184
A. Francillon et al.
11.1.1 Lack of Transparency
Today, many smart devices are compromised during massive attacks, and may be
abused to form large botnets (networks of compromised devices). Record-high
Distributed Denial of Service (DDoS) attacks (i.e., network flooding) reportedly
generated between 620 Gbps and 1 Tbps of traffic [241, 344]. These DDoS attacks
were reported to use several hundred thousand compromised embedded/smart
devices, comprising dozens of different models of Commercial Off-The-Shelf
(COTS) products like IP/CCTV cameras and home routers. Most of those devices
were compromised using default or hard-coded credentials set by the manufacturer [345]. Malware running on such devices has complete control over the traffic
that is generated, and most smart devices do not embed any infection detection or
prevention mechanism. Worse yet, the users or owners of the device are often not
aware of the problem, and unable to solve it. In fact, devices are not designed to
be inspected and modified by end-users (e.g., to perform forensics as discussed in
Chap. 13).
11.1.2 Lack of Control
Another important problem is that smart devices are generally provided as a fixed
software (i.e., firmware) and hardware platform, often tied to a cloud service
and bundled together as a closed system that the user has little control over. An
example of the negative consequences of this customer lock-out is the Revolv smart
thermostat. Revolv’s manufacturer was acquired by its competitor Nest, and after a
year Nest stopped the cloud service, rendering the Revolv thermostats installed in
homes impossible to use [271]. Users often have no choice regarding which software
the device should run, or which cloud service to use, or what the device should do.
Choosing, installing and using alternative software for such devices is difficult, if
not impossible, often due to the single-purpose nature of the hardware and software
design, the lack of public documentation, in addition to any anti-tampering measures
imposed by the manufacturer.
11.1.3 Lack of Resistance to Attacks
In practice, Internet scanning botnets are active enough that some devices will be
compromised within a few minutes after being connected to the Internet [344]. To be
considered trustworthy, devices need to have a certain level of resistance to attacks.
This is astonishing, because in essence many of the recurring security issues with
smart devices have already been “solved” for many years. If vulnerabilities and
corresponding attack situations could ultimately be avoided, it is important to ask
Précédent

- 191/268

Suivant