Our penetration and system analysis testing goes beyond basic analysis to consider the whole ecosystem of the IoT technology, covering every segment and how each impacts the security of the whole. Our testing includes the IoT mobile application, cloud APIs, communication and protocols, and embedded hardware and firmware.
- Hardware testing
TÜV SÜD will examine the physical security and internal architecture of the device – including internal components – to determine the breadth and depth of its physical attack surface. This service may include component indication, firmware extraction, identification of test points, and reconfiguring the device’s hardware to bypass authentication, intercept traffic, and/or inject commands that may pose a significant risk to your organization and clients.
- Protocol testing
TÜV SÜD will test communications to and from the device. This includes testing the cryptographic security of encrypted transmissions, the ability to capture and modify transmissions of data, and fuzzing of the communication protocols. We will assess the security of communication protocols and determine the risk to your organization and clients.
- Firmware Analysis
TÜV SÜD will extract and examine the content of the firmware in an attempt to discover backdoor accounts, injection flaws, buffer overflows, format strings, and other vulnerabilities. We will also assess the device's firmware upgrade process for vulnerabilities and perform a secure boot review process to ensure that public key encryption and upgrade functionality is secure.
Designing hardware is often the first step of a major project and can determine your limitations and weaknesses. This service provides your engineers with one-on-one time with our security consultants during design time. We offer consulting from the ground up so that hardware issues don’t become the Achilles heel of your software security architecture.
Helping Prepare, Plan, and Architect Security for IoT Implementations
If the forecasts are correct, by 2020 billions of IoT devices around the world will be connected to the Internet. As organizations move quickly to capture space in this emerging market, it is important to prepare, plan, and architect security into IoT projects from the very beginning. Device authentication, encrypting sensitive messages, and being able to verify the integrity of patches or software updates are just a few of the areas in which our experts can provide valuable insight and guidance.
Within TÜV SÜD, internationally accredited certification bodies offer services for various management systems. We have extensive experience in auditing and certifying a wide range of internationally recognized management systems. Our experienced team of consultants will guide you through the process, from on-site audits to certification. We will help you to identify opportunities and minimize potential risks. By being your partner, your company’s commitment to the safest standards will gain global recognition.