are proving their pertinence in critical missions.

As the focus shifts from the ostensible glamour of a smart gadget over to its functionality, organizations will be faced with the task of ensuring that the functional soundness of their systems is on point. When we look at connected devices from the perspective of smart cities, what really matters is how secure the data streams all along the path they take. As far as IoT is concerned, 99.9% secure = 100% vulnerable.

“Data integrity is the one parameter that will determine the usability of the ‘electronic skin’ that Neil Gross envisioned. Accurate data is the one factor that can turn a cool toy into a useful tool.”

Data is the life-blood of any monitoring or control system. For data analytical tools to deliver accurate and actionable insights, data needs to stay unaltered along the path it takes from the systems and applications to the cloud and back again.

Understanding threats to IoT data security
The data that devices record, typically passes through gateways, servers and applications before coming to rest in the data centers. Securing the route of this data in motion depends on loss prevention measures that are consistent and multi-faceted. What most systems overlook is adequate security at the sensor level, where implementation of security measures is typically a complex task. As a result of vulnerabilities in the networking protocols and devices, the streams of data (including service data logs that are sent back to the manufacturer) could be altered or distorted apart from being leaked away. As is obvious, faulty/tampered data leads to bad decisions or in the worst case, fatal errors as demonstrated by the Medjack attack vector.

“One simple way to ensure that your data stays intact is to look beyond standard compliance norms and really dig deep enough to understand the threat sources in your IT asset ecosystem. 
 Security stature assessment is not a one-time task. However, an overall risk assessment to understand weak points can pave the way for the development of your very own security incident prevention strategy.”

Issues impacting IoT data security
On an average, about 2.3 trillion gigabytes of raw big data is generated every day and collected by systems across the world. Disappointingly, most organizations do not have access to adequate guidance in life-cycle maintenance for their IoT devices. They also rarely have a defined process for performing secure updates, configuring and patching for firmware. This can jeopardize data integrity since these devices open holes within your cloud space when communicating with third-party data analytic systems.

The lack of standardization and commonality in drives, transport protocols, operating systems and platforms makes the IoT environs prone to complexities in configuration and compatibility, opening loopholes for eavesdropping. The influx of several portable device controllers has made traffic monitoring even more indispensable.
Weak links in the IoT interconnections are often situational and not readily identifiable. A pertinent risk management strategy requires threat awareness at the various subsystems of your infrastructure.

“Even before implementing a new IoT initiative, an exhaustive impact study is crucial to validate your stature with regard to data privacy. A deeper understanding of the threat environment studied in the light of evolving stealth attack patterns will yield actionable insights.”

Narrowing down to contextual threat sources
When legacy industrial systems are networked with enterprise IT, it gives rise to operational challenges and limitations. An organization investing in IoT devices has to exercise caution and ensure that the equipment they procure is from a manufacturer who invests in a secure development process. Disappointingly, only a few makers think security through. HP Security Research report last year hinted that about 70% of the ten most popular IoT devices had at least 25 vulnerabilities each. These vulnerabilities seem to be crop up from weak points in network security, application security, mobile security, and communication protocols, all of which could snowball into something graver.  The most common vulnerabilities assessed on the basis of OWASP Top 10 include inadequate authentication, insecure web interfaces and cursory encryption.

The simplest way to counteract IoT data security challenges is a block by block appraisal of web solutions, interfaces and their implementation in your enterprise.

Aleph Tav Technologies strives to enable pioneering ideas to take shape and stay successful. With proven techniques and contemporary hacks, our experts are poised to help you leverage our cost-efficient methods.
If you are looking for a responsive security assessment program for your connected devices, talk to us for insights on how your assets can best be protected.



How Secure is your Start-up? Analyse your security posture


A nascent technology organization can often have a pretty long ‘to-do list’. A mad rush ensues in the early stages of inception when business development efforts take up highest priority and security often ends up as one of the very last items on the list.

If there’s anything to deduce from the pattern of cybercrime victims in recent times, it should be that startups can no longer bank on the “we’re not there yet” excuse to shrug off or postpone security management. It is easy to empathize with them because all along, we’ve been led to believe that cyber criminals only target bigger companies. Sadly, this is far from the truth. Read on to know why your business might be at stake as long as that misconception exists.

