Skip to main content

Securing internet infrastructure in the age of zero-day exploits

Frequent incidents underscore the critical importance of designing devices with security in mind.

November 23, 2023
Aline Rivas, Head of Content & Social Media

On 16 October 2023, a hacker identified a vulnerability in the GUI in a major network manufactures software, adding to the already long list of major network and firewall equipment vulnerabilities active at scale. Within a single day, the number of compromised devices of the entity reached approximately 40,000. A second zero-day exploit was discovered on October 20th, escalating the total count of affected devices to an alarming 60,000.

Incidents like these underscore the critical importance of designing devices with security in mind and are quickly becoming a focal point in discussions as well as being emphasised by the Australian Cyber Security Centre (ACSC).

How are standalone network devices exploited?

Manufacturers often ship devices with a default configuration aimed at balancing security and functionality. Typically, this configuration minimises exposure to security vulnerabilities by closing most ports by default, leaving only those essential for device management and crucial functions open.

However, these open ports often include those used for management interfaces like SSH, Telnet, or HTTP/HTTPS. The responsibility then falls on the customer to either harden these ports or enable secure management options that eliminate their exposure to the internet or other networks.

To enhance security further, these devices can connect to additional authentication systems such as RADIUS and TACACS, which customers may need to set up and manage, adding another layer of complexity.

Modern alternatives for device security

If you are concerned about the security of your corporate networks protected by these kinds of devices, there are modern alternatives that can either augment or replace them.

Cloud-native networking and security solutions operate on the internet and adopt an internet-centric approach to security. Many of these solutions offer features like 'call home securely,' device authentication, and integrated certificate authorities. Access to these devices is often restricted and managed through a centralised controller or cloud-based user interface that includes multiple layers of security measures such as Single Sign-On (SSO) and authorisation mechanisms.

Effectively, these systems can 'hide' your internet-exposed devices from prying eyes. These platforms are tailor-made for the cloud-native world we currently inhabit.

How do hackers find devices on the internet?

One of the first things hackers do is conduct internet reconnaissance, scouring the web for easy entry points such as devices with open ports, unsecured systems, and vulnerable servers. They use common tools and exploits to target and infiltrate these systems.

Many of these tools are publicly accessible services that are extremely useful for seeing the world from a hacker’s point of view. Shodan.io is a great tool for viewing exposed internet infrastructure, including your own, while FullHunt.io provides insights into the attack surface of web domains and applications. However, these tools are a double-edged sword; they are as useful to customers and organisations as they are to individuals with nefarious purposes.

A simple example

Running a Shodan search for "IOS XE," revealing the IOS XE devices currently visible on the internet. Some of these networks are Service Provider networks – either SP Internet Routers which have not been hardened/misconfigured or customer routers.

The below image is an example of the Shodan search: The data reveals that over 1,700 devices remain visible on the internet as of late October 2023.

What can you do to ensure that your companies’ internet infrastructure footprint is minimised?

Understand your attack surface: Identify which elements of your company's infrastructure and services are exposed to the internet.

  • While tools like Shodan provide initial insights into what is accessible online, organisations require a more in-depth approach. This is where penetration (PEN) tests and vulnerability scans prove highly effective.

  • Utilise dark web monitoring to discover leaked credentials and vulnerabilities in third-party supply chain email domains.

Conduct penetration tests and act on test outcomes:
Penetration Tests are an important cybersecurity technique to evaluate the security of computer systems, networks, or applications inside and outside the organisation. These tests simulate an attack from malicious external threats. It aims to identify and exploit vulnerabilities to understand potential risks and improve security measures.

  • Reduce your attack surface based on the findings.

  • Remediate any vulnerabilities and secure risky assets.

Plan for attack surface regular scans:

  • The threat landscape is constantly evolving, making it essential to budget for and plan regular vulnerability scans.

  • Regular scans provide critical information on the size and health of your attack surface including potential gaps. Closing and remediating these gaps quickly is essential.

Automation with manual testing:

  • Opt for testing that integrates both automated and manual techniques.

  • Include automated attack surface scanning to assess the entire environment.

  • Work with supply chain partners to scan their environment and understand 3rd party risk.

  • While automation is effective for routinely scanning broad attack surfaces, human intervention is crucial when specific issues are identified.

Patch, patch, patch

  • Develop a rigorous and frequent patching schedule.

  • Develop a “instant response” approach for Common Vulnerabilities and Exposures that have CVSS (scoring of CVE) of Critical (9-10).

The recent discovery of vulnerabilities in the entity’s IOS XE software highlights the critical need for robust cybersecurity measures. Within a short span, these vulnerabilities led to the compromise of 60,000 devices, emphasising the urgency of secure-by-design principles. Organisations must understand their "Attack Surface" and employ both automated and manual penetration testing for comprehensive security.

Modern solutions, such as cloud-native networking and security offerings, can offer better protection by operating on an internet-centric approach, requiring stringent device authentication and multiple layers of security. Superloop's semi-autonomous subscription for regular Penetration Testing, coupled with security automation and human oversight, can greatly help in minimising cyber risk and the likelihood of potential intrusions.

Get started today

We all know that security automation is a key to staying ahead of cyber threats. Superloop has created a semi-autonomous subscription to Penetration Testing that can be run regularly from every week to twice a year.

Contact our Cyber Security team today to find out how you can combine security automation and human oversight to provide maximum protection.

Written by

Aline Rivas
Head of Content & Social Media

I've spent the last 4 years at Superloop making complex telco topics genuinely easy to read, driven by a mission to help challenger telcos take on the big guys.

Related articles

Our key takeaways from the OAIC annual report on the Notifiable Data Breaches (NDB).

August 20, 2019

As more organisations turn to cloud-based apps, they increasingly collide with cost and complexity around network management and security. Enter: SASE.

September 19, 2021

Learn how IT departments can encourage better password practices from their users and clients.

May 7, 2018

Refresh your internet

Type to show suggested addresses. Use the up and down arrow keys to move through the list, Enter to select an address, and Escape to close the listbox.