ANPR systems provide a good case study for cyber-attacks. Clean air zones, one of their primary uses, are being introduced across the UK at a rapid pace. Many authorities directly procure and operate them. They also provide vehicle data that can be used for other smart streets purposes such as traffic enforcement, traffic control and generation of data for traffic pattern study. The IoT-style architecture of ANPR systems is also reflected in other smart streets systems, such as those related to variable message signs (VMS), traffic control, gully monitoring, air quality monitoring, etc. Thus, parallels can be drawn with other use cases, and different impacts explored. Finally, ANPR systems have been the target of recent, successful cyber-attacks, lending credibility to ANPR as a generic case study.
The following case study is fictional, however the narrative is composed of elements derived from real, recent cyber incidents or examples of practice shared during stakeholder engagement. It is not intended to embarrass or suggest negligence by any institution. Rather it intends to highlight security risks posed by the industry’s nascent security maturity.
To enforce a new authority-wide low-emissions zone, Northdale County Council (NCC) is deploying ANPR systems with a network of over 500 CCTV cameras. These cameras and their associated data processing systems capture millions of instances of personal information each week. The many geographically dispersed cameras are connected, and 4G/5G telecoms networks generally provide the most effective solution. This scenario is not unique to ANPR. Many other smart streets solutions include hundreds of geographically dispersed IoT devices (e.g. sensors, controllers, interfaces or digital signage), and commercial mobile telecoms are increasingly providing the solution to link them.
The smart streets project team responsible has worked with a major ITS system integrator to design the ANPR system. Security requirements were placed in the procurement specification stating that the system integrator needed to be ISO 27001 certified, however, no requirements related to the system security engineering lifecycle were specified. Northdale has a long working relationship with their supplier and trusts that their security maturity means the council’s already stretched resources have one less thing to worry about.
Under the contract, CCTV cameras and SIM cards are free-issue by the authority. They have tasked their procurement department with purchasing cameras and SIM cards at preferable rates available to the authority. The procurement team has identified that, under the contract with their corporate mobile phone provider, additional data SIMs can be added very cheaply. Uptime is not guaranteed at 100%, but the impact of occasional dropouts is small. Without any specific security requirements, and without security expertise in the team, the purchaser selects the lowest cost camera vendor.
Unfortunately, Northdale has failed to recognise that, in principle, connecting an IoT device to a 4G or 5G connection is essentially the same as connecting the device directly to the internet. This means the device is, without specific considerations, subject to the highest possible level of exposure to cyber threats. The IP address of these devices would generally be detected by online security research tools like Shodan, allowing anyone in the world to identify and communicate with the device. Without cyber security risk mitigation, an attack on the smart streets infrastructure is likely.
Within a week of the system being commissioned, CCTV cameras belonging to the solution are detected by Shodan, a security research website that detects and documents devices that are accessible at a public IP address. Six months later, security researchers find a vulnerability in the CCTV camera used by Northdale County Council: a backdoor admin password used by the firmware development team was left active. Northdale does not have vulnerability monitoring in place for the cameras and is unaware of the issue or that the vendor has released a patch. Cyber criminals read of the camera’s vulnerability and search Shodan for cameras made by this vendor. They progressively work through the list, trying the password on each camera. When they reach Northdale’s cameras, they gain access.
With admin access to the camera, they find configuration data that allows them to connect to the central ANPR server. Here, they download records of millions of journeys, tied to vehicle registration numbers, and place it for sale on the dark web. Furthermore, they configure the cameras to act as proxy servers for illicit internet traffic.
In summer 2020, an anti-lockdown activist group purchases the stolen data and publicises it online. Anyone can search for vehicle journeys made in Northdale with the registration plate of the vehicle in question, and the breach becomes a national sensation. Journalists use the data to prove that a public figure illegally travelled during lockdown. Tabloids report on spouses detecting marital infidelity using the data. Lawsuits are brought against Northdale County Council, and the Information Commissioner’s Office (ICO) opens an investigation.
Around the same time, Northdale County Council detects thousands of pounds in excess charges for data consumed by SIM cards used by ANPR cameras. These charges however, are insignificant compared to the £18m GDPR fine being considered by the ICO, legal fees for various court cases and political pressures facing the council.
Authorities face challenges building their security posture and securing their smart streets solutions given financial and resource limitations. However, a failure to appropriately manage risks relating to the smart streets system during the planning, delivery and operation of smart streets could lead to far greater costs in the medium to long term. Given the diversity of both authorities and smart streets projects, there is no one-size-fits-all solution. Authorities are encouraged to take a risk-based approach to cyber security that can be tailored to their needs. Part 2 of this guidance looks at taking a risk-based approach to smart streets security.