A massive internet attack that paralyzed Twitter, Netflix and other services is being blamed on a specific kind of malware created to harness the power of ordinary consumer devices. Unfortunately, using the malware isn’t particularly hard and doesn’t require much money. The "Mirai" malware was recently posted online for others to adapt for their own attacks. (Awesome, right?)
Experts say Mirai exploited security vulnerabilities in thousands of internet-connected devices, like web cameras, then used those devices to attack a major internet firm, resulting in widespread outages. Researchers say Mirai has been used before, but not on the scale of Friday’s attacks. While distributed denial-of-service attacks have been around for years, hackers have many more devices they can use to pull off their attacks, thanks to the proliferation of internet-connected cameras, thermostats, lights and more.
Any conversation about the Industrial Internet of Things quickly turns to the underlying fear of cyber-insecurity. The recent Mirai attack, understandably, will continue to feed that fear. However, that doesn't mean that IIoT doesn't hold value and should be avoided. It simply calls for users to be smart.
What should industry learn from this episode?
- Through no fault of your own, your IIoT application can be rendered useless because I installed a Wi-Fi security system in my house and have a smart TV and didn't secure them. As an IIoT user, you would need to include this risk as part of your application design. What happens when the application is unavailable for 5 minutes, 30 minutes, 1 hour, or 1 day, for example?
- The IIoT devices you install should have embedded security to prevent the installation of malware from outside your corporation AND from inside the firewall. A DMZ doesn't guarantee the security of your devices, it is simply one security measure of many.
- You should have antivirus applications that scan your IIoT devices as well as monitor your network traffic, not just your servers and workstations. You don't want your devices to be part of the problem, either.
Cyber risks are part of the "new normal." The game now, similar to process safety, is mitigation. The value that today's Digital Transformation promises and the increasing rapidity of change means that users need to embrace it with both eyes open. The recent attack simply reasserts users' need to "IIoT responsibly."