IoT security and hardening

Over the years, smart connected devices have become smaller, cheaper, and easier to use in critical infrastructure, fintech, defence and industrial systems. Such devices often work with sensitive data and IP: gather and send telemetry data, run ML models, process video and photos, or control other devices—so, they should be protected against unauthorized access and misuse.

Edge Compute / IoT / ICS / SCADA security issues are centered around a fragmented ecosystem (different OS, languages and hardware capabilities), power and performance constraints, and unique threat models (grab-n-run). Unless specific actions are taken to secure the devices, applications, and communications, they are at risk.

IoT security challenges

Software and firmware vulnerabilities

Any vulnerability discovered in IoT firmware or software can affect thousands or millions of devices. In many cases, patches can’t be easily propagated to all the devices. The owners become responsible for following the news and updating their devices, which is complicated for many users.

Lack of strong cryptography and TEE

A mix of available operating systems, lack of Trusted Execution Environment and a separate cryptographic coprocessor, restricted memory and power, and difficulty of patching software lead to weak cryptographic choices. Often, IoT devices rely on old unsuited cryptography and leak sensitive data via timing attacks or power analysis.

Platform security is complicated

Operating systems for IoT are very fragmented. Platforms and schedulers (Simba), specialized OS (FreeRTOS and HeliOS), ported OS (Google Mendel Linux, Raspberry Pi OS) or even full-scale OS (Debian, Ubuntu or Android)—all of them provide different security controls and require proper configuring, maintenance, and patching.

Closed and legacy systems

The legacy lives with bleeding edge in one box, from integrated electronics to large industrial systems. Being able to bridge specialized protocols (such as IEC 60870-5-10*, Modbus TCP, Profibus, Profinet, etc.), add security to simple over-the-wire telemetry, and deal with physical constraints requires a special combination of skills and patience.

IoT security solutions and approaches

Data and IP protection

Application level encryption, including end-to-end encryption, aims to protect stored data and communicate with the backend server securely. The data should be protected during the whole lifecycle: from generation to backups.

See AcraIoT security solutions and approaches

OS security and hardening

OS security includes patching OS core, removing unused components, configuring data at rest encryption, enabling access control, and befriending OS security with application security. Read below about the approach we use.

Reverse engineering protections

Reverse engineering protections are security controls employed to ensure that if the device is remotely attacked or physically stolen from the end-user, it’s not easy to debug it or steal valuable data and IP.

Our offerings

Relevant products

Acra

A DATABASE SECURITY SUITE

Acra makes field level encryption and searchable encryption easily integrated into existing infrastructures. Acra allows encrypting database fields “on the fly” without changing code, while Acra’s Data firewall and Anomalies Detection protect against suspicious activity.

Read more Our offerings

Themis

A CROSS PLATFORM CRYPTO LIBRARY

As a high-level cross-platform cryptographic library for mobile, web, and server platforms, Themis helps to integrate application level encryption fast and easy. It solves 90% of typical data protection use cases that are common for most apps.

Read more Our offerings

Custom solutions and consulting

OS and device hardening for IoT

The exact steps of Linux hardening depend on the risks & threats of particular device usage. We configure OS, remove unused libraries, enable security controls, logging and monitoring, fail2ban, restrict access, and set up honeypots and fake accounts. We build an “emergency wipe” mechanism that cleans the data and apps if a device is thought-to-be compromised.

IP protection and anti-reverse engineering

Telemetry data, ML models, videos and photos, logs, user PII—if the device stores data, it should protect it. We configure LUKS—for data at rest encryption and additional application level encryption—for application data. We use a combination of controls to detect and prevent reverse engineering, including decrypting the data only after receiving a special token via NFC / Bluetooth devices.

Read more Our offerings

Secure communications for IoT

For devices that should communicate with each other or the central hub, we build multi-layer communication security. It spreads from “just use TLS” to mutual authentication, TLS over VPN and application level encryption of packets with sensitive data. Devices might communicate over Wi-Fi, cellular network, pure TCP sessions or even SMS.

Read more Our offerings

Specialized cryptography for IoT

IoT devices require using lightweight cryptography, like AES-SIV, Super ChaCha or BLAKE2, that is suited for low power devices. Cryptographic usage should be protected against side channels, use constant memory computations, add noise and zero key material after encryption.

Read more Our offerings

Auditing and reviewing

We do security audits and review designs of existing implementations to give you a picture of how your application protects sensitive data, APIs, performs authentication, attest devices, etc.

Read more Our offerings

Security engineering

Encryption never comes alone. We will advise you on data migration, key management, designing application level encryption flow, implementing certain security features, assessing your product, verifying its security properties, and providing actionable advisory on improvements.

Read more Our offerings

Relevant customer story

Securing an ecosystem of edge ML devices
Designing and implementing security of specialised IIoT devices that run ML. Data protection, ML models protection, secure communication, fleet management, and anti-reverse engineering.
Read story

Why do IoT security with us

Relevant engineering experience

We’ve done IoT security for projects with thousands of smart devices, powered by Raspberry Pi, Google Coral, and STM32. We’ve designed and built mesh networks for device communication, integrated radio and NFC connections, implemented IP protection, custom encryption protocols, ML model protections, and many more.

Full-cycle security

We work on all fronts to ensure our customers' systems function securely: starting from device provisioning, OS hardening, implementing application security, integrating data encryption, and building secure communications up to long-term maintenance and support.

Addressing real-world risks

We make IoT security work for your use case. Starting from assessing real risks and threats for every case and device, we develop a spectrum of hands-on solutions best suited for your hardware, goal, and constraints.

Suitable for hard tasks

Our hardened devices work in defence and critical infrastructure, power generation management and remote data acquisition. We understand the nuance of highly-available devices in hostile conditions.

For innovators, by innovators

We've started Cossack Labs to develop new tools and methods for protecting the data and enabling novel solutions to emerging problems — so that at the edge of your innovation, you’ve already got fitting tools handy.