
When developing IoT devices, it is necessary to recognize the various threats lurking in IoT and implement appropriate security measures. In the first part of
*
Countermeasures Against Security Threats
The Information-technology Promotion Agency (IPA)'s " Security Design Guide for IoT Development " summarizes the main security countermeasure candidates as follows.


Security countermeasures vary depending on the threats to be addressed, but in any case, it is difficult to achieve 100% protection from attacks with a single countermeasure. Therefore, multi-layered defense combining multiple countermeasures is necessary. However, in reality, it is not possible to implement all countermeasures due to CPU processing capacity, memory capacity, cost, and other factors, and it is necessary to select countermeasures based on the impact of incidents when they occur.
Threats and Countermeasures Lurking in IoT - Using Smart Homes as an Example
Let's look at what countermeasures are necessary for threats expected in typical IoT devices, using smart homes as an example. The diagram below uses the model example from Part 1 and adds examples of necessary countermeasures for each threat.

Cloud Services
First, as a countermeasure to prevent unauthorized access, it is necessary to regularly check server security and respond promptly if problems are found. When vulnerabilities are detected, urgent action is required. For user authentication, it is desirable to combine multiple authentication factors to prevent unauthorized access through user impersonation. Firewall (FW) functions that restrict destinations by IP address • port number, IDS/IPS that monitors input/output data to detect • prevent unauthorized access, and log analysis that analyzes various logs to detect unauthorized access and determine what was done are also effective.
For DoS attacks that cause serious damage to cloud servers, countermeasures to block attacks are essential. It is also necessary to promote data encryption and minimization of collected data to ultimately prevent damage from information leakage.
HEMS Controller
By encrypting data communication channels, even if leaked, the data becomes worthless to attackers, avoiding eavesdropping and tampering. For viruses, vulnerability countermeasures such as software update distribution • application and patch application, antivirus that detects • removes viruses, and software signing First Name that permits only the operation of signed First Name software are effective.
Note that secure development with security considerations from early design and development stages is important, implementing secure programming during implementation, and confirming that security testing has been conducted at the time of shipment.
Home Router
As an unauthorized access countermeasure, when vulnerabilities are detected, urgent action such as software update distribution • application and patch application is required. For user authentication, it is important to combine multiple authentication factors to prevent access through user impersonation. Firewall (FW) functions that restrict destinations by IP address • port number are also effective.
For DoS attacks that render home routers unresponsive or stopped, implement countermeasures to block attacks.
Wireless Communication • Mobile Communication
For threats of eavesdropping and tampering expected in wireless and mobile communication channels, encrypting data communication channels is effective. Even if leaked, the data is encrypted and meaningless to attackers.
Network Camera
For unauthorized access to steal camera images, it is necessary to alert users in the manual about the need to set and change passwords, and to have mechanisms that do not allow unset passwords or default passwords at the user authentication stage, and mechanisms that lock out after a certain number of failed login attempts.
Also, if data communication channels are encrypted, even if leaked, the data is worthless and can be protected from attackers. Since there are many cases of DoS attack damage, DoS countermeasures are also essential.
Smartphones • Tablet Devices • PCs
To prevent unauthorized use by third parties, it is important to first properly perform user authentication and prevent threats from impersonation. Device functions can also be locked remotely. For viruses, vulnerability countermeasures such as software update distribution • application and patch application, antivirus that detects • removes viruses, and software signing First Name that permits only the operation of signed First Name software and prevents the operation of infected or tampered software are effective.
Smart Meter
As an unauthorized access countermeasure, when vulnerabilities are detected, urgent action such as software update distribution • application and patch application is required. For user authentication, it is important to combine multiple authentication factors to prevent access through user impersonation. Firewall (FW) functions that restrict destinations by IP address • port number are also effective.
As preparation for information leakage, encryption of the data itself is fundamental, but depending on the situation, it will also be necessary to reset devices to factory state and delete all data and post-shipment settings. Secure erasure that makes data recovery impossible, and tamper-resistant H/W • tamper-resistant S/W that make analysis of internal structure and stored data difficult are also options.
Summary
Through Part 1 • Part 2 of this article, we have seen that various threats exist that endanger the security of IoT devices, and that security countermeasures appropriate to each device are essential when developing devices. IoT devices with insufficient countermeasures not only cause damage to users but also bring disadvantages to manufacturers. From developers to management, everyone should recognize the importance of security countermeasures and work on them.
" IoT Security Guidelines ver1.0 "(IoT Acceleration Consortium • Ministry of Internal Affairs and Communications • Ministry of Economy, Trade and Industry)
" Product Security Countermeasure Guide for SMEs Developing IoT Devices "(Ministry of Economy, Trade and Industry)
" Security Design Guide for IoT Development "(Information-technology Promotion Agency, Japan)
* Please also read these articles.