sacon - fresh thinking iot (arnab chattopadhayay)

18
SACON SACON International 2017 CISO Platform and TiE IOT Forum India | Bangalore | November 10 – 11 | Hotel Lalit Ashok Securing Internet of Things

Upload: priyanka-aash

Post on 21-Jan-2018

1.159 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON

SACONInternational2017

CISOPlatformandTiEIOTForum

India|Bangalore|November10– 11|HotelLalit Ashok

SecuringInternetofThings

Page 2: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON 2017

TheInternetofThings

TheContext Data&Analytics Information&ActionsTheState

BLE,ZigBe

e,W

iFi

TheEnvironm

ent

Insights&W

orkflow

Ethe

rnet/LTE/FTH

RESTAPI

TheRoof TheCloudTheThings TheApps&Services

Page 3: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON 2017

TheImplicationoftheHyperScale

BiggerAttackSpace

BigDataDay-to-DayUsage

Diversity

LackofExperience

Varietyofprotocols,devices,applications,environmentsusers,vendors.

Morepersonal

Realtimeinformation

Poordesign

Page 4: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON 2017

WhoIsResponsibleforSecurity

DeviceManufacturers

SoftwareVendors

NetworkBuilders

ServiceProviders

Standardswillbringtheecosystemtogethertobuildsecuresystems.

Page 5: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON 2017

IoTSecurity!=CyberSecurity

IoTSecurityRootofTrustNetworkSecurityPrivacy

NetworkSecurity=SecureProvisioning+SecureKeyManagement+Authentication&Authorization+SecureCommunication

Page 6: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON 2017

KeyPlayers

• IoTUsers• ISP• SecurityServiceProviders• NetworkServiceProviders• VarietyofCloudServiceProviders

Page 7: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON 2017

KeySecurityFunctions

• Identity– ofPeople,DeviceandNetworks• AccessControl– Zero-TrustModel,segregatednetworkforIoT• Monitoring– includinginvasiveactivitymonitoring• De-boarding– disconnect,block,de-registerandinitiatelegalactionagainstentitiessuspectedwithadversarialbehavior

Page 8: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON 2017

FunctionalAspectsofIoTSecurity

• ChannelSecurity• Protectthecommunicationpath

• RootofTrust• SecureBootCapabilities

• SecurityManagement• ManagementofCryptoMaterials,Policiesandupdates

• SecurityFusion• Detect,blockandreportadversarialattempts

• Cooperation• Shareinformationandlearnbestpractices

Page 9: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON 2017

FunctionalAspectsofIoTSecuritycontd.

• SecurityBootstrapping• InitialSecurityConfigurationandProcedures

• SecurityServices• ProtecttheSourcesandManageVulnerabilities

• DataProtection• Protectdataatrestinserversandend-pointequipments,protectdatainmotion

• Identify,AuthenticateandAuthorize• Primary,SecondaryandTertiaryauthentication,MFA,Zero-trust

Page 10: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON 2017

Identity

HWRootofTrust*

DeviceID

Ownership

OwnerID

DeviceConfiguration&ServiceIdentification

ServiceEnablement

Blockchain/TrustedDatabase

PKI

Page 11: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON 2017

AccessControl

UninternettingDon’texposethingsovertheInternet

IndirectionMovesecuritycomputingonelevelup

SecurityGateAllowonlytrustedsource

SecurityFusionContextualanalysis

MultiFactorAuthenticationExtralayersofsecurity

Acombinationofthesewouldhelpinbuildingrobustprotectionagainstthethreats.

Page 12: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON 2017

IoTSecurity– byIndirection

Communication

SecurityNegotiation

ResourceOwner

SecurityManager

ResourceServerClient

SecurityProvisioning

SecurityProvisioning

SecurityProvisioning

SecurityProvisioning

Cloud

Roof

Things

Page 13: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON 2017

SecuringNetworkSegments

CloudPAN WANLAN Internet

IPSecTunnel

CoAP/UDP/DTLS/IPv6

IPSecTunnel

WiFi/Ethernet

BB/LTE/MPLS

OTAEBLE,802

.15.4,W

iFi

SSPEdgeRouterApps

Page 14: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON 2017

NetworkAccessProxy

• SimilarArchitectureasGoogle’sBeyondCorp• Zero-Trust• Real-timeBehaviorAnalysis

Page 15: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON 2017

MonitoringandDe-boarding– SecurityFusion

Authorization

Authentication

ChannelSecurity

SecurityFusion

Security

Managem

ent

RootofTrust

• SecuritybyDesign• ContextualAnalysis• MFA• DoS PreventionmechanismonDevices• MinimizeDeviceComputing

Page 16: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON 2017

PrivacyManagement

InformedDecisionMaking

End-to-EndTransparency

WeighingPrivacyvs.Benefits

ContextualAwareness PrivacybyDesignGovernmentRegulations

Page 17: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON 2017

StrategicPrinciplesforIoTSecurity

* UnitedStatesDepartmentofHomelandSecurity,November2016

Incorporatesecurityatthedesignphase

Promotesecurityupdatesandvulnerabilitymanagement

Buildonprovensecuritypractices

Prioritizesecuritymeasuresaccordingtopotentialimpact

PromotetransparencyacrossIoT

Connectcarefullyanddeliberately

1 2 3

4 5 6

Page 18: Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)

SACON 2017

ThankYou