The Goal
Discover and remediate security weaknesses that exist within IOT devices provided to customers and in the back-end services that empower these devices.
Our Method
Simulate an attacker attempting to reverse engineer the hardware device, network communications, connected services, and mobile applications for a hybrid full-scope review of the platform and device.
The Result
Urbane provides assessment reporting that includes:
- Detailed Findings and Observations
- Tailored Remediation Strategies
- Remediation Validation Testing
Testing Scopes
Urbane recommends to focus testing to simulate actual risks and areas of concern to the organization. As such, Urbane focuses their insider threat assessments on the following methods of testing.
Device Testing
Reverse engineering a device as an attacker or security researcher would, Urbane reviews IOT devices for weaknesses in the hardware, network communications, exposed services, and management to determine the risk of compromise, both physical and via network in the hands of a targeted attacker.
Mobile, API, and Web Testing
As most IOT devices integrate with backend APIs with control provided through mobile applications, Urbane expands their IOT testing to include the device's APIs, Mobile Applications, and Mobile Application APIs for full coverage of the risk facing the IOT device's ecosystem. Urbane optionally assesses source code in conjunction with these applications to provide an in-depth review.
Wireless Protocol Review
With depth of experience in Bluetooth, WiFi, ZigBee, and proprietary wireless protocol security, Urbane also evaluates the implementation of wireless protocol stacks for IOT devices to determine their resiliency to compromise, monitoring, and other consumer privacy related concerns.
The Urbane Difference
Innovative. Sophisticated. Refined.
Urbane demonstrates our founding principles in every engagement through attention to the details, modern techniques, and strong union with our clients.
Request more information
Other Urbane Solutions That May Interest You
Application Penetration Testing
The goal of application penetration tests are to analyze the logic and operation of exposed applications, as an attacker would, in attempt to access sensitive data, compromise a system, or bypass logic controls.
Infrastructure and Cloud Review
With in depth analysis of existing network and server architecture, Urbane provides proven security strategies for decreasing the various risks affecting the unique business needs of the organization with the least amount of impact or resource use.
Application Code Review
Static analysis and review of source code detects risks and vulnerabilities not easily detected with penetration testing alone. With a combination of manual review assisted by the efficiency of cutting-edge automated toolsets, Urbane provides expert source code review.
Gap Analysis and Remediation
Assessing and bridging the gaps that exist with an organization’s technical and procedural compliance, Urbane’s diverse gap analysis and remediation process provides in depth review of existing technical and procedural infrastructure with customized remediation guidance for the organization’s unique needs and challenges to meet compliance requirements.