26
Next-gen advanced threat detection system The role of IPv6 in securing IoT System

The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

  • Upload
    others

  • View
    6

  • Download
    0

Embed Size (px)

Citation preview

Page 1: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

Next-genadvancedthreatdetectionsystem

TheroleofIPv6insecuringIoTSystem

Page 2: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

#1.Security– abigchallengeforIoT

Page 3: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

Fromuserperspective:Whichonewouldyouchoose?

Safer: + 1$

Page 4: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

[Cyber] safer: + 20$

Fromuserperspective:Whichonewouldyouchoose?

Page 5: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

Protocols&Standards:easysetup,wearable,wireless

Safer: + 1$

IoT - Wireless - Security ?

Page 6: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

HackerandDDOS….byIoTdevices

20 -> 50 billion devices IoT by 2020

Page 7: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

IoTSecurityisdifficult

Technical and Cost challenges for Vendors User’s willingness to pay

Page 8: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

IoTandSecurity

How to secure the IoT world ???

Page 9: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

#2.IoTSecurityRisks

Page 10: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

IoTandSecurity

Device Firmware

Device Memory

Mobile Apps

Device InterfacesLocal Data Storage

Network Traffic

Vendor Backend API

3rd party Backend API

Update mechanism

Cloud web interface

And many things.....

OTA

Read/writedevicebywireless

Page 11: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

• Manystandard• Manyconnection• NoIP(BLE,Zigbee,Z-wave,RF)• NoSecurityStandard

IoTProblems

Page 12: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

IoTandSecurity

Gartner

Page 13: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

IoTandSecurity

Gartner

Page 14: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

#3.HowIPv6helpsecurityforIoT

Page 15: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

• RemoteGatewayBLE,zigbee,z-wave

SimplewithIpv6

Page 16: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

• RemoteGatewayBLE,zigbee,z-wave• Otherbrand,protocolcaninterface:Thinktalkthink

SimplewithIpv6

IPv6

Page 17: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

• ReconnaissanceAttacks• DenialofServiceAttacks• Man-in-the-middleAttacks• ARPpoisoningAttacks• DDoS• MalwareAttacks

IPv4Problems

Page 18: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

• MandatoryuseofIPSec• AH(AuthenticationHeader)• ESP(EncapsulatingSecurityPayload)

IPv6EnhancementforSecurity

Page 19: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

• LargeAddressingSpace• Allocating64bitsforaddressing(asexpectedinanIPv6subnet)meansperforminganetscanof2^64(18446744073709551616)hosts.Itispracticallyimpossible.

IPv6EnhancementforSecurity

Page 20: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

• NeighborDiscovery• BothNDandaddressauto-configurationcontributetomakeIPv6moresecurethanitspredecessor.

IPv6EnhancementforSecurity

Page 21: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

• ReconnaissanceAttacks=>Better• DenialofServiceAttacks =>Better• Man-in-the-middleAttacks =>Better• ARPpoisoningAttacks =>Better• MalwareAttacks =>Better

IPv6EnhancementforIoT Security

Page 22: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

IPv6EnhancementforIoT Security

Edge Technology Aspect Vulnerability Areas Remediation Options

Network: Wired and Wireless •Large attack surface•Flat networks and unauthenticated network access•Missing security

•Connectivity inventory•Secure protocols•Network zoning•Device authentication

Network: Internet and Other Public Connectivity

•Missing security•Legacy protocol support•Unsecure inbound connections

•Secure protocols•Inbound access control

Devices: Hardware/Software •Physical and logical tampering•Software reverse engineering

•Secure software development•Software hardening•Hardware tamper-proofing

Devices: Capability Constraints •Limited cryptographic options•Limited active security options

•Passive security•Low-power security techniques•Use of more-powerful edge devices, such as gateways

Devices: "Non-IT" Technology •Lack of applicable IT security capabilities, technologies and practices

•Combined cybersecurity and engineering practices•Adapted security patterns and technologies

Devices: COTS Components •Vulnerable common components •Secure software development•Secure updates

Devices: Software Updates •Lack of secure software update functions•Lack of updatability

•Verified update connectivity•Verified update packages

Devices: Actuator Hardware •Safety implications•Lack of manual user controls

•Use of hardware-based safety controls•Use of manual (backup) controls

Page 23: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

IPv6EnhancementforIoT Security

Platform Technology Aspect Vulnerability Areas Remediation Options

Network: Edge and Enterprise Communications

•Lack of built-in protocol security•Legacy protocol support

•Secure protocols and secure protocol configuration•Use of TLS or DTLS as a default option•Use of standardized protocols, such as HTTP and MQTT

Network: Internet and Other Public Networks

•DoS attacks•API abuse

•Network-based API security measures•Client authentication

Software: Privileged User Access and Data Security

•Loss of security through risk aggregation

•Scope limits for privileged users•Privileged user monitoring•Strong authentication•Secure platform component configuration

Software: Security Capabilities •Lack of security capabilities, such as security monitoring and security management

•Using available platform capabilities•Extending platform software capabilities to powerful edge devices

Page 24: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

#4.Conclusion

Page 25: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

• SecurityisabigchallengeforIoT• IPv4hassomeprobleminsecurity• IPv6withenhancedfeaturescanhelpIoT

#4.Conclusion

Page 26: The role of IPv6 in securing IoT System2017.ipv6event.vn/sites/default/files/FPT-IPv6 and IoT Security-V2.pdf · How IPv6 help security for IoT •Remote Gateway BLE, zigbee, z-wave

Q&A!