Security Pattern

Security Pattern is a dynamic scale-up specialized in consultancy and security solutions for embedded systems and IoT.

Security Pattern

We support our clients from the project's inception, assisting in defining security requirements, selecting appropriate building blocks, and developing hardware and software components. We provide the development methodologies for clients requiring a "secure by design" approach. We are the first cybersecurity company in Italy to have achieved certification under the IEC 62443-4-1:2018 standard. We offer a state-of-the-art vulnerability monitoring service, including SBOM creation, to meet requirements of regulations, like RED and CRA, and vertical standards for medical, industrial automation, automotive and consumer IoT.

Software Services

Services:

Consulting

Operating Systems:

Android, Embedded Linux, FreeRTOS, OpenWRT, Torizon, Yocto

SUM is a SBOM and vulnerability management platform for connected devices and systems. Build upon the principles of a strong vulnerability management process, SUM supports device manufacturer to identify, triage, address and report vulnerabilities, including the widely used CVEs (Common Vulnerabilities and Exposures). The platform enables the generation, management and export of SBOM (Software Bill of Material).

Projects Overview

Security Pattern demonstrated the capabilities of SUM, their SBOM and vulnerability management platform, on Toradex hardware at Embedded World 2024..

  • Toradex Apalis iMX6 System on Module running on Torizon OS (kirkstone 6.1.80)
  • On top of the Torizon OS, they implemented a custom application layer, that consist of a Samba service and a Python server.
  • In this demo they show how a known vulnerability of a software component in the custom application layer (samba 4.1.17+dfsg-2), can be easily exploited by an attacker to compromise the functionality of the whole system.
  • They demonstrate how this kind of situations can be prevented by implementing a vulnerability management process, aimed at proactively identifying, evaluating and addressing known vulnerabilities within the system before being exploited by attackers.

Additional Services

Services:

Programming language independent solutions

We provide pre-packaged and custom cybersecurity consultancy services, such as code review, penetration testing and training.

Contact

Address
Via Torri Bianche 3, Vimercate 20871, Monza e Brianza, Italy

Region

Worldwide

Have a Question?