0% found this document useful (0 votes)
5 views47 pages

IoT Security Challenges and Solutions

IoT security is essential for protecting connected devices, their data, and the networks they operate on, addressing vulnerabilities through various security techniques and standards. Challenges include rapid device proliferation, insufficient user knowledge, and lack of compliance from manufacturers, leading to risks such as device hijacking and data theft. To mitigate these risks, implementing robust security measures, adhering to standards, and ensuring continuous updates are critical for maintaining the integrity and safety of IoT systems.

Uploaded by

tojan050
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views47 pages

IoT Security Challenges and Solutions

IoT security is essential for protecting connected devices, their data, and the networks they operate on, addressing vulnerabilities through various security techniques and standards. Challenges include rapid device proliferation, insufficient user knowledge, and lack of compliance from manufacturers, leading to risks such as device hijacking and data theft. To mitigate these risks, implementing robust security measures, adhering to standards, and ensuring continuous updates are critical for maintaining the integrity and safety of IoT systems.

Uploaded by

tojan050
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter 10

IoT and Security


Understanding IoT security

• IoT security focuses on protecting connected devices, their data, and the networks
they use. Because IoT devices communicate through the Internet—which is a
common source of attacks—they must be secured with strong protection methods.
IoT security means adding security features to devices to prevent attacks and reduce
vulnerabilities.
• It includes many elements, such as security techniques, architectures, tools,
standards, and protocols. As IoT expands, the need for stronger and more advanced
security also grows. Common areas of protection include network security, physical
device security, API security, encryption, and public key infrastructure (PKI).
• A complete IoT security solution should provide protection, visibility, and
segmentation across the whole network. It must also include three key features:
learning (to understand device risks), segmentation (to group devices), and
protection (to secure each part of the system).

• Overall, IoT security aims to maintain confidentiality, integrity, and availability


(CIA) while identifying and fixing risks.
IoT security challenges:

summarizes all major security challenges:


• IoT security faces many challenges because the number of devices is increasing
rapidly. Manufacturers often fail to follow strong security standards, creating
problems such as weak hardware, hard-coded passwords, insecure data storage,
missing updates, and unpatched software.
• Many users also lack awareness about how to use IoT devices safely. They often
share too much personal information and ignore security features like updates and
patches. When companies or users do not update devices, attackers can exploit
newly discovered vulnerabilities, especially during unencrypted data transfers.
1. Compliance issues on IoT manufacturer side: Many IoT manufacturers release
new devices quickly but do not invest enough time, money, or effort in strong
security features. This leads to weaknesses during the design and development
stages. One major reason is the lack of universal security standards. For example,
Bluetooth pairing can expose devices to risks after the first connection. Other
common manufacturer-side issues include weak or hard-coded passwords, insecure
hardware, poor data management, ignoring update features, unsafe data
transmission and storage, and software that is not patched properly.
2. Insufficient user knowledge: The number of IoT users has been rising daily. The IoT is a
modern technology and is still in the development stage. Users have enough expertise and
resources to use existing technologies securely.
• They are using security software and devices to secure their laptops, mobiles, and data. But
they do not have sufficient knowledge and awareness about the secured uses of IoT
devices. Some groups have been taking care of their wearable devices.
• Although, major users are ignoring safety while using any type of IoT devices and
wearable devices. They are providing a lot of personal information to their all-connected
devices.
• They are not much aware of what information they should share and put into the
devices. It is a serious issue as it might allow attackers to make social engineer
attacks. The malicious users might target these groups and succeed in obtaining
sensitive information.
3. Unawareness in device update and patch management: Many IoT companies
fail to provide regular updates and patches, and they often do not test devices
properly. Because of this, many users turn off automatic updates and ignore new
security fixes.
• This creates risks for both companies and users, since updates are essential for
fixing new vulnerabilities.
• During an update, devices send backup data to cloud servers. If the Internet
connection drops and the data is not encrypted, attackers can intercept and steal
sensitive information. This makes poor update and patch management a serious
security problem.

