Consulting and Security Test Suites for Critical Infrastructures
Together with partners, achelos is offering customers dealing with critical infrastructures a full-service for implementing their IT security compliance goals, such as the implementation according to ISO 27001 or industry-specific IT security standards or cyber security (based on the German BSI recommendations).
Automated TLS and IKE/IPsec tests ensure secure network connections
With our flexible and automated security test suites, you can test the configuration and implementation of TLS and IKE/IPsec network connections manufacturer-independent.
Benefits when using security test suites from achelos
- Prevention of IT configuration errors
- Compliance with security guidelines of the Federal Office for Information Security (BSI)
- Cost savings thanks to faster certification
- Efficient testing thanks to high degree of automation
- Convenient simulation environment and excellent ease-of-use
- Scope and depth of testing, as well as attack scenarios can be individually selected
- Reproducible and audit-compliant documentation of test results
Checking the TLS configuration
- Protocol version (no SSL 3.0, TLS 1.0, …)
- Cipher suite (no EXPORT cipher suites, no weak encryption algorithms, …)
- Cryptographic parameters (RSA key length ≥ 2048 Bit, …)
- Protocol extensions (TLS compression, heartbeat, …)
Tests for correct TLS implementation
- Robust protocol implementation (manipulation of the message sequence, …)
- Correct checking of the padding (adding invalid padding values)
- Constant-time implementation (for example Lucky Thirteen attacks)
Test coverage IKE/IPsec test suite
- Verification of the Internet Key Exchange implementation on the basis of IKE v.2.
- Handling of testaspects of the IPsec level
- Definition bases of the IKE/IPsec test suite:
- IETF RFC 3602 "The AES-CBC Cipher Algorithm and its use with IPsec"
- Federal Office for Information Security (BSI) "Requirements of cryptographically secured VPN channels / trusted channel in the German CC certification scheme IKE/ IPsec version 0.0.2“
- Simulation of an IKE responder
Automated test procedure for professionals
A large number of tes and evaluation bodies are already using the Qumate test suites from achelos to perform tests within the framework of accredited test procedures.
The architecture and implementation of the test suites has a modular structure. Various test suites, tools and simulations can be integrated on the basis of Qumate by achelos. Automated tests and detailed test reports are used to measure product quality. All you need is a powerful PC without a special IT infrastructure or a complex laboratory environment.
Take advantage of our security test suites!
Get to know the IT security experts of achelos and meet us at the booth of IS4IT – Security Liga hall 10.0 | booth 311.
We are looking forward to your visit!
Yours achelos team
For more information visit: