When Refrigerators Attack - Defending (and weaponizing) IoT

Presented at THOTCON 0xA (2019), May 3, 2019, noon (50 minutes)

"IoT is in the press almost daily. This talk presents 3 abstracts with live examples of weaponizing, defending and securing IoT devices. Relive my encounters of: ""When Refrigerators Attack"" or ""How I beat back the Deadly Dishwasher"". And of course, the all time favorite, ""Killer Webcams from Outer Space!"" This talk opens with brief introduction to IoT types of attacks and vulnerabilities, over the five IoT verticals of wearables, connected car, connected homes, connected cities, industrial. Time to expand on the IoT specifics of how devices are developed, including issues such as reused code, crypto limitations as well as re-used firmware. The talk continues with connecting to how IoT utilizes the cloud for data storage, type of data and how the cloud is overlooked in most IoT security issues. Live (backup recordings, just in case) demos are now shown with several IoT devices, exploring attack methodologies and details of the attack surface presented by most IoT devices. Connect with IoT security development and OWASP methodologies, especially related to APIs and Big Data (in the cloud). Final section of talk expands on IoT honeypots with several examples showing SCADA devices, routers and webcams. A recorded example of ""Iot_Reaper"" was actually caught by a custom honeypot and will be shown in this part of the talk. Conclusions of better methods for development of IoT but at the same time, how to better protect against weaponized IoT devices when your device (or your company) is the target. The key is to think just a bit differently when approaching IoT security, but also using existing skillsets and tools in the world of attacking refrigerators. The talk uses live examples (or recorded video as backup) and shows real-world scenarios with a variety of devices. A win-win for this talk is that attendees not only learn, but they walk away with tools and methods that are practical and can be put into use immediately."


Presenters:

  • Kat Fitzgerald
    You can typically find me sipping Casa Noble Anejo whilst simultaneously defending my systems using OSS, magic spells and Dancing Flamingos.

Similar Presentations: