Security for IoT

IoT की openness ही इसका danger है: billions cheap, rarely-updated devices internet पर attack surface widen करती हैं, तो security हर layer पर फैली है, device से cloud तक, CIA triad yardstick के साथ।

11 min read · 9 cards · 2 checks

Read in: English · हिन्दी · ગુજરાતી


Theory

Tank को और कौन सुन रहा है?

SmartHostel ने water tank, gate और corridor cameras internet पर डाल दिए। Convenient: warden इन्हें घर से check करता है।

पर "internet पर" दोनों तरफ़ काटता है। वही connectivity जो warden को अंदर आने देती है एक stranger को भी अंदर आने दे सकती है: cameras देखना, motion logs से rooms कब खाली हैं पढ़ना, या gate खोल देना।

IoT की greatest strength: openness: इसकी सबसे severe weakness भी है। इसे secure करना कोई bolt on करने वाला feature नहीं है; यह हर layer में फैली एक concern है, और यह lesson इसकी वजह है।

Theory

IoT Uniquely Exposed क्यों है

IoT का attack surface concrete reasons से ordinary computing से बड़ा है:

  • sheer numbers: billions devices, हर एक एक possible door
  • constrained hardware: tiny sensors में heavy encryption के लिए power और memory नहीं
  • rare updates: firmware एक बार ship होती है और शायद ही patched होती है, तो old holes खुले रहते हैं
  • default/weak passwords: shipped credentials जिन्हें कोई नहीं बदलता
  • physical accessibility: एक gate sensor बाहर बैठता है, touchable
  • internet exposure: वह connectivity जो IoT-vs-M2M lesson prize करती है exactly वही है जो remote attack invite करती है

At a glance

Security Yardstick: CIA Triad (Plus 2)

Goalयह कौन सा Question Answer करता हैSmartHostel Stake
Confidentialityक्या सिर्फ़ authorised लोग data देख सकते हैं?Camera feeds और occupancy logs private रहते हैं
Integrityक्या data unaltered, untampered है?एक forged 'tank full' reading एक real shortage छुपा नहीं सकती
Availabilityक्या attack होने पर system up रहता है?Gate control एक denial-of-service flood survive करता है
Authenticationक्या यह device/user वही है जो claim करता है?एक fake sensor room 214 के sensor को impersonate नहीं कर सकता
Authorizationक्या यह action उनके लिए permitted है?सिर्फ़ warden का login gate खोल सकता है

Theory

Threats, और वे Defences जो उनका Answer देते हैं

Common threats: eavesdropping/sniffing (unencrypted traffic पढ़ना), man-in-the-middle (2 parties के बीच intercept करना), DoS/DDoS (एक device या service को तब तक flood करना जब तक वह collapse न हो), spoofing (identity fake करना), physical tampering, firmware attacks।

एक real, widely-documented case: Mirai botnet ने हज़ारों IoT cameras और routers को enslave किया जो अभी भी default passwords इस्तेमाल कर रहे थे, फिर उन्हें massive DDoS attacks launch करने के लिए इस्तेमाल किया।

Defences: strong unique credentials, encryption (transit AND at rest दोनों में data), regular firmware updates, device authentication, network segmentation (IoT devices isolate करना), और secure boot।

Quiz

Mirai botnet को इतने सारे IoT devices enslave करने के लायक किसने बनाया?

  1. Devices military-grade encryption इस्तेमाल करते थे जो attackers ने crack किया
  2. Devices default/weak passwords के साथ shipped हुए जो owners ने कभी नहीं बदले
  3. Devices का कोई internet connection ही नहीं था
  4. Attackers के पास हर device तक physical access था
Show the answer

Devices default/weak passwords के साथ shipped हुए जो owners ने कभी नहीं बदले

Mirai की power सबसे boring imaginable vulnerability से आई: unchanged factory-default credentials, हज़ारों internet-exposed cameras और routers पर automatically try की गईं। यह canonical lesson है कि IoT का weakest link अक्सर basic hygiene है, exotic cryptography नहीं: यही वजह है default passwords बदलना हर defence list के top पर है। Option A reality को invert करता है (strong crypto DEFENCE है, hole नहीं)। Option C उन devices को describe करता है जिन्हें remotely attack ही नहीं किया जा सकता था। Option D एक physical threat को उस remote, at-scale attack से confuse करता है जो Mirai असल में था।

Think first

एक Leaked Tank Sensor असल में क्या Reveal करता है?

Tank level sensor harmless लगता है: यह बस water है। फिर भी एक security review इसे flag करता है। सोचिए innocent data में patterns क्या betray कर सकते हैं, फिर tap कीजिए।

Show the answer

Water usage एक occupancy signal है। एक tank जो पूरे हफ़्ते मुश्किल से drain होता है whisper करता है hostel खाली है (holidays): एक burglar का dream। अचानक 3 am usage patterns routines reveal करते हैं। Motion logs के साथ combined, एक outsider reconstruct कर सकता है कब कौन सा wing vacant है। यही IoT security का quiet lesson है: यहाँ तक कि innocuous data भी meaningful inferences leak करता है, तो confidentiality boring sensors पर भी apply होती है, और exam-worthy point यह है कि IoT threats जितने dramatic break-ins के बारे में हैं उतने ही aggregated data से inference के बारे में हैं। Mundane को secure कीजिए।

Watch out

IoT-Security Answer Slips

Security को एक Layer का Job मानना: यह CROSS-CUTTING है: security functional block device, network, processing और application फैला है: यह कहिए।

सिर्फ़ Transit में Encryption: REST (stored) data को भी protection चाहिए; attackers databases target करते हैं, सिर्फ़ wires नहीं।

Fake CVEs या Exploits Name करना: सिर्फ़ Mirai जैसे well-documented general cases cite कीजिए; कभी specific vulnerabilities, product flaws या attack details invent मत कीजिए: honest, exam-safe move।

Theory

Openness की एक Price और एक Payoff है

यह lesson IoT-vs-M2M comparison का shadow है: वह internet connectivity जिसने IoT को powerful बनाया exactly वही है जिसने इसे vulnerable बनाया। Good IoT engineering दोनों truths एक साथ hold करती है: payoff के लिए connect कीजिए, price के लिए secure कीजिए। Unit 2 अगला उस coin के दूसरे side से close होती है: वे ENABLING technologies (wireless sensor networks, big-data analytics, embedded systems) जो IoT को इसकी powers देती हैं: वे capabilities जिन्हें defend करना worth है।

Summary

Key takeaways

  • IoT uniquely exposed है: कई devices, weak hardware, rare updates, default passwords, physical access, internet exposure।
  • CIA triad: Confidentiality (encryption), Integrity (कोई tampering नहीं), Availability (DoS survive करना); plus Authentication और Authorization।
  • Threats: eavesdropping, man-in-the-middle, DoS/DDoS, spoofing, tampering, firmware attacks।
  • Mirai ने unchanged default passwords के ज़रिए IoT devices enslave किए: basic hygiene weakest link है।
  • Defences: unique credentials, transit AND at rest दोनों में encryption, firmware updates, authentication, network segmentation, secure boot।
  • Security सारे layers में cross-cutting है, और innocuous data भी inferences leak करता है।
  • Memory hook: वह door जो warden को अंदर आने देता है एक stranger को भी अंदर आने दे सकता है।

Study this properly

This page is the lesson to read. In Gri-Learn the same topic is a graded deck: the self-checks are scored and your weak topics are tracked. Free to start.

Start this topic

Already have an account? Sign in

More from IoT and M2M

Gri-Learn · syllabus-mapped B.C.A. lessons in English, Hindi and Gujarati

Security for IoT · Internet of Things (IoT) (Minor option A) · Gri-Learn