Security-focused routers may help to mitigate IoT threats

Posted by   Martijn Grooten on   Apr 24, 2018

Walking around the RSA show floor last week, it was clear that the Internet of Things, or IoT, is a hot topic in security.

Indeed, the number of connected devices continues to grow and new IoT botnets continue to be discovered, with Saikin and Hajime being two of the most recent examples.

It is important to realise that most of these IoT botnets consist of routers (Mirai, which included IP cameras, is a notable exception). There are two fundamental, and rather obvious, differences between routers and other kinds of connected devices.

The first is that routers are supposed to be connected to the Internet. One can have a discussion about whether it is a good idea to connect a fridge or a coffee maker to the Internet, but for a router, the whole point is to connect it to the Internet.

router-all-evil-fig1.jpgPlacement of the router in the network. (From the VB2017 paper The router of all evil: more than just default passwords and silly scripts by Himanshu Anand & Chastine Menrige.)

The second is that security issues for most IoT devices are mitigated by them being behind a NAT, and thus not directly reachable from the Internet. A router is typically connected directly to the Internet – in fact, routers are gateways to the aforementioned NATs.

What most routers do have in common with other kinds of IoT devices is that their software tends to be weak and poorly maintained, and that if the device even allows for security patches to be installed in the first place, users often don't bother. Indeed, a recent survey found that more than half of Internet users had never made a change to their router, and hadn't even changed the default Wi-Fi password.

And this is why I feel optimistic about a new trend in which security companies are producing their own routers (or in some cases, devices that sit directly behind routers). Firstly, we can expect such routers to be designed with security in mind and thus both to have fewer vulnerabilities and, more importantly, to include the ability to install security patches automatically.

Secondly, while NATs do mitigate some of the risks that come with IoT, they aren't perfect and are likely to become less effective as IPv6 becomes more prevalent. A security-focused router has the ability to block malicious traffic and thus prevent devices from being infected with malware and, if they do get infected, prevent them from reaching out to C&C servers.

None of this should be a reason for device manufacturers to ignore security in the design process. But getting the IoT industry to take security more seriously is likely to be a long process. In the meantime, anything we can do to mitigate the risks is very welcome.

twitter.png
fb.png
linkedin.png
hackernews.png
reddit.png

 

Latest posts:

VB2019 paper: APT cases exploiting vulnerabilities in region-specific software

At VB2019, JPCERT/CC's Shusei Tomonaga and Tomoaki Tani presented a paper on attacks that exploit vulnerabilities in software used only in Japan, using malware that is unique to Japan. Today we publish both their paper and the recording of their…

New paper: Detection of vulnerabilities in web applications by validating parameter integrity and data flow graphs

In a follow-up to a paper presented at VB2019, Prismo Systems researchers Abhishek Singh and Ramesh Mani detail algorithms that can be used to detect SQL injection in stored procedures, persistent cross-site scripting (XSS), and server‑side request…

VB2020 programme announced

VB is pleased to reveal the details of an interesting and diverse programme for VB2020, the 30th Virus Bulletin International Conference.

VB2019 paper: Cyber espionage in the Middle East: unravelling OSX.WindTail

At VB2019 in London, Jamf's Patrick Wardle analysed the WindTail macOS malware used by the WindShift APT group, active in the Middle East. Today we publish both Patrick's paper and the recording of his presentation.

VB2019 paper: 2,000 reactions to a malware attack – accidental study

At VB2019 cybercrime journalist and researcher Adam Haertlé presented an analysis of almost 2000 unsolicited responses sent by victims of a malicious email campaign. Today we publish both his paper and the recording of his presentation.

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.