Unique test solution from Rohde & Schwarz analyzes IP security mechanisms in IoT and mobile devices
Adding the R&S CMW-KM052 analysis option makes the R&S CMW500 wideband radio communication tester a valuable tool for improving the security of IP-based data communications for mobile devices and Internet-of-Things modules. Users are provided with a detailed overview of security-related parameters in a controlled wireless environment. Developers can detect and close security gaps at an earlier point in the development process.
Munich, February 28, 2017 – The Internet of Things (IoT) is integrating the Internet into our daily lives, with products such as home automation, wearables and even connected cars. Sensitive data is increasingly being transmitted via wireless IP-based connections. The high demand for mobility, large ranges and reliability is best met with cellular technologies, especially LTE and LTE-Advanced as well as 5G in the future.
However the components, particularly for IoT, are often not fully mature or have undergone only the most basic testing and are therefore poorly protected against attacks and provide potential portals for hacker attacks.
The new solution from Rohde & Schwarz makes it possible to analyze security mechanisms for IP data communications during the early development phases of mobile devices and IoT modules. Potential security gaps can be identified and closed.
A test instrument for the entire development process
It is not necessary to install additional software on the DUT for the analysis. The DUT also doesn’t have to have a debug interface. In the Rohde & Schwarz solution, the R&S CMW500 sets up the wireless connection and functions as a wireless network during IP data communications with the World Wide Web. Developers can flexibly configure the cells to simulate real-world applications in the end customer’s target network. They only need a single test instrument for RF analysis in cellular and non-cellular networks, protocol tests and IP application tests as well as for analysis of security-relevant parameters for IP data communications. This is not available anywhere else.
Key security parameters clearly displayed
The new reporting module, R&S CMW-KM052 IP connection security analysis, is used in conjunction with the Rohde & Schwarz cybersecurity software R&S
PACE2 to analyze IP traffic in realtime within a controlled test environment. The software generates statistics for the IP connections in realtime and outputs a clear overview of the results. The software module allows the user to define sensitive and device-specific information.
Statistics show whether this information appears in unencrypted connections. The module also analyzes parameters for SSL/TLS handshake sequences as well as certificates, the country name and the domain name of the endpoint server. Another important function is the active scanning of the IP ports on the mobile or IoT device. This makes it easy to detect invalid configurations and suspicious communications behavior.
Lab use with controlled wireless network
The R&S CMW500 emulates a controlled cellular network or a WLAN access point for IP security checks. The security analysis requires the data application unit (DAU), which provides IP addresses for the DUT and sets up an IP connection to servers in the World Wide Web.
The R&S CMW-KM052 reporting module can now be ordered from Rohde & Schwarz.
About Rohde & Schwarz
The Rohde & Schwarz electronics group offers innovative solutions in all fields of wireless communications as well as in IT security. Founded more than 80 years ago, the independent company has an extensive sales and service network with subsidiaries and representatives in more than 70 countries. On June 30, 2016, Rohde & Schwarz had approximately 10,000 employees. The group achieved a net revenue of approximately EUR 1.92 billion in the 2015/2016 fiscal year (July to June). The company is headquartered in Munich, Germany, and also has strong regional hubs in Asia and the USA.
About Rohde & Schwarz Cybersecurity
Rohde & Schwarz Cybersecurity is an IT security company that protects companies and public institutions around the world against cyberattacks.
The company develops and produces technologically leading solutions for information and network security, including highly secure encryption solutions, next generation firewalls and software for network analysis and endpoint security. The multiple award-winning “made in Germany” IT security solutions range from compact, all-in-one products to customized solutions for critical infrastructures. The trusted IT solutions are developed based on the new security-by-design approach for preventing cyberattacks proactively instead of reactively. Around 400 employees work at the current locations in Berlin, Bochum, Darmstadt, Hamburg, Leipzig, Munich and Saarbruecken.