In this episode of Cyber Security Inside, Camille and Tom get to chat with Malcolm Harkins, Chief Security & Trust Officer at Epiphany Systems, and Rob Bathurst, Co-Founder & Chief Technology Officer at Epiphany Systems about the Internet of Things and thinking like attackers to protect systems. The conversation covers:

  • How the systems in a building physically can be a vulnerability in an organization’s systems.

  • How thinking like an adversary and what their goals might be is the key to protecting your systems the best you can.

  • How complex Internet of Things systems are, and ideas on how to protect them.

  • The difference between vulnerability and exploitability, and how to look at both.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • The Internet of Things, or IoT, enables a lot of capabilities, but also creates a lot of security issues. To adjust for this, we have to change the way industry views security.

  • Everything is connected to technology and networks now, from air conditioning regulation to elevators, it is all connected and inside of a network. Securing that system is incredibly important, because it is now about peoples’ safety inside the building.

  • It might be easier for an attacker to go after these systems than the computers and servers inside the buildings. For example, at a large sporting event, if you own the stadium, you own the event.

  • To learn how to protect a building or an organization, you have to work backwards by thinking about how somebody might disrupt that building. You can then work on protecting it with that information. This is tricky when you have many different parties in a space with different goals and access levels.

  • At a stadium, for example, you have food vendors, the entertainment, and more. They all need access to process credit cards, access for fans to tweet, etc. So do you put them on your internal network or on an outside network? Assessing the threat is an important part of this decision.

  • This is similar to threat modeling, but with an extra complexity with the IoT systems and the interacting networks. If one vulnerability in one area could take down an entire operation, it is a big deal that requires a lot of consideration. Even removing one system, like the elevator system, can create panic and shut down an entire operation.

  • To really start to secure these systems, you need to think like the people trying to take them down. Take a good look at your organization, your business, and ask yourself: if I were an adversary, where would I go for maximum disruption?

  • There are differences between enterprise and IoT, including IoT having less visibility and more complexity because it is nested. The connectivity of everything is deep, and protecting a perimeter isn’t as realistic in IoT as it is in enterprise.

  • Coming together as a team to talk about security and what could potentially happen is one of the best ways to create a defensive understanding. We can’t stay in our small silos with this connectivity - we have to talk to each other and expand the reach of each of our scopes.

  • It is impossible to prevent every attack. That’s why it is important to identify the goal of the attacker and evaluate your system based on that information. It is more about managing the cumulative impact and reducing it.

  • When looking at something like Log4j, you need to look at where the maximum impact to your business is and address the vulnerability there. Otherwise, you might cripple the enterprise because of the effort and time put into testing, checking, and remediating areas that aren’t as critical.

  • Exploits apply to more than just vulnerabilities, and vulnerabilities are not just flaws in software or hardware. It is all about the adversary’s ability to take advantage of either. And they don’t just apply to single technical conditions, but the relationship between them.

  • A way to think about this is to relate it to fire prevention. You can’t prevent every fire ever from occurring in your building. But you can have smoke detectors, sprinklers, fire doors, and ways to call the fire department. And the more protections you have in place, the faster you can isolate the problem and resume operations, rather than the whole building going down. Proactivity is important!

Some interesting quotes from today’s episode:

“If you look at a building, most people just think of it as a shell with glass and doors and floors. And when you really look at it, it really is a connection of different systems. In most modern buildings because of energy regulation and things they get for LEED certification (basically how efficient their building is) they put in automated control systems for their furnaces, their boilers, their air conditioning units, elevators, power systems, access control.” - Rob Bathurst

“Think of the recent ransomware trend where organizations have been impacted and they’ve been held hostage. In some cases, it might be easier for an attacker to, in essence, attack and exploit the building and create that ransomware event rather than just all the PCs and servers.” - Malcolm Harkins

“You have to understand the way an adversary or somebody might disrupt that building, that organization, the people within it. And based on those objectives, based on those goals, you can kind of work backwards and say, how do I protect those systems?” - Rob Bathurst

“What might seem like an obscure vulnerability that could be exploited in one area could actually take down the entirety of an operation. Shut down the elevator system, turn off the fire life safety system, shut down the heating and air conditioning… Think of the chaos that would create.” - Malcolm Harkins

“People naturally want to think good thoughts. They want to be positive. They want to do the best for the places they work. And that sometimes keeps them from thinking: oh, if X, Y, Z went down, the whole place would fall apart. Because that’s the place they work. But what we try and tell people is that's the mentality you need to be able to start to understand how to more properly architect and defend yourself.” - Rob Bathurst

“That’s how the bad folks go from an initial foothold, that toehold, by popping one thing. And then all of a sudden navigating their way through the daisy chain of connections, to the moment of material impact.” - Malcolm Harkins

“When you look at things at a: what are we trying to do? We’re not trying to stop all things all the time forever, because it’s just an impossible task. The environment is too dynamic, everything else is going on. What we’re trying to do is we’re trying to limit the attacker’s opportunity at the moments of greatest weakness.” - Rob Bathurst

“You can build a strategy, as Malcolm pointed out, to reduce the exploitable paths. And for the ones you can’t reduce, create resilience, create friction as we typically call it, so that you are aware the adversary is trying something or that you’re able to block it.” - Rob Bathurst

“You can be vulnerable, but not be exploitable. You could have an exploit happen again at a laptop or a pinpoint device, but that doesn’t mean your organization is exploitable to a material event.” - Malcolm Harkins

“When you build the building, you have a building inspector, you have a fire marshal, you have people come around and check it and evaluate it, and make sure it’s up to code. And we don’t have that kind of same rigidity in the security space.” - Rob Bathurst