Business

search close
  • Solutions
    • By Challenge
      • By Challenge
        • By Challenge
          Learn more
      • Understand, Prioritize & Mitigate Risks
        • Understand, Prioritize & Mitigate Risks

          Improve your risk posture with attack surface management

          Learn more
      • Protect Cloud-Native Apps
        • Protect Cloud-Native Apps

          Security that enables business outcomes

          Learn more
      • Protect Your Hybrid World
        • Protect Your Hybrid, Multi-Cloud World

          Gain visibility and meet business needs with security

          Learn more
      • Securing Your Borderless Workforce
        • Securing Your Borderless Workforce

          Connect with confidence from anywhere, on any device

          Learn more
      • Eliminate Network Blind Spots
        • Eliminate Network Blind Spots

          Secure users and key operations throughout your environment

          Learn more
      • See More. Respond Faster.
        • See More. Respond Faster.

          Move faster than your adversaries with powerful purpose-built XDR, attack surface risk management, and zero trust capabilities

          Learn more
      • Extend Your Team
        • Extend Your Team. Respond to Threats Agilely

          Maximize effectiveness with proactive risk reduction and managed services

          Learn more
      • Operationalizing Zero Trust
        • Operationalizing Zero Trust

          Understand your attack surface, assess your risk in real time, and adjust policies across network, workloads, and devices from a single console

          Learn more
    • By Role
      • By Role
        • By Role
          Learn more
      • CISO
        • CISO

          Drive business value with measurable cybersecurity outcomes

          Learn more
      • SOC Manager
        • SOC Manager

          See more, act faster

          Learn more
      • Infrastructure Manager
        • Infrastructure Manager

          Evolve your security to mitigate threats quickly and effectively

          Learn more
      • Cloud Builder and Developer
        • Cloud Builder and Developer

          Ensure code runs only as intended

          Learn more
      • Cloud Security Ops
        • Cloud Security Ops

          Gain visibility and control with security designed for cloud environments

          Learn more
    • By Industry
      • By Industry
        • By Industry
          Learn more
      • Healthcare
        • Healthcare

          Protect patient data, devices, and networks while meeting regulations

          Learn more
      • Manufacturing
        • Manufacturing

          Protecting your factory environments – from traditional devices to state-of-the-art infrastructures

          Learn more
      • Oil & Gas
        • Oil & Gas

          ICS/OT Security for the oil and gas utility industry

          Learn more
      • Electric Utility
        • Electric Utility

          ICS/OT Security for the electric utility

          Learn more
      • Automotive
        • Automotive
          Learn more
      • 5G Networks
        • 5G Networks
          Learn more
    • Small & Midsized Business Security
      • Small & Midsized Business Security

        Stop threats with easy-to-use solutions designed for your growing business

        Learn more
  • Platform
    • Vision One Platform
      • Vision One Platform
        • Trend Vision One
          Our Unified Platform

          Bridge threat protection and cyber risk management

          Learn more
      • AI Companion
        • Trend Vision One Companion

          Your generative AI cybersecurity assistant

          Learn more
    • Attack Surface Management
      • Attack Surface Management

        Stop breaches before they happen

        Learn more
    • XDR (Extended Detection & Response)
      • XDR (Extended Detection & Response)

        Stop adversaries faster with a broader perspective and better context to hunt, detect, investigate, and respond to threats from a single platform

        Learn more
    • Cloud Security
      • Cloud Security
        • Trend Vision One™
          Cloud Security Overview

          The most trusted cloud security platform for developers, security teams, and businesses

          Learn more
      • Attack Surface Risk Management for Cloud
        • Attack Surface Risk Management for Cloud

          Cloud asset discovery, vulnerability prioritization, Cloud Security Posture Management, and Attack Surface Management all in one

          Learn more
      • XDR for Cloud
        • XDR for Cloud

          Extend visibility to the cloud and streamline SOC investigations

          Learn more
      • Workload Security
        • Workload Security

          Secure your data center, cloud, and containers without compromising performance by leveraging a cloud security platform with CNAPP capabilities

