Slashdot Mirror


MITRE Dangles $50,000 Prize For Spotting Rogue Internet of Things Devices (securityledger.com)

Long-time Slashdot reader chicksdaddy quotes Security Ledger: MITRE Corporation, the non-profit corporation that helps tackle some of the trickiest technical and security challenges out there, is dangling a $50,000 prize for anyone who can develop a solution for spotting rogue devices within an Internet of Things network...saying that it's looking for ground breaking new approaches to securing diverse Internet of Things networks like those in connected homes.

"Network administrators need to know exactly what is in the environment, or the network -- including when an adversary has switched out one device for another. In other words, is the smart thermostat we see today the same one that was there yesterday? We are looking for a unique identifier or fingerprint to enable administrators to enumerate the IoT devices while passively observing the network... "
Their registration form will be open through October, and the challenge will end after four weeks in November, or "whenever someone wins."

23 of 51 comments (clear)

  1. Select *.* by Anonymous Coward · · Score: 1

    So where do I collect my prize?

    1. Re:Select *.* by BarbaraHudson · · Score: 1

      So where do I collect my prize?

      That's pretty much it. IoT devices have to be cheap to be even remotely attractive, to make up for the obvious uselessness of many of them, Most of these devices have no real justification, or the hazards outweigh the benefits.

      --
      "Transparent" is a shit show that trades on every stereotype going. A man in drag is NOT a transsexual.
    2. Re:Select *.* by ShanghaiBill · · Score: 1

      IoT devices have to be cheap to be even remotely attractive

      It is not an issue of cheapness. Security is can be done in a few kilobytes of firmware, which is a negligible additional cost. It is about convenience. When a customer plugs in a smart lightbulb, they want it to "just work" and they don't want to spend five minutes configuring it.

      Disclaimer: I have a Amazon Echo, a Wink Hub, and several connected IoT devices (lightbulbs, door locks, motion sensor, garage opener). Some features are useful, like opening the garage door with my cellphone, and using voice to control the kitchen light. But unless you are a geeky early adopter, I would recommend waiting a few years for the bugs to get ironed out.

    3. Re:Select *.* by BarbaraHudson · · Score: 1

      Opening a garage door with your smartphone is stupid and dangerous when you're pulling into your driveway. Unlike a regular garage door remote, you can't do the smartphone purely by feel. Also, pretty much impossible when riding your bike, whereas again, it can be done by feel from 100 feet away, no problem. AND no internet needed.

      A regular remote, you have to be within range. An IoT remote, you can open someone's door from anywhere in the world. Really stupid. Your insurance is going to bitch about covering you when you get robbed repeatedly because some prankster wants to have fun and swatting you is too high-risk.

      --
      "Transparent" is a shit show that trades on every stereotype going. A man in drag is NOT a transsexual.
    4. Re:Select *.* by Anonymous Coward · · Score: 1

      Dont put your garage door on the internet, just need to get to it off my x509 WiFi then setup a GeoFence task that if its paired with my car and just entered the fence, open the door.. and vice versa.. hands free, and considerably more secure than the garage door opener I was using with strong end-to-end crypto.

      Just pretend the I in IoT is a lowercase L and setup a Lan of Things.. then run a VPN Server on your router for remote access and dont buy anything thats 'Cloud' enabled or requires a subscription fee.

    5. Re:Select *.* by BarbaraHudson · · Score: 1

      Automatic doors and gates are real great, until you have pets and kids running around on the property.

      --
      "Transparent" is a shit show that trades on every stereotype going. A man in drag is NOT a transsexual.
    6. Re:Select *.* by BarbaraHudson · · Score: 1

      Don't be silly. If your dog is in the garage and your garage door automatically opens when you pull in the driveway, your dog is gone. Same with kids if they're in the back yard and the door leading to the garage is open.

      --
      "Transparent" is a shit show that trades on every stereotype going. A man in drag is NOT a transsexual.
  2. Solution by 110010001000 · · Score: 1

    if (thing_is_iot) { rogue_device_probability_pct = 100; } else { rogue_device_probability_pct = 99; }

  3. $50k? by Xenna · · Score: 1

    I'll build as many rogue devices as they need for that price!

  4. Halting Problem by pz · · Score: 1

    Is the smart thermostat we see today the same one that was there yesterday?

    I bet this can be demonstrated to be equivalent to the halting problem. The question should be really: here are the spcifications of a certain device (whether dictated by the manufacturer, or determined empirically): does the present device match them? With every query from here to eternity? Under all circumstances? That smells like the halting problem.

    So, in other words, you can never be completely certain of the answer, only confident up to specific bounds. Maybe that's good enough, but $50K for that kind of work is not, and the amount of effort involved for the general case, is not. A good solution for the problem is going to be the sort of thing that would take a startup into a medium-to-large corporation.

    But there are really much better ways to avoid the problem in the first place. I mean, to paraphrase a processor of mine, we don't need a microprocessor in every doorknob. Just don't use the damned things. Your fridge does not need to be on the net. Nor do your chairs. Nor each door in your house. Your washing machine works perfectly well without being on the net. So does your garage door. The risks of putting highly insecure interfaces on such items just does not justify the potential benefit.

    --

    Put my fist through my alarm clock with its ding-dong death inside my ear. - The Blackjacks.
    1. Re:Halting Problem by ArtemaOne · · Score: 1

      Shockingly, adding unnecessary things to common objects makes rich people pay more for them.

