Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Cybersecurity News

Defending the Network from Real IoT Threats

By Rishi Agarwal
July 28, 2015

The Internet of Things (IoT), once the stuff of science fiction, has stepped off the page and into the real world – and the world will never be the same. Analyst firm IDC forecasts that by 2020, 32 billion “things” will be connected: thermostats, refrigerators, parking meters, cars and so on.

More than just the latest technology fad, IoT holds real potential for the business community. Cisco predicts that between now and 2022, $19 trillion in value is at stake for organizations willing to take advantage of the increasingly interconnected world. However, not only legitimate enterprises are looking for ways to profit from IoT.

Cyber criminals demonstrated last year how adept they are at capitalizing on new opportunities and manipulating technology for their purposes. Hackers have become more efficient and effective, developing new methods to manipulate the protocol and accessibility of any home device that has an operating system and an open IP address. They can create a nearly instantaneous volumetric assault on intended targets through the use of a massive number of networked machines (often called botnets or “zombies”). The intent is to flood the network with unnecessary requests that eventually lead to a server crash or the insertion of malware into the network. Either way, it’s bad for business and brand reputation, and very bad for the bottom line.

The Threat Landscape Expands

Consumer Internet routers have today become instruments of what is now known as the simple service discovery protocol, or SSDP, reflective amplification distributed denial-of-service (DDoS) attack. It’s a long name with a significant impact; globally, more than 7 million SSDP devices have the potential to be exploited to launch SSDP and other DDoS attacks.

Last year, this kind of attack gained in popularity. SSDP attacks use smart devices (routers, webcams, etc.) to amplify attack bandwidth by as much as 75 times. With IoT bringing billions of such devices online, there will be an exponential growth in this type of attack.

Today’s smart devices include vulnerabilities such as:

  • Always on. Unless you have programmed all the “things” in your home to automatically shut down when you leave or go to sleep, connected appliances, routers and webcams generally stay online 24 hours a day, seven days a week.
  • Fairly high bandwidth. A router’s job is to provide your household with the bandwidth you need to stream movies, access the Internet and send email.
  • Password problems. The majority of us create weak passwords, just for the sake of convenience. But like your PC, Mac or phone, any equipment that connects to the Internet must be password-protected. While consumers are familiar with creating passwords in those environments, accessing the interface to password-protect a router or webcam may not be quite as intuitive.
  • Standards are lagging. Though federal standards bodies are looking into these types of attacks and developing recommendations, it is not up to the manufacturers to secure the consumer home network. Instead, currently this responsibility falls to the consumer who purchases the device.
  • Upgrade cycles are long. When was the last time you updated the firmware on your router? Most of us would say, “Never.” In fact, certain smart devices may never be upgraded after deployment.

Defending the Network in the IoT Age

Though enterprises and vendors are working on solutions to protect IoT devices, but in the interim, the battle against DDoS will continue to challenge enterprises and ISPs. At RSA 2015 in San Francisco, IDC analyst Chris Christiansen noted that with consumer devices, there is no money in security. He went on to say that as such, the security that is embedded in a consumer IoT device is minimal, which, he noted, will eventually lead to major privacy and future litigation issues, especially in Europe.

Traffic-based attacks that lead to latency or network crashes can be prevented, but enterprises, ISPs and hosting providers need to think outside of the traditional security stack. When looking for solutions to mitigate DDoS attacks, it is important to not only defend against DDoS attacks on the transport layer, such as flood attacks related to SYN, SYN-ACK, ACK, FIN/RST, UDP, ICMP and IP Fragment, but also those targeting the application layer, such as HTTP GET/POST Flood, slow-rate attacks, DNS attacks, game service attacks and audio/video attacks. Furthermore, in terms of application scenarios, look for solutions that defeat DDoS attacks launched via a multitude of agent servers, like CDN and WAF gateways.

There are even more evolved solutions available. Instead of relying solely on traditional fingerprint matching or similar methods, for example, advanced DDoS mitigation solutions also conduct behavior anomaly detection, which can then be filtered through an intelligent multi-layer identification and cleaning matrix. This consolidates the mechanisms of anti-spoofing, protocol stack behavior analysis, specific application protection, user-behavior analysis, dynamic fingerprint identification, bandwidth control and so forth.

There’s no question that IoT is changing the way we do business, the opportunities that lie before us, and the security threats we face. Government and financial standards bodies are working on creating policies to safeguard both businesses and their customers, but such undertakings usually take a long time to be finalized. Meanwhile, enterprises and hosting providers should look to implement DDoS protection solutions that monitor for and defend against SSDP and other attacks.

For more detailed information about SSDP DDoS attacks, other DDoS attacks from 2H2014 and predicted potential threats for 2015, download the NSFOCUS DDoS Threat Report here: http://www.nsfocus.com/2015/SecurityReport_0416/196.html

KEYWORDS: Internet of Things (IoT) network security security convergence

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Rishi Agarwal is Chief Evangelist and Director of Product Marketing at NSFOCUS, Inc. He has 12+ years’ experience in Product Marketing, Strategy, Business Development and Product Management. He has broad domain expertise in Network Security, Compute and Storage. Prior to NSFocus, he was a Senior Manager at Arbor Networks. Additionally, he has worked for leading technology vendors such as Microsoft, Intel and SanDisk.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Man with covered face

Why Most Workplace Violence Prevention Starts Too Late

Coding

What Security Leaders Say About the First AI-Developed Zero-Day Exploit

SEC 2026 Benchmark Banner

Events

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

July 8, 2026

The 2026 Security Maturity Benchmark Report: Insights From Senior Security Leaders

In this webinar, speakers will share key insights from the report, including why today’s threat environment demands greater maturity and how to evaluate your organization’s current security posture.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Person yelling in megaphone

    2 out of 3 Americans cannot distinguish AI voices from real voices

    See More
  • shield-cyber-freepik1170.jpg

    The sneaky security risk of overprovisioning the network

    See More
  • perimeter-enews

    Securing a Moving Target: The Network Perimeter

    See More

Related Products

See More Products
  • The Database Hacker's Handboo

  • intelligent.jpg

    Intelligent Network Video: Understanding Modern Video Surveillance Systems, Second Edition

  • Career Network (60 days)

See More Products

Events

View AllSubmit An Event
  • May 21, 2026

    From Referral to Response: Managing Domestic Violence Threats in the Workplace

    ON DEMAND: Domestic violence remains a complex driver of workplace violence, creating scenarios that require coordination across departments without clear ownership. Learn how threat management teams can manage domestic violence referrals from the start.
  • November 19, 2025

    From Chaos to Clarity: How Real-Time, Location-Aware Intelligence Strengthens Security Programs

    ON DEMAND: When disruptive events hit, security teams must move fast to protect people, executives, and assets. Learn how integrating verified, real-time alerts into ArcGIS empowers security leaders with the situational awareness and geospatial advantage needed to respond quickly.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing