• Contact
  • Customer Portal
  • Partner Portal
  • Jobportal
  • Search
  • DE
LogoGenua Logo
  • Solutions
    IT Security Solutions

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Firewalls & Gateways

      • High Resistance Firewall genugate
      • High Resistance Firewall genugate Virtual
      • Firewall & VPN-Appliance genuscreen
      • Industrial Firewall genuwall
    • VPN

      • Firewall & VPN Appliance genuscreen
      • High-Speed VPN Appliance genuline
      • Adva FSP 150-XG118Pro
      • Highly Secure Certificate Solution genutrust
    • Remote Maintenance

      • Remote Service Solution genubox
    • Mobile Working

      • Comprehensive Security Solution genusecure Suite
      • VPN Software Client genuconnect
      • VPN Software Client genuconnect Enterprise
      • Zero Trust Application Access genusphere
      • ECOS SecureBootStick SX
    • Diodes

      • Data Diode cyber-diode
      • Data Diode vs-diode
    • Internal Network Security

      • IDS & IPS cognitix Threat Defender
    • Central Management Station genucenter

      • Central Management Station genucenter

    Comprehensive Security Solution genusecure Suite

    Comprehensive solution for workplaces complient with the classification level German VS-NfD
    [Translate to English:]
  • Fields of Use
    Fields of Use

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Public Sector

      IT Security Solutions for Authorities and Public Institutions

    • Critical Infrastructure

      Protection of Critical Infrastructures and Sensitive Systems

    • Defense

      IT Security for Military Networks and Data Communications

    • Classified Industry

      IT Protection for Projects with Confidentiality Requirements

    • IT Security for Mechanical and Plant Engineering

      IT Security for Networked Machines and Systems

    Fotocollage zur High Resistance Firewall genugate (Verwendung nur für die Presse)

    Our sales team will be happy to answer your enquiries. Let us advise you!

    Get in Touch

  • Service & Support
    Service & Support

    Contact

    + 49 89 991950-0info@genua.deContact us
    • IT Security Services

      On-site Support, 24/7 Hotline and Regular Update Services

    • Trainings

      Product and Solution Trainings for Your Team - Practical and Up-to-date

    • Hacking Bootcamp

      Improve the Defence of Your Systems and Get to Know the Techniques of Real Hackers

  • Topics & Trends
    Topics & Trends

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Topics

      • Security by Design
      • Zero Trust
      • AI Security
    • Knowledge Base

      Case Studies, White Papers, Specialist Articles, Interviews and Insights from the IT Industry

    • Research Projects

      Whether it's Post-Quantum Cryptography or a Secure Cloud - Here You Will Find an Overview of our Current Research Projects

  • Partners
    Partners

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Sales Partner

      Benefit from the expertise of our qualified Sales Partners

    • Partnerlocator

      Find your genua Sales Partner in our overview

    Three employees in a sales dialogue

    In our Partner Portal we provide services to support you in your sales activities.

    To the Partner Portal

  • Career
    Career

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Working at genua

      Start Your Career with the Leading IT Security Specialist

    • Vacancies

      Our current vacancies at all locations

    • Speculative Application

      Send us your application now.
We look forward to hearing from you.

    Two genua employees engrossed in a cheerful conversation

    Start Your Career now at the Leading IT Security Specialist genua

     Career site

  • About Us
    About Us

    Contact

    + 49 89 991950-0info@genua.deContact us
    • Facts & Figures

      Milestones in genua's Success Story: a Look at the Figures

    • News

      The Latest News on Products and Company Updates

    • Trade Fairs & Events

      Meet us and Our Experts at the Most Important IT Security Events

    • Press & Media

      Press Releases and Media Downloads

    • Trainee Firm genufix

      Fast & Free Help for Charitable and Social Organisations in and Around Kirchheim near Munich

    • genukids

      In-house Childcare for Employees and Residents of Kirchheim

  • DE
  • Solutions
    • Firewalls & Gateways
      • High Resistance Firewall genugate
      • High Resistance Firewall genugate Virtual
      • Firewall & VPN-Appliance genuscreen
      • Industrial Firewall genuwall
    • VPN
      • Firewall & VPN Appliance genuscreen
      • High-Speed VPN Appliance genuline
      • Adva FSP 150-XG118Pro
      • Highly Secure Certificate Solution genutrust
    • Remote Maintenance
      • Remote Service Solution genubox
    • Mobile Working
      • Comprehensive Security Solution genusecure Suite
      • VPN Software Client genuconnect
      • VPN Software Client genuconnect Enterprise
      • Zero Trust Application Access genusphere
      • ECOS SecureBootStick SX
    • Diodes
      • Data Diode cyber-diode
      • Data Diode vs-diode
    • Internal Network Security
      • IDS & IPS cognitix Threat Defender
    • Central Management Station genucenter
      • Central Management Station genucenter
  • Fields of Use
    • Public Sector
    • Critical Infrastructure
    • Defense
    • Classified Industry
    • IT Security for Mechanical and Plant Engineering
  • Service & Support
    • IT Security Services
    • Trainings
    • Hacking Bootcamp
  • Topics & Trends
    • Topics
      • Security by Design
      • Zero Trust
      • AI Security
    • Knowledge Base
    • Research Projects
  • Partners
    • Sales Partner
    • Partnerlocator
  • Career
    • Working at genua
    • Vacancies
    • Speculative Application
  • About Us
    • Facts & Figures
    • News
    • Trade Fairs & Events
    • Press & Media
    • Trainee Firm genufix
    • genukids
  • Contact
  • Customer Portal
  • Partner Portal
Displaying results 113 to 128 of 211.
Results per page:
pages 93
press 48
knowledgebase 37
news 17
product 16

The service offer of genua at a glance

Services Service for our IT security solutions is provided directly by genua or our trained sales partners. We can provide you with support for all of your security needs. In addition, we offer a 24/7 hotline and a regular update service. We would also be happy to put a custom service package together for you. Your advantages: The IT security systems run faultlessly and are always up-to-date, you save the cost for employing highly qualified administrators – and can concentrate on your actual core business. Download Service Flyer Powerful IT security 24/7: An Overview of genua's Service Offer Security System Management Using strongly encrypted Internet connections, we constantly monitor our systems installed within your network to ensure complete IT security. We carry out all maintenance work and keep our systems up to date at all times. Should a system nevertheless malfunction, we will know immediately and take remedial action straight away. System Management If you opt for the comprehensive system management, you don't need to take care of anything else. We have more than ten years experience with unix-based system management and TCP/IP networks. Because we have excellent knowledge of external systems based on AIX, Solaris, Linux and the BSDs, we can take charge of your complete network administration: the construction as well as the configuration of the systems, the setting of backup procedures and continuous monitoring, up to the import of upgrades and installation of new software and hardware. In addition, we provide you with comprehensive support for IT security, system enhancements and system changes. Hotline Service Just call us or send us an email – you will get qualified support for our IT solutions immediately. Instead of wasting time with long formalities we start solving the problem. A 24/7 hotline service in German or English is optionally available. Contact Us Update Service Our update service guarantees automatic supply of all new versions. In addition, you have access to our complete patch database. This means that your systems are always up to date. Visit Customer Portal Hardware Support For our hardware we provide Germany-wide next business day replacement service: If one of your appliances breaks down, you will receive an identical exchange unit on the next working day. We also ship exchange units to international locations, but due to shipping restraints cannot guarantee delivery until the next working day. Depending on the hardware model, this service is free up to three years after purchase. Individual Software For Customized IT Security When standard solutions cannot cover important processes or can fulfil requirements only inadequately, the development of customized software is the right approach. Sometimes customized software is called for: When standard solutions cannot cover important processes or can fulfil requirements only inadequately, the development of customized software is the right approach. In the field of IT security, we guarantee that, upon completion of the project, genua’s customized solutions will precisely meet your requirements profile. We can make this commitment to our customers, as we are able to draw upon many years of expert knowledge. The method we follow in projects requires a regular exchange with the users and thereby eliminates the possibility of undesirable developments. Advantages of Customized Software Development with genua Exact implementation of your requirements Regular tests and acceptance of important development steps Comprehensive support starting with the design all the way to ongoing support Our sales team will be glad to answer your questions. Contact Us Customer Statements on the Services of genua The security of the company network and fault free operation of the global remote maintenance of our print machines have top priority in manroland’s IT. This can be ensured through the very proactive and flexible, reactive service by genua. Karlheinz Huber manroland Even though firewalls and VPN systems only form a part of our complex security strategy, it was extremely important for us that the hardware offers a high potential for integration and that our partners have extensive expertise both as a solution and as a service provider. Therefore we are pleased to have found the right solutions for our needs with a company such as genua, giving us the optimal strategic preparation we require. Andreas Braunmiller RTL 2 We can rely on genua’s service at all times. We receive quick and competent assistance if we have any queries. They not only provide us with solutions but are also always there with useful background information. I can recommend genua every time. Martin Marshall Schreiner Group We have been working with genua since the first genuboxes came on the market. Since then, genua has helped us to develop a complex system linking and providing Internet access for our sites. This collaboration is characterized by a high level of technical expertise and extraordinary helpfulness. The comprehensive and reliable service provided by genua enables us to operate our IT systems securely. Rüdiger Schwan Julius Kühn-Institut genua has been reliably meeting our IT security needs since 2004. The genua Team has always shown a high level of competence and engagement, whether they were developing the first security policy or implementing the rigorous Bavarian Administration’s network guidelines. System modifications and extensions were technically sound and implemented quickly, pleasantly and with a minimum of trouble. genua is very recommendable. Walter Dittrich Ansbach District Office Do you need more information? Contact Us

IT security for the protection of classified information

IT Security Partner for the Protection of Sensitive Data up to German Security Level RESTRICTED Anyone who accesses data classified as RESTRICTED while in branch offices or while traveling must be able to count on absolute confidentiality. A strong IT security partner is essential here. Government organizations and companies in industries with an obligation to maintain secrecy that need to satisfy security requirements up to the classification level German VS-NfD use appropriate IT applications from genua. These work not only with the strongest encryption algorithms but are also manufactured exclusively in Germany. Both the use of stationary IT systems and devices as well as flexible work via smartphone and tablet thereby satisfy the highest security criteria upon connection to RESTRICTED networks. More Information Whitepaper: Highly secure remote access to classified networks (PDF) Reasons Why IT Security Made in Germany For us, the label "IT Security Made in Germany" means combining quality, performance and service at a world-class level with a company culture whose pillars are integrity, customer orientation, sustainability and loyalty to location. Maximum Security genua meets the highest national and international security standards, a fact documented by, among other things, certificates and approvals. Our VPN solutions, for example, are approved by the German Federal Office for Information Security (BSI) up to the German classification level RESTRICTED (Classified – For official use only). Stability and Reliability genua considers itself to be part of the IT security ecosystem in Germany. As a company of Bundesdruckerei, we combine long-term, strategic and financial stability with innovation and research intensity. Quality Without Compromise The solutions from genua are developed on the basis of certified quality management processes. Our QM certification verifies the highest quality standards for products, services and processes. Furthermore, genua uses the IT security certificates of the BSI for periodic quality assurance by an external, recognized testing authority. Products Secure IT Infrastructure from genua for the Protection of Classified Data High Resistance Firewall genugate Complete data analysis for maximum network security Certified Approved Firewall & VPN Appliance genuscreen Reliable protection for data transfers and networks Certified Approved High-Speed VPN Appliance genuline Secure high-speed transfer of large amounts of data with FPGA technology Approved VPN Software Client genuconnect Secure connection of Windows devices to internal networks up to classification level German VS-NfD Approved IDS & IPS cognitix Threat Defender High-performance attack detection for reliable protection of IT and OT networks Data Diode vs-diode One-Way Data Transfer in SECRET-Classified Networks Approved Highly Secure Certificate Solution genutrust Highly Secure Certificate Solution Remote Service Solution genubox Secure service access to sensitive networks supports Zero-Trust concepts Central Management Station genucenter Convenient and efficient administration of IT security solutions ECOS SecureBootStick SX Flexible solution for VS-NfD-compliant working in the home office Approved High Resistance Firewall genugate Virtual Virtualized application level gateway for processing classified data Certified Approved Zero Trust Application Access genusphere Secure, browser-based access to shared applications Comprehensive Security Solution genusecure Suite Comprehensive solution for workplaces complient with the classification level German VS-NfD See all IT security solutions Get More Information Would you like to set up a highly secure and sustainable IT infrastructure? Our experts will be happy to help you: ANREDE Mr. Ms./Mrs. Various Keine Angabe Salutation * First Name Last Name * E-Mail * Phone Government Organization or Company * Your Request * For further information on the processing of your personal data, please refer to our data privacy police . Submit Public Sector genuas Solutions for Government Organizations Industry genuas Solutions for Industrial Value Networks Critical Infrastructure genuas Solutions for Critical Infrastructure Organizations Protection of Classified Information genuas Solutions for Projects with Confidentiality Requirements

