Stuff

    Subscribe to our newsletter

    What's Hot
    Canon EOS R7 R10

    Canon’s mirrorless EOS R7 and R10 are inbound for budding amateur photographers

    May 24, 2022
    Priority

    Priority delivery on Uber Eats ensures you get your food first… for a fee

    May 24, 2022
    Toyota Starlet Main

    The 2022 Toyota Starlet hatchback lands in South Africa starting at R226,200

    May 24, 2022
    Facebook Twitter Instagram YouTube SoundCloud
    Trending
    • Canon’s mirrorless EOS R7 and R10 are inbound for budding amateur photographers
    • Priority delivery on Uber Eats ensures you get your food first… for a fee
    • The 2022 Toyota Starlet hatchback lands in South Africa starting at R226,200
    • The SABC is bringing big changes to the way TV licences in South Africa are paid
    • Millions in Savings: Get incredible deals on home entertainment, thanks to the LG Life’s Good Celebration Sale
    • Nissan unveiled its latest EV in the metaverse and it was as crazy as it sounds
    • Asus will bring the very first 500Hz gaming monitor to market
    • Two 100MW solar projects approved for SA, should go into operation from September 2023
    Facebook Twitter Instagram YouTube
    Stuff Stuff
    • News
      • App News
      • Business News
      • Camera News
      • Gaming News
      • Headphone News
      • Industry News
      • Internet News
      • Laptops News
      • Motoring News
      • Other Tech News
      • Phone News
      • Tablet News
      • Technology News
      • TV News
      • Wearables News
    • Reviews
      • Camera Reviews
      • Featured Reviews
      • Game Reviews
      • Headphone Reviews
      • Laptop Reviews
      • Other Tech Reviews
      • Phone Reviews
      • Tablet Reviews
      • Wearables Reviews
    • Columns
    • Stuff Guides
    • Podcasts & Videos
      • Videos
      • Stuffed
      • Stuffing Around
      • Tech Byte
      • T2S2
    • Win
    • Subscribe
      • Print
      • Digital
        • Google Play
        • iTunes
        • Download
        • Zinio
    • Stuff Shop
      • Shop Now
      • My Account
      • Downloads
    • Contact Us
      • Get In Touch
      • Advertise
    0 Shopping Cart
    Stuff
    Home » News » Internet News » Hacked by your fridge: the Internet of Things could spark a new wave of cyber attacks
    Columns

    Hacked by your fridge: the Internet of Things could spark a new wave of cyber attacks

    The ConversationBy The ConversationOctober 12, 2016Updated:October 1, 2021No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The past few weeks have seen a remarkable and somewhat alarming development in cyber security. It comes in the wake of a distributed denial of service (DDoS) attack that has forced a rethink of how we can deal with attacks of this nature in the future.

    The attack was aimed at the Krebs on Security website, a well established source of valuable information on cyber crime.

    What was remarkable about this particular attack was the sheer volume of traffic involved. According to the author himself, the attack reached around 620 gigabits per second, which is nearly twice the amount seen in the previous record-breaking DDoS attack.

    To put things in perspective, this is like the website being hit by one and a half Blu-ray discs’ worth of data every second. The average DDoS in 2014 involved traffic of around 7.5Gb/s, and yet only two years later the volume has increased by a factor of 10-15.

    The sustained attack eventually forced the website’s DDoS protection provider, Akamai cloud services, which had been providing security for the site free of charge, to admit that it could not handle that sort of attack pro bono, and thus the Krebs on Security site had to move.

    However, since the Krebs attack, there has been a claim made of yet another attack that involved more than 1 terabit per second of traffic.

    The claim is currently being investigated, and if it is confirmed, it highlights the challenge that organisations face in dealing with massive DDoS attacks.

    Apart from the record volume of data involved, the Krebs attack also set an unfortunate precedent by forcing a high-profile security website offline for several days. The attack was successful and has demonstrated the vast potential of this type of weaponised DDoS attack.

    Internet of threats

    This DDoS was also remarkable in terms of how it was executed. Most DDoS attacks use a tried-and-true method called amplification or reflection. This involves using a number of computers on the internet – often in the form of a “botnet” of compromised computers – to exploit quirks in the internet’s domain name server (DNS) system to turn a small amount of data into a torrent directed at the target website or server.

