Successfully reported this slideshow.
Your SlideShare is downloading. ×

The Real Internet of Things: How Universal Daemonization Will Change Everything

Ad
Ad
Ad
Ad
Ad
Ad
Ad
Ad
Ad
Ad
Loading in …3
×

Check these out next

1 of 62 Ad
Advertisement

More Related Content

Similar to The Real Internet of Things: How Universal Daemonization Will Change Everything (20)

Advertisement

Recently uploaded (20)

The Real Internet of Things: How Universal Daemonization Will Change Everything

  1. 1. The Real Internet of Things How universal daemonization will change everything Daniel Miessler HouSecCon October 2014
  2. 2. Me - Practice Principal at HP Fortify on Demand - Lead the research and development team - Web and mobile pentesting focus - 15 years in infosec - OWASP project leader (IoT, Mobil…) - danielmiessler.com - @danielmiessler
  3. 3. The Internet of Things Image from cloudtimes.com
  4. 4. Common IoT Narrative Image from navigantresearch.com - analog things go online - toasters, microwaves, cameras - device to device interaction - your alarm starts your coffee maker - your car opens your garage - a factory floor self-optimizes
  5. 5. Actual IoT IoT Narrative
  6. 6. Agriculture
  7. 7. Start the press
  8. 8. Industrial
  9. 9. Tubes
  10. 10. IoT
  11. 11. Personal Servers Avatars by iconizeme.com
  12. 12. Personal Servers: Julie Avatars by iconizeme.com - single - loves coffee - favorite movie: sneakers - went to Aldrin high school - hates sand - dog person - afraid of owls - wishes she was Arya Everyone will be broadcasting a geo-based daemon
  13. 13. Personal Servers: Chris Avatars by iconizeme.com - single - loves coffee - favorite movie: chaos theory - favorite band is Zao - hates sponges - cat person - afraid of owls - has broken 19 bones Everyone will be broadcasting a geo-based daemon
  14. 14. Personal Servers: Interaction - single - loves coffee - afraid of owls The power comes from the continuous interaction between daemons
  15. 15. Personal Assistants Avatars by iconizeme.com Siri and Google Now will become integral to our lives - managing calendar - texting - emailing - finding you movies - picking food for you - filtering mates - parsing daemons
  16. 16. Personal Assistants: Burden-- - single - loves coffee - afraid of owls We won’t be managing those interactions—our PAs will
  17. 17. Personal Daemons + AssistantsConstant managed interactions between personal daemons
  18. 18. Businesses are people, tooBusinesses will have daemons as well, powerfully extending their functionality
  19. 19. Businesses + RDF = PowerBusinesses will have daemons as well, powerfully extending their functionality
  20. 20. Business Daemon AttributesThink of what a business would want to broadcast in their daemons
  21. 21. Business Daemon AttributesBusinesses will have daemons as well, powerfully extending their functionality - Menu - Item1 - Item2 - Safety - Allergies - Construction - Hiring - Openings - Music - Current - Playlist - Recommend - Climate - Raise - Lower - Condiments - Request
  22. 22. Business Daemon InputsEach business will have different types of APIs that are useful for customers - Menu - Item1 - Item2 - Safety - Allergies - Construction - Hiring - Openings - Music - Current - Playlist - Recommend - Climate - Raise - Lower - Condiments - Request
  23. 23. Business Daemon APIsNot just read-only https://stores.bww.api/8941/api/climate
  24. 24. Rich Business API FunctionalityBusinesses will expose powerful functionality that our PAs can manage for us
  25. 25. Sync 1. Personal Daemons broadcast information about us
  26. 26. Sync 1. Personal Daemons broadcast information about us 2. Businesses will have daemons as well
  27. 27. Sync 1. Personal Daemons broadcast information about us 2. Businesses will have daemons as well 3. Our personal assistants will broker on our behalf
  28. 28. Sensors will be on everything… - Video - Audio - Vibration - Air Quality - Air Pressure - Radiation
  29. 29. - Architect - Built - Materials - Certification - /api/climate - /api/doors - /api/cameras - /api/pool - /api/cameras - /api/windows House
  30. 30. - Birthday - Gender - Ancestry - Profession - Books - Movies - Education - /api/connect Human
  31. 31. - Make - Model - VIN - Features - /api/climate - /api/music - /api/voice - /api/video - /api/cameras - /api/sensors Car
  32. 32. - Brand - Model - Version - Features - /api/battery - /api/video - /api/audio - /api/sensors Watch
  33. 33. - Type - Age - Planted By - Birthday - /api/status - /api/water - /api/camera Tree
  34. 34. Baby Clothes - Video - Audio - Vibration - Air Quality - Air Pressure - Radiation
  35. 35. Furniture - Video - Audio - Vibration - Air Quality - Air Pressure - Radiation
  36. 36. Park Benches - Video - Audio - Vibration - Air Quality - Air Pressure - Radiation
  37. 37. - City - Street - Geo - Hours - /api/pay - /api/tickets - /api/camera - /api/sensors Parking Meter
  38. 38. - Brand - Model - Version - BuildDay - BulbStatus - /api/light - /api/audio - /api/video - /api/air Lamp
  39. 39. Character Sheet - Shoes - Pants - Watch - Purse - Total CPU cycles - Total memory - Brands - Year - Season - Gucci - Louboutin
  40. 40. - Owner - Height - Architect - Materials - /api/climate - /api/video - /api/audio - /api/sensors - /api/security Building
  41. 41. Sensors + Daemon + API - Video - Audio - Vibration - Air Quality - Air Pressure - Radiation
  42. 42. Ubiquitous Customization
  43. 43. Ubiquitous CustomizationYour business experiences will be customized based on constant PA-to-daemon interaction /api/purchase /api/music /api/tv /api/connect /api/browse /api/test
  44. 44. Also, much will be recorded - Video - Audio - Vibration - Air Quality - Air Pressure - Radiation
  45. 45. “Computer: Show me video of this location between the hours of midnight and 4am.” Official Investigations
  46. 46. Public access to events
  47. 47. TCP/IP vs. victimUniversal Daemonization
  48. 48. Universal Daemonization Ubiquitous Customization Personal AssistantsUniversal Daemonization - Everything is an object - Everything has a daemon - Everything has an API
  49. 49. Ok, now what?
  50. 50. Options
  51. 51. What’s the protocol? - Security? - Privacy?
  52. 52. ? How do we handle auth? - Owner - Height - Architect - Materials - /api/climate - /api/video - /api/audio - /api/sensors - /api/security - Google? - Facebook? - Local/State/Federal/Global?
  53. 53. How do we maintain privacy? - Killswitches? - Do-not-monitor? - Darkzones?
  54. 54. How do we disconnect?
  55. 55. What we're doing -OWASP Internet of Things Top 10
 https://www.owasp.org/index.php/OWASP_Internet_of_Things_Top_Ten_Project -HP FoD Top 10 IoT Device Research Report
 http://fortifyprotect.com/HP_IoT_Research_Study.pdf -Offering IoT assessments using the IoT Top 10
  56. 56. What you can do -Reach out and help on the IoT Top 10 daniel.miessler@owasp.org - I am the Cavalry (https://www.iamthecavalry.org)
  57. 57. Wizard Wars Wizard Wars http://www.dilbert.com/blog/entry/wizard_wars/
  58. 58. daniel@hp.com

×