In May of 2015, over 60 Incapsula customers were attacked by a Botnet made up of over 10,000 home routers. Later in the year, we noticed 900 Internet-connected CCTV cameras flooding one of our customers with bogus traffic. These are just two cautionary tales of what can happen when the IoT is compromised for malicious purposes – what we call the Botnet of Things. Our security research team has noticed a steady uptick on devices used in attacks on websites and web applications. Poorly secured and infrequently updated devices – from home routers to nanny cams to networked storage — are the perfect target for hackers. Then, rounded up by the hundreds, thousands, or tens of thousands, compromised devices make up a giant recruiting target for bot herders looking to grow the size of their botnets. The Botnet of Things is a growing problem. Botnets are used for comment spam, site scraping, vulnerability probing, denial of services attacks, and worse. At Incapsula, we see these attacks on a weekly basis. This talk will cover: • How hackers discover and compromise Internet connected devices • Case studies of IoT botnet attacks • How to identify IoT botnets and protect yourself against them We plan to incorporate new research findings from the Incapsula security research team on the state of the Botnet of Things into our session, including: device trends, recent exploits and vulnerabilities.