4. IoT devices' hijacking and ransomware: Weak IoT device management and
missing updates give attackers opportunities to install malware, including ransomware.
Ransomware can lock or destroy data and demand payment to restore access. A real
example occurred when attackers infected 70% of Washington DC surveillance cameras
during a presidential inauguration.
• As industries adopt more IoT technologies, they store large amounts of sensitive
data, increasing risks of espionage and spying. Some countries have even banned
certain IoT devices because they were used for spying, such as the toy ball banned
in Germany.
• Healthcare faces similar threats. Attackers target medical devices and fitness
trackers to steal personal health information and then demand ransom to return the
data.
5. Lack of physical security: This is a common issue that can happen at any time. It
can occur when there is a lack of physical security in the locations where IoT devices
have been implemented.
• When the manufacturer or end-user companies do not employ any kind of physical
security, some natural incident or intentional man-made attacks might harm the
devices.
• This security issue can also be associated with the physical damage of the devices
from elements like water, fire, air, or any dangerous activities. For instance, people
use and install security cameras at internal and external areas.
• These devices could be tampered due to lack of security. Hence, the physical
hardening of IoT devices is a must to prevent its security risks.
6. Home invasions: It has been considered as another security issue that is taking place
between the physical and virtual worlds.
• It is known that IoT is creating a virtual world from the physical world. For
instance, earlier, houses had ordinary music systems, TV, refrigerator, and other
gadgets.
• Now, they have been replaced with smart devices including TV, speakers,
refrigerator, washing machine, coffee makers, cameras, and so on.
• This smart home automation might pose some security threats because of unsafe
rogue devices and poor defense methods that access IP addresses unethically. The
attackers might locate these addresses to get access to those smart gadgets.
7. Counterfeit and Rogue IoT devices: Rogue devices are those malicious IoT
devices that pose some vulnerabilities.
• Attackers try to install these devices into the secured network without any
authorization.
• The installation of such devices might break the whole network or replace the
original one. Mostly, malicious hackers use a video camera, access point, or
similar devices as rogue devices.
• And, lack of security awareness among users has been increasing these issues as
they are installing such devices in their secured networks.
8. Unreliable data storage and communication: Another security concern is related to
unreliable data storage in IoT applications that might occur because of rogue devices.
• The compromised devices have been used by attackers to break the network, access
sensitive information, and make communication unsafe.
• Lack of encryption and authentication during the communication process is the main
reason behind the issue. The history has an example to explain this issue. In 2017,
Darktrace researchers had identified an attack that happened on an unnamed casino.
• In this case, the cyber attackers attacked a network and after breaking it using an
attached thermostat to a fish tank, they succeeded in accessing a big database "high
roller." They filtered about 10 GB of data after this database access.
9. Lack of expertise: The industry is facing lack of knowledge.
• This skill gap is causing problems of security as that group is unable to identify
the IoT device vulnerabilities on time, rouge devices, and other malicious
activities over secured networks.
• Besides, the industry is not taking steps to conduct the training on increasing
security awareness.

• The recent IoT security issues highlight that there is still a gap between IoT and
security. As soon as IoT develops, security challenges would increase. The
variation in the devices will enhance the security complexities.
Why We Need IoT Security

We need security for IoT devices to stop attacks and protect people’s personal
information. Without security, IoT devices can be easily attacked and cause big
problems for users and networks.
When devices do not have good security, attackers find weak spots and use them to
cause harm. Many big security incidents in the past happened because companies did
not build strong security into their IoT devices. This made security experts and
developers realize that IoT security is very important to keep networks and devices
safe.
 some examples that encourage every IoT company and developer to consider high
security designing while developing any device.
 Mirai (2016)
•The Mirai botnet found IoT devices with weak security (like default passwords).
•It took over these devices and used them to launch one of the biggest DDoS attacks.
•The attack made the internet go down for big services like Netflix, Twitter, Reddit, and
others.
•This happened because the IoT devices were not protected.
 Jeep Hack (2015)
•Hackers showed they could control a Jeep car through its software over a cellular
network.
•This proved that connected vehicles can be attacked if security is weak.
 St. Jude Cardiac Devices (2019)
•Some medical devices like pacemakers had security flaws.
•Hackers could possibly take control of these devices, showing how dangerous weak
security can be.
 Security Camera Breaches (Ring)
•Some Ring cameras had problems that exposed user data.
•Hackers also accessed some devices, showing that home IoT devices must be
secure.
 These real examples show that many IoT attacks happen because IoT devices have
common weak points. Here are five main vulnerabilities:
[Link]
•A botnet is a group of devices controlled by attackers.
•Hackers use botnets to spread malware, send fake emails, steal information, or crash
networks (DDoS attacks).
[Link]-In-The-Middle Attacks
•This happens when an attacker intercepts data between two devices.
•The attacker can read or change the information while it travels over the internet.
[Link] of Service (DoS / DDoS)
•Some IoT devices can only do one task at a time.
•Attackers overload the device to stop it from working, causing service interruptions.
[Link] Engineering Attacks
•Attackers trick people into giving personal information.
•For example, people use default passwords or trust devices without checking
security.
[Link] and Identity Theft
•Users often do not protect their personal data.
•Hackers study people online and use that data to attack their devices and steal
identities.
 Other Problems in IoT Security
In addition, many IoT systems suffer from things like:
•No security updates or patches
•Poor device management
•Weak network services and interfaces
•Old systems still in use
These weaknesses make IoT devices risky for both regular users and businesses. So
high security is very important to protect data and prevent attacks.
Basic security requirements for IoT

• In the past, people did not think security was important in IoT. But many attacks
showed that devices must be secure. Before building IoT devices or systems, we must
know the security needs. This helps developers, companies, and users trust the IoT
devices.
• The IoT consists of various devices, including small to large, simple to complex, and
consumer gadgets to sophisticated systems. Thus, security requirements for every
category differ, although every device should be required to adopt general security
requirements.
 The major key requirements are as follows:

• Implement security features to the embedded devices, stored data, and communication.
• Avoid keeping a weak password as the default password.
• Minimize the use of universal plug and play features.
• Develop, implement, and run security operations at an IoT scale.
• Fulfillment of standards and compliance defined by committees.
• Fulfillment of performance requirements according to the use case.
• Use multiple levels of security protections (Firewalls, encryption/authentication,
protocols, physical security systems, and intrusion/detection prevention systems).
• Besides the requirements, it is advised to use some functional blocks to fulfill the
needs of IoT scale, device trust, data security, and other conditions. The device trust
establishes and manages its integrity whereas data trust ensures privacy. At last,
operationalize trust ensures small operations. All these have been done through
automation and proven technologies.

• The accomplishment of these security requirements would make any IoT device
more secure and reliable. Apart from these, some factors must be considered while
selecting the security requirements based on the type of IoT devices:
• Ensure secure booting in the device and develop application solutions. The developers
can use cryptography and signed code to embed this security requirement.
• Implement data security through encryption.
• Implement secure code updates using secured booting or signed code. This would
ensure safety from patches, bugs, or other malware.
• Implement authentication protocol to ensure the authenticity of devices.
• Implement encrypted communication protocols and cryptography to provide secure
communication.
• Add a layer of embedded firewalls to protect from hackers, flood attacks, known
protocol exploits, or buffer overflow attacks.
• Embed security policies, standards, and frameworks to enhance the level of security
in devices.
• Arrange for intelligence workshops, training, bulletins, hands-on, and newsletters
to remove the IoT skill gap.
Considering these factors would complete the security requirements for IoT devices
and solutions. It would ensure to build Internet of Secure Things.
Security requirements defined by the ETSI

The Technical Committee, European Telecommunications Standards Institute


(ETSI), is a top company offering a code of practice and guidelines. The ETSI
identified 13 key security requirements and applicable devices in 2020. Table
highlights both:
Key Security Requirements and applicable devices
These key requirements could also be used as references before initiating any IoT
solutions. Besides these, the following Table is highlighting the general checklist for
IoT device manufacturers and users.
General checklist for IoT Device manufacturer and users
• IoT devices face physical attacks, lifecycle assaults, software damage, and
data-transmission threats. Attackers routinely exploit these weaknesses, creating incidents.
Developers embed required security features to meet device objectives, but designing
comprehensive protection remains a challenging task, especially as new vulnerabilities
emerge and integration complexity grows across diverse environments globally.
• Beyond hardware and software, attackers now leverage social engineering and human
flaws, exploiting trust to launch attacks such as credit-card fraud or traffic manipulation
toward target sites. Consequently, any IoT security framework must incorporate defenses
against these non-technical attack vectors, including user education, robust authentication,
and monitoring of anomalous behavior to mitigate risk.
Developers are responsible for defining precise IoT security requirements, while
consumers should adopt basic safeguards: apply regular firmware updates, replace
default
.
IoT security standards

• The rapid growth of IoT devices has led to massive storage of confidential data,
raising user concerns about security. Vulnerabilities in IoT hardware and software are
driving a surge in cyberattacks, implementing security features essential during
design and deployment.
• To address these risks, various international committees have created “standards” – a
collective term for rules, regulations, guidelines, and laws governing technology
development and use. ISO provides general internet and communication guidelines,
while specific IoT standards have been issued by organizations in the US, UK, India,
and other countries.
• Without consistent security standards, IoT products remain exposed to threats
such as weak user knowledge, poor manufacturing practices, and absent
best-practice codes. The global expansion of the IoT market therefore demands
unified security standards, ensuring all stakeholders can mitigate risks and
protect sensitive information.
User group needs to follow the IoT standards

Table highlights the audience which must follow the IoT security standards:

User groups that need to follow Security Standards


Committees and groups that design standards and codes of practices:

IoT standard organizations, trade associations, and industry groups provide


guidelines, rules, codes of practice, and regulations to protect IoT devices. Each
group is an authorized committee to ensure the safety of devices and data.

The table discusses top organizations and their main purposes to support IoT
security:
Government regulations

Currently, there are no specific global IoT device security standards or codes of
practice; however, different manufacturers and users are following NIST-
recommended standards and codes of practice in their respective regions. Let's discuss
the guidelines designed based on areas.
IoT security architecture

IoT security architecture encompasses a range of security solutions tailored to protect


IoT devices and systems, regardless of their complexity. It focuses on safeguarding
data, communication, and overall system integrity through a comprehensive
approach to managing vulnerabilities. This architecture incorporates various tools
and strategies to address potential security issues across its components.
Additionally, developers utilize established methodologies, such as traditional IoT
frameworks or by creating trusted zones, to effectively design IoT security
architectures, ensuring robust protection against exploitation.
Chapter 3, Understanding IoT Workings, explained the concept of an IoT architecture.
It was discussed that IoT architecture consisted of varied components, including
devices, software, hardware, protocols, standards, and tools. The four layers have been
explained within the IoT architecture. The IoT security architecture would be described
based on those four layers and stages of IoT architecture. Each layer would correspond
to the same layer to offer security services.
Stage 1 security involves a layer of sensors and actuators focused on data
acquisition and processing initiation. This layer interfaces directly with physical
devices, networks, and processing platforms.
The primary objectives are to secure sensor data and ensure encryption. Key
security requirements include physical protection against attacks and
interference, safeguarding embedded software from malware, and maintaining
data integrity at the CIA levels.
Major threats include Denial of Service attacks, unauthorized access, data
forgery, and manipulation. Recommended solutions involve strong network
security, end-to-end encryption, multi-factor authentication, cryptography, and
source authentication to mitigate these vulnerabilities.
Stage 2 security in IoT architecture focuses on ensuring the security of gateways
and networks through data routing and forwarding.
This layer's primary objectives include identity authentication, network security,
communication security, and the protection of network protocols.
Key security threats include DDoS attacks, eavesdropping (such as man-in-the-
middle attacks), and traffic analysis. To mitigate these threats, robust security
measures are essential, including high encryption, two-way authentication, and
network authentication. Additionally, security protocols such as IPSec, SSL/TLS,
HTTPS, S/MIME, and SET are critical for safeguarding both the network layer and
application protocols, as data integrity is paramount in preserving privacy and
security.
Stage 3 security in IoT architecture involves managing IoT services and
centralized data processing, primarily on cloud platforms. Key security
requirements include ensuring operating system and software security, as well as
safeguarding data services. Major threats at this layer include DDoS attacks and
unauthorized data access. Recommended security measures involve using
software like firewalls and intrusion detection systems, along with implementing
access control, conducting regular security audits, and managing user access.
Additionally, employing data backup and recovery methods enhances security for
IoT systems.
Stage 4 security focuses on safeguarding applications interacting with end-users,
emphasizing privacy protection and user authentication. Key requirements include
ensuring data security, protecting user identity and location privacy, securing IoT
systems, and securing user mobile devices. Potential threats involve unauthorized
data access, necessitating robust privacy measures like encryption, and weak
passwords, which can be mitigated through various strong authentication
techniques.
The following figure summarizes the whole IoT security architecture:

Summary of IoT Security Architecture


Like previous layers, this layer is required to follow security standards and
mechanisms to make a secured IoT system. Adding trusted boundaries between
two layers can also enhance the security between the two layers. These
boundaries could provide physical and logical isolation levels to divide the
layers securely. The event data tampering, elevated privilege exploits, spoofing
identification, DDoS attacks, and information disclosure could be prevented
using these boundaries. Thus, designing an IoT security architecture mitigates
malicious coding and attacks and ensures secured communication.

You might also like