-

Wind River Delivers Cybersecurity and Anti-tamper Protections for Mission-Critical Intelligent Systems

ALAMEDA, Calif.--(BUSINESS WIRE)--Wind River®, a global leader in delivering software for intelligent systems, today announced security enhancements to Wind River Studio, a cloud-native platform for the development, deployment, operations, and servicing of mission-critical intelligent systems. Studio enables companies to meet rigorous cybersecurity and anti-tamper requirements, further helping secure devices and systems through development, deployment, and operations.

The steep rise in security threats shows a concerning trend. As new devices become connected, each represents a point of entry that can be exploited by a cyberattack. In 2020, IoT devices were responsible for 32.72% of infections observed in wireless networks, more than twice that in 2019.(1) Industries with higher dependency on software and intelligence-based systems will need to start demanding that security be addressed at every step in an intelligent system’s lifecycle.

“In an intelligent systems world where devices are expected to connect and compute together in near real time, cyber security is a design necessity and no longer a 'nice to have.' This is even more true for mission-critical systems, such as those in the energy, aerospace and defense, and industrial sectors. Recent research with executive leaders in these sectors has shown us that companies on a successful path with their intelligent systems were twice as likely to have built-in deep cyber protections for their systems than any other group,”(2) said Cyra Richardson, chief product officer, Wind River. “Security must be taken seriously – the only way to do that is to be proactive. With billions of new devices constantly connecting locations around the world, the attack surface is staggering. It will be important for solution builders, both hardware and software, to be thoughtful stewards and strong advocates for cybersecurity in order to deliver trustworthy compute infrastructure.”

The latest version of Wind River Titanium Linux, developed by the Wind River technology protection and cybersecurity group Star Lab, offers a robust Linux system-hardening and security capability and is available on the market for operationally deployed Linux systems. Key features for Titanium Linux include secure boot, anti-tamper protections, and the ability to simplify mandatory access control (MAC) policy creation. To further address security problems across multiple industries and geographies, Titanium Linux security controls also map to key IoT security guidelines, such as NIST IoT cybersecurity-related initiatives; OWASP IoT security projects; IoT Security Foundation protocols; and guidance from the European Union Agency for Cybersecurity, ETSI, GSMA, and several others.

Designed using a threat model presuming an attacker will gain root (admin) access to a system, Titanium Linux maintains the integrity and confidentiality of critical applications, data, and configurations while assuring operations. Titanium Linux hardens the kernel against attack while enforcing MAC on customers’ applications and data. Even if an attacker exploits the system and gains administrative access, they still cannot extract or maliciously modify sensitive data and code.

Additional key security capabilities that Wind River Studio enables include:

  • Support in preventing the accidental release of vulnerable code using industry-leading code scanning and analysis tools. Capabilities include code coverage analysis, static analysis, both quick and deep code scan, and secure container management.
  • Cloud and device attestation based on x.509 certificates and secure secret storage to mitigate person-in-the-middle attacks that would leak customer, device, and mission-sensitive data.
  • Hardened Linux kernel to prevent tampering and reverse-engineering attacks on the Wind River Linux kernel, sensitive applications, and data. This includes prevention of stack overflows, heap overflows, information disclosure (zeroing freed memory), and kernel overwrite. The hardened kernel uses two additional techniques to thwart exploits: kernel address space layout randomization (KASLR) to limit injection attacks and hardware segregation to limit modification of kernel memory.

Wind River is recognized as #1 in edge compute OS platforms. The company has four decades of experience powering secure, safe, and reliable mission-critical systems across industries, this includes software in over 600 programs in more than 100 civilian and military aircraft. This experience helps Wind River understand the evolving threat landscape and support customers in following well-established information security principles to help ensure that data is protected at every phase of the lifecycle, and at every stage — from boot time, throughout use, in transit, and at rest.

About Wind River

Wind River is a global leader in delivering software for intelligent systems. The company’s technology has been powering the safest, most secure devices in the world since 1981 and is found in billions of products. Wind River offers a comprehensive portfolio, supported by world-class global professional services and support and a broad partner ecosystem. Wind River software and expertise are accelerating digital transformation of mission-critical intelligent systems that will increasingly demand greater compute and AI capabilities while delivering the highest levels of security, safety, and reliability. To learn more, visit Wind River at www.windriver.com.

(1) Nokia Threat Intelligence Report 2020
(2) Forbes/Wind River, “Characteristics of Intelligent Systems,” 2021

Wind River is a trademark or registered trademark of Wind River Systems, Inc., and its affiliates. Other names may be the trademarks of their respective owners.

Contacts

Jenny Suh
Wind River
510-749-2972
jenny.suh@windriver.com

Wind River


Release Versions

Contacts

Jenny Suh
Wind River
510-749-2972
jenny.suh@windriver.com

More News From Wind River

Wind River and Hyundai Rotem Advance Industrial Rail Systems with a Modern Software Development Environment

ALAMEDA, Calif. & SEOUL, South Korea--(BUSINESS WIRE)--Wind River, an Aptiv company and global leader in delivering software for the intelligent edge, today announced that Hyundai Rotem, a leading provider of industrial rail and smart logistics solutions, will use Wind River® Studio Developer to modernize and automate its railway system software development environment. Building on a 30-year relationship as a longtime VxWorks® customer, Hyundai Rotem will expand its use of Wind River solutions...

Wind River Collaborates with ServiceNow to Launch AI-Ready Private Cloud Solution with Intelligent Automation and Lifecycle Management

ALAMEDA, Calif.--(BUSINESS WIRE)--Wind River, an Aptiv company and global leader in software for the intelligent edge, today announced a new solution that allows enterprises to host the ServiceNow AI Platform within their own data centers. Enabled through Wind River® Cloud Platform, the offering allows organizations to deploy, scale, upgrade, and manage ServiceNow applications on-premises — providing enhanced privacy, data governance, and operational control across a wide range of industries an...

Wind River Selected by Vodafone for Open RAN Deployments Across Europe

ALAMEDA, Calif.--(BUSINESS WIRE)--Wind River, an Aptiv company and global leader in delivering software for the intelligent edge, today announced that Vodafone has selected Wind River® Cloud Platform as the containers-as-a-service (CaaS) layer for its Open RAN deployments across Germany and other European countries. This latest collaboration marks a significant expansion of Vodafone’s Open RAN footprint, reinforcing its commitment to building a more open, flexible, and energy-efficient network...
Back to Newsroom