Security-focused routers may help to mitigate IoT threats

Posted by   Martijn Grooten on   Apr 24, 2018

Walking around the RSA show floor last week, it was clear that the Internet of Things, or IoT, is a hot topic in security.

Indeed, the number of connected devices continues to grow and new IoT botnets continue to be discovered, with Saikin and Hajime being two of the most recent examples.

It is important to realise that most of these IoT botnets consist of routers (Mirai, which included IP cameras, is a notable exception). There are two fundamental, and rather obvious, differences between routers and other kinds of connected devices.

The first is that routers are supposed to be connected to the Internet. One can have a discussion about whether it is a good idea to connect a fridge or a coffee maker to the Internet, but for a router, the whole point is to connect it to the Internet.

router-all-evil-fig1.jpgPlacement of the router in the network. (From the VB2017 paper The router of all evil: more than just default passwords and silly scripts by Himanshu Anand & Chastine Menrige.)

The second is that security issues for most IoT devices are mitigated by them being behind a NAT, and thus not directly reachable from the Internet. A router is typically connected directly to the Internet – in fact, routers are gateways to the aforementioned NATs.

What most routers do have in common with other kinds of IoT devices is that their software tends to be weak and poorly maintained, and that if the device even allows for security patches to be installed in the first place, users often don't bother. Indeed, a recent survey found that more than half of Internet users had never made a change to their router, and hadn't even changed the default Wi-Fi password.

And this is why I feel optimistic about a new trend in which security companies are producing their own routers (or in some cases, devices that sit directly behind routers). Firstly, we can expect such routers to be designed with security in mind and thus both to have fewer vulnerabilities and, more importantly, to include the ability to install security patches automatically.

Secondly, while NATs do mitigate some of the risks that come with IoT, they aren't perfect and are likely to become less effective as IPv6 becomes more prevalent. A security-focused router has the ability to block malicious traffic and thus prevent devices from being infected with malware and, if they do get infected, prevent them from reaching out to C&C servers.

None of this should be a reason for device manufacturers to ignore security in the design process. But getting the IoT industry to take security more seriously is likely to be a long process. In the meantime, anything we can do to mitigate the risks is very welcome.

twitter.png
fb.png
linkedin.png
hackernews.png
reddit.png

 

Latest posts:

In memoriam: Dr Alan Solomon

We were very sorry to learn of the passing of industry pioneer Dr Alan Solomon earlier this week.

New paper: Nexus Android banking botnet – compromising C&C panels and dissecting mobile AppInjects

In a new paper, researchers Aditya K Sood and Rohit Bansal provide details of a security vulnerability in the Nexus Android botnet C&C panel that was exploited in order to gather threat intelligence, and present a model of mobile AppInjects.

New paper: Collector-stealer: a Russian origin credential and information extractor

In a new paper, F5 researchers Aditya K Sood and Rohit Chaturvedi present a 360 analysis of Collector-stealer, a Russian-origin credential and information extractor.

VB2021 localhost videos available on YouTube

VB has made all VB2021 localhost presentations available on the VB YouTube channel, so you can now watch - and share - any part of the conference freely and without registration.

VB2021 localhost is over, but the content is still available to view!

VB2021 localhost - VB's second virtual conference - took place last week, but you can still watch all the presentations.

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.