https://urgentcomm.com/wp-content/themes/ucm_child/assets/images/logo/footer-logo.png
  • Home
  • News
  • Multimedia
    • Back
    • Multimedia
    • Video
    • Podcasts
    • Galleries
  • Commentary
    • Back
    • Commentary
    • Urgent Matters
    • View From The Top
    • All Things IWCE
    • Legal Matters
  • Resources
    • Back
    • Resources
    • Events
    • Webinars
    • White Papers
    • Reprints & Reuse
  • IWCE
    • Back
    • IWCE
    • Conference
    • Special Events
    • Exhibitor Listings
    • Premier Partners
    • Floor Plan
    • Exhibiting Information
    • Register for IWCE
  • About Us
    • Back
    • About Us
    • Contact Us
    • Advertise
    • Terms of Service
    • Privacy Statement
    • Cookies Policy
  • Related Sites
    • Back
    • American City & County
    • IWCE
    • Light Reading
    • IOT World Today
    • Mission Critical Technologies
    • Microwave/RF
    • T&D World
    • TU-Auto
  • In the field
    • Back
    • In the field
    • Broadband Push-to-X
    • Internet of Things
    • Project 25
    • Public-Safety Broadband/FirstNet
    • Virtual/Augmented Reality
    • Land Mobile Radio
    • Long Term Evolution (LTE)
    • Applications
    • Drones/Robots
    • IoT/Smart X
    • Software
    • Subscriber Devices
    • Video
  • Call Center/Command
    • Back
    • Call Center/Command
    • Artificial Intelligence
    • NG911
    • Alerting Systems
    • Analytics
    • Dispatch/Call-taking
    • Incident Command/Situational Awareness
    • Tracking, Monitoring & Control
  • Network Tech
    • Back
    • Network Tech
    • Interoperability
    • LMR 100
    • LMR 200
    • Backhaul
    • Deployables
    • Power
    • Tower & Site
    • Wireless Networks
    • Coverage/Interference
    • Security
    • System Design
    • System Installation
    • System Operation
    • Test & Measurement
  • Operations
    • Back
    • Operations
    • Critical Infrastructure
    • Enterprise
    • Federal Government/Military
    • Public Safety
    • State & Local Government
    • Training
  • Regulations
    • Back
    • Regulations
    • Narrowbanding
    • T-Band
    • Rebanding
    • TV White Spaces
    • None
    • Funding
    • Policy
    • Regional Coordination
    • Standards
  • Organizations
    • Back
    • Organizations
    • AASHTO
    • APCO
    • DHS
    • DMR Association
    • ETA
    • EWA
    • FCC
    • IWCE
    • NASEMSO
    • NATE
    • NXDN Forum
    • NENA
    • NIST/PSCR
    • NPSTC
    • NTIA/FirstNet
    • P25 TIG
    • TETRA + CCA
    • UTC
Urgent Communications
  • NEWSLETTER
  • Home
  • News
  • Multimedia
    • Back
    • Video
    • Podcasts
    • Galleries
  • Commentary
    • Back
    • All Things IWCE
    • Urgent Matters
    • View From The Top
    • Legal Matters
  • Resources
    • Back
    • Events
    • Webinars
    • White Papers
    • Reprints & Reuse
    • UC eZines
  • IWCE
    • Back
    • Conference
    • WHY ATTEND
    • Exhibitor Listings
    • Floor Plan
    • Exhibiting Information
    • Registration Opens April 2019-Join Our Mailing List
  • About Us
    • Back
    • About Us
    • Contact Us
    • Advertise
    • Terms of Service
    • Privacy Statement
    • Cookies Policy
  • Related Sites
    • Back
    • American City & County
    • IWCE
    • Light Reading
    • IOT World Today
    • TU-Auto
  • newsletter
  • In the field
    • Back
    • Internet of Things
    • Broadband Push-to-X
    • Project 25
    • Public-Safety Broadband/FirstNet
    • Virtual/Augmented Reality
    • Land Mobile Radio
    • Long Term Evolution (LTE)
    • Applications
    • Drones/Robots
    • IoT/Smart X
    • Software
    • Subscriber Devices
    • Video
  • Call Center/Command
    • Back
    • Artificial Intelligence
    • NG911
    • Alerting Systems
    • Analytics
    • Dispatch/Call-taking
    • Incident Command/Situational Awareness
    • Tracking, Monitoring & Control
  • Network Tech
    • Back
    • Cybersecurity
    • Interoperability
    • LMR 100
    • LMR 200
    • Backhaul
    • Deployables
    • Power
    • Tower & Site
    • Wireless Networks
    • Coverage/Interference
    • Security
    • System Design
    • System Installation
    • System Operation
    • Test & Measurement
  • Operations
    • Back
    • Critical Infrastructure
    • Enterprise
    • Federal Government/Military
    • Public Safety
    • State & Local Government
    • Training
  • Regulations
    • Back
    • Narrowbanding
    • T-Band
    • Rebanding
    • TV White Spaces
    • None
    • Funding
    • Policy
    • Regional Coordination
    • Standards
  • Organizations
    • Back
    • AASHTO
    • APCO
    • DHS
    • DMR Association
    • ETA
    • EWA
    • FCC
    • IWCE
    • NASEMSO
    • NATE
    • NXDN Forum
    • NENA
    • NIST/PSCR
    • NPSTC
    • NTIA/FirstNet
    • P25 TIG
    • TETRA + CCA
    • UTC
acc.com

Cybersecurity


Partner content

3 security flaws in devices and IoT that need fixing

3 security flaws in devices and IoT that need fixing

  • Written by Grigorii Markov / Dark Reading
  • 26th February 2021

Rapid changes in how Internet of Things (IoT) devices around us interact with each other have created a landscape defined by unprecedented security vulnerabilities. There are three main security concerns with them and some possible fixes.

In December 2020, Forescout identified 33 vulnerabilities impacting four open source TCP/IP stacks. These are used by millions of devices around the world. They allow attackers to target a smart home or an automated industrial environment and use nearly any device as an entry point into the network.

According to IBM, the average cost of a data breach is just under $4 million, and it takes organizations an average of 280 days to identify and contain a breach. Meanwhile, the destructive potential of botnets has grown over the past few years. They propagate malware, mount distributed denial-of-service (DDoS) attacks, and spread disinformation on social media.

Problem 1: Unsecured API Connections
Application programming interfaces are widely used for devices to communicate with one another but are rarely built with robust security. For instance, when a data analyst directly accesses a database, most security systems will log that user’s name and role. But an external user may not have to offer those credentials. So, two log entries can be as such:

● John_Smith: Data Analyst – 172.20.118.97

●  App_User: Service Account – 172.20.0.159

Only one of these gives you useful information about the user’s identity. If your smart devices and IoT equipment don’t collect useful data, you lack edge-to-end network visibility.

Cybercriminals scour the Internet for exposed API tokens. It’s one of the easiest ways to quickly create and leverage an enormous botnet made up of zombie IoT devices.

How to Solve API Connection Issues
Security engineers and enterprise IT teams should treat apps and APIs like data gateways. This means reviewing API connections to make security-oriented changes.

If an IoT device has any external connection capacity, it should be configured to securely categorize incoming user requests and block unauthorized ones. Developers need to inform security professionals about “shadow APIs” that might go unnoticed. Teams must work together to identify deprecated and outdated APIs.

To read the complete article, visit Dark Reading.

 

Tags: Alerting Systems Applications Critical Infrastructure Cybersecurity Drones/Robots Enterprise Federal Government/Military Incident Command/Situational Awareness Internet of Things IoT/Smart X News Policy Public Safety Regional Coordination Security Software State & Local Government Subscriber Devices System Design System Operation Test & Measurement Tracking, Monitoring & Control Training Partner content

Related


  • Unlocking the power of ESInets: Different NG911 provisioning approaches exist; level of control is key differentiator
    Next-generation 911 (NG911) systems represent a quantum leap forward for the public-safety community and the citizens that it serves. Internet Protocol (IP)-based and broadband-enabled, such systems are capable of considerably more than legacy 911 systems, which is why many emergency communications centers (ECCs) from coast to coast are clamoring to implement them. The broadband capabilities […]
  • Biden's $100 billion broadband plan raises four big questions
    After much discussion, President Biden finally released the general outlines of his $2 trillion infrastructure plan, of which $100 billion will be devoted to broadband services. Whether Biden will be able to get his proposal through Congress remains to be seen. But if he is successful, his proposal could dramatically alter the contours of the US broadband […]
  • Newscan: Satellite-technology revolution means there are swarms of spacecraft in orbit
    Newscan: Satellite-technology revolution means there are swarms of spacecraft in orbit
    Web Roundup Items from other news organizations The revolution in satellite technology means there are swarms of spacecraft no bigger than a loaf of bread in orbit Democrats win crucial tool to enact Biden’s plans, including infrastructure 911 Saves Act reintroduced in U.S. House Large Florida school district hit by ransomware attack LG is quitting […]
  • Broadband expansion part of American Jobs Plan to rebuild country's infrastructure
    President Joseph Biden has announced his bold plans to rebuild America’s infrastructure. Part of the $2 trillion American Jobs Plan is $100 billion to revitalize the country’s digital infrastructure, including improving high-speed broadband to reach 100-percent coverage. In releasing the plan, the White House stated that broadband internet is the new electricity. “It is necessary […]

Leave a comment Cancel reply

To leave a comment login with your Urgent Comms account:

Log in with your Urgent Comms account

Or alternatively provide your name, email address below:

Your email address will not be published. Required fields are marked *

Related Content

  • Codan to buy Zetron for $45 million cash, will keep Zetron brand
  • Newscan: U.S. Army to spend $22 billion on Microsoft-based IVAS augmented-reality headsets
  • What we know (and don't know) so far about the 'Supernova' SolarWinds attack
  • Biden's big infrastructure plan targets broadband access, puts subsidy programs on notice

Commentary


Unlocking the power of ESInets: Different NG911 provisioning approaches exist; level of control is key differentiator

7th April 2021

Ransomware? Let’s call it what it really is: extortionware

21st February 2021

Redefining communications for today’s mobile workforces

18th February 2021
view all

Events


UC Ezines


IWCE 2019 Wrap Up

13th May 2019
view all

Twitter


UrgentComm

Newscan: Single sign-in for government services expands to states, localities dlvr.it/RxLQNR

9th April 2021
UrgentComm

‘Life-saving technology’: AST SpaceMobile CEO outlines capabilities of direct-to-smartphone LEO satellite service dlvr.it/RxKqvp

9th April 2021
UrgentComm

Handcuffs over AI: Solving security challenges with law enforcement dlvr.it/RxGtpD

8th April 2021
UrgentComm

Fujistsu: Cyber cretins are casing out private 5G dlvr.it/RxGnfN

8th April 2021
UrgentComm

Faster in-vehicle Wi-Fi dependent on faster connectivity dlvr.it/RxGnZL

8th April 2021
UrgentComm

Digital-health infrastructure benefits from cloud-to-edge architecture dlvr.it/RxFcjx

8th April 2021
UrgentComm

All actions monitored: The 10 most surveilled major cities in the U.S. dlvr.it/RxFZHV

8th April 2021
UrgentComm

Unlocking the power of ESInets: Different NG911 provisioning approaches exist; level of control is key differentiat… twitter.com/i/web/status/1…

7th April 2021

Newsletter

Sign up for UrgentComm’s newsletters to receive regular news and information updates about Communications and Technology.

Expert Commentary

Learn from experts about the latest technology in automation, machine-learning, big data and cybersecurity.

Business Media

Find the latest videos and media from the market leaders.

Media Kit and Advertising

Want to reach our digital and print audiences? Learn more here.

DISCOVER MORE FROM INFORMA TECH

  • American City & County
  • IWCE
  • Light Reading
  • IOT World Today
  • Mission Critical Technologies
  • Microwave/RF
  • T&D World
  • TU-Auto

WORKING WITH US

  • About Us
  • Contact Us
  • Events
  • Careers

FOLLOW Urgent Comms ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookies Policy
  • Terms
Copyright © 2021 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X