How do you hack an aquarium?
Security issues of IoT– ECER 2022
Peter Pistek
Senior researcher @ KInIT
Kempelen Institute of Intelligent Technologies
Outline
2
Kempelen Institute of Intelligent Technologies
Introduction
3
Kempelen Institute of Intelligent Technologies
Aquarium and other cases
Source: scmagazine.com
Irresponsible Fishes = Unsecured Aquarium [2017]
5
https://www.securityweek.com/hacked-smart-fish-tank-exfiltrated-data-rare-external-destination
https://www.hackread.com/hackers-casinos-fish-tank-smart-thermometer-hack/
Source: Tripadvisor
Kempelen Institute of Intelligent Technologies
I want to sleep - Hotel [2017]
6
Source: www.seehotel-jaegerwirt.at
Kempelen Institute of Intelligent Technologies
How much insulin is enough? [2019]
7
Source: securityweek.com
Kempelen Institute of Intelligent Technologies
Keep calm and meditate? [2017]
8
Source: news-medical.com
https://www.zdnet.com/article/fda-forces-st-jude-pacemaker-recall-to-patch-security-vulnerabilities/
Kempelen Institute of Intelligent Technologies
I don’t give you your drugs, but I may run over you [2022]
9
Source: wsj.net
Kempelen Institute of Intelligent Technologies
Hurrying somewhere? Just take a break [2019]
10
Source: mi.com
Kempelen Institute of Intelligent Technologies
Would you like a glass of poison ehm water [2021]
11
Source:bleepingcomputer.com
Kempelen Institute of Intelligent Technologies
Distance is not a problem [2022]
12
Source: guidehouseinsights.com
Kempelen Institute of Intelligent Technologies
Similarities between these attacks
13
Kempelen Institute of Intelligent Technologies
Questions
Are you using wireless connection?
Are you using wire to connect to your robot?
Do you use any type of security?
Best practices in software security
Best practices
19
Kempelen Institute of Intelligent Technologies
Network attacks
Types of attacks
21
Kempelen Institute of Intelligent Technologies
Features
22
Kempelen Institute of Intelligent Technologies
Challenges
23
Source: 9gag.com
Kempelen Institute of Intelligent Technologies
Supervised learning
24
Source: neurospace.io
Kempelen Institute of Intelligent Technologies
Unsupervised learning
25
Source: youtube.com
Source: towardsdatascience.com
Kempelen Institute of Intelligent Technologies
Real-world situation
26
Kempelen Institute of Intelligent Technologies
Real-world situation
27
Classification
Anomaly detection
Traffic
Traffic without well-known attacks
Benign traffic
Well-known attacks
Anomalies
Kempelen Institute of Intelligent Technologies
Conclusion
28
Kempelen Institute of Intelligent Technologies
Nivy Tower
Mlynské Nivy II. 18890/5
811 09 Bratislava
Slovakia
/kinit.sk
/company/kempelen-institute-of-intelligent-technologies/
/KInIT_sk