Theory
Tank ને કોણ સાંભળી રહ્યું છે?
SmartHostel એ water tank, gate અને corridor cameras ને internet પર મૂક્યા. Convenient છે: warden ઘરેથી check કરી શકે છે.
પણ "on the internet" બંને બાજુએ કાપે છે. જે connectivity warden ને અંદર લાવે છે એ જ stranger ને પણ અંદર લાવી શકે છે: cameras જોવા, motion logs થી rooms ક્યારે ખાલી છે એ વાંચવું, અથવા gate ખુલ્લું કરી દેવું.
IoT ની સૌથી મોટી તાકાત, એટલે કે openness, એ જ તેની સૌથી ગંભીર નબળાઈ પણ છે. Security ને bolt-on feature તરીકે નહીં, પરંતુ દરેક layer પર spanning concern તરીકે સુરક્ષિત કરવું પડે છે, અને આ પાઠ એ જ સમજાવે છે.
Theory
IoT uniquely exposed કેમ છે
IoT નું attack surface ordinary computing કરતાં concrete કારણોસર મોટું છે:
- sheer numbers: અબજો devices, દરેક સંભવિત door
- constrained hardware: tiny sensors પાસે heavy encryption માટે power અને memory નથી
- rare updates: firmware એકવાર ship થાય છે અને ભાગ્યે જ patch થાય છે, એટલે જૂના holes ખુલ્લા રહે છે
- default/weak passwords: shipped credentials જે કોઈ બદલતું નથી
- physical accessibility: gate sensor બહાર છે, touchable છે
- internet exposure: IoT-vs-M2M lesson માં prized થયેલી connectivity જ remote attack ને invite કરે છે
At a glance
Security yardstick: CIA triad (plus 2)
| Goal | એ કયો question answer કરે છે? | SmartHostel stake |
|---|---|---|
| Confidentiality | ફક્ત authorised જ data જોઈ શકે? | Camera feeds અને occupancy logs private રહે છે |
| Integrity | Data unaltered, untampered છે? | Forged 'tank full' reading real shortage ને છુપાવી શકતું નથી |
| Availability | Attack હેઠળ system up રહે છે? | Gate control denial-of-service flood survive કરે છે |
| Authentication | આ device/user claim કરે છે તેવું જ છે? | Fake sensor room 214 નું impersonate નથી કરી શકતું |
| Authorization | તેમના માટે આ action permitted છે? | માત્ર warden નું login gate ખોલી શકે છે |
Theory
Threats, અને તેમને answer કરતા defences
Common threats: eavesdropping/sniffing (unencrypted traffic વાંચવું), man-in-the-middle (2 parties વચ્ચે intercept કરવું), DoS/DDoS (device કે service પર flood કરીને collapse કરવું), spoofing (identity fake કરવી), physical tampering, firmware attacks.
Real, widely-documented case: Mirai botnet એ હજારો IoT cameras અને routers ને ગુલામ બનાવ્યા હતા જે હજુ default passwords વાપરતા હતા, પછી તેનો ઉપયોગ massive DDoS attacks launch કરવા માટે કર્યો.
Defences: strong unique credentials, encryption (data in transit AND at rest), regular firmware updates, device authentication, network segmentation (IoT devices ને isolate કરવા), અને secure boot.
Quiz
Mirai botnet ને આટલા બધા IoT devices ને ગુલામ બનાવવા શું સક્ષમ બનાવ્યું?
- Devices એ military-grade encryption વાપર્યું જે attackers એ crack કર્યું
- Devices default/weak passwords સાથે ship થયા હતા જે owners એ ક્યારેય બદલ્યા નહોતા
- Devices ને internet connection જ નહોતું
- Attackers ને દરેક device પર physical access હતો
Show the answer
Devices default/weak passwords સાથે ship થયા હતા જે owners એ ક્યારેય બદલ્યા નહોતા
Mirai ની power સૌથી boring vulnerability માંથી આવી: unchanged factory-default credentials, જે હજારો internet-exposed cameras અને routers પર automatically try કરવામાં આવ્યા. આ canonical lesson છે કે IoT નો weakest link ઘણીવાર exotic cryptography નહીં પરંતુ basic hygiene છે: એટલે જ default passwords બદલવા દરેક defence list ની ટોચ પર છે. Option A reality ને invert કરે છે (strong crypto DEFENCE છે, hole નહીં). Option C એવા devices describe કરે છે જેને remotely attack જ ન કરી શકાય. Option D એક physical threat ને remote, at-scale attack Mirai સાથે confuse કરે છે.
Think first
Leaked tank sensor ખરેખર શું reveal કરે છે?
Tank level sensor harmless લાગે છે: એ માત્ર water છે. પણ security review એને flag કરે છે. Innocent data ના patterns શું betray કરી શકે છે તે વિચારો, પછી tap કરો.
Show the answer
Water usage એ occupancy signal છે. Tank જે અઠવાડિયે barely drain થાય છે એ whisper કરે છે કે hostel ખાલી છે (holidays): burglar નું dream. અચાનક 3 am usage patterns routines reveal કરે છે. Motion logs સાથે combine કરીને, outsider reconstruct કરે છે કે ક્યારે કઈ wing vacant છે. આ IoT security નો quiet lesson છે: even innocuous data leaks meaningful inferences, એટલે confidentiality boring sensors પર પણ લાગુ પડે છે, અને exam-worthy point એ છે કે IoT threats dramatic break-ins કરતાં aggregated data માંથી inference વિશે વધારે છે. Mundane ને secure કરો.
Watch out
IoT-security answer slips
Security ને એક layer નું job માનવું: એ CROSS-CUTTING છે: security functional block device, network, processing અને application પર spanning છે: એ કહો.
ફક્ત in transit encryption: data at REST (stored) ને પણ protection જોઈએ છે; attackers databases ને target કરે છે, માત્ર wires નહીં.
Fake CVEs કે exploits નામ આપવાં: Mirai જેવા well-documented general cases ને જ cite કરો; specific vulnerabilities, product flaws કે attack details ક્યારેય invent ન કરો: honest, exam-safe move.
Theory
Openness ની કિંમત અને payoff
આ પાઠ IoT-vs-M2M comparison ની shadow છે: internet connectivity જે IoT ને powerful બનાવે છે એ જ તેને vulnerable પણ બનાવે છે. Good IoT engineering બંને truths ને એક સાથે hold કરે છે: payoff માટે connect, price માટે secure. Unit 2 next એ coin ની બીજી બાજુ સાથે close કરે છે: ENABLING technologies (wireless sensor networks, big-data analytics, embedded systems) જે IoT ને powers આપે છે: defend કરવા જેવી capabilities.
Summary
Key takeaways
- IoT uniquely exposed છે: many devices, weak hardware, rare updates, default passwords, physical access, internet exposure.
- CIA triad: Confidentiality (encryption), Integrity (no tampering), Availability (survive DoS); plus Authentication અને Authorization.
- Threats: eavesdropping, man-in-the-middle, DoS/DDoS, spoofing, tampering, firmware attacks.
- Mirai એ unchanged default passwords દ્વારા IoT devices ને ગુલામ બનાવ્યા: basic hygiene weakest link છે.
- Defences: unique credentials, in transit AND at rest encryption, firmware updates, authentication, network segmentation, secure boot.
- Security બધી layers પર cross-cutting છે, અને innocuous data પણ inferences leak કરે છે.
- Memory hook: જે door warden ને અંદર લાવે છે એ stranger ને પણ લાવી શકે છે.