Attack

The threat of cyberattacks intensifies annually, affecting not only large enterprises but also critical infrastructure. Alongside a proliferation of malware variants, particularly those instrumental in data encryption and subsequent extortion, increasingly sophisticated attacks are being executed by state-sponsored advanced persistent threat (APT) groups. The attacks on SolarWinds and Microsoft Exchange Server have starkly demonstrated the profound impact security vulnerabilities can have on digital infrastructure and data privacy.

We also observe a continuous increase in widespread, untargeted, and targeted attacks on our clients' applications and systems.
The most common attack vectors include:

  • Phishing
  • Attacks exploiting known vulnerabilities in e-commerce platforms and Content Management Systems (CMS)
  • Attacks targeting third-party plugins
  • Brute-force attacks on servers and backend access points
  • DDoS Attacks

Protection

As an engineering firm specializing in digital solutions and processes, the security of applications and infrastructure has been a core focus and central theme in our projects for many years. Given that we typically maintain full access to the client systems we manage, IT security and the often-associated data protection are fundamental pillars of our operations.

In alignment with the BSI IT-Grundschutz Compendium and the TISAX certification for the German automotive industry, GREEN-M INTERFACE DESIGN GmbH has internally implemented the following measures:

  • Employee Awareness Training
  • Access Controls
  • Video Surveillance
  • Alarm Systems and Sensors
  • Network Protection and Intrusion Prevention Systems
  • Endpoint Protection on all Clients
  • DNS Filtering
  • Email Encryption
  • Encrypted Data Transmission
  • Encryption of all Data Carriers
  • Password Management
  • Robust Password Policies
  • Two-Factor Authentication
  • Zero Trust Principle
  • Asset and Patch Management
  • Application and Infrastructure Monitoring within a Security Information and Event Management (SIEM) system
DOWNLOAD GREEN-M SECURITY GRID (PDF, 5MB)

Application Security

Before deploying an application into the “wild”, we perform a Security Source Code Analysis to verify the consistency and security of our source code and test the application for vulnerabilities using vulnerability scanners. Through external penetration testing and the simultaneous remediation of identified weaknesses, we enhance the security, data protection, and availability of your applications.

Security Plugins and Hardening

Drawing from our penetration testing experience, we have developed application hardening measures and ready-made plugins that can protect systems like Zend2, Shopware, and WordPress even against targeted attacks.

  • Implementation of All Security Headers
  • Protection Against SQL Injection
  • Protection Against XSS Injection
  • Deployment of Secure Cookies
  • IP Restrictions for Backend Access
  • Deactivation of Unused Software Components
  • Deactivation of Unused Interfaces
  • Secure TLS Configurations
  • Implementation of 32-Character Passwords
  • Two-Factor Authentication
  • and many more.

For WordPress, we have developed the GREEN-M X-SECURITY 2.0 security plugin, which has been validated for its security through multiple external penetration tests. For more information, please contact us.

Security Source Code Analysis

Programming errors responsible for security vulnerabilities frequently occur in applications at typical, systematically identifiable locations within the code and configuration.
Static Code Analysis is performed semi-automatically, and the findings from the tools utilized are evaluated, prioritized, and remediated by the development team.

We analyze both proprietary and third-party source code within our development process using Security Source Code Analysis to rectify application errors. Furthermore, we document and monitor deployed open-source components for known security issues.

Penetration Testing

Most attacks are automated and typically pass quickly if the most common application vulnerabilities have been addressed promptly through updates and patches. However, to conduct a more in-depth security assessment of an application and prevent insider threats, a professional, manual penetration test, also known as a pentest, should be performed. During a pentest, an attack on the target system is simulated, with the pentester employing the same tools and methodologies as a real attacker.

In collaboration with our partner Securai GmbH from Ingolstadt, we offer professional penetration testing and simultaneously remediate identified vulnerabilities. Detailed reporting on these vulnerabilities assists in implementing your compliance requirements for application security.

Updates & Patches

Once security vulnerabilities in software solutions become publicly known, attacks targeting these specific weaknesses on the network have typically already commenced.

Proactive monitoring of security vulnerabilities, their assessment, and defined processes enable us to promptly provide applications with necessary updates and patches.
Should a successful breach still occur, a robust backup strategy facilitates the deployment of a clean application version predating the exploit.

Verification processes and update documentation are crucial for addressing potential errors that may arise from updates and patches.

  • Active Monitoring of Security Patches for Open-Source Components
  • Active Monitoring of Known Vulnerabilities and Exposures (CVE)
  • Timely Remediation of Critical and High-Severity Security Vulnerabilities
  • Regular Updates & Patches for Systems, Applications, and Plugins
  • Testing of Key Application Functionalities Following an Update
  • Documentation of Updates & Patches
  • Delivery of Reports
  • Deployment of Backups

At GREEN-M INTERFACE DESIGN, we routinely perform updates and patches for all clients whose applications we continuously manage.

Threat Detection

Applications typically allow users to upload images and documents, which can inadvertently lead to the publication of malware or links to compromised websites, or their dissemination to other users or systems.

Traditional antivirus software installed on web servers often reaches its limitations in this regard. GREEN-M leverages Sophos Intelix to scrutinize all data inputs using an engine equipped with machine learning, deep learning, threat response, sandboxing, and reputation control, thereby verifying and, if necessary, blocking them before storage within the application.

Applications can thus benefit from the dynamic protection offered by one of the world's leading endpoint protection providers.

We manage the integration with the Sophos Intelix SaaS service on AWS and provide comprehensive reporting and integration into a Security Information and Event Management (SIEM) system.

Graphic Source: Gartner Magic Quadrant Endpoint Protection 2021

Vulnerability Scans

Vulnerability testing is a one-time or recurring process for identifying and classifying security weaknesses within an application or network.
Regular scans reveal known vulnerabilities in applications, services, and networks, thereby enabling targeted remediation and system hardening.

GREEN-M deploys one of the leading scanners to identify the latest known vulnerabilities that could be exploited by attackers. We typically conduct these scans quarterly, or following updates and releases, and evaluate the results collaboratively with our clients.

Infrastructure Security

The security of an application is fundamentally contingent upon the security of the underlying infrastructure in which it is embedded. Hosting, backups, access control, and protective layers constitute the pillars of our Infrastructure Security and are integral components of a security framework that approaches application protection holistically. To achieve this, we collaborate with certified and proven service providers.

Managed Hosting Germany

As a 'Business Partner,' we have consistently hosted our clients' applications for nearly 10 years on Managed Flexservers provided by Profihost GmbH in Hanover. Beyond the flexible performance scaling, we benefit from direct personal contact and extremely rapid response times, avoiding any hotline queues.
These systems are continuously supplied with updates, patches, and optimizations by Profihost and utilize the Gaia OS platform from the Israeli security company Checkpoint.

With Germany as our location, data protection can be implemented in accordance with German and European data protection laws.

  • Server Location Germany
  • Monitoring of Server Systems
  • Automatic Scaling During Bottlenecks
  • VDS-certified
  • DIN EN ISO / IEC 27001 : 2017
  • Triple redundant
  • 2-32 CPU Cores
  • 6-96 GB RAM
  • SSD Storage
  • 99.9% High Availability
  • Geographically separated backups
  • Cybercrime Protection with DDoS Protection
  • LAMP
  • Podman Containers
  • Elastic Search
  • Pimcore

For our clients utilizing Managed FlexServer Hosting with Profihost, we fully manage all communication with the hosting provider regarding scalability, performance, security, and technical inquiries.

Identity and Access Management

Identity and Access Management (IAM) is a framework comprising policies, processes, and technologies that enables organizations to manage digital identities and control and regulate user access to critical corporate data and applications.

By assigning specific roles to users and ensuring they possess the appropriate level of access to corporate resources and applications, IAM enhances security and user experience, facilitates superior business outcomes, and improves the feasibility of mobile and remote work.

Without Identity and Access Management, it becomes exceedingly difficult to ascertain which user requires what rights, when, for what purpose, and how they utilize access privileges on a device. IAM provides a streamlined navigation through this labyrinth of data.

We integrate applications with existing IAM systems via SAML 2.0 or OpenID, or we deploy the RED HAT-supported open-source solution 'Keycloak' and assist you with your organization's identity management.

DDoS Protection

In Distributed Denial-of-Service (DDoS) attacks, adversaries attempt to overwhelm active services by flooding a web server with a multitude of targeted requests, aiming to crash the server and its hosted applications. In most instances, botnets comprising compromised computers are utilized to launch a critical mass of requests. DDoS attacks are frequently part of extortion campaigns linked to monetary demands.

According to a survey, global attacks increased by over 500% in Q4 2021. Furthermore, the bandwidth of deployed botnets is continuously expanding.

For web server protection, GREEN-M relies on Cloudflare, a US-based provider recommended by the Federal Office for Information Security. In addition to DDoS protection, the security and performance of a website can be significantly enhanced through a Web Application Firewall (WAF) and a Content Delivery Network (CDN).

Sources: https://securelist.com/ddos-attacks-in-q4-2021/105784/

Web Application Firewall

A Web Application Firewall (WAF) is deployed in front of the web application to inspect incoming requests and the web server's responses. The WAF thus provides protection against common attack scenarios such as SQL injections, cross-site scripting, and zero-day exploits, and can also safeguard against known and unknown vulnerabilities within a web application.

GREEN-M leverages Cloudflare's global cloud solution and its centralized, proactive approach to managing firewall rules:

  • Optimal performance without compromising web application speed
  • Protection against Zero-Day exploits through active management by Cloudflare
  • Protection against the most common attack patterns as per OWASP Top 10
  • Customized protection for established Content Management Systems (WordPress) and frameworks (PHP)
  • Access restriction for IPs and countries
  • Statistics and Logging
  • and many more.

GREEN-M handles the setup, configuration, and monitoring of the Web Application Firewall for you.

DOWNLOAD GREEN-M SECURITY GRID (PDF, 5MB)