Innovative cybersecurity approach from Dahua Technology
Share this content
In the AIoT era, the world is getting smarter. Everything is going to have an online “ID” and be connected into a vast net of IoT devices, like a laptop computer, a mobile phone, a connected thermostat, or a network security camera.
Cybersecurity to watch in the AIoT era
According to a Marketsandmarkets report, IoT is extensively used by smart cars to smart manufacturing and connected homes and building automation solutions. However, currently there are no unified global technical standards for IoT, especially in terms of communications. This results in inefficient data management and reduced interoperability mechanism and ultimately may cause reduced security in the IoT network. The global Internet of Things (IoT) security market size is expected to grow from US$12.5 billion in 2020 to US$36.6 billion by 2025, at a Compound Annual Growth Rate (CAGR) of 23.9%.
Dahua Technology believes cybersecurity is of vital strategic importance in the age of AIoT. In various vertical industries, such as traffic, banking & finance, hospital and critical infrastructure, organisations collect, process and store unprecedented amounts of data on devices like IP cameras and NVRs. A significant portion of that data can be sensitive or private information, which can be prone to cyberattacks and the situation is getting worse because there are more devices than people. As a security solution provider, Dahua Technology continuously invests in cybersecurity and actively copes with network security issues.
Committed to becoming a leader in cybersecurity and privacy protection in the global security industry, Dahua Technology has been developing and exploiting cybersecurity for nearly 10 years. The company keeps investing about 10% of its annual sales revenue in R&D every year, including cybersecurity. In addition, the company has put together a professional team of nearly 100 personnel to focus on cybersecurity issues. With rich experience and sufficient resources, Dahua Technology promises to be positive, open, cooperative and responsible when it comes to cybersecurity.
Dahua Technology cybersecurity approach
In order to achieve better efficiency, Dahua operates a comprehensive system to cope with all cybersecurity related issues. The system, led by a cybersecurity committee, also contains a cybersecurity & data protection compliance group, cybersecurity institute and product security incident response team (PSIRT). The cybersecurity committee, above all departments or teams, can call resources from the whole company, from the R&D centre to legal department, supply chain, overseas business department, etc. when necessary. The Cybersecurity Institute is in charge of building the sSDLC process and implementing the process to all Dahua product series, making sure that all Dahua products are strong against cyberattacks.
Security Development Lifecycle
Dahua Technology adopts a range of professional sSDLC (Security Development Lifecycle) security software to improve product security. During the security design phase, STRIDE + Attack Tree + PIA is adapted to improve threat modelling. During the security realisation phase, OWASP top 10 and over 150 CWEs are used to achieve static code analysis. During the security test phase, over 20 tools within seven fields are applied to realise the multiple security testing. CompTIA PenTest+/Security+ is used to carry out professional penetration testing, while compliance ISO 30111&290147 and MITRE org CAN are followed during vulnerability management after the products are sold.
Emergency Response System
Cooperation with professionals from across the globe is a great way to improve vulnerability detection. Therefore, the Dahua Cybersecurity Center(DHCC) has been established to solve cybersecurity issues with security vulnerability reporting, announcement/notice and cybersecurity knowledge sharing with our global customer base in order to provide them with more robust and secure products/solutions. Product Security Incident Response Team(PSIRT) is an integral part of DHCC. Composed of professionals ranging from marketing, supply chain, service and legal representatives, PSIRT is responsible for receiving, processing and disclosing Dahua product and solution related security vulnerabilities. Team members are on dutyseven days a weekand guarantee to respond to an emergency within48 hours. End user, partner, supplier, government agency, industry association and independent researcher are encouraged to report potential risk or vulnerability to PSIRT by email. Dahua PSIRT: CyberSecurity@dahuatech.com
Personal data & privacy protection
Dahua Technology also attaches great importance to personal data & privacy protection. Complying with applicable laws and regulations such as EU’s General Data Protection Regulation, EDPB’s Guidelines on the concepts of controller and processor in the GDPR, ETSI EN 303645’s Cyber Security for Consumer Internet of Things: Baseline Requirements as well as US’s California Consumer Privacy Act, the company established the Personal Data & Privacy Protection Standard. The standard stipulates that privacy protection methods such as de-identification, data encryption and systematic access control, privacy-friendly settings are fully adapted to the complete data life cycle all the way from collection, transmitting, storage to sharing, copying and deleting. In addition, working with world-renowned third-party institutions, Dahua Technology has received Protected Privacy IoT Product Certification and ETSI Certification from TÜV Rheinland, as well as ISO 27018 Certification and ISO 27701 Certification from BSI, which helps demonstrating its capability in managing personal information and compliance with privacy regulations around the world.
Centred on the core principles of Security by Design and Security by Default, the Dahua security baseline initiative taps into product safety technology to provide users with adequate safety guarantees. Based on and practicing the security and privacy design principles, the security baseline builds a security element layout of “AAA+CIA+P“, forming a systematic protection framework covering physical security, system security, application security, data security, network security and privacy protection. Seven versions of baseline and 100+ principles have been developed to adapt Authentication, Authorisation, Audit, Confidentiality, Integrity, Availability and Privacy protection deeply into the product quality assurance system, making sure that all Dahua products enjoy the factory default security.
Product security centre
In order to help users clearly understand the security status and capabilities of the device, the product security centre will assist users to conveniently and quickly set up the right security configuration to suit the scenarios. General security capabilities include privacy protection (face occlusion, information hiding, etc.), video encryption, security alarm, trusted protection, CA certification management, key management service, attack defence and so on.
Adhering to openness and cooperation, Dahua Technology keeps cooperating with international authoritative security institutions to jointly build a security ecosystem. By rich & in-depth communication and cooperation with institutions like TÜV Rheinland, BSI, DNV·GL, Intertek EWA-Canada and brightsight security lab, the company stays advanced in its security capabilities and systems.