기본 콘텐츠로 건너뛰기

Keeping Smart Homes Safe And Secure

Bad actors are increasingly targeting connected devices, and network providers are fighting back. But when it comes to protecting the IoT, a one-size-fits-all approach simply doesn’t fit. The security measures that protect IoT devices in business settings don’t readily translate to devices in consumers’ homes, says Marcio Avillez, SVP of networks at CUJO AI. In the latest Intelligence of Things Tracker, Avillez makes a case for taking a device-specific approach in thwarting threats to smart homes.



Consumers often find the promise of greater convenience to be a convincing reason to buy connected devices. Unfortunately, reports of breached connected devices are all too frequent, and consumers may find they are introducing not just connectivity, but also bad actors, into their homes.
IoT-related breaches are innumerable. In 2017, the FBI warned consumers against purchasing IoT-connected toys, stating that such devices could be hacked and used to record and spy on children. Later the same year, researchers at a security firm in Tel Aviv found a weakness in an LG-manufactured connected vacuum that could allow malicious actors to watch people in their homes through the vacuum’s camera. Stories of good tech falling to bad actors have only continued to come out as IoT presence in homes increases.
Marcio Avillez, senior vice president of networks for software solutions provider CUJO AI, believes that protecting smart home devices presents a unique challenge.
“On a computer or laptop, or tablet or even mobile phone, you can put software on it — an endpoint solution that can protect it,” Avillez said. “But when you look at all these devices people are bringing into their homes in increasing quantities — cameras, thermostats — you’re not able to add to them. [And] the threats that those enable are very different than the threats you get with a computer.”
While cybercriminals are more likely to get the most bang for their buck by accessing large organizations with troves of valuable data, there are several reasons that draw them to exploit security flaws in home devices, Avillez said. Among the most common are gaining remote access for spying, commandeering the device for bitcoin mining and using the device to launch part of a DDoS attack.
But change may be on the way. According to Avillez, artificial intelligence (AI) and machine learning (ML) could provide a cure for at least some of what ails the connected home space.
Home Is Where the Hacking Is?
There are several reasons why many security solutions that work effectively in other sectors fall short of protecting smart home devices, Avillez said.
The inability to add security software to most connected appliances means an approach that works well for devices like laptops or mobile phones won’t work for IoT-enabled tech.
Turning to businesses for security models also falls short, he explained, making matters even more complicated. Enterprises hoping to ensure a secure network typically use a firewall box equipped with powerful computational abilities to decrypt and examine network packets, which will be flagged for further examination by the company’s system operator if suspicious behaviors are detected.
Protecting consumers is more complex, however, because network operators serving residential customers cannot simply use the same approach that works for businesses. For example, while enterprises’ firewall boxes tend to have robust computational power, regular customers avoid such high-quality boxes due to their high price tags. Instead, they equip their residences with cheaper routers that have less power.
Network operators may also be tasked with protecting the broadband networks of as many
as 20 million homes, Avillez said. That’s often too much analysis work for a systems operator team to handle.
“The industry has developed very good solutions to protect organizations and enterprises against cyber threats … [but the home] is a completely different environment,” Avillez said. “The whole premise of being able to rely on a super-powerful computer at the edge of the network, know what ‘bad’ looks like and have people make decisions about remediation just does not scale when you start talking about protecting 10, 15, 20 million broadband homes.”
(Behavior) Knowledge Is Power
There are solutions to these consumer complications, however – and, according to Avillez, they may lie in leveraging data, and AI and ML platforms for threat analysis and response. Because consumers typically have less powerful routers than enterprises, Avillez believes that making security solutions more effective means using cloud-based services to increase the computational capacity that can be used for detecting threats. With network providers trying to protect millions of homes, AI-enabled solutions may be better suited than humans to deal with the increased workload.
To detect threats, AI-enabled cloud-based platforms need to identify specific home devices, analyze their network activity and identify when behavior is abnormal for a particular device. For instance, these platforms must be able to recognize if a Nest device suddenly starts interacting with an unusual IP address, or communicating at a more rapid rate than is normal. That line of problematic communication can then be blocked without taking the device offline, helping to shut down threats as they appear.
“You’re looking for [instances like], ‘I have this one Nest thermostat here in this one home that’s behaving differently from the 10,000 other Nest devices I’ve seen,’” he said. “That’s a good indication that the device has been compromised.”
To support this threat detection strategy, the system must quickly amass data in order to establish what activity is normal for that device, and to which vulnerabilities it is most likely to be exposed. This is assisted by the fact that these home devices tend to have very specific purposes, enabling the system to more easily gain an understanding of what typical behavior looks like, Avillez said.
For security companies using such a strategy, staying ahead of intruders requires keeping up-to-date on new devices that come to market and preparing their ML platform to understand each one.
Regarding Remote Access
Sometimes, IoT security solutions even turn to the consumers for help.
Instances of remote access are becoming increasingly important to monitor. When this activity is detected, users are alerted via app-based notifications and asked to confirm whether the activity appears legitimate or not.
A U.S.-based homeowner, for example, might install a connected camera to allow him to check in on his second home. Then, when the AI platform detects that someone from Argentina is accessing the home’s smart camera, it will notify the user. He can then either confirm in-app that this is a strange occurrence and likely an act of spying or, if he believes there’s a legitimate reason — for instance, if he has family in Argentina who may be checking in — he can let it pass, Avillez said.
As more consumer IoT solutions roll out, residences will likely become more connected than ever before. Of course, if consumers decide that adopting the latest technological conveniences is too dangerous, that IoT expansion could grind to a halt, upsetting business for manufacturers and retailers. Enabling consumer IoT to advance safely means tailoring a security approach that is unique to the characteristics of different home devices.
That often means taking a smart, AI-powered approach to identifying and thwarting threats, to keep the home – and the tech inside – safe and sound.

