Open by default: the hidden cost of convenience in network security

No ratings

Presented at Virus Bulletin 2024 by

This presentation will discuss the almost obvious realization I had after a year of reviewing anonymized network security event logs for more than two billion devices spread across North America and Europe, tracking malware, trending TTPs, IOT software updates, targeted devices, botnet compositions and behaviours, etc. Ultimately, the only reason the majority of current botnet spreading and behaviour is happening is because the household routers have auto port forwarding enabled by default. In this talk, I will share some of the statistical data I gathered during my day-to-day threat research, most commonly targeted device types, ports used, techniques, and scenarios in which a device gets compromised and later used as part of the threat actor infrastructure. Then I will look at what I believe is one of the core problems in current household network security: "auto port forwarding". We dig down a bit into the UPNP protocol and coming replacements, but still the same problem persists. I will propose solutions and alternatives and call for manufacturers to stop the auto port forwarding being enabled by default.