17.5 C
New York
Monday, October 7, 2024

A Profitable Penetration Take a look at by White Knight Labs – sUAS Information – The Enterprise of Drones


At Aloft, we take nice satisfaction within the safety of our merchandise and group. In partnership with Anzu Robotics, we’ve launched Air Management for the Raptor. This product has been constructed over the past twelve months to safeguard your information and allow safe flight. We engaged White Knight Labs, a famend third-party cybersecurity agency, to conduct a complete penetration take a look at to make sure that the Anzu Raptor meets the best safety requirements. Because the previous saying goes, “With nice energy comes nice duty,” so we additionally wished to make sure that buyer information was at all times encrypted with communications solely to Aloft servers.

In constructing and designing the Raptor flight expertise, we wished to deliver ahead the most effective parts of the {hardware} and firmware offered within the licensed expertise whereas making a basically higher and extra empowered flight expertise. For instance, we eliminated the geofencing so there isn’t a spurious geofencing or blocking of your flights with Raptor drones.

White Knight Labs examined and validated these core information parts of their evaluation. With the default setup with Aloft operating out of the field, your information is safe and stays solely within the Aloft Air Management platform.

What’s Static and Dynamic Evaluation of Site visitors?

White Knight Labs utilized static and dynamic evaluation methodologies to evaluate the safety of the Anzu Raptor and Air Management utility. These methodologies contain inspecting the system’s code and conduct in a managed surroundings to establish vulnerabilities or weaknesses.

Static Evaluation entails reviewing the supply code, configuration information, and system structure with out executing the code. By meticulously analyzing the static elements of the Anzu Raptor, White Knight Labs can establish any potential safety flaws within the design and implementation phases.

Dynamic Evaluation entails observing the system in operation, analyzing the info site visitors, and monitoring the drone’s conduct in real-time. By executing the system in a stay surroundings, White Knight Labs can establish vulnerabilities that solely develop into obvious throughout precise use. Particularly, we wished to check all the lifecycle of the Raptor, from preliminary registration to takeoff, touchdown, images, and flight logs.

The White Knight Labs Evaluation

White Knight Labs is extremely regarded within the cybersecurity business for its static and dynamic site visitors evaluation experience. Their crew of seasoned professionals employed fashionable info safety instruments and strategies to scrutinize the info stream of Anzu Raptor, coming from the Anzu Raptor, and talk with the Aloft Air Management utility and servers.

1. Information Transmission Targets: One of many major issues for this expertise is the safety/vacation spot of knowledge transmission. White Knight Labs meticulously analyzed the info stream from the Anzu Raptor and confirmed that every one information was completely being despatched to Aloft servers. This verification ensures that no delicate info was noticed being leaked or intercepted by unauthorized events.

2. References to Chinese language Domains: Throughout their evaluation, White Knight Labs recognized a number of references to Chinese language domains throughout the system, though no information was flowing to them. Aloft promptly remediated these findings by eradicating the references, additional enhancing the safety of our platform. This proactive measure underscores our dedication to sustaining a safe and reliable product.

The Significance of Third-Occasion Attestation

Partaking a good third celebration like White Knight Labs gives an extra layer of assurance for our prospects. Their thorough and unbiased analysis of the Anzu Raptor validates our dedication to information safety. By remediating findings and making certain that every one information is securely transmitted to encrypted Aloft servers, we have now strengthened the integrity and reliability of the Raptor+Aloft platform. We consider that safety wants transparency and bringing in exterior events for evaluation is one of the simplest ways to believe in our platform.

Whereas Aloft undergoes annual SOC 2 Kind II and ISO 27001 safety certifications, together with FAA audits as an authorised UAS Service Provider for LAANC, we often endure third-party analyses and penetration assessments. Working with suppliers like White Knight Labs will proceed to be a core a part of our course of for our airspace, UTM, fleet administration, and {hardware} integrations.

Conclusion

The profitable penetration take a look at performed by White Knight Labs is a big milestone for the Anzu Raptor. It demonstrates our unwavering dedication to delivering a safe and dependable product. At Aloft, we perceive the significance of belief and safety in in the present day’s digital panorama. By partnering with main cybersecurity specialists and constantly bettering our safety measures, we purpose to supply our prospects with peace of thoughts, figuring out that their information goes precisely the place they intend it to.

Our vigilance doesn’t cease with this report. As with something in safety, it’s an iterative and ongoing course of. We’ll proceed to enhance the platform’s posture within the coming weeks, months, and years. For any firmware updates or product expansions with Anzu, we’ll be conducting related and ongoing analyses to make sure that your information stays safe, encrypted, and solely on US-based Aloft servers always.

If you need a replica of the attestation letter or want to focus on the Anzu+Aloft product in additional element, please e mail infosec@aloft.ai.

Related Articles

Latest Articles