{"id":217206,"date":"2017-06-07T18:43:43","date_gmt":"2017-06-07T22:43:43","guid":{"rendered":"http:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/uncategorized\/infosec17-iot-testing-must-focus-on-the-entire-ecosystem-infosecurity-magazine.php"},"modified":"2017-06-07T18:43:43","modified_gmt":"2017-06-07T22:43:43","slug":"infosec17-iot-testing-must-focus-on-the-entire-ecosystem-infosecurity-magazine","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/eco-system\/infosec17-iot-testing-must-focus-on-the-entire-ecosystem-infosecurity-magazine.php","title":{"rendered":"#Infosec17 IoT Testing Must Focus on the Entire Ecosystem &#8211; Infosecurity Magazine"},"content":{"rendered":"<p><p>    Security professionals need to evaluate entire IoT ecosystems    rather thanfocus on individual elements if they    wanttesting to be as accurate as possible,according    to Rapid7.  <\/p>\n<p>    The firms research lead, Deral Heiland, explained that the    interconnected nature of separateIoT components demands a    holistic approach to testing covering: embedded hardware;    mobile and control applications; cloud APIs and web services;    network communication; and data.  <\/p>\n<p>    When you want to test an IoT solution, if you test the product    alone your test is insufficient, and if you test just the cloud    APIs thats not enough, heargued.  <\/p>\n<p>    Youve got to look at the entire ecosystem What happens in    the cloud can impact the hardware  and if you compromise    thehardware, it could lead to a compromise of the mobile    or cloud elements.  <\/p>\n<p>    Effective IoT testing should follow an eight-step process    starting with a functional evaluation which takes the product    and puts it in a normal operating stance. From here, its    various features, functions, components and communication paths    can be examined, said Heiland.  <\/p>\n<p>    Next comes device reconnaissance; that is, finding out info    including its software version, vulnerability history, whether    it uses any open source tech, if it's white labelled, and so    on.  <\/p>\n<p>    Often user manuals, spec sheets and even information from    regulators such as the FCC can help with intel gathering here,    said Heiland.  <\/p>\n<p>    The testing should continue on with cloud and web APIs, the    mobile and control apps, and networks, looking at things like    use of encryption, access controls and communication.  <\/p>\n<p>    Its also important to take a lookinside the hardware at    its chips, ports and circuit connections, and to test for    physical device attacks by reverse engineering the firmware and    checking configurations.  <\/p>\n<p>    Radio RF emissions form the final component that needs    evaluating, said Heiland.  <\/p>\n<p>    Too many products are going out with common repeatable    vulnerabilities that could be easily removed with better    testing, he concluded. [Every time I] dig into the IoT    system, looking at the eight steps, I learn something new, and    every time I learn something new it becomes possible to make    better products for everybody.  <\/p>\n<p>    Heilands words come as new research this week highlighted the    huge number of vulnerabilities in IoT systems. High-Tech Bridge    claimed that 98% of web interfaces and admin panels in IoT    devices have fundamental security problems.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Read the rest here:<\/p>\n<p><a target=\"_blank\" href=\"https:\/\/www.infosecurity-magazine.com\/news\/infosec17-iot-testing-focus-entire\/\" title=\"#Infosec17 IoT Testing Must Focus on the Entire Ecosystem - Infosecurity Magazine\">#Infosec17 IoT Testing Must Focus on the Entire Ecosystem - Infosecurity Magazine<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Security professionals need to evaluate entire IoT ecosystems rather thanfocus on individual elements if they wanttesting to be as accurate as possible,according to Rapid7. The firms research lead, Deral Heiland, explained that the interconnected nature of separateIoT components demands a holistic approach to testing covering: embedded hardware; mobile and control applications; cloud APIs and web services; network communication; and data. When you want to test an IoT solution, if you test the product alone your test is insufficient, and if you test just the cloud APIs thats not enough, heargued.  <a href=\"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/eco-system\/infosec17-iot-testing-must-focus-on-the-entire-ecosystem-infosecurity-magazine.php\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"limit_modified_date":"","last_modified_date":"","_lmt_disableupdate":"","_lmt_disable":"","footnotes":""},"categories":[33],"tags":[],"class_list":["post-217206","post","type-post","status-publish","format-standard","hentry","category-eco-system"],"modified_by":null,"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/217206"}],"collection":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/comments?post=217206"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/217206\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/media?parent=217206"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/categories?post=217206"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/tags?post=217206"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}