DEF CON 26 IoT VILLAGE — Lee and Park — Exploiting the IoT hub What happened to my home

Дата: 21.11.2018. Автор: CISO CLUB. Категории: Подкасты и видео по информационной безопасности

In the home IoT service, the IoT hub is an important device that links users and various things in the house.
What are the security threats to these hubs and are they securely configured?
This presentation explores the importance of targeting IoT hubs in the home IoT environment and the role and features of the IoT hub in the IoT environment. We will explain the analysis process and related issues about the vulnerabilities of various IoT hubs discovered through the research, and present the threat scenarios that may arise in the home IoT service.
Finally, we will talk about what security factors to consider in a home IoT environment, including the IoT hub, and how to solve them.
We found various 0-days (Buffer Overflow, Command Injection, Local Privilege Escalation, Backdoor etc) for IoT hubs in terms of STRIDE threat model. In addition, we can show the practical threats in modern smart home by exploiting the IoT hub.


