SlideShare uma empresa Scribd logo
1 de 35
IIoT Endpoint Security –
The Model in Practice
February 22, 2017
Industrial Internet Security Framework
#IICSeries
Guest Speakers
2
MARCELLUS BUCHHEIT
President and CEO, Wibu-Systems USA
Editor, Industrial Internet Consortium Security Framework
@WibuSystems
TERRENCE BARR
Head of Solutions Engineering, Electric Imp, Inc.
@electricimp
Motivation
Unprotected devices in internet are dangerous!
They can be used to:
• Intrude into local networks: stealing or deleting private data
• Block or alter websites or internet communication
• Upload viruses and start Denial-of-Service (DoS) attacks
Additional for IIoT:
• Shut down public or private services (electricity, water, sewer etc.)
• Prevent commercial usage (production, hospitals, hotels, PoS etc.),
• Damage or destroy industrial installations or produced parts
3
Motivation
Unprotected devices problematic for component manufacturer
• Example: FTC charges D-Link for unsecure routers and IP cameras
• https://www.ftc.gov/news-events/press-releases/2017/01/ftc-charges-d-link-put-consumers-privacy-risk-
due-inadequate
Unprotected devices problematic for users/operators
• Example: Point-of-Sale (POS) attack at Target end of 2013
• 40 million credit cards and 70 million addresses stolen
• Target paid $50M+ for settlements
• http://krebsonsecurity.com/2014/02/target-hackers-broke-in-via-hvac-company/
4
A few words about Wibu-Systems
• Wibu-Systems was founded in 1989 in Germany
• Global company targeting secure software licensing
• Offer security and licensing solutions for IIoT systems and devices
• More about the company: www.wibu.com
• More about the key product: http://www.wibu.com/codemeter
• More about IIoT security: http://www.wibu.com/embedded-software-
security
• And since 2015 member of the Industrial Internet Consortium (IIC)
5
About the IIC
Industrial Internet Consortium
Security Webinar
February 22, 2017
Kathy Walsh, walsh@iiconsortium.org
Director of Marketing
The Industrial Internet is Leading the Next Economic Revolution
7GDP data extracted from the Futurist 2007
Bring Together the Players to Accelerate Adoption
8
Connectivity
Standards
Technology
Research Academia
Systems
Integration
Security
Government
Big Data Industries
The Industrial Internet:
A $32 trillion opportunity
The IIC: Things are Coming Together
9
Things are coming together.
Academia
Standards
Research Systems Integration
Government
IndustriesConnectivity
Technology
Big Data
Security
The Industrial Internet Consortium is a global, member supported
organization that promotes the accelerated growth of the Industrial
Internet of Things by coordinating ecosystem initiatives to securely
connect, control and integrate assets and systems of assets with people,
processes and data using common architectures, interoperability and
open standards to deliver transformational business and societal
outcomes across industries and public infrastructure.
Launched in March 2014 by five founding members:
AT&T, Cisco, General Electric, IBM & Intel.
The IIC is an open, neutral “sandbox” where industry, academia and
government meet to collaborate, innovate and enable.
Industrial Internet Consortium Mission
Over 250 Member Organizations
Spanning 30 Countries
Securing IIoT Endpoints --
The Model
Industrial Internet Consortium
Security Webinar
February 22, 2017
Marcellus Buchheit, mabu@wibu.com
Wibu-Systems USA Inc.
Overview
What is an endpoint?
Why endpoint security?
Security functions of an endpoint
Implementing endpoint security
12
What is an Endpoint?
13
The IIoT Landscape: Where are Endpoints?
E
P
E
PE
P
E
P
E
P
E
P
E
P
What is an Endpoint (II)?
IISF and IIC defines endpoints similar as ISO/IEC 24791-1:2010 standard
does:
• An endpoint is one of two components that either implements and
exposes an interface to other components or uses the interface of another
component.
14
IIC simplified this definition (see IIC Vocabulary, version 2.0):
• An endpoint is a component that has an interface for network
communication.… but added a note for clarification:
• An endpoint can be of various types including device endpoint or an
endpoint that provides cloud connectivity.
Endpoint 1 Endpoint 2
Communication
What is an Endpoint (III)?
15
The IIoT Landscape: Endpoints are
everywhere!
E
P
E
PE
P
E
P
E
P
E
P
E
P
What is an Endpoint (IV)?
Summary:
• Endpoints are everywhere in an IIoT System (including edge and cloud)
• One single (security) model for all locations
• A single computer, even a device, can have several endpoints
• Example Router: One LAN endpoint, one WAN endpoint
• Frequently shared code/data between multiple endpoints
• Endpoint and its communication is another model
16
Why endpoint security?
Endpoints are the only location in an IIoT system where:
• Execution code is stored, started and updated
• Data is stored, modified or applied (“Data at Rest” / “Data in Use“)
• Communication to another endpoint is initiated and protected
• Network security is analyzed, configured, monitored and managed
17
Result: An attack to an IIoT system typically starts in attacking one or more
endpoints:
• Try to access the execution code and analyze to find weak security
implementation
• Attack weak communication protection via network
• Modify or replace (“hijack”) the execution code in a malicious way
IISF Endpoint Protection Model
18
Threats and Vulnerabilities to an IIoT Endpoint
19
1. Hardware components
2/3. Boot process
4. Operating System
5. Hypervisor/Sep. Kernel
6. Non-OS Applications
7. Applications and their API
8. Runtime Environment
9. Containers
10. Deployment
11. Data at Rest, Data in Use
12. Monitoring/Analysis
13. Configuration/Management
14. Security Model/Policy
15. Development Environment
Endpoint security: Solutions
• Start with a clean design of the security model and policies
• Define endpoint identity, authorization, authentication
• How other endpoints see me? What can they do with me?
• Define proper data protection model
• Integrity and confidentiality, especially of shared data-in-rest but also data-in-
use
• Define secure hardware, BIOS, roots of trust
• Includes lifetime of hardware, BIOS update, consistent root of trust
• Select secure OS, hypervisor, programming language
• Consider lifetime of (open source?), dynamic of programming language
• Consider isolation principles (4 different models explained in IISF)
• Plan remote code update and provide code integrity
• Security has an unspecific expiration date: needs update
• Code integrity prevents malicious remote code-hijacking
20
Endpoint security: Solutions (II)
• Plan “beyond the basics” security instantly
• Plan security configuration and management
• For example: defining, replacing and updating of keys and certificates
• User-friendly setting of access rights and authorization
• Plan endpoint monitoring and analysis
• For example: log all security configuration changes
• Log all unexpected remote activity
• Provide user-friendly analysis, alerts etc.
• Implement “state of the art”:
• Have a team of experienced security implementers
• Use latest versions of development tools, OS, hypervisors, libraries
• Test a lot, including malicious attacks
• Prepare and test your first remote update
21
Endpoint Security in Practice
Example which implements this endpoint security model in practice:
Terrence Barr, Electric Imp
22
Securing IIoT Endpoints --
In Practice
Industrial Internet Consortium
Security Webinar
February 22, 2017
Terrence Barr, terrence@electricimp.com
Head of Solutions Engineering
Endpoint Security
Electric Imp Introduction
Electric Imp
Industrial-strength IoT starts here
Secure IoT Connectivity Platform
Authorized Hardware
for connected devices
impOS™ and hardware
impCloud™
imp Enterprise API’s
BlinkUp™ & impFactory™
impSecure™
Proven IoT Deployments at Scale
• 2016: surpassed 1 Million WiFi/Ethernet devices
• 18B+ data messages per month
• 100+ customers; 105+ countries
Full Lifecycle, Trusted Security
• Passed security review
and pen-testing:
• In process: UL 2900-2-2: Cybersecurity Certification for
Industrial Controls plus first Affiliate program
• Aligned with IIC Security Framework
Fastest Prototype-to-Production
• 5 months for GE connected air conditioner
Endpoint Security
Implementation Approach
Endpoint Security: Part of Integrated and Managed Security
Silicon-to-Cloud Security – Defense in Depth & Defense in Time
7. Full Lifecycle
Managed Services
1. Edge Device Security
incl. Secure Silicon &
Managed Software
4. Secure Communication
via Managed Tunnel
3. Trusted
Manufacture &
Commissioning
6. Secure Cloud and Application
Integration
2. Data Privacy, Integrity &
Confidentiality
5. Protected Public &
Private Cloud
IISF Endpoint Protection
Techniques
Electric Imp Implementation
Protecting Endpoints: General Endpoint protection from the silicon upwards, every level tightly
integrated and tested for full coverage of security objective and no weak
links
Architectural Considerations for
Protecting Endpoints
Designed from the ground up for resource-constrained IoT devices and
real-world use cases and proven in large-scale customer deployments
Endpoint Physical Security Disabled hardware interfaces, tampering destroys individual module
Establish Roots of Trust Unique per-device keys, secure provisioning via cloud device
management
Endpoint Identity One-Time-Programming at module manufacturing time
Endpoint Access Control Mutual authentication with RSA certificates and ECC challenge-
response
Endpoint Integrity Protection HSM protected keys, secure boot, non-execution barriers with cloud
alerts
Endpoint Data Protection All processing on-die, all off-die storage with device-unique encryption.
TLS 1.2, AES-128, EDH forward secrecy.
Endpoint Monitoring and Analysis Extensive monitoring of security-sensitive operations
Endpoint Configuration and
Management
Endpoints managed, configured, and provisioned from the impCloud, all
updates signed, encrypted, and logged © Property of Electric Imp, Inc.
CONFIDENTIAL – NOT FOR DISTRIBUTION
Endpoint Security
Real-World Case Study
• Replace analogue lines
• Customer delight exceeds
expectations
• Recognized as Business
Transformation success story
1.5M
Customers
worldwide
Security
for regulated
markets
Reduce
service calls by
20%
© Property of Electric Imp, Inc.
CONFIDENTIAL – NOT FOR DISTRIBUTION
ROI –
Payback in 45 days on
connectivity costs
alone
impSecureTM: Integrated Silicon-to-Cloud Security and Connectivity managed by Electric Imp
‘Drop-In’ Postage Meter Retrofit: Device-to-Cloud Security and Connectivity
imp Application
Module
impOSTM
Meter
Integration
Code
Virtual Machine
paired Virtual Machine
Cloud
Meter
Code
Cloud
Integration
Code
Operations &
Device Lifecycle Management
Cloud Services
Electric Imp
Managed Cloud
USB
Commerce Cloud
Device-paired
Virtual Machines
Scalable to
millions of
devices
No changes to meter
No changes to cloud
Audited and Tested
Meets Postal and Government
Security Requirements
WiFi
Ethernet
IP tunnel
&imp
Endpoint Security
Conclusion
Integrated Security Platform: Customer Benefits
Leverage Proven Solution
• Build on tested and trusted security at a platform level
Isolation of Security Concerns
• Minimize time-to-market and risk of security mistakes
Integrated, Silicon to Cloud Security
• No weak links, even devices exposed in the field for many years
Managed Security as a Service
• Offload headache of ongoing security monitoring and maintenance
Qualify once, reuse many times
• Enable rapid, low-risk multi-product IoT strategy
®
Transforming the world
through the power
of secure connectivity
Thank you!
35
Things are coming together.
Community. Collaboration. Convergence.
www.iiconsortium.org
Additional Resources available as attachments
• Industrial Internet Security Framework
• Security Claims Evaluation Testbeds
• White Paper: Business Viewpoint of Securing the Industrial Internet
• Upcoming Webinars:
• March 30, 2017 Building Blocks for Securing the Smart Factory
• April, 2017 TBD

Mais conteúdo relacionado

Mais procurados

The Internet of Things (IoT) and its evolution
The Internet of Things (IoT) and its evolutionThe Internet of Things (IoT) and its evolution
The Internet of Things (IoT) and its evolutionSathvik N Prasad
 
Internet of things (IOT) | Future Trends
Internet of things (IOT) | Future TrendsInternet of things (IOT) | Future Trends
Internet of things (IOT) | Future TrendsDevanand Hariperumal
 
IoT Standards: The Next Generation
IoT Standards: The Next GenerationIoT Standards: The Next Generation
IoT Standards: The Next GenerationReadWrite
 
Iot.pptx
Iot.pptxIot.pptx
Iot.pptxgagag8
 
Industry 4.0 and the Internet of Things
Industry 4.0 and the Internet of Things Industry 4.0 and the Internet of Things
Industry 4.0 and the Internet of Things Schneider Electric
 
IoT (Internet of Things)
IoT (Internet of Things)IoT (Internet of Things)
IoT (Internet of Things)TusharSoam
 
A Reference Architecture for IoT
A Reference Architecture for IoT A Reference Architecture for IoT
A Reference Architecture for IoT WSO2
 
Industrial Internet of Things (IIoT)
Industrial Internet of Things (IIoT)Industrial Internet of Things (IIoT)
Industrial Internet of Things (IIoT)Aman Soni
 

Mais procurados (20)

The Internet of Things (IoT) and its evolution
The Internet of Things (IoT) and its evolutionThe Internet of Things (IoT) and its evolution
The Internet of Things (IoT) and its evolution
 
IoT
IoT  IoT
IoT
 
Internet of things (IOT) | Future Trends
Internet of things (IOT) | Future TrendsInternet of things (IOT) | Future Trends
Internet of things (IOT) | Future Trends
 
Fog computing in IoT
Fog computing in IoTFog computing in IoT
Fog computing in IoT
 
Blockchain+IOT
Blockchain+IOTBlockchain+IOT
Blockchain+IOT
 
Internet of things
Internet of thingsInternet of things
Internet of things
 
Industrial IoT bootcamp
Industrial IoT bootcampIndustrial IoT bootcamp
Industrial IoT bootcamp
 
IoT and Energy
IoT and EnergyIoT and Energy
IoT and Energy
 
IoT Standards: The Next Generation
IoT Standards: The Next GenerationIoT Standards: The Next Generation
IoT Standards: The Next Generation
 
Understanding IoT
Understanding IoTUnderstanding IoT
Understanding IoT
 
Iot.pptx
Iot.pptxIot.pptx
Iot.pptx
 
IOT System.pptx
IOT System.pptxIOT System.pptx
IOT System.pptx
 
Industry 4.0 and the Internet of Things
Industry 4.0 and the Internet of Things Industry 4.0 and the Internet of Things
Industry 4.0 and the Internet of Things
 
Internet of Things
Internet of ThingsInternet of Things
Internet of Things
 
IoT ecosystem
IoT ecosystemIoT ecosystem
IoT ecosystem
 
Internet Of Things
 Internet Of Things Internet Of Things
Internet Of Things
 
Lecture 10
Lecture 10Lecture 10
Lecture 10
 
IoT (Internet of Things)
IoT (Internet of Things)IoT (Internet of Things)
IoT (Internet of Things)
 
A Reference Architecture for IoT
A Reference Architecture for IoT A Reference Architecture for IoT
A Reference Architecture for IoT
 
Industrial Internet of Things (IIoT)
Industrial Internet of Things (IIoT)Industrial Internet of Things (IIoT)
Industrial Internet of Things (IIoT)
 

Semelhante a IIoT Endpoint Security

IIoT Endpoint Security – The Model in Practice
IIoT Endpoint Security – The Model in PracticeIIoT Endpoint Security – The Model in Practice
IIoT Endpoint Security – The Model in Practiceteam-WIBU
 
Protecting IIoT Endpoints - an inside look at the Industrial Internet Securit...
Protecting IIoT Endpoints - an inside look at the Industrial Internet Securit...Protecting IIoT Endpoints - an inside look at the Industrial Internet Securit...
Protecting IIoT Endpoints - an inside look at the Industrial Internet Securit...team-WIBU
 
[Webinar] Why Security Certification is Crucial for IoT Success
[Webinar] Why Security Certification is Crucial for IoT Success[Webinar] Why Security Certification is Crucial for IoT Success
[Webinar] Why Security Certification is Crucial for IoT SuccessElectric Imp
 
IoT Security Challenges and Solutions
IoT Security Challenges and SolutionsIoT Security Challenges and Solutions
IoT Security Challenges and SolutionsIntel® Software
 
Securing your IoT Implementations
Securing your IoT ImplementationsSecuring your IoT Implementations
Securing your IoT ImplementationsTechWell
 
IoT Security: Debunking the "We Aren't THAT Connected" Myth
IoT Security: Debunking the "We Aren't THAT Connected" MythIoT Security: Debunking the "We Aren't THAT Connected" Myth
IoT Security: Debunking the "We Aren't THAT Connected" MythSecurity Innovation
 
Industrial IoT Security Standards & Frameworks
Industrial IoT Security Standards & FrameworksIndustrial IoT Security Standards & Frameworks
Industrial IoT Security Standards & FrameworksPriyanka Aash
 
Technology & Policy Interaction Panel at Inform[ED] IoT Security
Technology & Policy Interaction Panel at Inform[ED] IoT SecurityTechnology & Policy Interaction Panel at Inform[ED] IoT Security
Technology & Policy Interaction Panel at Inform[ED] IoT SecurityCableLabs
 
Fundamental Best Practices in Secure IoT Product Development
Fundamental Best Practices in Secure IoT Product DevelopmentFundamental Best Practices in Secure IoT Product Development
Fundamental Best Practices in Secure IoT Product DevelopmentMark Szewczul, CISSP
 
IoT Security, Threats and Challenges By V.P.Prabhakaran
IoT Security, Threats and Challenges By V.P.PrabhakaranIoT Security, Threats and Challenges By V.P.Prabhakaran
IoT Security, Threats and Challenges By V.P.PrabhakaranKoenig Solutions Ltd.
 
Io t security defense in depth charles li v1 20180425c
Io t security defense in depth charles li v1 20180425cIo t security defense in depth charles li v1 20180425c
Io t security defense in depth charles li v1 20180425cCharles Li
 
The Subversive Six: Hidden Risk Points in ICS
The Subversive Six: Hidden Risk Points in ICSThe Subversive Six: Hidden Risk Points in ICS
The Subversive Six: Hidden Risk Points in ICSTripwire
 
Cyber security event
Cyber security eventCyber security event
Cyber security eventTryzens
 
Drobics trustworthy io-t-for-industrial-applications
Drobics trustworthy io-t-for-industrial-applicationsDrobics trustworthy io-t-for-industrial-applications
Drobics trustworthy io-t-for-industrial-applicationsMario Drobics
 
CCNA RS_ITN - Chapter 11
CCNA RS_ITN - Chapter 11CCNA RS_ITN - Chapter 11
CCNA RS_ITN - Chapter 11Irsandi Hasan
 
IoT Security Assessment - IEEE PAR Proposal
IoT Security Assessment - IEEE PAR ProposalIoT Security Assessment - IEEE PAR Proposal
IoT Security Assessment - IEEE PAR ProposalSyam Madanapalli
 
CCNA RS_NB - Chapter 11
CCNA RS_NB - Chapter 11CCNA RS_NB - Chapter 11
CCNA RS_NB - Chapter 11Irsandi Hasan
 

Semelhante a IIoT Endpoint Security (20)

IIoT Endpoint Security – The Model in Practice
IIoT Endpoint Security – The Model in PracticeIIoT Endpoint Security – The Model in Practice
IIoT Endpoint Security – The Model in Practice
 
Protecting IIoT Endpoints - an inside look at the Industrial Internet Securit...
Protecting IIoT Endpoints - an inside look at the Industrial Internet Securit...Protecting IIoT Endpoints - an inside look at the Industrial Internet Securit...
Protecting IIoT Endpoints - an inside look at the Industrial Internet Securit...
 
