June 30, 2016 By Douglas Bonderud 2 min read

Internet of Things (IoT) security concerns have shifted from early adopter observations to mainstream worries. As noted by the Computer Business Review, almost 50 percent of companies surveyed said that security was the “biggest inhibitor” to getting the most out of their IoT network.

According to Softpedia, these worries may be worthwhile — a massive closed-circuit television (CCTV) botnet was recently pinpointed as the source of aggressive DDoS attacks. Is this camera compromise the first sign of big IoT trouble?

Smile for the CCTV Botnet!

As noted by Network World, the camera conundrum first came to light when a jewelry store tapped digital defense firm Sucuri to mitigate a serious distributed denial-of-service (DDoS) attack — more than 35,000 HTTP requests were being generated each second, making it impossible for the site to operate. Sucuri dropped the site behind their web application firewall (WAF) and expected the attack to abate, but instead found the intensity ramped up to 50,000 HTTP requests.

This number was worrisome enough, but the company also noticed that there was no flutter to the attacks as bots went online or offline, suggesting that all endpoints connected to the botnet were active at all times.

Research led Sucuri to 25,513 unique IP addresses, all linked to CCTV cameras around the world. Twenty-four percent were located in Taiwan, 12 percent in the U.S. and 9 percent in Indonesia, but all told, 95 different countries had cameras that were part of the botnet. Of note is that 46 percent of these systems were running a generic H.264 DVR made by Chinese firm TVT, which was notified about firmware issues by security expert Rotem Kerner earlier this year, Softpedia reported.

The result? A botnet bonanza — much larger than the first CCTV botnet detected last October, which used only 900 cameras to carry out attacks.

No Small Problem

IoT networks present a unique security challenge: While connected devices are typically small and have limited functionality, in large groups they’re extremely dangerous. Take the camera botnet. Not only were tens of thousands of CCTV endpoints available to compromise, but these devices were designed for i4/7 Internet connection, granting attackers nearly limitless DDoS power.

While there’s interest in better IoT security, new issues continue to emerge. Dark Reading pointed to the recent Nissan Leaf debacle, which saw security researcher Troy Hunt easily hack the car’s climate controls after the vehicle-maker refused to plug the holes in the app, one of which was a total lack of authorization.

Here’s the bottom line: This CCTV botnet is an obvious symptom of a larger disease — the continued corporate assumption that IoT offerings don’t require the same level of IT security as traditional devices. Instead, companies need to think of IoT devices like ants, where a single bite is annoying but 10,000 could be incapacitating. In aggregate, IoT devices are capable of zooming in on even the smallest security flaws.

More from

AI decision-making: Where do businesses draw the line?

4 min read - "A computer can never be held accountable, therefore a computer must never make a management decision."- IBM Training Manual, 1979Artificial intelligence (AI) adoption is on the rise. According to the IBM Global AI Adoption Index 2023, 42% of enterprises have actively deployed AI, and 40% are experimenting with the technology. Of those using or exploring AI, 59% have accelerated their investments and rollouts over the past two years. The result is an uptick in AI decision-making that leverages intelligent tools…

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today