The global cyberattack of WannaCry showed how vulnerable corporate IT systems are for well-trained hackers. At the same time, protected systems were attacked, and very soon tens of billions of devices will appear in the world, many of which will be practically defenseless against intruders.
More Internet devices of things - wider opportunities for intruders.
According to various forecasts in four years in the world will be more than 22 billion devices of the Internet of things (IW), and most of them will be with minimal cyber protection and without regular software updates. For hackers, IW is of particular interest, because even simple DDoS attacks are very effective if they are implemented with the help of millions of "spamming" video cameras, sensors and other Internet devices of things.
According to the system engineer of Fortinet Dmitry Kupetsky, in the near future IV equipment will be subjected to more and more attacks. There are several main reasons for this.
"In modern conditions, the infrastructure of the Internet for things is growing rapidly, the number of devices with access to public networks. Accordingly, along with this, the number of opportunities for intruders is growing, "the expert notes.. - In this case, IV-devices often have limited computing resources, outdated and vulnerable software without any means of protection. This facilitates the process of compromising and hacking of such devices.
Today, regulatory authorities do not impose stringent requirements on the provision of information security functions to IT equipment manufacturers. As a result, a combination of a very wide distribution of the Internet of things, a high vulnerability of devices and a lack of clearly regulated requirements for their cyber defense. Not surprisingly, the Internet of things is an attractive destination for cyber attacks. At the same time, potentially these attacks can be very large and destructive in the near future ".
How to protect the Internet devices of things.
The first example of a large-scale successful DDoS attack using IW is dated 2016. , When cybercriminals managed to gain access to surveillance cameras, children's monitors and other household devices. Then followed the DDoS-attack, which for several hours blocked access to large Internet resources, for example, Twitter, Netflix and Facebook. Many IV devices did not even change the factory passwords, which allowed attackers to quickly intercept control and create a huge botnet.
Fortunately, the attack did not affect critical infrastructure facilities, such as utilities or hospitals. But the example of WannaCry showed that it is possible. In addition, in the space of the Internet of things there are systems responsible for the physical safety of people, for example, robot cars, which in three years on the roads will be about 10 million.
Of course, cars will be protected from cyberattacks, but attackers will certainly be looking for the vulnerabilities of connected cars.
If cybercriminals manage to successfully carry out several large-scale attacks, confidence in IW may decrease, which will slow the transition to new more efficient technologies. Therefore, companies - developers of cyber defense systems, such as Fortinet, are already creating tools to ensure information security of the Internet of things.