[Webinar] Why Security Certification is Crucial for IoT Success
[Webinar] Why Security Certification is Crucial for IoT Success[Webinar] Why Security Certification is Crucial for IoT Success
[Webinar] Why Security Certification is Crucial for IoT Success
 
ASDF WSS 2014 Keynote Speech 1
ASDF WSS 2014 Keynote Speech 1ASDF WSS 2014 Keynote Speech 1
ASDF WSS 2014 Keynote Speech 1
 
Iio t security std
Iio t security stdIio t security std
Iio t security std
 
IoT security
IoT securityIoT security
IoT security
 
IoT Security Challenges and Solutions
IoT Security Challenges and SolutionsIoT Security Challenges and Solutions
IoT Security Challenges and Solutions
 
Securing your IoT Implementations
Securing your IoT ImplementationsSecuring your IoT Implementations
Securing your IoT Implementations
 
IoT Security: Debunking the "We Aren't THAT Connected" Myth
IoT Security: Debunking the "We Aren't THAT Connected" MythIoT Security: Debunking the "We Aren't THAT Connected" Myth
IoT Security: Debunking the "We Aren't THAT Connected" Myth
 
Industrial IoT Security Standards & Frameworks
Industrial IoT Security Standards & FrameworksIndustrial IoT Security Standards & Frameworks
Industrial IoT Security Standards & Frameworks
 
Technology & Policy Interaction Panel at Inform[ED] IoT Security
Technology & Policy Interaction Panel at Inform[ED] IoT SecurityTechnology & Policy Interaction Panel at Inform[ED] IoT Security
Technology & Policy Interaction Panel at Inform[ED] IoT Security
 
Fundamental Best Practices in Secure IoT Product Development
Fundamental Best Practices in Secure IoT Product DevelopmentFundamental Best Practices in Secure IoT Product Development
Fundamental Best Practices in Secure IoT Product Development
 
IoT Security, Threats and Challenges By V.P.Prabhakaran
IoT Security, Threats and Challenges By V.P.PrabhakaranIoT Security, Threats and Challenges By V.P.Prabhakaran
IoT Security, Threats and Challenges By V.P.Prabhakaran
 
Io t security defense in depth charles li v1 20180425c
Io t security defense in depth charles li v1 20180425cIo t security defense in depth charles li v1 20180425c
Io t security defense in depth charles li v1 20180425c
 
The Subversive Six: Hidden Risk Points in ICS
The Subversive Six: Hidden Risk Points in ICSThe Subversive Six: Hidden Risk Points in ICS
The Subversive Six: Hidden Risk Points in ICS
 
Cyber security event
Cyber security eventCyber security event
Cyber security event
 
Drobics trustworthy io-t-for-industrial-applications
Drobics trustworthy io-t-for-industrial-applicationsDrobics trustworthy io-t-for-industrial-applications
Drobics trustworthy io-t-for-industrial-applications
 
CCNA RS_ITN - Chapter 11
CCNA RS_ITN - Chapter 11CCNA RS_ITN - Chapter 11
CCNA RS_ITN - Chapter 11
 
IoT Security Assessment - IEEE PAR Proposal
IoT Security Assessment - IEEE PAR ProposalIoT Security Assessment - IEEE PAR Proposal
IoT Security Assessment - IEEE PAR Proposal
 
CCNA RS_NB - Chapter 11
CCNA RS_NB - Chapter 11CCNA RS_NB - Chapter 11
CCNA RS_NB - Chapter 11
 

Mais de Industrial Internet Consortium (9)

DER Integration Testbed at a Glance
DER Integration Testbed at a GlanceDER Integration Testbed at a Glance
DER Integration Testbed at a Glance
 
Smart Manufacturing Connectivity for Brown-field Sensors Testbed at a glance
Smart Manufacturing Connectivity for Brown-field Sensors Testbed at a glanceSmart Manufacturing Connectivity for Brown-field Sensors Testbed at a glance
Smart Manufacturing Connectivity for Brown-field Sensors Testbed at a glance
 
How to Lead in IIoT
How to Lead in IIoTHow to Lead in IIoT
How to Lead in IIoT
 
Smart Factory Web Testbed at a Glance
Smart Factory Web Testbed at a GlanceSmart Factory Web Testbed at a Glance
Smart Factory Web Testbed at a Glance
 
Year in Review - IIC's Greatest Hits 2017
Year in Review - IIC's Greatest Hits 2017Year in Review - IIC's Greatest Hits 2017
Year in Review - IIC's Greatest Hits 2017
 
