Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Internet of Thingbots
Articles

The Internet of Thingbots

Brian A. McHenryBy Brian A. McHenryOctober 25, 2017Updated:June 30, 20213 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Internet
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

If you follow technology news, then it’s almost impossible to avoid some mention of “the Internet of Things” or IoT, for short. With the proliferation of smart home devices ranging from lighting to garage door openers to thermostats to cameras and the use of other smart devices in enterprises, the challenges and growth in IoT can be very difficult to pin down.

Usually, when conjuring an image of a botnet poised to mount a massively distributed Denial-of-Service (DDoS) attack, the thought of a small army malware- and virus-infected PC’s and servers controlled by some shadowy, anonymized command and control (C&C) server comes to mind. However, the largest botnets and associated DDoS attacks recently have not been sourced from compromised laptops, servers, and smartphones. Attackers have found that it’s much easier to compromise a vulnerable IoT device than to trick a user into clicking a malicious link or download malware-infected file.

The Mirai and subsequent Persirai botnets were comprised almost completely of compromised IoT devices which used the popular embedded-Linux distribution, BusyBox. These botnets were built via self-replicating (worm-like) malware which, once infected, scanned the Internet for other vulnerable hosts. These botnets were not built overnight, as data shows the scans increasing over time with no attacks immediately thereafter. This infection pattern has the result of keeping the IP addresses of the infected IoT devices or Thingbots off many ISP and threat feed blacklists.

Other vigilante Thingbots have also surfaced, such as Hajime, which seeks to inoculate IoT devices using default administrator usernames and passwords. These botnets are built in the same way, but the vigilante attacker merely changes the username and password and leaves a note behind. These activities, while helpful, still do damage by locking legitimate users out of their own devices.

Patching these devices is often difficult, if not impossible, if the IoT device manufacturer is not actively maintaining the firmware. While a server or laptop running a popular operating system is easily updated, these potential Thingbots have tightly-controlled update mechanisms (if any, at all). Attempting to independently update the embedded-Linux BusyBox could easily result in bricking the IoT device, as the dependencies between hardware and software are often quite brittle.

To prevent IoT devices in your network (at home or in the enterprise) from becoming another Thingbot, follow a few simple steps.

  • Know what’s on your network. Maintain an asset inventory.
  • Seek reputable IoT vendors (e.g. avoid bargain bin Internet-connected security cameras.)
  • Disable UPnP in home office routers.
  • Avoid the use of port-forwarding or any-any firewall ACL’s.
  • Of course, never use default username/password combinations.

A few pro tips strictly for those in the enterprise:

  • Monitor outbound traffic, highlighting any traffic sourced from IoT devices.
  • Know the firmware levels in the asset inventory.
  • Enable 2-factor authentication in addition to privileged user access controls.
  • Use advanced WiFi security protocols to authenticate endpoints, where possible.
  • Demand better security features and defaults from IoT vendors who market solutions to the enterprise.

With DDoS attacks escalating in an ongoing effort by attackers to overwhelm the infrastructure of enterprises and service providers alike, it is imperative that we all do our best to secure all the would-be Thingbots in the networks we maintain. A safer Internet is everyone’s responsibility, and password maintenance tops the list of things we can all easily do to further that goal.

Brian_McHenry
Brian A. McHenry

As a Senior Security Solutions Architect at F5 Networks, Brian McHenry focuses on web application and network security. McHenry acts as a liaison between customers and F5 product teams, providing a hands-on, real-world perspective. He is a regular contributor on InformationSecurityBuzz.com, a co-founder of BSidesNYC, and a speaker at AppSecUSA, BC Aware Day, GoSec Montreal, and the Central Ohio Infosec Summit, among others. Prior to joining F5 in 2008, McHenry, a self-described IT generalist, held leadership positions within a variety of technology organizations, ranging from startups to major financial services firms.

  • Brian A. McHenry
    The WAF Is Not Enough
  • Brian A. McHenry
    Access Management, With A Side Order Of Identity
  • Brian A. McHenry
    Black Hat USA 2017: Bigger and Better (?)
  • Brian A. McHenry
    What’s New In The OWASP Top 10 And How TO Use It

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

How to Protect Your VoIP System from DDoS Attacks

September 9, 20258 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}