          Learn more
      • Container Security
        • Container Security

          Simplify security for your cloud-native applications with advanced container image scanning, policy-based admission control, and container runtime protection

          Learn more
      • File Security
        • File Security

          Protect application workflow and cloud storage against advanced threats

          Learn more
    • Endpoint Security
      • Endpoint Security
        • Endpoint Security Overview

          Defend the endpoint through every stage of an attack

          Learn more
      • XDR for Endpoint
        • XDR for Endpoint

          Stop adversaries faster with a broader perspective and better context to hunt, detect, investigate, and respond to threats from a single platform

          Learn more
      • Workload Security
        • Workload Security

          Optimized prevention, detection, and response for endpoints, servers, and cloud workloads

          Learn more
      • Industrial Endpoint Security
        • Industrial Endpoint Security
          Learn more
      • Mobile Security
        • Mobile Security

          On-premises and cloud protection against malware, malicious applications, and other mobile threats

          Learn more
    • Network Security
      • Network Security
        • Network Security Overview

          Expand the power of XDR with network detection and response

          Learn more
      • XDR for Network
        • XDR for Network

          Stop adversaries faster with a broader perspective and better context to hunt, detect, investigate, and respond to threats from a single platform

          Learn more
      • Network Intrusion Prevention (IPS)
        • Network Intrusion Prevention (IPS)

          Protect against known, unknown, and undisclosed vulnerabilities in your network

          Learn more
      • Breach Detection System (BDS)
        • Breach Detection System (BDS)

          Detect and respond to targeted attacks moving inbound, outbound, and laterally

          Learn more
      • Secure Service Edge (SSE)
        • Secure Service Edge (SSE)

          Redefine trust and secure digital transformation with continuous risk assessments

          Learn more
      • Industrial Network Security
        • Industrial Network Security
          Learn more
      • 5G Network Security
        • 5G Network Security
          Learn more
    • Email Security
      • Email Security
        • Email Security

          Stop phishing, malware, ransomware, fraud, and targeted attacks from infiltrating your enterprise

          Learn more
      • Email and Collaboration Security
        • Trend Vision One™
          Email and Collaboration Security

          Stop phishing, ransomware, and targeted attacks on any email service including Microsoft 365 and Google Workspace

          Learn more
    • OT Security
      • OT Security
        • OT Security

          Learn about solutions for ICS / OT security.

          Learn more
      • XDR for OT
        • XDR for OT

          Stop adversaries faster with a broader perspective and better context to hunt, detect, investigate, and respond to threats from a single platform

          Learn more
      • Industrial Endpoint Security
        • Industrial Endpoint Security
          Learn more
      • Industrial Network Security
        • Industrial Network Security
          Industrial Network Security
    • Threat Insights
      • Threat Insights

        See threats coming from miles away

        Learn more
    • Identity Security
      • Identity Security

        End-to-end identity security from identity posture management to detection and response

        Learn more
    • All Products, Services, and Trials
      • All Products, Services, and Trials
        Learn more
    • On-Premises Data Sovereignty
      • On-Premises Data Sovereignty

        Prevent, detect, respond and protect without compromising data sovereignty

        Learn more
  • Research
    • Research
      • Research
        • Research
          Learn more
      • Research, News, and Perspectives
        • Research, News, and Perspectives
          Learn more
      • Research and Analysis
        • Research and Analysis
          Learn more
      • Security News
        • Security News
          Learn more
      • Zero Day Initiatives (ZDI)
        • Zero Day Initiatives (ZDI)
          Learn more
  • Services
    • Our Services
      • Our Services
        • Our Services
          Learn more
      • Service Packages
        • Service Packages

          Augment security teams with 24/7/365 managed detection, response, and support

          Learn more
      • Managed XDR
        • Managed XDR

          Augment threat detection with expertly managed detection and response (MDR) for email, endpoints, servers, cloud workloads, and networks

          Learn more
      • Incident Response
        • Incident Response
          • Incident Response