Welcome to the Hacking Bootcamp

Topics of the genua Hacking Bootcamp In a workshop, the participants slip into the role of an attacker or penetration tester and, using previously introduced tools and methods, attempt to access the critical company data of a fictional company. The target is a realistically depicted virtual company network consisting of approximately 30 systems and constructed with various security zones, servers and client computers. Using a flexible sequence of operations, participants can surreptitiously access the web server, the Wi-Fi, internal web cams or even the general manager’s mobile phone. The elements of the workshop are as diverse as the approach used by real attackers! Other topics include information gathering and scanning for the identification of servers and services as well as web hacking. Here, we show you how confidential information can be read out using clever queries and how Metasploit is used. This is an established framework that identifies security gaps and is used for penetration tests. Participants consider the topic of "password (in)security" in this context as well as phishing tricks, Trojan horses, and attacks on apparently secure SSH and TLS connections. Your Instructor Team Qualified and experienced genua employees serve as instructors in the Hacking Bootcamp. They are at your disposal for the duration of the workshop. Andreas Hempel , Hacker Carsten Arzig , Hacker Raimund Specht , Hacker, OSCP, OSWP At a Glance: Structure of the Hacking Bootcamp Duration & Workshop Times three days, generally from Tuesday through Thursday, daily from 9am until approx. 5:30pm; no later than 4:30pm on the last day Number of Participants no more than six persons Dates English speaking trainings are available on request. If you are interested in German speaking courses, please switch to our German website. Price and Included Services 2,995EUR (net) per person, incl. comprehensive accompanying materials on fundamentals, protective measures, sample solutions and further information, including small snacks, cold and hot beverages as well as three à la carte lunches Training Location genua Training Center , Überrheinerstraße 5, 85551 Kirchheim near Munich (directions) We would also be happy to hold individual workshops on-site. Simply contact us for more information Pleasantly challenging. Great course, highly recommended. Very likeable and competent instructors. Great landscape, lots to do. Your Contact +49 89 991950-906 training@genua.eu Information material IT Security Trainings Flyer Product trainings overview Training Catalog All about genua's product and partner trainings

Service & Support – Reliable IT Security Operations

genua Services Service & Support IT Security Services On-site Support, 24/7 Hotline and Regular Update Services Read more Workshops & Trainings Bootcamps and Product Training at genua Product and Solution Trainings for Your Team - Practical and Up-to-date Read more Workshops & Trainings Change Your Perspective: Join the Hacking Bootcamp Improve the Defence of Your Systems and Get to Know the Techniques of Real Hackers Read more Company Story Contact Headquarter, Training Centers and Locations – Contact and Directions Read more Fields of Use IT Security Solutions for Industry, Critical Infrastructure, Public Sector and Secret Protection Products IT Security Solutions for High Security Requirements

Facts & Figures about genua at a Glance

Milestones of genua’s Success Story: Our Awards VERTRAUENSZEICHEN "IT Security Made in Germany" As a member of the IT Security Association of Germany (Bundesverband IT-Sicherheit e.V.), genua bears the TeleTrusT symbol " IT Security Made in Germany ". AUSZEICHNUNG "Qualified Manufacturer" in the New BSI Approval Process In 2019, genua was the first company to be awarded the manufacturer qualification for the "Qualified Approval Process" of the German Federal Office for Information Security (BSI). AUSZEICHNUNG Innovator of the Year An analysis conducted by the business magazine "brand eins Wissen" and the statistics portal "Statista" named genua "Innovator of the Year" in 2019 and 2018. AUSZEICHNUNG TeleTrusT Innovation Award genua received the TeleTrusT Innovation Award for the cyber-diode Data Diode in 2016. TeleTrusT – the IT Security Association of Germany – is the largest competence network for the protection of IT in Germany and Europe and supports the development of trustworthy IT systems. AUSZEICHNUNG Outstanding Security Performance Award (OSPA) The OSPAs honor outstanding performances of companies and persons from the security industry. In 2016, genua received the award in the "Outstanding Information Security" category. The OSPAs are organized by World Excellence Awards Limited in collaboration with security associations and groups from numerous countries. AUSZEICHNUNG Innovative Through Research In 2016, the Donors' Association (Stifterverband) awarded genua the "Innovative Through Research" seal. The Donors’ Association is one of the largest private sponsors of science in Germany. With the seal, the association recognizes research-oriented companies for the responsibility that they assume for the state and society. Quality management system genua is certified according to ISO 9001 & IEC 62443-4-1 The relevant certificates are available here. For basic information, we recommend the TÜV SÜD certification marks overview . Certificate Head Office Scope: Development, sales, support, maintenance and operation of IT security products, provision of IT services Certificate IEC-62443-4-1 Scope: Validates the secure product development lifecycle for industrial automation systems Certificate Office Berlin Scope: Development, distribution, maintenance and operation of IT security products, provision of IT services Certificate Office Leipzig Scope: Development, distribution, maintenance and operation of IT security products, provision of IT services Business Reports Since the 2023 financial year, genua GmbH has been fulfilling its reporting obligations as part of group reporting.

