Securing the Future of Embedded Systems
CIO Review Europe | Tuesday, May 07, 2024
Embedded computing systems, like ATMs and gas stations, are often overlooked in cybersecurity due to limited functionality, resources, and regulatory requirements. Manufacturers use default-deny mode application control technology.
FREMONT, CA: Embedded computing systems are indispensable tools for numerous companies, yet their security is frequently overlooked. These systems, including ATMs, payment terminals, vending machines, ticket kiosks, medical computer tomographs, and automated gas stations, manage sensitive financial and confidential data that malicious actors can exploit. Consequently, they become prime targets for cyberattacks, necessitating companies' high priority on cybersecurity measures.
Despite their resemblance to traditional computers, embedded systems possess distinct differences that demand careful consideration in crafting a security strategy. Please address these differences to avoid exposing companies to many formidable challenges.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Features of Embedded Systems
Usage Model
Embedded systems differ significantly from conventional computers, typically used by individual employees for various tasks. An embedded system can accommodate unlimited users but usually offers a limited set of functions established during its initial development. Interactions with these systems often require specific input devices like digital keypads or specialised touch screens, restricting the execution of arbitrary commands or files. External peripheral connections are typically accessible only to technical experts. Communication occurs via the internet or local network, and these systems may be linked to functionally restricted storage devices like banking cards. It's crucial to note that embedded systems should not be used for tasks like reading emails or browsing websites to prevent potential security breaches. However, their network connectivity is significant, as it is a primary avenue for attacks, especially within a company's local network, where attackers can target these specialised machines. Additionally, hackers can exploit the physical placement of devices.
Physical Location
Embedded systems are often deployed in public spaces and protected by sturdy casings to deter unauthorised access. Despite these measures, maintenance requirements necessitate access, typically via crucial mechanisms. Attackers can exploit this by gaining physical access to the device and connecting standard input devices or storage units containing malicious software. They might even introduce alternative operating systems to bypass the device's security measures. This access enables them to manipulate the system for various malicious activities, from financial fraud to data theft, underscoring the importance of robust security measures.
Long-Term Use and Limited Resources
Embedded systems are designed for specific tasks and often operate with minimal processing power, reflecting a "necessary and sufficient" approach. Over time, these systems may become outdated, running on obsolete hardware that poses security challenges. The longevity of such systems also leads to outdated software, making them vulnerable to attacks as security updates become unavailable.
Weak Internet Connection
Some embedded systems, like ATMs or fuel dispensers, may operate in remote areas with limited internet connectivity, relying on cellular networks. While application software can handle asynchronous transactions, modern security solutions reliant on stable connections may face performance issues in such environments.
Regulatory Requirements
Regulatory bodies mandate robust security measures given the sensitive data embedded systems handle. However, implementation specifics often fall to companies, requiring them to balance risk mitigation with detailed logging for incident investigation. Regulatory guidelines may recommend technologies like system integrity control, which may not be readily available in standard security solutions, necessitating specialised approaches.
Systems that manage sensitive data, such as medical records, operate as multi-user, single-task platforms with low power consumption, making them vulnerable to various attack vectors. These systems handle confidential information and data that require strict integrity measures. However, endpoint security solutions can encounter challenges on underpowered hardware and outdated operating systems. To address this, manufacturers have embraced default-deny mode application control technology, which blocks unnecessary programs without relying on threat detection mechanisms. This approach minimises resource usage and is effective even on less robust systems, ensuring strong data protection and integrity.
More in News