Thank you for Subscribing to CIO Applications Weekly Brief

OP(4) Advances IoT and Embedded System Security with its New Automated Solution
"Competitors would have you believe that finding more vulnerabilities is better," noted OP[4] CEO and Co-founder Irby Thompson.
By
CIO Applications | Tuesday, June 20, 2023

OP[4] reveals their new automated solution to detect vulnerabilities in Internet of Things (IoT) devices and embedded systems.
FREMONT, CA: "Competitors would have you believe that finding more vulnerabilities is better," noted OP[4] CEO and Co-founder Irby Thompson. "This is because their technology can't actually distinguish between exploitable vulnerabilities and those that don't impact the health and safety of your products. We created OP[4] to directly address this issue, so development teams can efficiently focus resources on the vulnerabilities that need to be remedied and don't waste time and money on those that don't."
One of the leaders in automated firmware security, OP[4], revealed their new automated program analysis solution for finding and fixing vulnerabilities in Internet of Things (IoT) devices and embedded systems. IoT devices and systems are growing rapidly, outpacing efforts to ensure adequate security for billions of them, which has significant implications for the commercial IoT industry.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
It can detect, verify, and differentiate between malicious vulnerabilities, which pose a real risk of compromising a device, and benign issues present in the software supply chain but aren't exploitable, unlike existing technologies. It is based on integrating static, dynamic, and symbolic program analysis methodologies. Another feature is that it prioritizes verified weaknesses according to their risk level, allowing development teams to focus resources on those most critical to the safety and compliance of the system.
In the current year, the company is delivering its automated firmware security system to the U.S. government, which developed it through contracts with DARPA and AFWERX. This pioneering approach has been adapted for the commercial sector over the past six months, and the company is launching its first two products.
Its flagship product, Aggressor, detects, validates, prioritizes, and helps remediate known N-Day and novel 0-Day vulnerabilities automatically and is a groundbreaking program analysis and remediation tool. To ensure quality before a product is built, Aggressor analyzes third-party security risks during the product design stage; it finds and fixes software bugs during development and validates the product before it is deployed to ensure a clean bill of health.
Developed on Aggressor technology, the second product, the Interrogator, is a real-time, subscription-based threat monitoring tool designed to complement Aggressor. It analyzes and alerts you to emerging exploitable threats within products that have already been released. Combining these two products provides proactive cybersecurity support across the entire lifecycle of IoT and embedded systems products, from their creation to their termination.
"Automated program analysis techniques have traditionally been the domain of academic research," noted binary analysis expert and OP[4] CTO and Co-founder Scott Lee, who oversees the development of the technology for the company. "When applied to real-world IoT and embedded systems, we have achieved a remarkable improvement in the accuracy of automated identification of exploitable software defects in commercial sector products."
More in News

