Ambimat GroupAmbimatAmbiSecureV2XeSIM & eUICCAmbiAutomationEngineering BlogAhmedabad · India · Est. 1982
IoT Security

IoT Security Challenges: Attack Surface (Part 1)

First of a two-part look at IoT security — how billions of devices communicate with enterprise systems, where the resulting attack surface sits, and the trust anchors that contain it.

IoT Devices with Outdated Secure Firmware

Security professionals historically focused on protecting mobile devices and computers. Today, over a billion IoT devices communicate with enterprises, creating billions of potential attack vectors. Manufacturers prioritize building new devices over security updates. Devices remain secure at purchase but become vulnerable when hackers discover bugs, especially in open source software. Legacy systems connected to IoT devices also pose risks.

A few years ago, security professionals were focused solely on protecting mobile devices and computers. Today, there is a proliferation of IoT devices. With more than a billion devices around communicating back to the enterprise, there are potentially billions of open points from where different attacks can be launched on the enterprise, by simply exposing the security vulnerabilities across the enterprise.

Since the IoT devices are being used increasingly, the manufacturers of these devices are focusing on building new ones and not paying enough attention to security.
 A majority of these devices don’t get enough updates, whereas some of them never get a single one. What this means is that these products are secure at the time of purchase but become vulnerable to attacks when the hackers find some bugs or security issues specifically when open source software was used. When these issues are not fixed by releasing regular updates for hardware and software, the devices remain vulnerable to attacks.

In addition to the vulnerabilities of the IoT devices, the other concern is with interconnected legacy systems. In an enterprise with a growing number of IoT devices, legacy technologies might seem out of place. A breach of an IoT device could also result in a breach of a legacy system that lacks modern security standards.

Use of Weak and Default Credentials

IoT companies sell devices with default credentials like "admin" and "password." Hackers use brute-force attacks. The Mirai botnet attack exemplifies this vulnerability.

Many IoT companies are selling devices and providing consumers default credentials with them — like an ‘admin’ username and ‘password’ as a password. Hackers need just the username and password to attack the device. When they know the username, they carry out brute-force attacks to infect the devices.
The Mirai botnet attack is an example that was carried out because the devices were using default credentials. Consumers should be changing the default credentials as soon as they get the device, but most of the consumers are never informed about the same by the manufacturers.

Lack of Encryption

Encryption prevents hacker access, but devices lack storage and processing capabilities of traditional computers. Unused bandwidth or processing power can be exploited. Hackers manipulate protection algorithms.

The result is an increase in attacks where hackers can easily manipulate the algorithms that were designed for the protection of the device. Unless an enterprise resolves this issue, encryption won’t be a security asset.

Malware and Ransomware

Cybercriminals lock consumers out of their devices. IoT-enabled cameras capturing confidential information can be hacked with malware, then encrypted through ransomware. City-wide infrastructure devices infected with malware can launch DDoS or man-in-the-middle attacks, compromising entire municipal command and control infrastructure.

The rapid rise in the development of IoT products will make cyberattack permutations unpredictable. Cybercriminals have become advanced today — and they lock out the consumers from using their own device.

For example, an IoT-enabled camera that captures confidential information from home or the work office — and the system is hacked using a virus which is called Malware. The attackers will encrypt the webcam system and not allow consumers to access any information. Since the system contains personal data, they can ask consumers to pay a hefty amount to recover their data. When this occurs, it’s called Ransomware.

Predicting and Preventing Phishing Attacks

Phishing affects all enterprise technologies, and IoT represents a new attack vector. Hackers send signals triggering device complications. Cloud services use threat intelligence, AI-powered monitoring, and analytics tools, though adapting these to IoT is complex due to instant data processing requirements.

Cybercriminals are proactively finding out new techniques for security threats. Phishing is already a security concern across all enterprise technologies, and IoT devices represent the latest attack vector. Hackers could send a signal to an IoT device that triggers numerous complications. Although it is one of the most common forms of security attacks, and it can be stopped, many organizations fail to properly train their workers about the latest phishing threats.

In such a scenario, there is a need for not only finding the vulnerabilities and fixing them as they occur but also learning to predict and prevent new threats.

Wide Area Networks

WAN are city-wide networks controlling communication between essential services like smart meters and street lights. Malware uploaded to one trusted device compromises entire enterprise security.

Smart Homes Devices

More homes and offices integrate IoT connectivity. Exposed IP addresses reveal residential addresses and contact details, risking consumer safety.

Today, more and more homes and offices are getting smart with IoT connectivity. The big builders and developers are powering the apartments and the entire building with IoT devices. While home automation is a good thing, not everyone is aware of the best practices that should be taken care of for IoT security. 
Even if the IP addresses get exposed, this can lead to exposure of residential address and other contact details of the consumer. Attackers or interested parties can use this information for evil purposes. This leaves smart homes at potential risk.

Case Studies Referenced

  • Smart lighting security flaw
  • Cheap IoT gadgets posing risks after disposal

Who is Ambimat Electronics?

Close to 4 decades of design experience.

Frequently asked questions

Why is the IoT attack surface so large?

Over a billion IoT devices communicate with enterprise systems, creating billions of potential attack vectors. Manufacturers generally prioritise building new devices over shipping security updates for old ones.

What makes default credentials such a persistent problem?

Devices ship secure at purchase but become vulnerable once attackers find bugs, and weak or default credentials give those attackers a reliable way in across an entire product line at once.

What is the current answer to these challenges?

IoT-grade secure elements have shipped at scale and attestation is now the default identity primitive, with EU Cyber Resilience Act baselines applying on top.

Why does open-source software feature in IoT vulnerability discussion?

Devices ship secure and become vulnerable when bugs are later discovered in components they embed. Widely reused open-source code means one disclosed bug can apply across many products at once.

What role do legacy systems play in IoT risk?

Older systems connected to new IoT devices extend the attack surface backwards. The device may be current while the system it talks to was never designed for network exposure.

More from the engineering blog.

Every post is grouped by subject, with newer coverage of the same topic linked wherever it exists.

Browse by topic