Can you secure security?

March 2018 Information Security, Surveillance, Infrastructure

With the rapid expansion of digitisation, the barrier between physical security and network security has disintegrated. Today, almost every security camera or sensor device sold operates on an Ethernet-based wired or wireless network, which means that physical security solutions, like CCTV surveillance systems, are vulnerable to the same types of attacks and exploitations that have plagued data networks for decades. However, because such IP infrastructure brings with it the benefits of high capacity, low-latency performance efficiencies and operational cost-effectiveness, it’s important for manufacturers and integrators to be able to educate and advise their clients on the risks and educate them on the importance of cybersecurity.

Laurence Smith, Executive at Graphic Image Technologies.
Laurence Smith, Executive at Graphic Image Technologies.

This means assisting organisations to secure their physical security network to ensure that the very infrastructure should be protecting business assets is not in fact their biggest vulnerability. This is achieved by treating the physical security infrastructure and devices in the same manner as network infrastructure and devices, which means securing everything, right down to switch level.

A real danger with real consequences

A hacker’s main goal is to find system and device vulnerabilities to exploit them. These vulnerabilities allow a hacker to unleash botnets, Denial of Service (DoS) attacks by acting as an entry-point from which they can launch themselves into the rest of the network. Once they’re inside the network, anything is possible.

Before ‘cybersecurity’ was even a buzzword, in 2008 hackers entered the operational controls of the Baku-Tbilisi-Ceyhan (BTC) oil pipeline (which runs more than 1 000 miles from the Caspian Sea to the Mediterranean) and quietly increased the oil pressure without setting off security alarms, resulting in an explosion on the pipeline near a town in eastern Turkey. Although the incident was declared a mechanical failure by the Turkish government, Bloomberg reported in 2014 that hackers had in fact disabled alarms, cut communications and super-pressurised the crude oil in the line.

How did they do this? By taking down the system of sensors and video cameras that monitored the pipeline in the area, there was no signal of the explosion. In fact, the incident was only called in 40 minutes later when a security worker spotted flames. It was later discovered that the hackers had erased video footage from the last 60 hours before the incident, in order to cover their tracks. It was only thanks to footage from a single offline thermal camera that showed two men with laptop computers walking near the pipeline days before the explosion.

The Internet of Things takeover

Since 2008, technology has advanced tremendously and we are now on the cusp of a total Internet of Things (IoT) assimilation. Everyday devices like door locks and smoke detectors are becoming smarter with the addition of a sensor to capture data and an IP connection over which to transmit this data to other things and people. It was predicted that the IoT market would grow from an installed base of 15.4 billion devices in 2015 to 30.7 billion devices in 2020 and a further 75.4 billion by 2025.

Protecting the physical security network

So how can businesses protect their IP-based security systems from intruders? There are a number of common-sense methods that bear repetition. Any IP-based security system needs network protection and each device must be treated as a possible vulnerability. Organisations should be advised by integrators to use a dedicated network for their clients and servers, to separate security from business-critical networks on top of establishing a secure perimeter with an intelligent firewall.

It is also advisable to research the various network access control solutions created by manufacturers to help protect IP devices against viruses and other malicious software, by sealing hardware and software devices off from outside attacks and isolating them from the rest of the network should they become affected or infected.

Protect those ports

Port protection should be used to establish switches within an organisation’s network, limiting user access to certain network locations. By placing protection at a port level, it becomes possible to quickly allow or block devices. These appliances have display panels that provide network information, such as device IP and MAC addresses, making it possible to identify the port number to which devices are connected as well as authentication status. In the event of an unauthenticated device (such as the two laptops that were used in the Turkish pipeline explosion) an alarm will be triggered in the security management system even if the appliance is turned off. These alarms provide information that allows security operators to take immediate informed action.

While it can be challenging to protect physical infrastructure against network-based exploitation, mercifully the tools, measures, and operational processes that make it possible already exist. Although there is no silver bullet or magical combination of technologies that will provide invulnerability, with a carefully planned security strategy that takes care of the details, right down to switch level, it becomes a lot easier to identify, understand, monitor and contain any potential cybersecurity incidents. By placing security at switch level, it is possible to effectively mitigate the risks present in the physical security infrastructure by remembering that every IP device is no longer just a product or a device – it is a vulnerability and must be treated accordingly



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Hytera supports communication upgrade for Joburg
News & Events Infrastructure Government and Parastatal (Industry)
By equipping Johannesburg’s metro police and emergency services with multimode radios which integrate TETRA and LTE networks, Hytera is bridging coverage gaps and improving response times across the city.

Read more...
Want effective Attack Surface Management? Think like an attacker.
Information Security
Effective ASM requires companies to think like attackers, anticipate risks, and act decisively to reduce exposure by knowing their environment, deploying a structured approach, leveraging capable tools, and addressing both internal and external risks.

Read more...
Your Wi-Fi router is about to start watching you
News & Events Surveillance Security Services & Risk Management
Advanced algorithms are able to analyse your Wi-Fi signals and create a representation of your movements, turning your home's Wi-Fi into a motion detection and personal identification system.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
POPIA non-compliance puts municipalities at risk
Information Security Government and Parastatal (Industry)
Digital responsibility must go beyond POPIA compliance to recognising that privacy and service delivery are fundamentally linked. Despite this, only 51 out of 257 municipalities submitted their mandatory data protection and access to information reports in 2024.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Most wanted malware
News & Events Information Security
Check Point Software Technologies unveiled its Global Threat Index for June 2025, highlighting a surge in new and evolving threats. Eight African countries are among the most targeted as malware leaders AsyncRAT and FakeUpdates expand.

Read more...
IoT-driven smart data to stay ahead
IoT & Automation Infrastructure AI & Data Analytics
In a world where uncertainty is constant, the real competitive edge lies in foresight. Businesses that turn real-time data into proactive strategies will not just survive, they will lead.

Read more...
Hydrogen is green but dangerous
Fire & Safety Infrastructure Power Management
Hydrogen infrastructure is developing quickly, but it comes with safety challenges. Hydrogen is flammable, and its small molecular size means it can leak easily. Additionally, fires caused by hydrogen are nearly invisible, making them difficult to detect and respond to.

Read more...
Welcome to the new cyber battleground
Information Security
The Iran-Israel conflict is rapidly redefining modern warfare, pushing the boundaries of cyber capabilities and creating a new, borderless digital battlefield. Fortinet’s CISO, Dr Carl Windsor, offers a critical, in-depth analysis of the escalating tactics and global implications in his latest report.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.