            Our trusted experts are on call whether you're experiencing a breach or looking to proactively improve your IR plans

            Learn more
        • Insurance Carriers and Law Firms
          • Insurance Carriers and Law Firms

            Stop breaches with the best response and detection technology on the market and reduce clients’ downtime and claim costs

            Learn more
      • Support Services
        • Support Services
          Learn more
  • Partners
    • Partner Program
      • Partner Program
        • Partner Program Overview

          Grow your business and protect your customers with the best-in-class complete, multilayered security

          Learn more
      • Partner Competencies
        • Partner Competencies

          Stand out to customers with competency endorsements that showcase your expertise

          Learn more
      • Partner Successes
        • Partner Successes
          Learn more
      • Managed Security Service Provider
        • Managed Security Service Provider

          Deliver modern security operations services with our industry-leading XDR

          Learn more
      • Managed Service Provider
        • Managed Service Provider

          Partner with a leading expert in cybersecurity, leverage proven solutions designed for MSPs

          Learn more
    • Alliance Partners
      • Alliance Partners
        • Alliance Partners

          We work with the best to help you optimize performance and value

          Learn more
      • Technology Alliance Partners
        • Technology Alliance Partners
          Learn more
      • Find Alliance Partners
        • Find Alliance Partners
          Learn more
    • Partner Resources
      • Partner Resources
        • Partner Resources

          Discover resources designed to accelerate your business’s growth and enhance your capabilities as a Trend Micro partner

          Learn more
      • Partner Portal Login
        • Partner Portal Login
          Login
      • Trend Campus
        • Trend Campus

          Accelerate your learning with Trend Campus, an easy-to-use education platform that offers personalized technical guidance

          Learn more
      • Co-Selling
        • Co-Selling

          Access collaborative services designed to help you showcase the value of Trend Vision One™ and grow your business

          Learn more
      • Become a Partner
        • Become a Partner
          Learn more
      • Distributors
        • Distributors
          Learn more
    • Find Partners
      • Find Partners

        Locate a partner from whom you can purchase Trend Micro solutions

        Learn more
  • Company
    • Why Trend Micro
      • Why Trend Micro
        • Why Trend Micro
          Learn more
      • Customer Success Stories
        • Customer Success Stories
          Learn more
      • The Human Connection
        • The Human Connection
          Learn more
      • Industry Accolades
        • Industry Accolades
          Learn more
      • Strategic Alliances
        • Strategic Alliances
          Learn more
    • Compare Trend Micro
      • Compare Trend Micro
        • Compare Trend Micro

          See how Trend outperforms the competition

          Let's go
      • vs. Crowdstrike
        • Trend Micro vs. Crowdstrike

          Crowdstrike provides effective cybersecurity through its cloud-native platform, but its pricing may stretch budgets, especially for organizations seeking cost-effective scalability through a true single platform

          Let's go
      • vs. Microsoft
        • Trend Micro vs. Microsoft

          Microsoft offers a foundational layer of protection, yet it often requires supplemental solutions to fully address customers' security problems

          Let's go
      • vs. Palo Alto Networks
        • Trend Micro vs. Palo Alto Networks

          Palo Alto Networks delivers advanced cybersecurity solutions, but navigating its comprehensive suite can be complex and unlocking all capabilities requires significant investment