Intelligent Urban Water Supply Testbed at a Glance
Intelligent Urban Water Supply Testbed at a Glance Intelligent Urban Water Supply Testbed at a Glance
Intelligent Urban Water Supply Testbed at a Glance
 
Time Sensitive Networking Testbed at a Glance
Time Sensitive Networking Testbed at a GlanceTime Sensitive Networking Testbed at a Glance
Time Sensitive Networking Testbed at a Glance
 
Microgrid Testbed at a Glance
Microgrid Testbed at a GlanceMicrogrid Testbed at a Glance
Microgrid Testbed at a Glance
 
IIC's Top 10 Accomplishments 2016
IIC's Top 10 Accomplishments 2016IIC's Top 10 Accomplishments 2016
IIC's Top 10 Accomplishments 2016
 

Último

Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdflior mazor
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsRoshan Dwivedi
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?Igalia
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Principled Technologies
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesBoston Institute of Analytics
 

Último (20)

Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 

IIoT Endpoint Security

  • 1. IIoT Endpoint Security – The Model in Practice February 22, 2017 Industrial Internet Security Framework #IICSeries
  • 2. Guest Speakers 2 MARCELLUS BUCHHEIT President and CEO, Wibu-Systems USA Editor, Industrial Internet Consortium Security Framework @WibuSystems TERRENCE BARR Head of Solutions Engineering, Electric Imp, Inc. @electricimp
  • 3. Motivation Unprotected devices in internet are dangerous! They can be used to: • Intrude into local networks: stealing or deleting private data • Block or alter websites or internet communication • Upload viruses and start Denial-of-Service (DoS) attacks Additional for IIoT: • Shut down public or private services (electricity, water, sewer etc.) • Prevent commercial usage (production, hospitals, hotels, PoS etc.), • Damage or destroy industrial installations or produced parts 3
  • 4. Motivation Unprotected devices problematic for component manufacturer • Example: FTC charges D-Link for unsecure routers and IP cameras • https://www.ftc.gov/news-events/press-releases/2017/01/ftc-charges-d-link-put-consumers-privacy-risk- due-inadequate Unprotected devices problematic for users/operators • Example: Point-of-Sale (POS) attack at Target end of 2013 • 40 million credit cards and 70 million addresses stolen • Target paid $50M+ for settlements • http://krebsonsecurity.com/2014/02/target-hackers-broke-in-via-hvac-company/ 4
  • 5. A few words about Wibu-Systems • Wibu-Systems was founded in 1989 in Germany • Global company targeting secure software licensing • Offer security and licensing solutions for IIoT systems and devices • More about the company: www.wibu.com • More about the key product: http://www.wibu.com/codemeter • More about IIoT security: http://www.wibu.com/embedded-software- security • And since 2015 member of the Industrial Internet Consortium (IIC) 5
  • 6. About the IIC Industrial Internet Consortium Security Webinar February 22, 2017 Kathy Walsh, walsh@iiconsortium.org Director of Marketing
  • 7. The Industrial Internet is Leading the Next Economic Revolution 7GDP data extracted from the Futurist 2007
  • 8. Bring Together the Players to Accelerate Adoption 8 Connectivity Standards Technology Research Academia Systems Integration Security Government Big Data Industries The Industrial Internet: A $32 trillion opportunity
  • 9. The IIC: Things are Coming Together 9 Things are coming together. Academia Standards Research Systems Integration Government IndustriesConnectivity Technology Big Data Security
  • 10. The Industrial Internet Consortium is a global, member supported organization that promotes the accelerated growth of the Industrial Internet of Things by coordinating ecosystem initiatives to securely connect, control and integrate assets and systems of assets with people, processes and data using common architectures, interoperability and open standards to deliver transformational business and societal outcomes across industries and public infrastructure. Launched in March 2014 by five founding members: AT&T, Cisco, General Electric, IBM & Intel. The IIC is an open, neutral “sandbox” where industry, academia and government meet to collaborate, innovate and enable. Industrial Internet Consortium Mission Over 250 Member Organizations Spanning 30 Countries
  • 11. Securing IIoT Endpoints -- The Model Industrial Internet Consortium Security Webinar February 22, 2017 Marcellus Buchheit, mabu@wibu.com Wibu-Systems USA Inc.
  • 12. Overview What is an endpoint? Why endpoint security? Security functions of an endpoint Implementing endpoint security 12
  • 13. What is an Endpoint? 13 The IIoT Landscape: Where are Endpoints? E P E PE P E P E P E P E P
  • 14. What is an Endpoint (II)? IISF and IIC defines endpoints similar as ISO/IEC 24791-1:2010 standard does: • An endpoint is one of two components that either implements and exposes an interface to other components or uses the interface of another component. 14 IIC simplified this definition (see IIC Vocabulary, version 2.0): • An endpoint is a component that has an interface for network communication.… but added a note for clarification: • An endpoint can be of various types including device endpoint or an endpoint that provides cloud connectivity. Endpoint 1 Endpoint 2 Communication
  • 15. What is an Endpoint (III)? 15 The IIoT Landscape: Endpoints are everywhere! E P E PE P E P E P E P E P
  • 16. What is an Endpoint (IV)? Summary: • Endpoints are everywhere in an IIoT System (including edge and cloud) • One single (security) model for all locations • A single computer, even a device, can have several endpoints • Example Router: One LAN endpoint, one WAN endpoint • Frequently shared code/data between multiple endpoints • Endpoint and its communication is another model 16
  • 17. Why endpoint security? Endpoints are the only location in an IIoT system where: • Execution code is stored, started and updated • Data is stored, modified or applied (“Data at Rest” / “Data in Use“) • Communication to another endpoint is initiated and protected • Network security is analyzed, configured, monitored and managed 17 Result: An attack to an IIoT system typically starts in attacking one or more endpoints: • Try to access the execution code and analyze to find weak security implementation • Attack weak communication protection via network • Modify or replace (“hijack”) the execution code in a malicious way
