IoT and the Future of Pentesting

No ratings

Presented at BSidesCanberra 2019 by

The penetration testing industry and the skills required by pentesters has largely followed the macro trends across the IT industry. From infrastructure and desktop applications, to web apps and mobile apps, and most recently cloud, the significant trends across IT have then naturally influenced what pentesters are targeting and attacking as part of their day job. I've observed over the years that when new technologies gain momentum it is most often through consumer applications. Following an incubation period with consumers, the technology then starts to migrate into traditional businesses and this is most often when pentesters start to get their hands dirty with the technology. I personally experienced this trend with web apps, mobile apps and cloud over the last 15 years. This talk will look at the next big trend which is already somewhat finding its way into traditional businesses - the Internet of Things (IoT) and its implications and opportunities for pentesters and the broader security community. Whilst IoT solutions are still largely built upon existing, well understood technologies, there is one big differentiator which will have a significant impact for all of us in the infosec industry... and that's hardware. Hardware is so often viewed as a 'secure enough' black box that can be largely ignored and left as is. With the evolving variance of hardware platforms available and implemented in IoT solutions, unfortunately the opposite is painfully true. The hardware component(s) of an IoT solution can be the weakest link and also the hardest one to understand, test and ultimately fix. Hardware comes with its own unique attack surface and threat model which I'll be discussing along with examples demonstrating the impact and outcomes which can be achieved by performing invasive hardware-based testing within standard pentesting engagements. This will incorporate the anatomy of a hardware pentest, including the required testing/attack hardware, skills, considerations and risks all while linking back to real world, tangible examples. This talk is aimed at pentesters and security consultants who are busy in the trenches and don’t necessarily get the opportunity to take a step back and consider where the industry is heading. They will gain insight into how hardware affects a solution and how to approach testing it when it is required. The talk is also aimed at the broader infosec industry, including practitioners and leaders who need to understand the implications fast emerging technologies, such as IoT pose to their businesses. They will gain insights into the inner workings of these black boxes and walk away with a much better understanding of the risk profile IoT pose to an organisation and its customers.