    However, in the Krebs attack, we saw something new: it wasn’t executed by conventional computers, but rather by Internet of Things (IoT) devices – including innocuous things like digital video recorders and security cameras.

    This is an important and worrying development for two reasons. First, the devices themselves are not designed with security as a key focus; convenience and cost are the main considerations.

    It is true that many of the IoT devices lack the computational and memory resources that are common in devices such as mobile phones, which reduces their capability from a hacker’s point of view. However, IoT devices are still susceptible to malware, and an enterprising criminal group can build a vast botnet given the time and relatively low investment.

    Second, even though their capabilities are lower than a regular computer, they are still more than capable of executing a DDoS attack if employed in sufficient numbers. And those numbers are growing daily. It is expected that more than 50 billion IoT devices will be plugged into the internet by 2020.

    Unless the security measures and settings improve significantly in the next four years, there will be literally billions of devices that could be compromised and used for malicious purposes. As Joseph Stalin is reputed to have said: quantity has a quality all of its own.

    These IoT DDoS attacks can be mitigated to some extent, but if the attack is well organised then the best we can aim for is damage mitigation. The nature of DDoS attacks makes them very difficult to handle, especially if the instigator is competent.

    Presently, we are not ready to handle large scale attacks of this nature. Most organisations, including major financial institutions, would be at least partially crippled by a sustained attack similar to the Krebs one.

    The reason for the lack of readiness is simple: the cost involved is, in most cases, beyond the financial capabilities of most organisations.

    However, one thing that is more affordable, and thus can be done to increase the readiness, is planning for such attacks. Rather than hoping that nothing significant will happen, it is best to plan for such attacks so that when they occur (and they will), everyone will know what they should be doing to mitigate the damage.

    • Mihai Lazarescu is Associate Professor and head of the Department of Computing, Curtin University
    • This article first appeared on The Conversation

    cybersecurity DDOS hacking internet of things Krebs The Conversation
    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    The Conversation

      Related Posts

      Canon EOS R7 R10

      Canon’s mirrorless EOS R7 and R10 are inbound for budding amateur photographers

      May 24, 2022
      Priority

      Priority delivery on Uber Eats ensures you get your food first… for a fee

      May 24, 2022
      Toyota Starlet Main

      The 2022 Toyota Starlet hatchback lands in South Africa starting at R226,200

      May 24, 2022

      Leave A Reply Cancel Reply

      In The Mag
      Stuff April-May 2022 Latest Issue

      In This Issue – The Smart Home (April-May 2022) Issue

      By Brett VenterApril 4, 20220

      It’s time for a brand-new issue of your favourite tech publication. The April-May- 2022 edition…

      2021 Wish List
      wish list Stuff Wish List 2021

      Stuff Wish List: for the tech impaired

      By Duncan PikeDecember 22, 20210

      Are you from the time before being glued to a smartphone was considered normal? Here’s…

      Wishlist DIY Stuff tech

      Stuff Wish List: for the DIY Diehard

      December 21, 2021
      Wish List Gearhead

      Stuff Wish List: For the petrol-soaked gearhead

      December 20, 2021
      outsiders

      Stuff Wish List: for the Outsiders

      December 17, 2021

      Latest Video

      Sonos

      SONOS Roam SL unboxing by Toby Shapshak

      March 30, 2022
      Mini Cooper

      The Mini Cooper SE Electric with Toby Shapshak

      March 18, 2022
      MSI Crosshair 15 Rainbox Six Extraction Edition unboxing

      MSI Crosshair 15 Rainbox Six Extraction Edition unboxing

      March 16, 2022
      Samsung Galaxy S22 Ultra Unboxing

      Samsung Galaxy S22 Ultra unboxing with Toby Shapshak

      March 16, 2022
      Contact

      South Africa's Consumer Tech News Hub

      General: [email protected]
      Subscriptions: [email protected] or 087 353 1291
      Editorial: 072 735 2614
      Sales: 083 375 2418

      Facebook Twitter Instagram YouTube SoundCloud

      Subscribe to Updates

      • Terms and Conditions
      • Privacy & POPI
      • My account
      © 2022 Stuff Group. Designed by Chronon.

      Type above and press Enter to search. Press Esc to cancel.