Overview
"The great power of Internet Of Things comes with the great responsibility of security". Being the hottest technology, the developments and innovations are happening at a stellar speed, but the security of IoT is yet to catch up. Since the safety and security repercussions are serious and at times life threatening, there is no way you can afford to neglect the security of IoT products.
"Practical Internet Of Things Hacking" is a research backed and unique course which offers security professionals, a deep understanding of the core of IoT Technology and the underlying vulnerabilities. The extensive hands-on labs enable attendees to master the art, tools and techniques to find-n-exploit or find-n-fix the vulnerabilities in IoT, not just on emulators but on real smart devices as well.
The course specifically focuses on the security issues and attacks on evolving IoT technologies including widely used IoT protocols and platforms in various domains such as home, enterprise and Industrial Automation. It covers grounds-up on various IoT protocols including internals, specific attack scenarios for individual protocols and open source software / hardware tools one needs to have in their IoT penetration testing arsenal. We also discuss in detail how to attackthe underlying hardware of the sensors and the connected mobile apps using various practical techniques.
Throughout the course, We will use DRONA, a VM created by us specifically for IoT penetration testing. DRONA is the result of our R&D and has most of the equired tools for IoT security analysis. We will also distribute DIVA – IoT, a vulnerable IoT sensor made in-house for hands-on exercises.
The "Practical IoT Hacking" course is aimed at security professionals who want to enhance their skills and move to / specialise in IoT security. The course is tructured for beginner to intermediate level attendees who do not have any experience in IoT, reversing, mobile security or hardware.
Who Should Attend
- Penetration testers tasked with auditing IoT
- Bug hunters who want to find new bugs in IoT products
- Government officials from defensive or offensive units
- Red team members tasked with compromising the IoT infrastructure
- Security professionals who want to build IoT security skills
- Embedded security enthusiasts
- IoT Developers and testers
- Anyone interested in IoT security
Prerequisite Knowledge
- Basic knowledge of web and mobile security
- Basic knowledge of Linux OS
- Basic knowledge of programming (C, python) would be a plus
Hardware / Software Requirements
- Laptop with at least 40 GB free space
- 4+ GB minimum RAM (2+GB for the VM)
- External USB access
- Administrative privileges on the system
- Virtualization software – VirtualBox 5.X
- Linux machines should have exfat-utils and exfat-fuse installed (ex: sudo apt-get install exfat-utils exfat-fuse)
- Virtualization (Vx-t) option enabled in the BIOS settings for virtualbox to work