Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers...

19
Disclosing Vulnerabilities and Breaches in the ‘Internet of Things’ Ross Anderson Cambridge CEPS, Sep 27 2017

Transcript of Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers...

Page 1: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

DisclosingVulnerabilitiesandBreachesinthe‘InternetofThings’

RossAndersonCambridge

CEPS,Sep272017

Page 2: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

WhatwilltheIoT change?

• PrivacymadetheearlyrunningwiththesmartTVandtheCayla doll– butyourphonealreadyhearseverythingandisfullofadware

• Denial-of-servicewasnextwiththeMiraibotnet– butwealreadyhavebotnets

• Butsafetylooksliketherealpressurepoint• Phonesandlaptopsdon’tkillmanypeopledirectly;carsandmedicaldevicesdo…

CEPS,Sep272017

Page 3: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

HowdoesIoT changesafety?

• Eireann Leverett,RichardClaytonandIdidaprojectfortheEuropeanCommission

• TheEUhascomplexregulatoryregimesforthesafetyofallsortsofdevices

• Howwillthesehavetochangeoncethere’ssoftwareeverywhere?

• Welookedspecificallyatvehicles,medicaldevices,andelectrotechnical equipment

• Butthelessonsaremorewidelyapplicable!

CEPS,Sep272017

Page 4: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

EUproblemstatement• Weregulatesafetyinmanyindustries• The“InternetofThings”putscomputersandcommunicationseverywhere

• Thiscreatesnewsafetyrisksaroundsecurity• Indeed,thetwoarethesameinthelanguagesspokenbymostEUcitizens(sicurezza,seguridad,sûreté,Sicherheit,trygghet…)

• Howdoweupdatesafetyregulation(andsafetyregulators)tocope?

CEPS,Sep272017

Page 5: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Background

• Marketsdosafetyinsomeindustries(aviation)waybetterthanothers

• CarsweredreadfuluntilNader’s‘UnsafeatAnySpeed’firedupthepublic,gotinsuranceindustryinvolvementandledtotheNHTSA

• IntheEU,wegottheProductLiabilityDirective85/374/EES,FrameworkDirective2007/43/EContypeapproval,andmuchmuchelse

• Broadprinciples,plusmanydetailedrules

CEPS,Sep272017

Page 6: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Background(2)

• Traditionalcarmakersmovingtoautonomyinsteps(adaptivecruisecontrol,automaticemergencybraking,automaticlanekeeping…)

• TeslahasalreadymovedtoregularupgradesandthelegacyOEMsareracingtofollow

• Butmanagingvulnerabilitiesishard,andexpensive:Androidispatchedfor3years,Windowsfor5

• Sohowwillwepatcha2017carin2037?

CEPS,Sep272017

Page 7: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

CEPS,Sep272017

Page 8: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

CEPS,Sep272017

Page 9: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Background(3)• TheMedicalDeviceDirectives(90/385EEC,93/42/EEC,98/79/EU)arenowbeingrevised

• ResearchbyHaroldThimbleby:intheUK,hospitalsafetyusabilityfailureskillabout2000p.a.(aboutthesameasroadaccidents)

• Priority:getregulatorstodopost-approvalstudiesandadverseeventreporting

• Atpresentdevicesaretypicallyapprovedonpaperworkalone

• Evenlesspost-marketfeedbackthaninpharma…CEPS,Sep272017

Page 10: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Background(4)

• Usabilityfailuresthatkillaretypicallyblamedonthenurse(ifnoticedatall)

• Butattacksaremuchhardertoignore– a2015wifi tamperingdemoledtheFDAtoblacklisttheHospira Symbiq infusionpump

• 2017:recallof450,000StJudepacemakers• Butsoftwareupgradescanbreakcertification!• Propersafety/securitylifecycleisneeded

CEPS,Sep272017

Page 11: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

TheBigChallenge

• Establishednon-ITindustriesusuallyhaveastaticapproach– pre-markettestingwithstandardsthatchangeslowlyifatall

• Thetimeconstantistypicallyadecade• Whenmaliciousadversariescanscalebugsintoattacks,industrieswillneedadynamicapproachwithpatching,asinIT

• Thetimeconstantisthentypicallyamonth

CEPS,Sep272017

Page 12: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Broadquestionsinclude…

• Whowillinvestigateincidents,andtowhomwilltheybereported?

• Howdoweembedresponsibledisclosure?• Howdowebringsafetyengineersandsecurityengineerstogether?

• Willregulatorsallneedsecurityengineers?• Howdowepreventabusivelock-in?NotetheUSDMCAexemptiontorepairtractors…

CEPS,Sep272017

Page 13: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

InstitutionalPlayers• DozensofEuropeanregulators(+hundredsinMemberStates)

• Standardsbodies(UNECE,ETSI,CEN,CENELEC)• Safetylabs(KEMA,EuroNCAP,…)• Securitylabs(CLEFs,Underwriters’Labs,commercialpentesters,ENCS,academics…)

• OthercustodiansofthemanysafetyandsecuritystandardsincludingNIST,IEEE,IEC

• Otherprincipals,e.g.insuranceindustry

CEPS,Sep272017

Page 14: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Policyrecommendationsincluded• Requirevendorstoself-certify,fortheirCEmark,thatproductscanbepatchedifneedbe

• Requireasecuredevelopmentlifecyclewithvulnerabilitymanagement(ISO29174,30111)

• CreateaEuropeanSecurityEngineeringAgencytosupportpolicymakers(now:ENISA)

• ExtendProductLiabilityDirectivetoservices• UpdateNISDirectivetoreportbreachesandvulnerabilitiestosafetyregulatorsandusers

CEPS,Sep272017

Page 15: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Translatingthistoengineering• Theproblemasalwayswillbescale• Europehas50,000fatalaccidentsayearandtentimesthatmanycausingseriousinjury

• Futurecarswillgeneratevastamountsofdata• Howdotherightdatagettotrafficcops,insurers,safetyregulatorsandothers?

• Wecan’tjustreportvulnerabilitiesandbreachestoENISA/SIAs/DPagencies!

• Culturechangetoo(e.g.VWvBirmingham)CEPS,Sep272017

Page 16: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Implicationsforcomputerscience• Computersciencehasalwaysbeenaboutmanagingcomplexity

• Safety-criticaldurablegoods,online,andcomposedofheterogeneouscomponentsfrommutuallymistrustfulsuppliers,arethenewgrandchallenge

• SincedoingthisprojectI’vestartedteachingsafetyandsecuritytogetherinthesamecoursetofirst-yearundergraduates

CEPS,Sep272017

Page 17: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

Conclusions• TheEUregulatessafetyindozensofindustries• Oncesafety-criticalgoodscanbeattackedonline,it’spatchorscrap

• Fordurablegoodslikecarsandmedicaldevices,thiswillbeareallyreallybigdeal

• Tomanagetheecosystem,avastamountofdataonvulnerabilities,breachesandaccidentswillhavetobemanaged

• Manypolicychallengeslieahead!CEPS,Sep272017

Page 18: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

More…

• Ourpaper“Standardisation andCertificationintheInternetofThings”isonmywebpagehttp://www.cl.cam.ac.uk/~rja14/

• Orsee“WhenSafetyandSecurityBecomeOne”onourblog

https://www.lightbluetouchpaper.orgwhichalsohasacoupleofvideos

Cambridge,Sep2017

Page 19: Disclosing Vulnerabilities and Breaches in the …...•The “Internet of Things” puts computers and communications everywhere •This creates new safety risks around security •Indeed,

CEPS,Sep272017