Beecham Research, technology market research, analysis and consulting firm, on May 8 revealed a new security report that maps out the extent of potential security threats facing the IoT. It’s called a Threat Map and it’s terrifying.
According to Beecham, the multitudes of devices, networks, platforms and applications that are being developed for implementation within the IoT greatly increases the potential for malicious attacks as the industry moves forward. The Map is designed to highlight those areas that Beecham’s research has identified as the key areas where external or internal attacks may originate, and what the industry needs to do to be better prepared.
Professor Jon Howes, Technology Director at Beecham Research, said that the only reason there haven’t been any major breaches yet is because the IoT isn’t big enough yet to attract bad actors. Once large-scale consumer or enterprise applications have been deployed, that will change.
“Traditional M2M applications are typically very focused, using specific edge devices, a single network and custom platform, making it relatively easy for security professionals to secure to the acceptable level,” said Howes. “But the IoT cuts across different sectors and embraces multiple devices and networks - from satellite to cellular – along with a growing number of IoT platforms and Big Data systems, which present threats on many different levels and fronts. Wherever there is a new interface between devices, networks, platforms and users, there is the potential for a new weak link.”
The Beecham Map points to a number of specific internal and external threats inherent in the IoT ecosystem. Sensors and devices are largely vulnerable in terms of identification, authentication and authorization, which need to be locked down to prevent application hijacking. Physical intrusion is also a risk.
The network level threat is in the gaps between different networks. “With a mix of fixed, satellite, cellular and low power wireless networks as well as personal and body area networks (PAN & BAN), the challenge is to secure the transfer of multiple streams of data between selected networks without exposure of key secrets or equipment control,” said Howes.
“Security in the IoT is significantly more complex than existing M2M applications or traditional enterprise networks,” said Robin Duke-Woolley, CEO, Beecham Research. “Data must be protected within the system, in transit or at rest and significant evolution is required in the identification, authentication and authorization of devices and people. We must also recognize that some devices in the field will certainly be compromised or simply fail; so there needs to be an efficient method of secure remote remediation – yet another challenge if the IoT is to live up to expectations.”
Click here to download the map. And sleep tight.