Improving IoT security with log management

2 min read
Curated from graylog.org →

The Internet of Things (IoT) revolution has set the beginning of a new age of data transfer. Each day, a massive number of new devices get added to all kinds of network infrastructures, transferring gargantuan amounts of data back and forth. In the next decade, we expect the number of IoTs to grow to a staggering 80 billion connected devices – practically outnumbering the human population tenfold.

As these devices communicate with each other and with the system networks, countless log files are generated in real-time on a constant basis. We know we can strengthen IoT security with a wise log management strategy. So, how can we leverage these event logs to improve the cybersecurity of these often extremely vulnerable access points to our systems?

It’s probably a known fact already that IoT devices often represent a vulnerable access point that could be exploited by hackers and other malicious actors. Even “ordinary” people who do not work in the IT field saw that Black Mirror episode with the webcam after all. However, did you know that, according to Symantec, cyberattacks targeting IoTs have increased by a jaw-dropping 600% between 2016 and 2017? Even today, 70% of these devices include some kind of vulnerability. In the (somewhat) near future, up to 90% of all our vehicles are going to be connected to the internet, so it’s easy to do the math.

Lack of proper manufacturing standards, corners being cut to keep the prices low at the expense of security, and the difficulties in properly encrypting IoT devices, all contribute at making these access points a known soft spot in every cyber attack strategy. Today, 99.9% of traffic to our honeypots is automated – a horrifically dangerous scenario, given that most modern bot armies and malware are scripted to attack at scale. You need just a simple ill-equipped IoT toothbrush to get infected by a malicious actor to bring a giant multinational corporation to its knees. Pitch-perfect tracking and in-depth log monitoring strategies aren’t a luxury anymore. You must employ them if you want to have a chance at spoofing these attacks in the event your enterprise becomes a target.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at graylog.org →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.