Hackers Are Using Consumer IoT Devices To Launch DDoS Attacks

Internet of Things (IoT) devices are being increasingly used to carry out distributed denial of service attacks (DDoS), spread malware and create botnets.

Research by Symantc’s Security Response team has discovered that cyber criminals are using home networks and everyday consumer connected devices to carry out DDoS attacks on large companies and profitable targets.

Cyber criminals are targeting these network as the lack of security standards in IoT device and a lax approach by their users to change default passwords in home networks makes them an easy target from which hackers can gather cheap bandwidth by stitching together a web of consumer devices and using it to launch DDoS attacks.

When IoT attacks

Nick Shaw,  Norton general manager for EMEA at Symantec, said that despite the benefits IoT device bring the user, cyber criminals are wise to the vulnerability of home IoT networks.

“As we continue to adopt more internet-connected devices in our daily lives – from fitness trackers and routers to home security systems, smart TVs and baby cameras – cybercriminals are starting to pay attention,” he said.

Many of the IoT devices that are attacked, according to Symantec, are designed to be plugged in and forgotten which leaves them ripe for hacking; so much so that the security company is claiming 2015 to be a record-breaking year for IoT-based attacks.

It noted that over half of these attacks have originated from China and the US, with high numbers coming out of Germany, Russia, the Netherlands, Ukraine and Vietnam. Essentially, the security vulnerabilities of the IoT are a world-wide problem.

IoT Solutions

Another problem with securing the IoT is the devices are designed to be used for very specific tasks so have little in the way of advanced operating systems and processing power which means they may have basic, if any security, features. While hacking individual sensors or smart lights may not pose a huge security risk in themselves, connecting all these devices together means hackers gain access to the bandwidth they need to launch attacks.

Users of these devices can feel a little relived that they, according to Symantac, are not normally the targets of such hack attacks, but for businesses in the sights of the attacker, they now have another attack vector to secure against.

Symamtec suggests that changing default passwords, keeping devices patched and updates, and disabling features that users do not use on devices, will help reduce the possibility of hackers infiltrating IoT devices.

But the research shines a light on how there needs to be a more rigorous approach to IoT security and standards if the activities of opportunistic cyber criminals are to be curtailed.

Increasingly cyber security companies are bolstering their ability to protect against IoT threats, such as Britain’s BullGuard with its acquisition of Israeli IoT security startup Dojo-labs.

Take our security quiz here!

Roland Moore-Colyer

As News Editor of Silicon UK, Roland keeps a keen eye on the daily tech news coverage for the site, while also focusing on stories around cyber security, public sector IT, innovation, AI, and gadgets.

Recent Posts

UK CMA Seeks Feedback On Microsoft, Amazon AI Partnerships

British regulator invites feedback on major partnerships Microsoft and Amazon have struck with smaller AI…

5 hours ago

Google Fires More Staff Over Israel Protest

Another 20 staff have been fired by Google over Israel protest and their “completely unacceptable…

6 hours ago

Australian PM Hits Out At Elon Musk Over Knife Attack Video

Censorship row brewing down under, after the Australian Prime Minister calls Elon Musk an 'arrogant…

7 hours ago

US SEC Seeks $5.3 Billion Fine From Terra’s Do Kwon

Financial regulator asks New York judge to impose $5.3 billion in fines against Terraform Labs…

7 hours ago

Microsoft Launches Smallest AI Model, Phi-3-mini

Lightweight artificial intelligence model launched this week by Microsoft, offering more cost-effective option for Azure…

11 hours ago

US Senate Passes TikTok Ban Or Divestment Bill

ByteDance protest falls on deaf ears, as Senate passes TikTok ban or divest bill, with…

12 hours ago