  • 19. Threats and Vulnerabilities to an IIoT Endpoint 19 1. Hardware components 2/3. Boot process 4. Operating System 5. Hypervisor/Sep. Kernel 6. Non-OS Applications 7. Applications and their API 8. Runtime Environment 9. Containers 10. Deployment 11. Data at Rest, Data in Use 12. Monitoring/Analysis 13. Configuration/Management 14. Security Model/Policy 15. Development Environment
  • 20. Endpoint security: Solutions • Start with a clean design of the security model and policies • Define endpoint identity, authorization, authentication • How other endpoints see me? What can they do with me? • Define proper data protection model • Integrity and confidentiality, especially of shared data-in-rest but also data-in- use • Define secure hardware, BIOS, roots of trust • Includes lifetime of hardware, BIOS update, consistent root of trust • Select secure OS, hypervisor, programming language • Consider lifetime of (open source?), dynamic of programming language • Consider isolation principles (4 different models explained in IISF) • Plan remote code update and provide code integrity • Security has an unspecific expiration date: needs update • Code integrity prevents malicious remote code-hijacking 20
  • 21. Endpoint security: Solutions (II) • Plan “beyond the basics” security instantly • Plan security configuration and management • For example: defining, replacing and updating of keys and certificates • User-friendly setting of access rights and authorization • Plan endpoint monitoring and analysis • For example: log all security configuration changes • Log all unexpected remote activity • Provide user-friendly analysis, alerts etc. • Implement “state of the art”: • Have a team of experienced security implementers • Use latest versions of development tools, OS, hypervisors, libraries • Test a lot, including malicious attacks • Prepare and test your first remote update 21
  • 22. Endpoint Security in Practice Example which implements this endpoint security model in practice: Terrence Barr, Electric Imp 22
  • 23. Securing IIoT Endpoints -- In Practice Industrial Internet Consortium Security Webinar February 22, 2017 Terrence Barr, terrence@electricimp.com Head of Solutions Engineering
  • 25. Electric Imp Industrial-strength IoT starts here Secure IoT Connectivity Platform Authorized Hardware for connected devices impOS™ and hardware impCloud™ imp Enterprise API’s BlinkUp™ & impFactory™ impSecure™ Proven IoT Deployments at Scale • 2016: surpassed 1 Million WiFi/Ethernet devices • 18B+ data messages per month • 100+ customers; 105+ countries Full Lifecycle, Trusted Security • Passed security review and pen-testing: • In process: UL 2900-2-2: Cybersecurity Certification for Industrial Controls plus first Affiliate program • Aligned with IIC Security Framework Fastest Prototype-to-Production • 5 months for GE connected air conditioner
  • 27. Endpoint Security: Part of Integrated and Managed Security Silicon-to-Cloud Security – Defense in Depth & Defense in Time 7. Full Lifecycle Managed Services 1. Edge Device Security incl. Secure Silicon & Managed Software 4. Secure Communication via Managed Tunnel 3. Trusted Manufacture & Commissioning 6. Secure Cloud and Application Integration 2. Data Privacy, Integrity & Confidentiality 5. Protected Public & Private Cloud
  • 28. IISF Endpoint Protection Techniques Electric Imp Implementation Protecting Endpoints: General Endpoint protection from the silicon upwards, every level tightly integrated and tested for full coverage of security objective and no weak links Architectural Considerations for Protecting Endpoints Designed from the ground up for resource-constrained IoT devices and real-world use cases and proven in large-scale customer deployments Endpoint Physical Security Disabled hardware interfaces, tampering destroys individual module Establish Roots of Trust Unique per-device keys, secure provisioning via cloud device management Endpoint Identity One-Time-Programming at module manufacturing time Endpoint Access Control Mutual authentication with RSA certificates and ECC challenge- response Endpoint Integrity Protection HSM protected keys, secure boot, non-execution barriers with cloud alerts Endpoint Data Protection All processing on-die, all off-die storage with device-unique encryption. TLS 1.2, AES-128, EDH forward secrecy. Endpoint Monitoring and Analysis Extensive monitoring of security-sensitive operations Endpoint Configuration and Management Endpoints managed, configured, and provisioned from the impCloud, all updates signed, encrypted, and logged © Property of Electric Imp, Inc. CONFIDENTIAL – NOT FOR DISTRIBUTION
  • 30. • Replace analogue lines • Customer delight exceeds expectations • Recognized as Business Transformation success story 1.5M Customers worldwide Security for regulated markets Reduce service calls by 20% © Property of Electric Imp, Inc. CONFIDENTIAL – NOT FOR DISTRIBUTION ROI – Payback in 45 days on connectivity costs alone
  • 31. impSecureTM: Integrated Silicon-to-Cloud Security and Connectivity managed by Electric Imp ‘Drop-In’ Postage Meter Retrofit: Device-to-Cloud Security and Connectivity imp Application Module impOSTM Meter Integration Code Virtual Machine paired Virtual Machine Cloud Meter Code Cloud Integration Code Operations & Device Lifecycle Management Cloud Services Electric Imp Managed Cloud USB Commerce Cloud Device-paired Virtual Machines Scalable to millions of devices No changes to meter No changes to cloud Audited and Tested Meets Postal and Government Security Requirements WiFi Ethernet IP tunnel &imp
  • 33. Integrated Security Platform: Customer Benefits Leverage Proven Solution • Build on tested and trusted security at a platform level Isolation of Security Concerns • Minimize time-to-market and risk of security mistakes Integrated, Silicon to Cloud Security • No weak links, even devices exposed in the field for many years Managed Security as a Service • Offload headache of ongoing security monitoring and maintenance Qualify once, reuse many times • Enable rapid, low-risk multi-product IoT strategy
  • 34. ® Transforming the world through the power of secure connectivity
  • 35. Thank you! 35 Things are coming together. Community. Collaboration. Convergence. www.iiconsortium.org Additional Resources available as attachments • Industrial Internet Security Framework • Security Claims Evaluation Testbeds • White Paper: Business Viewpoint of Securing the Industrial Internet • Upcoming Webinars: • March 30, 2017 Building Blocks for Securing the Smart Factory • April, 2017 TBD

