Onekey Enables Continuous Firmware Monitoring
The Düsseldorf-based cybersecurity company Onekey has developed digital twin technology that enables automated scans to monitor firmware around the clock. Onekey's monitoring system reanalyzes the firmware daily to ensure continuous security throughout its entire lifecycle. When new vulnerabilities arise, the constantly updated database and enhanced detection capabilities alert users to critical developments that could compromise a product’s security.
“Manufacturers must know which software components are included in their products and which new vulnerabilities arise in order to react quickly and effectively protect their systems," CEO Jan Wendenburg said.
As part of a modern firmware monitoring approach, a product’s firmware is continuously monitored, not just analyzed once. The goal is to automatically detect emerging security vulnerabilities in software components and assess their impact on existing products.
First, a detailed analysis of the firmware is conducted. This process identifies all the software components contained within the firmware and creates a structured software bill of materials (SBOM). Based on this information, dependencies within the software supply chain can be transparently mapped.
Next, the SBOM is continuously compared against global vulnerability databases. As soon as new security vulnerabilities are published, for example in an open-source library, it can automatically be determined whether an affected product contains the vulnerable component.
Onekey’s CRA Fast Start program provides continuous monitoring throughout the entire product lifecycle. This program enables manufacturers of connected devices, machines and systems to rapidly and structurally assess compliance with the Cyber Resilience Act.
