Security for IoT

IoT ની openness એ જ તેનું જોખમ છે: અબજો સસ્તા, ભાગ્યે જ update થતા devices internet પર attack surface ને પહોળો કરે છે, એટલે security device થી cloud સુધી દરેક layer પર ફેલાયેલી છે, CIA triad ને yardstick તરીકે લઈને.

11 min read · 9 cards · 2 checks

Read in: English · हिन्दी · ગુજરાતી


Theory

Tank ને કોણ સાંભળી રહ્યું છે?

SmartHostel એ water tank, gate અને corridor cameras ને internet પર મૂક્યા. Convenient છે: warden ઘરેથી check કરી શકે છે.

પણ "on the internet" બંને બાજુએ કાપે છે. જે connectivity warden ને અંદર લાવે છે એ જ stranger ને પણ અંદર લાવી શકે છે: cameras જોવા, motion logs થી rooms ક્યારે ખાલી છે એ વાંચવું, અથવા gate ખુલ્લું કરી દેવું.

IoT ની સૌથી મોટી તાકાત, એટલે કે openness, એ જ તેની સૌથી ગંભીર નબળાઈ પણ છે. Security ને bolt-on feature તરીકે નહીં, પરંતુ દરેક layer પર spanning concern તરીકે સુરક્ષિત કરવું પડે છે, અને આ પાઠ એ જ સમજાવે છે.

Theory

IoT uniquely exposed કેમ છે

IoT નું attack surface ordinary computing કરતાં concrete કારણોસર મોટું છે:

  • sheer numbers: અબજો devices, દરેક સંભવિત door
  • constrained hardware: tiny sensors પાસે heavy encryption માટે power અને memory નથી
  • rare updates: firmware એકવાર ship થાય છે અને ભાગ્યે જ patch થાય છે, એટલે જૂના holes ખુલ્લા રહે છે
  • default/weak passwords: shipped credentials જે કોઈ બદલતું નથી
  • physical accessibility: gate sensor બહાર છે, touchable છે
  • internet exposure: IoT-vs-M2M lesson માં prized થયેલી connectivity જ remote attack ને invite કરે છે

At a glance

Security yardstick: CIA triad (plus 2)

Goalએ કયો question answer કરે છે?SmartHostel stake
Confidentialityફક્ત authorised જ data જોઈ શકે?Camera feeds અને occupancy logs private રહે છે
IntegrityData unaltered, untampered છે?Forged 'tank full' reading real shortage ને છુપાવી શકતું નથી
AvailabilityAttack હેઠળ system up રહે છે?Gate control denial-of-service flood survive કરે છે
Authenticationઆ device/user claim કરે છે તેવું જ છે?Fake sensor room 214 નું impersonate નથી કરી શકતું
Authorizationતેમના માટે આ action permitted છે?માત્ર warden નું login gate ખોલી શકે છે

Theory

Threats, અને તેમને answer કરતા defences

Common threats: eavesdropping/sniffing (unencrypted traffic વાંચવું), man-in-the-middle (2 parties વચ્ચે intercept કરવું), DoS/DDoS (device કે service પર flood કરીને collapse કરવું), spoofing (identity fake કરવી), physical tampering, firmware attacks.

Real, widely-documented case: Mirai botnet એ હજારો IoT cameras અને routers ને ગુલામ બનાવ્યા હતા જે હજુ default passwords વાપરતા હતા, પછી તેનો ઉપયોગ massive DDoS attacks launch કરવા માટે કર્યો.

Defences: strong unique credentials, encryption (data in transit AND at rest), regular firmware updates, device authentication, network segmentation (IoT devices ને isolate કરવા), અને secure boot.

Quiz

Mirai botnet ને આટલા બધા IoT devices ને ગુલામ બનાવવા શું સક્ષમ બનાવ્યું?