Technology-intensive startups are learning the hard way that they are indeed potential targets for millions of attackers looking for ways to make quick bucks off confidential information or just intending to wreak havoc on infrastructure. No matter what the intent is, an unguarded spot in your assets and networks can prove to be a major setback for your emerging business. Native startups like Ola Cabs and Gaana.com were basking in the glory of a fresh wave of patronage when both companies were caught unawares by hackers. Loss of user credentials and user behavior information were just one aspect of the price they paid for neglecting security risk assessment. The real damage is always the loss of credibility and a diminishing interest in what the company has to offer. The age of internet business has the inherent risk of offending a huge portion of the target audience owing to a seemingly minor security flaw.

Hacking entities are being managed like any other business whose central goal is to maximize its return on investment. Naturally, they would prefer the easier targets with long windows of exposure to which they could latch on like a spile and drink up. With a lack of the requisite IT resources and expertise for a holistic security set up, startups and SMBs universally fit the bill.

One grave blunder that small businesses and young tech companies make is relying on basic antivirus, firewall and anti-spam software for their defense. Symantec recently made a public confession that your antivirus is no longer relevant in the era of cloud computing. Startups are reportedly the most common adopters of cloud-hosted software and infrastructure for the sheer cost-efficiency and ease of integration they offer. The best way to stay protected is by understanding the third party vendor’s security policies and that of the channels leading back to your internal networks. 

Vigilant companies prefer a cloud service provider whose security measures focus on data-centric defense rather than application-centric defense. Encryption is the most widely-acknowledged safeguard especially for companies that manage raw, big data. A start-up is liable to face legal action for a breach of its information even while it is at rest with one of its cloud service providers.

Inside-out Approach to Security
Yet another smart move is to look at security initiation from the inside – what experts would call information-centric security. This approach would ensure that the company is aware of the kind of security flaws and potential exploits that each data asset is exposed to. Analyzing the environment where data is at rest and in motion requires a pervasive vulnerability assessment. This exercise will help your IT department zero in on deviations from normal behavior that could invite malicious interception.

‘Organizations must acknowledge the fact that security is not a one-time task but a continuous process of monitoring and evaluation’

Companies that have a BYOD policy must educate themselves about imminent threats like accidental loss of data caused by a minor error of a well-meaning employee.
That takes us to the next important aspect of maintaining the health of your internal defense mechanism.

Employee-centric social sensitization
Otherwise referred to as social engineering in security parlance, this concept is gaining popularity among technology enterprises that wish to acquaint employees with major technology migrations. Ponemon Institute discovered that about 64 percent of data breaches were caused by human error and access mismanagement.

Organizations are now adopting Unified Threat Management devices that offer composite control over employee access to cloud and enterprise assets. Detecting misconfigurations in these control devices can be challenging. Security personnel can adequately educate your employees to avoid naive actions that may put themselves and the company’s assets in a dicey situation. Every team needs to understand how their negligence can give way for advance persistent threats to weaken the company’s line of defense.

Security audit experts usually offer this sensitivity training as part of their vulnerability status reviews and recommendations. Today, one can no longer demarcate benign areas from blatantly malign ones. The goal is to get every member involved in managing individual practices with diligence. This can also help eliminate the perceived hostility surrounding the idea of a hardcore surveillance policy.

Understand the objective of security assessment for your enterprise and application
Security experts assert that it may be time to accept that security management is moving from the goal of breach prevention to breach detection and mitigation. The ugly truth is that it is no longer practical to think one can prevent all data breaches. The only way out is a continuous appraisal to evaluate your posture and what are the latest attack vectors that have developed after your last evaluation. Young enterprises can leverage on a security testing partner who works with you from scratch and provides long term assistance in ensuring continuous excellence.
The most important step in adjudging your security posture is identifying the key focus areas with respect to your enterprise and the technology platforms your applications are dependent on. Security assessment is not a generic, ‘one size fits all’ capsule. Most tools in the market fail to offer focused results simply because they are quite generic in approach. An ideal vulnerability and risk appraisal would begin by investigating existing operational pathways and dependencies and give you valuable insights on what it can offer for your enterprise. This way, you will only have to pay for the services that you actually need.

Evaluate your options
While it is every organization’s responsibility to make an informed decision in hiring or partnering with a security services provider, the most desirable trait one must look for in security partner is their ability to understand your environment and their capability to offer a focused and complementary service package.

Organizations must acknowledge the fact that security is not a one-time task but a continuous process of monitoring and evaluation. However, it is indispensable at certain points in time including before you go live following a major upgrade or a change in the product portfolios. Identify a cyber security analyst with a constantly updating threat databases of attack modes that cause high damage from a safe distance.