Notas do Editor

  1. Thank you, Marcellus. As an introduction to the Industrial Internet Consortuim, let‘s have a little bit of history. Around 1840 we had the Industrial Revolution with its steam power locamotives and factory machines which created enormous disruption in jobs worldwide; There was a jump in productivity as human energy & muscle moved to machine muscle. The jump in productivity was huge – a 2.5 to 4.0 times increase, not percentage, times increase in productivity. Initially, jobs were lost but because of the huge leap in productivity, there was a huge leap in consumer demand which led to more jobs created. Far more jobs were created than lost. We saw this happen again 100 years later with the Internet Revolution. The Internet Revolution was the movement from human connectivity to machine connectivity. Again we saw productivity increase between 2.5 and 4 times. And again saw disruption. Again, new jobs were created. We know this is going to happen again. Where this is going to happen is in the application of internet technologies to the industries that have traditionally had no impact of internet technology on those industries. Again, we think you will see a large leap in productivity which will lead to a large leap in consumer demand and a large leap in job creation. But, it will be disruptive and it is hard to know what those disruptions will be.
  2. There is a real problem in figuring out how we use internet technologies in those industries that have essentially been untouched by this interent technology. So what we need to do is bring together the players in that world. The standards people, the manufacturers, banks, healthcare companies, technology providers, research organizations and universities to figure out: what are the standards we need, what are the priorities for those standards, what are the best practices, how do we hire people, how do we reskill, what products do we need, How do we secure our networks that were originally designed to be isolated but are now exposed to continuous attacks of ever-increasing sophistication How do we address the unprecedented increases in risks to plant personnel, to society and the environment at large, as well as to the businesses which operate industrial processes With the proliferation of connected devices, how do we protect against error, mischance and malicious intent? All of these questions represent the challenges of applying internet technologies to industries that have essentially been untouched by interent technology.
  3. That is essentially what the Industrial Internet Consortium is all about. That is why we call it the Industrial Internet - the application of IoT to industrial. And this is why we have a made it a priority to build, together a safe, reliable and secure Industrial Internet. Through testbeds, through reference architectures, through the Industrial Internet Security Framework.
  4. This is our mission statement, with 2 key phrases highlighted in red: Coordinating ecosystem initiatives – creating an ecosystem of small and large industry players, academia and government organizations. We have hundreds of companies from dozens of countries working together to figure this out. Transformational business and societal outcomes – what is the impact on all of these industries; In March of 2014 our founders came together and said let’s work together to learn how to apply internet technologies to industry because our industries are going to be disrupted. Rather than be disrupted, we will lead the disruption to deliver the transformational business and societal outcomes across industries and public infrastructure. With that, I will turn it back over to Jesus and Dan.
  5. Analogue lines from AT&T start at $60/month.