Testing scope

The testing focused on validating network security in various aspects, including concealing internal network details, securing access points, identifying and addressing vulnerabilities, ensuring data privacy, and defending against common attacks.

Penetration testing

The testing was conducted onsite in the customer's lab in accordance with the OWASP Testing Guide v4 methodology. The lab was equipped with an exact replica of the real train systems. Our approach began with a detailed mapping of communication between all units to establish a logical communication scheme. This foundational step ensured a comprehensive understanding of the network’s structure and interactions.

We conducted an in-depth assessment by executing various attack scenarios, including those requested by the client and additional potential vectors identified during the testing process. Specific tests included analyzing the security hardening of the deployed systems, verifying the correct networks segmentation, the effectiveness of domain name resolution against unauthorized changes, assessing the network's vulnerability to rogue DHCP servers, testing the resilience against traffic interception or disruption through ARP poisoning, assessing the impact and detection of rogue wireless access points, identifying potential interception and alteration of communication through Man-in-the-Middle (MITM) attacks, evaluating the network's capacity to handle and recover from overwhelming traffic through Denial of Service (DoS) simulations, testing the robustness of the DHCP service against depletion attacks, and many more. This comprehensive testing approach ensured that the all potential vulnerabilities were identified, providing a clear overview of the system's security posture.

Results

During the testing, no significant vulnerabilities were discovered. All findings were primarily informational and related to the general operation of the network technology itself. These findings highlighted certain design limitations rather than security flaws. 

Based on the findings from the initial assessment, AMiT implemented necessary adjustments to the software and subsequently conducted thorough retesting to ensure the resolution of all identified issues, aiming to achieve an optimal and secure solution.

The penetration tests confirmed that the system is well protected against a wide range of potential attack vectors, ensuring the safety and reliability of the train system communication network and its users.

Conclusion

These positive results are a testament to the importance of regular penetration testing. By routinely evaluating the security of their systems, AMiT Transportation ensures that potential vulnerabilities are identified and mitigated before they can be exploited. This proactive approach to security maintenance has played a crucial role in maintaining the robustness and reliability of their proprietary technology.

Regular penetration testing not only helps in identifying and addressing potential threats but also contributes to the continuous improvement of the system’s design and functionality. The findings from this test, although primarily informational, provide valuable insights that can be used to further enhance the security posture of the network.

In conclusion, the AMIT’s commitment to regular security assessments and a proactive approach to addressing potential vulnerabilities have resulted in a secure and resilient communication network for their train systems.

About the client

AMiT Transportation has established itself as a leader in the design and manufacture of control systems and electronic solutions for the transport sector, with a particular focus on rail and rolling stock. Their core strengths revolve around proprietary expertise, advanced manufacturing processes and a customer-focused approach.

Its product portfolio is unique in the world for its complexity and breadth, encompassing passenger information systems, IP surveillance and audio solutions, TCN communications technologies, communications infrastructure and on-board control systems. These offerings are meticulously designed to meet customer specifications and comply with international standards such as EN and UIC regulations.

Our other references

Our client, a leading entity in the financial sector, asked us to conduct a comprehensive penetration test of its web application portfolio.

More info

The electronic ID card system (eObčanka) contains a vulnerability that could potentially lead to identity theft.

More info
WardenSec
WardenSec

Services

Logo

Penetration Testing

Penetration testing is the process where security experts test and evaluate an organization's security practices and systems. The aim is to identify potential weaknesses and vulnerabilities that could be exploited by unauthorized individuals.

Read more
Logo

Incident Response

Under attack? We're here to help. Our experienced incident response team provides containment, threat elimination, and system recovery. Contact us now to minimize damage and get your business back up and running.

Read more
Logo

Security Consulting

Security consulting services provide organizations with expert guidance and advice on improving their security measures. Consultants assess the organization's existing security practices, identify vulnerabilities, and propose solutions to mitigate risks and strengthen overall security.

Read more