How Should IT Teams Secure IoT Deployments?

273 views
β€’
May 2, 2018
by
RSAC Cybersecurity
YouTube video player
How Should IT Teams Secure IoT Deployments?

TL;DR

IT teams should secure IoT deployments by identifying threats across endpoint, transport, application, and cloud components, then selecting controls suited to each device and connection type. Traditional IT tools cannot always address IoT systems because devices differ in hardware, software, functionality, connectivity, exposure, and manageable security capabilities.

Transcript

Uh, good morning, everybody. Uh, my name is Senthil Ramakrishnan, and I'm part of AT&T's, uh, IoT team. Um, thank you all for coming out this morning. Um, so today, uh, we're gonna be talking about moving from IT to IoT and, uh, what some of the security concerns and some possible solutions and paths forward, uh, that, uh, that we can look at. So A... Read More

Key Insights

  • IoT architecture consists of endpoint devices, transport mechanisms, back-end applications or cloud infrastructure, supporting services, and end users. Security must be incorporated throughout this architecture because vulnerabilities and exposure points can exist at every layer rather than only at the network boundary.
  • Endpoint devices are the most exposed layer of the described IoT architecture. They collect operational data and may communicate directly through cellular, Wi-Fi, or low-power wide-area connections, or indirectly through gateways that aggregate device traffic before sending it to a cloud application.
  • IoT connectivity is expected to rely mostly on standard Wi-Fi, with roughly 70 to 80 percent of devices using it, while about 10 to 15 percent use cellular. Wi-Fi can be secured, but the presentation says doing so requires substantial additional care.
  • Cellular IoT adoption is expected to grow because technologies such as LTE-M, LTE Cat 1, and Narrowband IoT allow enterprises to use cellular security capabilities at a cost described as approaching what Wi-Fi can support.
  • Traditional IT security tools and skills are not directly applicable to every IoT deployment. Although IoT shares concerns such as malware, distributed denial-of-service attacks, and unauthorized data access with IT, its architecture and device constraints introduce additional security issues requiring new capabilities.
  • A single enterprise can operate multiple IoT verticals at once, including connected vehicles, factories, technician devices, and smart buildings. Each deployment can involve distinct endpoints, applications, management requirements, policies, security capabilities, and risks, making one universal back-end security solution difficult to use.
  • Back-end integration is a significant source of IoT exposure because the application layer can include third-party services, identity and access management, an IoT platform, hosting infrastructure, and end users. Increasing integration expands the number of components that security planning must address.
  • Effective IoT risk management begins by identifying threat vectors for the specific deployment. Security teams should then pinpoint controls appropriate to its devices, connectivity, applications, and operating environment, with the practical objective of reducing risk to an acceptable level.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should IT teams secure an IoT deployment?

IT teams should first map the complete deployment, including endpoint devices, gateways, transport connections, back-end applications, cloud infrastructure, third-party services, and end users. They should identify threat vectors at every layer and select controls appropriate to the specific hardware, software, functionality, and connectivity involved. Existing IT tools can contribute, but they must be supplemented with IoT-specific capabilities where direct application is unsuitable.

Q: Why are traditional IT security tools insufficient for IoT?

Traditional IT security tools are insufficient on their own because IoT devices and deployments differ widely in hardware, software, functionality, connectivity, exposure, and available security capabilities. Some familiar threats remain, including malware, distributed denial-of-service attacks, and unauthorized data access. However, the structure of IoT systems creates additional concerns that existing IT products, processes, and skill sets cannot always address directly.

Q: What are the main layers of an IoT architecture?

The described IoT architecture begins with endpoint devices that collect and transmit data. The transport layer carries that data through options such as cellular, Wi-Fi, low-power wide-area networks, Bluetooth-connected gateways, or other backhaul arrangements. The data and application layer processes the information using cloud infrastructure, IoT platforms, identity services, or third-party components, after which enterprise or consumer users apply the resulting data.

Q: Why are endpoint devices especially exposed in IoT systems?

Endpoint devices are described as the most exposed layer because they are the connected assets that directly collect data and communicate with gateways, networks, or cloud applications. Their hardware, software, functions, connectivity methods, and security capabilities can vary substantially. This variation means that controls suitable for one endpoint, such as a connected car device, may not be suitable for another, such as a thermostat.

Q: How do gateways work in an IoT deployment?

Gateways provide connectivity backhaul when individual IoT endpoints do not communicate directly with the cloud application. On a factory floor, for example, multiple connected devices may communicate over Wi-Fi or Bluetooth with a cellular access point. The gateway or access point aggregates their data and then sends it through the transport layer to the back-end cloud environment for processing and use.

Q: How does connectivity choice affect IoT security?

Each connectivity option brings its own security capabilities or weaknesses. The presentation estimates that roughly 70 to 80 percent of IoT devices will use standard Wi-Fi and about 10 to 15 percent will use cellular. Wi-Fi can be secured but requires additional care, while cellular provides inherent security capabilities and is becoming more attractive through LTE-M, LTE Cat 1, and Narrowband IoT.

Q: Why is one IoT security solution difficult for an enterprise?

One enterprise may deploy IoT across several operational areas rather than within a single vertical. A company can connect vehicles, factories, service technicians' devices, and buildings for efficiency or automation. These systems use different endpoints and applications, support different security capabilities, and require different device-management and policy approaches. Consequently, relying on one back-end solution across every deployment can be very difficult.

Q: Where can security risks appear in an IoT ecosystem?

Security risks can appear throughout the IoT ecosystem, including endpoint devices, gateways, transport networks, data applications, cloud infrastructure, IoT platforms, identity and access management services, third-party integrations, and end-user access. The endpoint layer is presented as the most exposed, while the application layer can accumulate risk as integration increases and more external services and infrastructure components become involved.

Summary & Key Takeaways

  • IoT systems collect data through connected endpoint devices and deliver it to back-end applications or cloud infrastructure. An endpoint may communicate directly through cellular, Wi-Fi, or a low-power wide-area network, or send data through a gateway that aggregates traffic before forwarding it to the application for processing and use.

  • Security must cover every layer of the IoT architecture because endpoints, transport links, applications, cloud infrastructure, third-party services, and user access can each introduce vulnerabilities. Devices are described as the most exposed layer, while extensive integration within the back-end application environment also creates substantial opportunities for data or system exposure.

  • Enterprises commonly apply existing IT security teams, tools, and skills to IoT projects, but direct reuse is insufficient because IoT deployments vary widely. Connected cars, factory equipment, service devices, and smart-building systems have different capabilities and risks, requiring threat identification, deployment-specific policies, and controls that reduce risk to an acceptable level.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š