Can you secure security?

March 2018 Information Security, Surveillance, Infrastructure

With the rapid expansion of digitisation, the barrier between physical security and network security has disintegrated. Today, almost every security camera or sensor device sold operates on an Ethernet-based wired or wireless network, which means that physical security solutions, like CCTV surveillance systems, are vulnerable to the same types of attacks and exploitations that have plagued data networks for decades. However, because such IP infrastructure brings with it the benefits of high capacity, low-latency performance efficiencies and operational cost-effectiveness, it’s important for manufacturers and integrators to be able to educate and advise their clients on the risks and educate them on the importance of cybersecurity.

Laurence Smith, Executive at Graphic Image Technologies.
Laurence Smith, Executive at Graphic Image Technologies.

This means assisting organisations to secure their physical security network to ensure that the very infrastructure should be protecting business assets is not in fact their biggest vulnerability. This is achieved by treating the physical security infrastructure and devices in the same manner as network infrastructure and devices, which means securing everything, right down to switch level.

A real danger with real consequences

A hacker’s main goal is to find system and device vulnerabilities to exploit them. These vulnerabilities allow a hacker to unleash botnets, Denial of Service (DoS) attacks by acting as an entry-point from which they can launch themselves into the rest of the network. Once they’re inside the network, anything is possible.

Before ‘cybersecurity’ was even a buzzword, in 2008 hackers entered the operational controls of the Baku-Tbilisi-Ceyhan (BTC) oil pipeline (which runs more than 1 000 miles from the Caspian Sea to the Mediterranean) and quietly increased the oil pressure without setting off security alarms, resulting in an explosion on the pipeline near a town in eastern Turkey. Although the incident was declared a mechanical failure by the Turkish government, Bloomberg reported in 2014 that hackers had in fact disabled alarms, cut communications and super-pressurised the crude oil in the line.

How did they do this? By taking down the system of sensors and video cameras that monitored the pipeline in the area, there was no signal of the explosion. In fact, the incident was only called in 40 minutes later when a security worker spotted flames. It was later discovered that the hackers had erased video footage from the last 60 hours before the incident, in order to cover their tracks. It was only thanks to footage from a single offline thermal camera that showed two men with laptop computers walking near the pipeline days before the explosion.

The Internet of Things takeover

Since 2008, technology has advanced tremendously and we are now on the cusp of a total Internet of Things (IoT) assimilation. Everyday devices like door locks and smoke detectors are becoming smarter with the addition of a sensor to capture data and an IP connection over which to transmit this data to other things and people. It was predicted that the IoT market would grow from an installed base of 15.4 billion devices in 2015 to 30.7 billion devices in 2020 and a further 75.4 billion by 2025.

Protecting the physical security network

So how can businesses protect their IP-based security systems from intruders? There are a number of common-sense methods that bear repetition. Any IP-based security system needs network protection and each device must be treated as a possible vulnerability. Organisations should be advised by integrators to use a dedicated network for their clients and servers, to separate security from business-critical networks on top of establishing a secure perimeter with an intelligent firewall.

It is also advisable to research the various network access control solutions created by manufacturers to help protect IP devices against viruses and other malicious software, by sealing hardware and software devices off from outside attacks and isolating them from the rest of the network should they become affected or infected.

Protect those ports

Port protection should be used to establish switches within an organisation’s network, limiting user access to certain network locations. By placing protection at a port level, it becomes possible to quickly allow or block devices. These appliances have display panels that provide network information, such as device IP and MAC addresses, making it possible to identify the port number to which devices are connected as well as authentication status. In the event of an unauthenticated device (such as the two laptops that were used in the Turkish pipeline explosion) an alarm will be triggered in the security management system even if the appliance is turned off. These alarms provide information that allows security operators to take immediate informed action.

While it can be challenging to protect physical infrastructure against network-based exploitation, mercifully the tools, measures, and operational processes that make it possible already exist. Although there is no silver bullet or magical combination of technologies that will provide invulnerability, with a carefully planned security strategy that takes care of the details, right down to switch level, it becomes a lot easier to identify, understand, monitor and contain any potential cybersecurity incidents. By placing security at switch level, it is possible to effectively mitigate the risks present in the physical security infrastructure by remembering that every IP device is no longer just a product or a device – it is a vulnerability and must be treated accordingly



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Genetec global leader in video management software
Genetec News & Events Surveillance
Independent analyst firms rank Genetec as global leader in video management software. Research shows continued market share gains for Genetec as both the VMS and VSaaS markets continue to expand worldwide.

Read more...
DeepAlert Launches COMMAND
News & Events Surveillance
Cloud-based, AI-powered surveillance monitoring platform cuts operator alert fatigue and response times, and becomes DeepAlert's primary monitoring platform for security companies and control rooms worldwide.

Read more...
Security has an identity problem
Access Control & Identity Management Information Security
Cybersecurity discussions have mainly focused on defence, including stronger firewalls, tighter network controls, and better endpoint security. However, in today's world, those traditional defences have become less relevant.

Read more...
Buying more security tools is not building a defence
Information Security
Sophisticated attacks are specifically engineered to bypass individual security tools, and companies absorbing the damage are those who have confused procurement with protection, says Richard Frost from Armata Cyber Security.

Read more...
Retailers expanding physical security beyond loss prevention
Genetec Facilities & Building Management Surveillance Retail (Industry)
Genetec released retail-specific findings from its 2026 State of Physical Security Report. The research shows retailers increasingly view physical security as a business function that supports operations, employee safety, and modernisation efforts.

Read more...
Modernising ‘smart’ ports
IoT & Automation Information Security Transport (Industry) Logistics (Industry)
A modern port is part of a much larger digital trade ecosystem where all systems need to work together. If one part of that ecosystem is disrupted, the impact can quickly move through the supply chain.

Read more...
Integrating the industry
News & Events Infrastructure
With private security, neighbourhood watches, CCTV, drones, control rooms and community safety networks expanding across the country, the next frontier may not be more technology, but connecting what already exists.

Read more...
Reinventing cybersecurity
NEC XON News & Events Information Security Commercial (Industry)
NEC XON helps a workforce solutions leader reinvent cybersecurity with an AI-enhanced XDR solution to keep pace with increasingly devious cyberattack techniques, including fileless malware, lateral movement, and credential misuse.

Read more...
Hold the line
BlueVision Information Security Editor's Choice
While most businesses are still focused on guarding the wall, the perimeter today has moved to the login screen, according to Christo Coetzer, founder and managing director of BlueVision Technologies.

Read more...
Attackers are turning AI to their advantage
Information Security AI & Data Analytics
ESET's H1 2026 Threat Report analysed around 900 000 AI skills and found more than 3000 to be outright malicious, exposing a fast-growing attack surface for organisations experimenting with AI.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.