          Let's go
    • About Us
      • About Us
        • About Us
          Learn more
      • Trust Center
        • Trust Center
          Learn more
      • History
        • History
          Learn more
      • Diversity, Equity and Inclusion
        • Diversity, Equity and Inclusion
          Learn more
      • Corporate Social Responsibility
        • Corporate Social Responsibility
          Learn more
      • Leadership
        • Leadership
          Learn more
      • Security Experts
        • Security Experts
          Learn more
      • Internet Safety and Cybersecurity Education
        • Internet Safety and Cybersecurity Education
          Learn more
      • Investors
        • Investors
          Learn more
      • Legal
        • Legal
          Learn more
      • Formula E Racing
        • Formula E Racing
          Learn more
    • Connect With Us
      • Connect With Us
        • Connect With Us
          Learn more
      • Newsroom
        • Newsroom
          Learn more
      • Events
        • Events
          Learn more
      • Careers
        • Careers
          Learn more
      • Webinars
        • Webinars
          Learn more
  • Free Trials
  • Contact Us
Looking for home solutions?
Under Attack?
Support
  • Business Support Portal
  • Education and Certification
  • Contact Support
  • Find a Support Partner
Resources
  • AI Security
  • Trend Micro vs. Competition
  • Cyber Risk Index/Assessment
  • What Is?
  • Threat Encyclopedia
  • Cyber Insurance
  • Glossary of Terms
  • Webinars
Log In
  • Vision One
  • Support
  • Partner Portal
  • Cloud One
  • Product Activation and Management
  • Referral Affiliate
arrow_back
search
close
  • Security News
  • Internet of Things
  • Inside the Smart Home: IoT Device Threats and Attack Scenarios

Inside the Smart Home: IoT Device Threats and Attack Scenarios

July 30, 2019
  • Email
  • Facebook
  • Twitter
  • Google+
  • Linkedin
The different threat scenarios that can happen to a smart home illustrate that compromised IoT devices can affect not just users' comfort and convenience but also their safety.

Download IoT Device Security: Locking Out Risks and Threats to Smart Homes Download IoT Device Security: Locking Out Risks and Threats to Smart Homes

By Ziv Chang, Trend Micro Research

A smart home is made up of a number of different devices connected to the internet of things (IoT), each with a specific set of functions. No matter how different these devices are from one another, they have the shared goal of streamlining the tasks and simplifying the lives of their users. Together they paint an enticing image of comfort and convenience. However, just as these devices have revolutionized home living, they have also given rise to new complications for home security.

We detail different smart home attack scenarios and discuss the different attack layers of IoT devices in our paper, "IoT Device Security: Locking Out Risks and Threats to Smart Homes." Here we give an overview of the possible attack scenarios for various smart home devices and suggest security solutions.

Inside a smart home

A smart home gives users extensive access to many aspects of their home, even from a remote location. For example, users can monitor their home in real time through a mobile app or web interface. They can also initiate certain actions remotely, such as communicating with their children using a smart toy or unlocking a smart lock for a trusted friend.

Smart home devices also provide automatic and chained functions that can make day-to-day living more convenient for users. For example, in the morning the smart coffee maker starts brewing before the users need to get up for work. Once the users are in the kitchen, the smart refrigerator alerts them that they are low on supplies, if it has not yet ordered the needed items. As the users go out the door, the smart lock automatically locks behind them. And now that the house is empty, the smart robot vacuum cleaner starts its scheduled cleaning.

This scenario and plenty of others are possible if users have good control and visibility over the deployed devices in their smart homes. But problems arise if this control and visibility, unbeknown to the users, shift to malicious actors.

Compromised devices in a smart home

Existing vulnerabilities, poor configuration, and the use of default passwords are among the factors that can aid a hacker in compromising at least one device in a smart home system. Once a single device is compromised, hackers can take a number of actions based on the capabilities and functions of the device. We illustrate some of them here.

Starting from the front door, there can be a smart lock. If compromised, the smart lock can give hackers control over who comes in or out of the house. The most obvious action available for hackers, then, would be to let intruders or accomplices in to the house, and another would be to lock out the actual residents.

Inside the living room, several other devices can be set up. One of these can be a smart speaker, which serves as the conduit for voice-initiated home automation commands. If compromised, a voice-activated device such as a smart speaker can allow hackers to issue voice commands of their own.

In the kitchen, devices like a smart refrigerator and a smart coffee maker can cause major issues if successfully hacked. Hackers can set up a smart refrigerator to register wrong expiration dates or order an immense amount of groceries online. And even a smart coffee maker can cause great inconvenience if commanded by hackers to brew coffee incessantly.

