CABLE360     CABLEFAX MAGAZINE     CABLEFAX DAILY  
AdvertiseSubscribe
Connect with us CT Chatter twitter RSS
 
                       
Products: CT Reports | Tech E-letters | Webcasts | Videos | Jobs

March 1, 2010

Reality Check: How Secure are Modems?

The two biggest challenges to cable modem security lie in protecting the operator from service theft and protecting the consumers from cyber attacks. Both weaknesses tend to fly under the radar screen.

"Security management is one of those things that tend not to get a lot of attention because it does not bring in any revenue," Scott Helms, vice president of technology at Zcorum, said. "A lot of cable operators don’t pay attention to it unless they have a problem."

The worst problem that most MSOs have is when individuals replace the firmware on their modems. Paul Scarff, director of product management, Sigma Systems, said the most exploited problem is theft of service, where a hacked modem requests a configuration file that supports a higher class of services.

Websites such as cablehack.net sell old Motorola Surfboard modems that consumers can reprogram easily. Although one of the owners of Cablehack, Thomas Swingler (aka DerEngel), faced a six-count indictment in November 2009, the site continues to sell the modems. The site now says that it can only sell un-modified cable modems, but provides consumers instructions and firmware for reprogramming the modems themselves.

"Chen said the most serious problem would be if a hacker changed the DNS settings."

Some consumers will steal service outright, by reconfiguring their modem to imitate or "spoof" a legitimate media access control (MAC) address.

When the cable operator has migrated the whole network to DOCSIS 1.1 and above, this type of theft is likely to raise a red flag. It is more common on older systems in which the operator has chosen to remain backwards compatible with DOCSIS 1.0 modems.

On older networks, operators might find that have some piracy, but don’t know how to lock out the pirates without angering legitimate paying consumers. If the problem is small, the costs of upgrading the network or finding the pirates might not justify the rewards of reducing piracy.

The other side of cable modem security lies in protecting consumers from attacks on the cable modems themselves.

For example, Time Warner Cable’s deployment of SMC8014 integrated cable modem/Wi-Fi routers left the devices vulnerable to hackers who could use them to gain access to the routers of about 65,000 customers. Last October, Time Warner reported taking steps to correct the problem.

David Chen, the software developer and blogger (chenosaurus.com) who discovered the vulnerability, said that by disabling JavaScript on his browser he could read the administrative user name and password of the modems. This same user name and password could access the administrative panels for all of the routers he scanned. Chen said the most serious problem would be if a hacker changed the DNS settings, which could redirect customers to fraudulent banking sites designed to steal banking credentials. This kind of vulnerability might not be that much of a problem if operator properly configures the DOCSIS settings on CMTS, according to Chris Busch, vice president broadband technologies, Incognito Software.

Busch said the DOCSIS configuration file can implement Layer 2 and Layer 3 filters and drop out any source IP addresses not matching that of the LAN side of the cable modem.

Sigma Systems’ Scarff said operators could reduce cable modem threats by taking these measures:

  • Control who has access to the CMTS.

  • Keep config files away from config servers.

  • Re-synch cached config files.

  • Use BPI+ to detect MAC moving between agents.

  • Track MACs that attempt to roam.

  • Encrypt config files specific to MACs requesting service and deny other devices requesting same file.

  • Dynamically filter DHCP MACs.

-George Lawton is a contributor to Communications Technology.








Columns

The Winning Season

What Is RF? It's Like Magic


Departments

Features

The 2011 System of the Year:  Buckeye CableSystem – 'The Right People, The Right Commitment'

To say that the markets served by Buckeye CableSystem are challenged doesn’t quite describe the economic status of much of northwest Ohio and parts of southeast Michigan. “Toledo has been in a
FULL STORY »

Bandwidth Goes Over The Top On 4G LTE Networks

Such “over the top” (OTT) content as that provided by Netflix and Pandora Radio is gaining market traction, opening up opportunities and challenging service provider networks. Internet video is now
FULL STORY »

Communications Technology’s 2011 Hall of Fame

Jorge Salinger In recognition of his work to explain and promote the Comcast, Time Warner Cable and other CableLabs members' Converged Cable Access Platform (CCAP) initiative. Jorge Salinger, vice
FULL STORY »

The 2011 CT Platinum Award Winners

Cloud Software for Subscribers Comcast Interactive Media – Xfinity TV App (operator winner) Targeting Comcast Xfinity TV customers who have digital cable subscriptions, the Xfinity TV product and its
FULL STORY »


CT-HOSTED WEBCASTS AVAILABLE ON DEMAND (to register for playback, click on title):

Advanced Upstream Troubleshooting
Sponsored by JDSU
May 27, 2010

Revealing CMAP's Potential: A Converged CMTS and EdgeQAM Platform
Sponsored by ARRIS
April 22, 2010


Measuring Techniques and Methodologies for Ensuring QoE in IP Video Distribution Networks
Sponsored by Trilithic
April 8, 2010

IPv6: Prep and Provisioning
Sponsored by Incognito
March 23, 2010


SERVICES







Add a Comment

Name:
Email:
Comments:

Please enter the letters or numbers you see in the image.
 
   Your message will be reviewed before it is posted

Register here to receive
CT Reports - FREE

 

View the latest issue



Communications Technology

Home

Smart View
» Video
» Voice
» Data
» Wireless
» Top Ten

News
Strategy
Deployment
Operations
Tools
Advertise
Subscribe

CT Reports
Tech Eletters
Webcasts
Videos
Jobs

About Us
Stay connected to thought leaders in the communications community:

CT Chatter Become a memeber of CTchatter.com,
the premier networking community for broadband professionals.
   
twitter Follow us on Twitter
   
CT Jobs Get personalized Job Alerts

CABLE360 © 2012 Access Intelligence LLC. All Rights Reserved. Reproduction in whole or in part in any form or medium without express
written perimission of Access Intelligence, LLC is prohibited.