bk99.de entertain the web since 1997

The internet of already dangerous things

Summary

Brian Krebs does not warn of a distant IoT risk but of millions of devices that were already reachable and could amplify DDoS attacks. For the report quoted, Arbor Networks surveyed almost 300 organisations. 38 percent reported more than 21 DDoS attacks per month.

Ideas

  • Default services that are switched on quietly turn consumer devices into public attack tools.
  • SSDP and open resolvers amplify small requests into large floods of traffic.
  • Spoofed sender addresses direct the responses of many systems to a single victim.
  • DDoS for hire lowers the cost and expertise needed for effective attacks.
  • The consequences of vendor decisions persist globally long after products have been sold.
  • Cleaning up devices requires coordinated action across operator and national borders.

Insights

  • Insecure defaults shift product costs onto the entire internet.
  • Millions of small misconfigurations together form critical attack infrastructure.
  • Network hygiene resembles public health, because individual inaction has collective consequences.

Quotes

  • The real threat is from The Internet of Things We Already Have That Need Fixing Today. – Brian Krebs

Habits

  • Krebs links measurement data from network operators with attacks on the blog’s own infrastructure.

Facts

  • Akamai found 4.1 million internet-facing UPnP devices that could potentially be abused.
  • The Open Resolver Project recorded more than 28 million devices that could be abused at the time.

References

Critique

  • The figures are a historical snapshot and do not describe today’s device population.
  • The disease metaphor explains coordination well but only roughly names who is responsible.

Remarks

  • The article appeared more than a year before Mirai’s publicly visible escalation.
  • Many problems of the time live on in new device classes and protocols.

Recommendations

  • Disable WAN services and automatic port forwarding you do not need.
  • Filter spoofed source addresses at network borders according to BCP 38.
  • Take inventory of reachable device services and monitor configuration changes.

Read the original article

Search the Web Archive