The secret life of IoT devices: DDoS botnets


This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.


Since the term was coined in 1999, the amount of “IoT devices” has grown exponentially. From their commercialisation in the mid-2000s, it only took until 2008 for the number of IoT devices to overtake the worldโ€™s population. Now, theyโ€™re used in every industry from healthcare to agriculture. Anything that connects to the internet and exchanges data can be classed as one, so anything from specialist industrial equipment to even pacemakers all come under the IoT banner.

At the moment, there are an estimated 15 billion IoT devices globally, with GSMA Intelligence predicting this number will double by 2030. While this increase in IoT availability brings benefits to both everyday life and business operations, itโ€™s also a sharp double-edged sword.

Sure, itโ€™s no bad thing that IoT devices have seen such a boost in popularity, but it does also massively increase the threat from botnets. IoT botnets are vast networks of compromised IoT devices that pool their power to launch massive cyber attacks. These botnets are most commonly used in Volumetric and Application layer DDoS attacks, generating the immense amounts of traffic and requests needed.

This is particularly worrying when you consider that IoT devices are notoriously vulnerable to manipulation by cyber attackers due to their typically weak security configurations. As more and more IoT devices become active, attackers are simultaneously receiving access to more and more resources to bulk out their botnets. And not only does this make DDoS attacks larger, but it also makes them more difficult to mitigate.  

With so many IoT devices โ€“ many in DDoS-prone industries โ€“ thereโ€™s a large chance organisations could see themselves hit by DDoS attacks powered by their very own IoT devices.

IoT here, there, everywhere

Because of their often specialised use cases, most IoT devices are built for functionality rather than security. Many have exceptionally weak security configurations, lack regular security updates, and by design, theyโ€™re always online, which makes them open to constant exploitation. This means cyber attackers can fairly easily take advantage of and integrate them into botnets to amplify cyber attacks. In most cases, the actual everyday user of the IoT device will never be aware of its secret life inside a botnet.

Cyber attackers usually pursue the path of least resistance, exploiting known security flaws, yet many IoT devices still operate with these known flaws. Theyโ€™re easily avoidable mistakes, from default passwords to out-of-date firmware. In a recent incident using the infamous Mirai malware, for example, cyber attackers targeted a specific and well-reported bug in a particular model of CCTV cameras. As a result of this bug remaining unfixed, the attackers were able to gain control of a vast number of cameras in one fell swoop.

Everyone gets a botnet!

Cyber attacks have long been aware of IoT devices but the growing awareness of their weak spots is fuelling a recent botnet boom. The vulnerabilities that cyber attackers are exploiting within these IoT devices are far from complex, opening them up to cyber attackers even with limited technical skills. Even amateur attackers can use botnets to massively boost their otherwise limited attack impact. It has led to DDoS botnets-for-hire, using relatively simplistic methods to great effect to set up multiple botnets.

DDoS attacks benefit greatly from IoT botnets, using them to generate the enormous volumes of bandwidth needed to create the most damaging attacks. While the methods of attack used with botnets arenโ€™t any different from a non-botnet DDoS attack, they have a far larger scale.

“Typical” DDoS impacts include financial loss, reputational damage and operational damage, and can occasionally bring down services and critical infrastructure. With botnet-assisted attacks, the more extreme-case scenarios, such as the takedown of critical infrastructure, become far easier to achieve.

Ironically, many of these critical infrastructure providers are using IoT devices more and more, having adopted them to make laborious tasks easier. But now, they may now be one of their weakest points for would-be attackers to exploit.

Wait, there IS a quick fix?

Sadly, thereโ€™s no magic button to stop cyber attackers from targeting IoT devices, but we can make life harder for them. Itโ€™s well-established that cyber attackers are taking advantage of known security vulnerabilities in these devices, but whatโ€™s easy for them to exploit is usually also easy for defenders to fix. These known vulnerabilities have, well, known solutions that are just as simple to implement.

Take the default password issue, for instance. Simply changing passwords to something that isnโ€™t just “1234” already goes a long way to improve the security of these IoT devices. In fact, earlier in the year, the UK government introduced the Product Security and Telecommunications Act (PSTI), banning manufacturers from supplying devices with default passwords.

Itโ€™s a significant step in the right direction as far as government support is concerned, but there are plenty of other steps to follow up with. Easy fixes like regular updating of firmware, securing administrative protocols, and fixing bugs promptly are also huge boosts to IoT device security. None require much effort to carry out but will protect IoT devices from being hijacked and folded into these botnets.

Depending on how many IoT devices you have in use within your organisation, these fixes might be a little time-consuming in the moment but could save you a headache down the line. After all, could there be anything worse than being the victim of a botnet-DDoS attack using IoT devices from inside your own organisation?

You might also be interested in the following:

Donny Chong
Donny Chong

Donny Chong is a Product & Marketing Director at Nexusguard, where he's responsible for designing the companyโ€™s solutions for the enterprise segment. He has contributed to TechFinitive under the Opinions section.