    2. Re:Halting Problem by gzuckier · · Score: 1

      Is the smart thermostat we see today the same one that was there yesterday?

      I bet this can be demonstrated to be equivalent to the halting problem. The question should be really: here are the spcifications of a certain device (whether dictated by the manufacturer, or determined empirically): does the present device match them? With every query from here to eternity? Under all circumstances? That smells like the halting problem.

      So, in other words, you can never be completely certain of the answer, only confident up to specific bounds. Maybe that's good enough, but $50K for that kind of work is not, and the amount of effort involved for the general case, is not. A good solution for the problem is going to be the sort of thing that would take a startup into a medium-to-large corporation.

      But there are really much better ways to avoid the problem in the first place. I mean, to paraphrase a processor of mine, we don't need a microprocessor in every doorknob. Just don't use the damned things. Your fridge does not need to be on the net. Nor do your chairs. Nor each door in your house. Your washing machine works perfectly well without being on the net. So does your garage door. The risks of putting highly insecure interfaces on such items just does not justify the potential benefit.

      That used to be a cartoon: "In a fit of manic brilliance, network engineer Joe Blow wires the shredder into the office network".

      --
      Star Trek transporters are just 3d printers.
  5. Highest Respect for MITRE by mallyn · · Score: 1
    Folks:

    MITRE. These people I hold the highest respect for.

    One of my former classmates from Worcester Polytechnic Institute (Who got FAR better grades that I ever did; and who was near the top of the Engineering class of 1976) is working for them.

    I also met some former MITRE folks here in Bellingham whom I immediately knew were very smart in the security field.

    If these folks are offering the prize; I know they will be very diligent in assessing the applications.

    --
    Most Respectfully Yours Mark Allyn Bellingham, Washington
  6. What exactly ... by PPH · · Score: 1

    ... is a rogue device?

    that we expect to be present being hijacked for nefarious purposes. And even if I don't plug my TV set into my home network, what's to stop it from turning on its WiFi and establishing a mesh network through the neighbors' TV sets until it can reach some remote command server?

    --
    Have gnu, will travel.
    1. Re:What exactly ... by plover · · Score: 1

      I suppose it would be your neighbors choosing not to buy TVs that run open access points.

      My neighbors aren't that smart, and neither are yours.

      --
      John
    2. Re:What exactly ... by PPH · · Score: 1

      So, something like this?

      I'm going to depend on my neighbors knowledge of secure IT systems to protect my privacy? Yeah, right. He works for Microsoft.

      --
      Have gnu, will travel.
    3. Re:What exactly ... by gzuckier · · Score: 1

      ... is a rogue device?

      that we expect to be present being hijacked for nefarious purposes. And even if I don't plug my TV set into my home network, what's to stop it from turning on its WiFi and establishing a mesh network through the neighbors' TV sets until it can reach some remote command server?

      Like my Comcast wifi which now routinely offers unsecured Xfinity wifi to all passers by in the neighborhood (by design); and as a bonus, occasionally drops my secure wifi so that my devices switch over to the public Xfinity network, silently?

      --
      Star Trek transporters are just 3d printers.
  7. Watch the lights? by cdxta · · Score: 1

    Just watch the router and cable modem lights when they should be idle and make sure they aren't blinking away.

    1. Re:Watch the lights? by Zero__Kelvin · · Score: 1

      How, prey tell, do you know when they should and should not be idle?

      --
      Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
  8. if you ask me all IOT devices are "rogue" by TractorBarry · · Score: 1

    From what I've seen all IOT (more like IOSS "Internet Of Shit Security") devices are insecure.

    So if you detect an IOT device it's pretty much guaranteed to be "rogue".

    It's a compelte joke how piss poor the security is on these devices. It's 2016 and we've had decades of devices beign hacked over the internet. Adn the complete morons making this crap are *STILL* shipping them with default username and passwords, back doors, etc.

    Personally I think the best way to get some focus on this shiot fest will be for a few huge class action lawsuits to head the way of the worst offenders who have helped create huge botnets of IOSS devices. The current situation is truly pathetic and gives the internet, coders and technology itself a 9well deserved bad name).

    personally I've got zero IOSS devices in my house and will not be adding any until the security is made a key focus of the manufacturing process. Maybe an ISO standard also needs to be introduced and any devices that don;t pass it simply aren't legal for sale - with a suitable punishment for connecting one to the public internet (law varying by countries - a fine in Europe, America, the death penalty in Singapore :))

    --
    Sky subscribers are morons. They pay to be advertised at !
  9. Raspberry Pi by thinkwaitfast · · Score: 1

    Are my Raspberry Pis considered iot devices?

  10. Re:Do IoT devices not have MAC addresses? by knorthern+knight · · Score: 1

    Dumb User Answer: My PC is Windows, not MAC

    Competent User Answer: My MAC address is blah-blah-blah...

    l33t h@x0r d00d answer: My MAC adress? What do you want it to be?

    --

    I'm not repeating myself
    I'm an X window user; I'm an ex-Windows user
  11. Re:The answer is simple by gzuckier · · Score: 1

    If it comes from China and is a brand you never heard of. It's going to be a problem.

    Or a famous quality brand name which you see sold new on Ebay for $3.50 from China with free shipping.

    --
    Star Trek transporters are just 3d printers.