Recent Attacks Show the Need for IIoT Embedded Software Lifecycle

Category:
Industry Trends
​Last week a Chinese network security company NSFocus reported ​that smart devices such as home Internet routers and networked printers are beginning to be used in denial of service (DoS) attacks, in addition to the ever-popular Windows PCs.  
The devices are exploited by using a protocol called SSDP, Simple Service Discovery Protocol, which survives today as part of the nearly ubiquitous Universal Plug and Play (UPnP) stack.  The clever part of the attack was that the Black Hats did not have to infect the devices with malware.  Rather, they exploited a feature of SSDP that enabled its traffic to be re-directed to a different network location.  Sony and Microsoft game services were victimized by major DoS attacks late last year, and  NSFocus estimates that 30% of the devices in the attack were not PCs but rather home routers and printers.
So what about the industrial IoT world?  Could something like this happen? Sadly the answer is absolutely yes, and the main reason is today’s defective lifecycle for embedded software. Consumer electronics products are notorious for containing very out of date embedded software.  At a recent MIT lecture on this topic, a researcher showed that the Linux kernel in most home routers was on average 4 years old at the time the router was shipped. The typical router in service, then has probably almost 10 years of unpatched vulnerabilities, unless you (or your ISP) have maintained it.  Furthermore, this embedded code has a supply chain, and much of it may be unknown to the final seller, the ISP.
ARC published a report last November ​on this topic.  The report contained this little chart. The chart shows that asset (“device”) installed costs can vary by a factor of 1,000,000, but equipment lifecycles do not vary nearly as much. The lifecycle of smartphone handsets is on the short end of the spectrum at two to three years, while a major production plant will have a design life of 30-40 years – varying only by a factor of 20. 
Image removed. 
The outlier points on this chart are the devices with long lifecycles and low installed cost (toward the lower right on the chart); smart meters, home routers, and home solar systems. Smart meters are still “safe” because utility companies overwhelmingly keep the home networking features turned off.  Home solar systems are still not that common (but what a fun malware playground they might become some day!).  Home internet routers, were another sweet spot on the chart, and they made up a significant portion of the big 2014 DoS attacks, according to NSFocus.
The 2014 ARC report concludes:
Since many IoT applications will utilize devices whose lifetime is measured in decades, the challenge for these devices (and applications) is to develop an embedded software support process that does not jeopardize the IoT business case. This requirement will complicate product design. ​From a design standpoint, devices will need to supplement their on-board resources (especially storage) to support software updates throughout their lifecycle. Supplier selection must identify components, products, suppliers, and purchasing practices that lead toward lifecycle sustainability.






Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients