Missed Opportunities: Measuring the Untapped TLS Support in the Industrial Internet of Things

06/01/2022
by   Markus Dahlmanns, et al.
0

The ongoing trend to move industrial appliances from previously isolated networks to the Internet requires fundamental changes in security to uphold secure and safe operation. Consequently, to ensure end-to-end secure communication and authentication, (i) traditional industrial protocols, e.g., Modbus, are retrofitted with TLS support, and (ii) modern protocols, e.g., MQTT, are directly designed to use TLS. To understand whether these changes indeed lead to secure Industrial Internet of Things deployments, i.e., using TLS-based protocols, which are configured according to security best practices, we perform an Internet-wide security assessment of ten industrial protocols covering the complete IPv4 address space. Our results show that both, retrofitted existing protocols and newly developed secure alternatives, are barely noticeable in the wild. While we find that new protocols have a higher TLS adoption rate than traditional protocols (7.2 Thus, most industrial deployments (934,736 hosts) are insecurely connected to the Internet. Furthermore, we identify that 42 (26,665 hosts) show security deficits, e.g., missing access control. Finally, we show that support in configuring systems securely, e.g., via configuration templates, is promising to strengthen security.

READ FULL TEXT

page 6

page 8

page 14

research
10/26/2020

Easing the Conscience with OPC UA: An Internet-Wide Study on Insecure Deployments

Due to increasing digitalization, formerly isolated industrial networks,...
research
10/17/2019

PropFuzz – An IT-Security Fuzzing Framework for Proprietary ICS Protocols

Programmable Logic Controllers are used for smart homes, in production p...
research
09/03/2018

Reasoning on Adopting OPC UA for an IoT-Enhanced Smart Energy System from a Security Perspective

Smart Services using Industrial Internet of Things (IIoT) applications a...
research
03/27/2020

Assessing the Security of OPC UA Deployments

To address the increasing security demands of industrial deployments, OP...
research
05/29/2019

Putting Things in Context: Securing Industrial Authentication with Context Information

The development in the area of wireless communication, mobile and embedd...
research
11/25/2020

Developing a Security Testbed for Industrial Internet of Things

While achieving security for Industrial Internet of Things (IIoT) is a c...
research
02/09/2022

Security of EV-Charging Protocols

The field of electric vehicle charging involves a complex combination of...

Please sign up or login with your details

Forgot password? Click here to reset