Demos
This combined demo video provides a comprehensive overview of Keysight’s IoT Security Assessment, including the automated IoT Firmware Analysis module. It highlights how these products can help meet the Cybersecurity Maturity Model Certification (CMMC) Level 2 requirements. The demo focuses on the software's application in securing IoT devices. Scott Register introduces the IT security assessment product, emphasizing its ability to scan web interfaces for vulnerabilities, which is crucial for IoT devices with Web APIs. The demo demonstrates the product's configuration, the detailed breakdown of vulnerabilities found, and their severity levels.
The demo also showcases system discovery, which analyzes devices to reveal non-critical information, and a full and fast scan that highlights the product's efficiency in identifying vulnerabilities. A key feature is the rich reporting engine, offering HTML or PDF results with varying levels of detail, from executive summaries to full reports. Protocol fuzzing is covered extensively, including IP fuzzing tests for TCP and UDP implementations, Bluetooth fuzzing for both classic and low energy protocols, and Wi-Fi fuzzing to test the resilience of access points and clients against malformed commands.
The automated IoT Firmware Analysis module is also introduced, showing how it helps organizations gain insights into the software bill of materials (SBOM) and vulnerabilities within IT firmware. The module identifies all software components within the firmware, providing detailed information such as component names, vendors, versions, licenses, URLs, and associated CVEs. Users can search, filter, and sort CVEs, with detailed information available for each one. The module also identifies security weaknesses within the firmware, such as default passwords, private keys, digital certificates, configuration issues, and exposed binaries lacking compiler security flags.
A unique feature of the firmware analysis is the binary analysis capability, which performs static binary analysis on executable files extracted from the firmware. The binary analysis engine lifts the binary code to an intermediate representation suitable for program analysis and runs several analysis plugins. This automated analysis significantly reduces the manual effort required for security researchers to identify potential vulnerabilities, offering a low false positive rate and actionable insights to improve firmware security.
By integrating these capabilities, Keysight’s IoT Security Assessment supports organizations in meeting CMMC Level 2 requirements, which focus on safeguarding Controlled Unclassified Information (CUI). The detailed vulnerability assessments, comprehensive reporting, and advanced analysis tools provided help organizations implement necessary security controls, conduct regular assessments, and maintain a robust security posture, all of which are critical components of CMMC Level 2 compliance.
What are you looking for?