80 likes | 184 Views
Protecting Embedded Devices from Internet Threats. Company Overview. Founded in 1992 Device Protection Floodgate Packet Filter – Embedded Firewall Floodgate SNMP Secure Access Iconfidant SSH Iconfidant SSL Network Management Envoy SNMP Custom software design & implementation.
E N D
Company Overview • Founded in 1992 • Device Protection • Floodgate Packet Filter – Embedded Firewall • Floodgate SNMP • Secure Access • Iconfidant SSH • Iconfidant SSL • Network Management • Envoy SNMP • Custom software design & implementation
Growing Threat for Embedded Devices • Hacking drones constantly scan Internet connected devices looking for vulnerabilities • Reported incidents • Electronic road signs reprogrammed by hackers • Electronic billboard reprogrammed to display adult content • Sewage spill caused by comprised control system • Packet flood/DoS attacks growing sharply* • 102% increase in attacks from 2009-2010 • 1000% increase in attacks from 2005-2010 * Arbor Networks Security Report, 2010
Growing Threat for Embedded Devices • Three main threats for embedded devices • Data security • Unauthorized access of the data on the device • Intercepting communications with the device • Device security • Someone actually hacking into and taking control of the device • DoS attacks • Packet floods or other attacks disable or disrupt device function
A Brief History of Device Security • Phase 1: Embedded systems lack security • Devices wide open to Internet attacks • Communication to devices easy to intercept • Phase 2: Encryption • Secures communication & access to the device • Still vulnerable to DoS attacks • Phase 3: Secure, protected devices • Embedded firewall for complete device protection • Control what packets are processed • Protect against DoS attacks
Device Security • Floodgate Packet Filter – portable embedded firewall • Protects embedded systems for DoS attacks • Layer based callbacks allow easy integration with any embedded device • Supports any embedded OS • Unique two stage filtering engine for greater protection and control • Rules-based filtering – controls what packets are processed • Threshold-based filtering protects from DoS attacks • Configurable/customizable for any application
Floodgate Operation Layer-based callbacks allow Floodgate to be easily inserted at any layer in the network stack Two stage filtering engine provides greater control of what packets are processed by the embedded device.
Contact us for a trial Icon Labs 3636 Westown Pkwy, Suite 203 West Des Moines, IA 50266 info@icon-labs.com www.icon-labs.com 515-226-3443