Smart devices can now also be found even in the bathroom, most commonly in the form of smart toilets. A smart toilet has different features, such as sensing the right amount of water for flushing waste, that can be very helpful for users. But hackers can use some of its features to make the device act up, by making the toilet flush repeatedly or let water flow continuously from the bidet.

Hover overTap warning sign for more info.

!!!!!!!!!!!!

Specific members of the household can also be targeted depending on the device being compromised. In the case of children, compromised smart toys pose a particular risk. Hackers can, for example, communicate with the child directly or quietly record the child’s activities using the toy. Vulnerable smart toys illustrate how even items that are safe enough for child use can still cause harm if compromised.

Smart bulbs can be installed all around the house, from the basement to the attic. They can be turned on or off depending on the time of day or amount of movement or ambient light detected. But hackers can use these seemingly simple devices to disturb residents, by switching them on at inconvenient times, among other actions.

Devices like smart robot vacuum cleaners, which have some mobility around the house, can provide hackers information about the home’s layout. This information can be used by the hackers in planning further activities and movements.

The point where smart devices are connected can also prove useful for hackers. Hackers can use the home gateway to redirect or modify connections to their advantage. This demonstrates that anything connected to the smart home network can be as useful to a resourceful hacker as it is to the actual owner.

Outside a smart home

Although our discussion of compromise and its consequences has centered on smart homes, the same problems can exist anywhere vulnerable or misconfigured devices are deployed. The consequences of a successful attack on a particular IoT system depend on the kind of environment the system is used for.

Many, if not all, of the devices mentioned above can easily be seen in an enterprise setting. An office pantry or break room, for example, can contain a smart refrigerator and a smart coffee maker. And smart bulbs certainly will not be out of place in an enterprise, especially as they can help the business conserve energy if deployed on a large scale.

Portable and wearable smart devices add another layer of complexity to IoT security concerns, as these devices traverse both enterprise and home environments, and have even given rise to updates on many companies’ “bring your own device” (BYOD) policies. These devices, such as smartwatches and smart yoga mats, are typically brought by users to the office, and then brought back home at the end of the work day. A malware infection picked up in one environment, for example, can spread to the other if the BYOD policies in place are weak or if adequate security measures are not taken to prevent such a threat.

Securing smart devices

More than showing what hackers can do with smart devices, these scenarios show how deeply the IoT has become integrated in people’s lives. This is apparent in how there is an applicable IoT device for every part of a home, from the living room and the kitchen to the bathroom and the attic. This deep involvement in people’s lives is what makes IoT attacks both viable for hackers and impactful for users. Arguably, nowhere have cyberthreats been more potentially invasive and personal than in smart homes.

It is all the more reason, then, for users to secure the IoT devices in their smart homes. Here are some security measures that users can take to protect and defend their smart homes against attacks on IoT devices:

  • Map all connected devices. All devices connected to the network, whether at home or at the enterprise level, should be well accounted for. Their settings, credentials, firmware versions, and recent patches should be noted. This step can help assess which security measures the users should take and pinpoint which devices may have to be replaced or updated.
  • Change default passwords and settings. Make sure that the settings used by each device are aligned toward stronger security, and change the settings if this is not the case. Change default and weak passwords to avoid attacks like brute force and unwanted access.
  • Patch vulnerabilities. Patching may be a challenging task, especially for enterprises. But it is integral to apply patches as soon as they are released. For some users, patches may disrupt their regular processes, for which virtual patching could be an option.
  • Apply network segmentation. Use network segmentation to prevent the spread of attacks, and isolate possibly problematic devices that cannot be immediately taken offline.

Read our paper, “IoT Device Security: Locking Out Risks and Threats to Smart Homes,” for more on this topic, including descriptions of other attack scenarios, a discussion of the different attack layers of an IoT device, and further security steps users can follow to keep their smart homes safe.


HIDE

Like it? Add this infographic to your site:
1. Click on the box below.   2. Press Ctrl+A to select all.   3. Press Ctrl+C to copy.   4. Paste the code into your page (Ctrl+V).

Image will appear the same size as you see above.

