Live data from Hacker News

What are Attackers after on IoT Devices?

arxiv.org

21–29 of 29 posts

Re: What are Attackers after on IoT Devices?

#21
post #15

Earlier quoted context omitted.

I currently rely pretty much exclusively on my Unifi gateway’s not-great IPS/IDS system, which allegedly receives updated threat intelligence feeds periodically. Outside of actual intrusion detection, I prevent my IoT devices (which are located in their own VLAN) from contacting the internet wherever possible, and entirely block any inter-VLAN traffic other than responses to connections initiated from devices residin…

> their own VLAN) from contacting the internet wherever possible, and entirely block any inter-VLAN traffic other than responses to connections initiated from devices residing on a “trusted clients network”, which hosts my phone, laptop etc. I am interested in this kind of setup but lack relevant experience. Is this stuff you set up in the stock Unifi admin pages?

many sort-of-recent home network equipment support this stuff or equivalent (i.e., multiple networks) just as a configuration from their admin UI. You don't really need relevant experience to set this up, just very basic networking knowledge and will to occasionally shake your head at the web-based-admin-user-experience of the box.

Re: What are Attackers after on IoT Devices?

#22
I was surprised to see Ireland pop up as one of the places with a significant number of connections to one of the honeypots. I’m not a security researcher, but hadn’t heard of Ireland as being a place with a lot of that sort of activity. Is this a well-known thing?

Re: What are Attackers after on IoT Devices?

#23
post #8

how are people performing intrusion detection on home iot devices?

If you’re running your custom homebuilt router, you can use IDS systems like snort[0] or suricata[1] It’s pretty fun to setup !, you can take any old desktop/laptop at your home and make them into your own custom router by running a linux or bsd instance on it. If you go this route, I would recommend suricata ids as you can setup more complex and sophisticated system easily, compared to snort. [0]( https://www.snort.…

Thanks this is a great idea.

One compromise would be to add an extra hop (like a raspberry pi ) to the IOT vlan, and install snort there. That way I could retain my primary router (currently Ubnt ERX).

Great tip!

Re: What are Attackers after on IoT Devices?

#24
post #23

Earlier quoted context omitted.

If you’re running your custom homebuilt router, you can use IDS systems like snort[0] or suricata[1] It’s pretty fun to setup !, you can take any old desktop/laptop at your home and make them into your own custom router by running a linux or bsd instance on it. If you go this route, I would recommend suricata ids as you can setup more complex and sophisticated system easily, compared to snort. [0]( https://www.snort.…

Thanks this is a great idea. One compromise would be to add an extra hop (like a raspberry pi ) to the IOT vlan, and install snort there. That way I could retain my primary router (currently Ubnt ERX). Great tip!

Yush, that works great too :D,

Happy tinkering ^^ and merry christmas

Re: What are Attackers after on IoT Devices?

#25
post #15

Earlier quoted context omitted.

I currently rely pretty much exclusively on my Unifi gateway’s not-great IPS/IDS system, which allegedly receives updated threat intelligence feeds periodically. Outside of actual intrusion detection, I prevent my IoT devices (which are located in their own VLAN) from contacting the internet wherever possible, and entirely block any inter-VLAN traffic other than responses to connections initiated from devices residin…

> their own VLAN) from contacting the internet wherever possible, and entirely block any inter-VLAN traffic other than responses to connections initiated from devices residing on a “trusted clients network”, which hosts my phone, laptop etc. I am interested in this kind of setup but lack relevant experience. Is this stuff you set up in the stock Unifi admin pages?

Rest assured it is not that difficult :). Correct, I've configured several firewall rules on the UniFi web UI, since I have a UniFi router/firewall (in my case a USG). If you'd like some help, feel free to reach out to me on keybase! I'm andrewnicolalde on there.

Re: What are Attackers after on IoT Devices?

#26
post #23

Earlier quoted context omitted.

If you’re running your custom homebuilt router, you can use IDS systems like snort[0] or suricata[1] It’s pretty fun to setup !, you can take any old desktop/laptop at your home and make them into your own custom router by running a linux or bsd instance on it. If you go this route, I would recommend suricata ids as you can setup more complex and sophisticated system easily, compared to snort. [0]( https://www.snort.…

Thanks this is a great idea. One compromise would be to add an extra hop (like a raspberry pi ) to the IOT vlan, and install snort there. That way I could retain my primary router (currently Ubnt ERX). Great tip!

Are you running stock firmware on the ERX and are you happy with it? Looking into potentially setting one up as well, any resources you could recommend for making best use of one?

Re: What are Attackers after on IoT Devices?

#27
In general, attackers can do anything. For example, they can find all the information about you through the Internet and take out what they need while you are not at home. In general, it's very sad. And I believe that this should not be. My husband and I talked and decided that we need to put an alarm system at home. And moreover, we decided to install Ajax because I read a lot of different articles and reviews and only good things were said about this company. I know that there is an application through which you can track everything and it is very convenient.

Re: What are Attackers after on IoT Devices?

#28
post #26
post #23

Earlier quoted context omitted.

Thanks this is a great idea. One compromise would be to add an extra hop (like a raspberry pi ) to the IOT vlan, and install snort there. That way I could retain my primary router (currently Ubnt ERX). Great tip!

Are you running stock firmware on the ERX and are you happy with it? Looking into potentially setting one up as well, any resources you could recommend for making best use of one?

Yep I use the stock /latest 2.x firmware. It includes a wizard to set up the lans, nat and firewall .

I recommend the 2 vlan setup and disable switch0 for the best performance .

It's a step up from consumer routers with more powerful firewall, qos, and configuration .

Ubiquitis docs are great

https://help.ui.com/hc/en-us/articles/115002531728-EdgeRoute...

Re: What are Attackers after on IoT Devices?

#29
post #28
post #26

Earlier quoted context omitted.

Are you running stock firmware on the ERX and are you happy with it? Looking into potentially setting one up as well, any resources you could recommend for making best use of one?

Yep I use the stock /latest 2.x firmware. It includes a wizard to set up the lans, nat and firewall . I recommend the 2 vlan setup and disable switch0 for the best performance . It's a step up from consumer routers with more powerful firewall, qos, and configuration . Ubiquitis docs are great https://help.ui.com/hc/en-us/articles/115002531728-EdgeRoute...

Thanks for this! What came out of that major breach they had earlier this year? Since I wasn't part of their ecosystem I never followed up.
Post reply on HN