댓글

이 블로그의 인기 게시물

지문 넘어 정맥·홍채로...4000억원 '생체인증' 선점경쟁

4000억원 규모 국내 생체인증 시장을 선점하기 위해 관련 업체 경쟁이 치열하다. 생체인증시스템이 현금자동입출금기( ATM )부터 공항 신분확인, 기업 출입관리까지 다양한 분야로 확대된다. 지문인증을 넘어 손바닥, 손가락 정맥(장정맥, 지정맥)과 안면, 홍채 등 다양한 신체 부위를 활용한 인증 솔루션이 각광 받는다. 25일 업계에 따르면  Sh 수협은행은 장정맥 기반 금융서비스를  ATM 에 먼저 적용한다. 자체 기기에 도입하는 데 그치지 않고, 장정맥 인증 확산을 위해 타행· GS 리테일과 제휴도 추진한다.  GS 25 편의점 내  ATM 에서 장정맥 인증으로 입·출금, 계좌이체 등이 가능해진다. 신협중앙회는 손가락 정맥패턴을 이용한 '지정맥' 인증 시스템을 고객 간편결제 서비스에 도입하는 방안을 검토한다. 지난해 시스템 통제와 임직원 확인용 지정맥 인증을 사내 도입했다. 생체인증은 금융권 중심으로  ATM 과 개인금고, 공항, 기업 출입 등 다양한 곳에 활용된다. 한국후지쯔는 신한은행 시작으로 국민은행, 우리은행,  NH 증권, 롯데카드, 케이뱅크 등에 장정맥 인증 서비스 '팜시큐어'를 공급했다. 제주·김포공항에 장정맥을 이용한 실명확인 시스템을 구축했다. 동서석유화학,  SK 텔링크 등 일반 기업도 도입했다. LG 히다찌는 지정맥 인증 서비스를 신협중앙회 사내통제시스템뿐 아니라  BNK 부산은행 스마트  ATM 에도 공급했다. 부산은행은  ATM 뿐 아니라 은행창구 등에도 지정맥을 활용한다.  LG 히다찌는 신한카드, 나이스정보통신 등과 업무협약을 맺고 오프라인 간편결제로 지정맥 활용 준비 작업에 나섰다. 계명대 동산의료원과도 업무협약을 맺고 병원 인증시스템 도입도 검토한다. 국내 스타트업 위닝아이는 카메라를 이용한 손바닥 인증 기술을 전북은행 '뉴스마트뱅킹', 한화손해보험 '스마트인슈', 신영증권 등에 공급했다. 현대모비스와 손잡고 차량용 인증 기술 개...

BLACK LABEL, An IoT Security and Platform Company, Signed An MOU of Developing Security Solution for WDF Cryptocurrency

On June 21, 2018, Black Label Gangnam signed an MOU for the development of an integrated security solution for electronic wallets, servers and shopping malls to be issued by (re) the WDF cryptocurrency by the World Distribution Federation.  (re) The World Trade Federation, under the umbrella of the United Nations, is building a global distribution platform with more than 80 member countries around the world. On this platform, we are developing cryptography for the payment of funds for distribution and for the payment of shopping malls, and have developed this security solution in conjunction with the black label and signed a working agreement for integration. We are going to issue an IC card with the black label's patented pattern-free personal identification code (RSA +, BLACK LABEL's Patent Technology) and apply it to individuals ' electronic wallets, company servers, and shopping mall payment security.  The biggest problem with cryptography is the physical security of...

BLACK LABEL IoT SECURITY SOLUTION, MUTUAL VERIFICATION SYSTEM

Black Label's security solution is a mutual verification system, which is a personal identification security solution through mutual verification between SIM and identity authentication server. Among existing wireless communication networks, a mobile communication network using a USIM, which is a personal identification device, is considered to be most secure against hacking. This is because the USIM card has a personal identification code, including the user's mobile communication number, so it sends and receives a telephone call or message after authentication. BLACK LABEL has developed a security solution called "Mutual Verification System" by utilizing the characteristics of SIM and enhancing the disadvantages of the personal identification process to enhance the personal identification security. The mutual verification system is a system that sends and receives personally identifiable information to the authentication server by infinitely changing the i...