Posted in Internet of Things, Research, Vulnerabilities, Exploits, Device Management

Related Posts

  • Cellular IoT Vulnerabilities: Another Door to Cellular Networks
  • UNWIRED: Understanding the Unforeseen Risks in Evolving Communication Channels
  • Pushing the Outer Limits: Trend Micro 2024 Midyear Cybersecurity Threat Report
  • Today’s Cloud and Container Misconfigurations Are Tomorrow’s Critical Vulnerabilities
  • Kong API Gateway Misconfigurations: An API Gateway Security Case Study

Recent Posts

  • Unveiling AI Agent Vulnerabilities Part II: Code Execution
  • Unveiling AI Agent Vulnerabilities Part I: Introduction to AI Agent Vulnerabilities
  • The Ever-Evolving Threat of the Russian-Speaking Cybercriminal Underground
  • From Registries to Private Networks: Threat Scenarios Putting Organizations in Jeopardy
  • Trend 2025 Cyber Risk Report

We Recommend

  • Internet of Things
  • Virtualization & Cloud
  • Ransomware
  • Security Technology
  • Cellular IoT Vulnerabilities: Another Door to Cellular Networks
    • UNWIRED: Understanding the Unforeseen Risks in Evolving Communication Channels
    • MQTT and M2M: Do You Know Who Owns Your Machine’s Data?
  • AI in the Crosshairs: Understanding and Detecting Attacks on AWS AI Services with Trend Vision One™
    • Today’s Cloud and Container Misconfigurations Are Tomorrow’s Critical Vulnerabilities
    • Uncover Cloud Attacks with Trend Vision One and CloudTrail
  • Trend 2025 Cyber Risk Report
    • Ransomware Spotlight: Ransomhub
    • From Vulnerable to Resilient: Cutting Ransomware Risk with Proactive Cyber Risk Exposure Management
  • CES 2025: A Comprehensive Look at AI Digital Assistants and Their Security Risks
    • AI Assistants in the Future: Security Concerns and Risk Management
    • The Realities of Quantum Machine Learning

2025 Trend Micro Cyber Risk Report

2025 Trend Micro Cyber Risk Report

View the report

The Easy Way In/Out: Securing The Artificial Future, Trend Micro Security Predictions for 2025

2025 Trend Micro Security Predictions

View the 2025 Trend Micro Security Predictions

Try our services free for 30 days

  • Start your free trial today

Resources

  • Blog
  • Newsroom
  • Threat Reports
  • Find a Partner

Support

  • Business Support Portal
  • Contact Us
  • Downloads
  • Free Trials

About Trend

  • About Us
  • Careers
  • Locations
  • Upcoming Events
  • Trust Center

Country Headquarters

Trend Micro - Philippines (PH)

8/F The Rockwell Business
Center Tower 2 Ortigas Avenue
Pasig City, Metro Manila
Philippines 1600

Phone: +632 8540 0933

Select a country / region

close

The Americas

  • United States
  • Brasil
  • Canada
  • México

Middle East & Africa

  • South Africa
  • Middle East and North Africa

Europe

  • België (Belgium)
  • Česká Republika
  • Danmark
  • Deutschland, Österreich Schweiz
  • España
  • France
  • Ireland
  • Italia
  • Nederland
  • Norge (Norway)
  • Polska (Poland)
  • Suomi (Finland)
  • Sverige (Sweden)
  • Türkiye (Turkey)
  • United Kingdom

Asia & Pacific

  • Australia
  • Центральная Азия (Central Asia)
  • Hong Kong (English)
  • 香港 (中文) (Hong Kong)
  • भारत गणराज्य (India)
  • Indonesia
  • 日本 (Japan)
  • 대한민국 (South Korea)
  • Malaysia
  • Монголия (Mongolia) and рузия (Georgia)
  • New Zealand
  • Philippines
  • Singapore
  • 台灣 (Taiwan)
  • ประเทศไทย (Thailand)
  • Việt Nam

Privacy | Legal | Accessibility | Site map

Copyright ©2024 Trend Micro Incorporated. All rights reserved