  1. Devices એ military-grade encryption વાપર્યું જે attackers એ crack કર્યું
  2. Devices default/weak passwords સાથે ship થયા હતા જે owners એ ક્યારેય બદલ્યા નહોતા
  3. Devices ને internet connection જ નહોતું
  4. Attackers ને દરેક device પર physical access હતો
Show the answer

Devices default/weak passwords સાથે ship થયા હતા જે owners એ ક્યારેય બદલ્યા નહોતા

Mirai ની power સૌથી boring vulnerability માંથી આવી: unchanged factory-default credentials, જે હજારો internet-exposed cameras અને routers પર automatically try કરવામાં આવ્યા. આ canonical lesson છે કે IoT નો weakest link ઘણીવાર exotic cryptography નહીં પરંતુ basic hygiene છે: એટલે જ default passwords બદલવા દરેક defence list ની ટોચ પર છે. Option A reality ને invert કરે છે (strong crypto DEFENCE છે, hole નહીં). Option C એવા devices describe કરે છે જેને remotely attack જ ન કરી શકાય. Option D એક physical threat ને remote, at-scale attack Mirai સાથે confuse કરે છે.

Think first

Leaked tank sensor ખરેખર શું reveal કરે છે?

Tank level sensor harmless લાગે છે: એ માત્ર water છે. પણ security review એને flag કરે છે. Innocent data ના patterns શું betray કરી શકે છે તે વિચારો, પછી tap કરો.

Show the answer

Water usage એ occupancy signal છે. Tank જે અઠવાડિયે barely drain થાય છે એ whisper કરે છે કે hostel ખાલી છે (holidays): burglar નું dream. અચાનક 3 am usage patterns routines reveal કરે છે. Motion logs સાથે combine કરીને, outsider reconstruct કરે છે કે ક્યારે કઈ wing vacant છે. આ IoT security નો quiet lesson છે: even innocuous data leaks meaningful inferences, એટલે confidentiality boring sensors પર પણ લાગુ પડે છે, અને exam-worthy point એ છે કે IoT threats dramatic break-ins કરતાં aggregated data માંથી inference વિશે વધારે છે. Mundane ને secure કરો.

Watch out

IoT-security answer slips

Security ને એક layer નું job માનવું: એ CROSS-CUTTING છે: security functional block device, network, processing અને application પર spanning છે: એ કહો.

ફક્ત in transit encryption: data at REST (stored) ને પણ protection જોઈએ છે; attackers databases ને target કરે છે, માત્ર wires નહીં.

Fake CVEs કે exploits નામ આપવાં: Mirai જેવા well-documented general cases ને જ cite કરો; specific vulnerabilities, product flaws કે attack details ક્યારેય invent ન કરો: honest, exam-safe move.

Theory

Openness ની કિંમત અને payoff

આ પાઠ IoT-vs-M2M comparison ની shadow છે: internet connectivity જે IoT ને powerful બનાવે છે એ જ તેને vulnerable પણ બનાવે છે. Good IoT engineering બંને truths ને એક સાથે hold કરે છે: payoff માટે connect, price માટે secure. Unit 2 next એ coin ની બીજી બાજુ સાથે close કરે છે: ENABLING technologies (wireless sensor networks, big-data analytics, embedded systems) જે IoT ને powers આપે છે: defend કરવા જેવી capabilities.

Summary

Key takeaways

  • IoT uniquely exposed છે: many devices, weak hardware, rare updates, default passwords, physical access, internet exposure.
  • CIA triad: Confidentiality (encryption), Integrity (no tampering), Availability (survive DoS); plus Authentication અને Authorization.
  • Threats: eavesdropping, man-in-the-middle, DoS/DDoS, spoofing, tampering, firmware attacks.
  • Mirai એ unchanged default passwords દ્વારા IoT devices ને ગુલામ બનાવ્યા: basic hygiene weakest link છે.
  • Defences: unique credentials, in transit AND at rest encryption, firmware updates, authentication, network segmentation, secure boot.
  • Security બધી layers પર cross-cutting છે, અને innocuous data પણ inferences leak કરે છે.
  • Memory hook: જે door warden ને અંદર લાવે છે એ stranger ને પણ લાવી શકે છે.

Study this properly

This page is the lesson to read. In Gri-Learn the same topic is a graded deck: the self-checks are scored and your weak topics are tracked. Free to start.

Start this topic

Already have an account? Sign in

More from IoT and M2M

Gri-Learn · syllabus-mapped B.C.A. lessons in English, Hindi and Gujarati

Security for IoT · Internet of Things (IoT) (Minor option A) · Gri-Learn