genusecure Suite Product Training

Product Trainings genusecure Suite The genusecure Suite enables VS-NfD-compliant mobile work and remote work without compromising usability or flexibility. Public sector organizations and companies can provide a secure workspace anytime and anywhere, where modern technologies simplify workflows and minimize the risk of data loss on all devices. Training Types genusecure Suite Administrator Training This 3-day training is designed for administrators who already have experience with genua products, particularly genuscreen and genucrypt, and who will install, configure, and manage genusecure Suite in complex environments or plan its deployment. Training Content Introduction Overview of VS-NfD workspace Software components of the suite Utimaco DiskEncrypt Introduction Installation of the Management Center Policy configuration for VS-NfD-compliant client setup Recommendations: Boot Buddy, certificate renewal Debugging genua genuconnect Basics of genucenter Installation of genuscreen Application of filters VPN definitions VS-NfD compliance genuconnect Introduction Installation Operation VPN and TND configuration Target Audience Administrators who will install, configure, and manage the genusecure Suite or plan its deployment. Prerequisites Previous participation in genuscreen Administrator Training Basic knowledge of IT security and network technologies recommended Duration, Participants & Location 3 days, Tuesday to Thursday, 09:00 – 17:00 Maximum 8 participants Training location: Kirchheim near Munich (no online alternative) Certification Certified genusecure Suite Administrator Venue and Costs Training takes place in genua’s training rooms in Kirchheim near Munich The fee includes training materials, beverages, and lunch (plus VAT) Training Duration Price genusecure Suite Administrator Training 3 days 3085 Euro Comprehensive Security Solution genusecure Suite Comprehensive solution for workplaces complient with the classification level German VS-NfD Your Contact +49 89 991950-906 training@genua.eu Information material IT Security Trainings Flyer Product trainings overview Training Catalog All about genua's product and partner trainings

genuscreen & genucrypt Product Training

Product Trainings genuscreen & genucrypt In the combined training courses for the Firewall & VPN Appliance genuscreen and the VPN Appliance genucrypt, we will show you how to correctly use and administrate the systems. Our training courses always deal with the current releases of the security solutions and are held at our company headquarters in Kirchheim near Munich. Please note that we offer our regular training dates only in German. English speaking courses are available on request. Training Types genuscreen & genucrypt Administrator Training First, the structure and function of genuscreen and genucrypt are explained in detail, then we cover installation, configuration and support. Other topics include high availability operation in clusters and the administration of multiple systems in complex environments using the genucenter Central Management Station. As a participant, you should have basic knowledge of UNIX and TCP/IP. At the end of the course, you can take an online test to become a Certified genuscreen Administrator. Venue and Costs The training courses take place in genua’s training rooms in Kirchheim near Munich . We also offer the genuscreen Administrator Training in Cologne and Berlin . English speaking trainings are available on request. If you are interested in German speaking courses, please switch to our German website. Firewall & VPN Appliance genuscreen Reliable protection for data transfers and networks Certified Approved Your Contact +49 89 991950-906 training@genua.eu Information material IT Security Trainings Flyer Product trainings overview Training Catalog All about genua's product and partner trainings

Cognitix Threat Defender Training

Product Trainings Cognitix Threat Defender The innovative solution cognitix Threat Defender goes beyond intrusion prevention and builds a second line of defense in the network. It complements your firewall solutions that control and secure data traffic at the interfaces. In this training, we teach installation, setup and integration of the product into the network. We also explain how to configure global rules and advanced correlation scenarios. We then go into detail about the various components of the Threat Intelligence system. Training Content Installation/Configuration Network analysis Integration into the network System update Structure and functions Advanced correlation scenarios Threat Intelligence System maintenance and logging Participants Administrators who install, configure, and support cognitix Threat Defender or design their use Prerequisites Good knowledge of UNIX, TCP-IP, and the administration of complex network environments Information About the Event The training course takes place in genua’s training rooms in Kirchheim near Munich . English speaking trainings are available on request. If you are interested in German speaking courses, please switch to our German website. Related Products IDS & IPS cognitix Threat Defender High-performance attack detection for reliable protection of IT and OT networks Your Contact +49 89 991950-906 training@genua.eu Information material IT Security Trainings Flyer Product trainings overview Training Catalog All about genua's product and partner trainings

Press & media information from genua GmbH

Press & Media Information From genua In our press & media area you will find news from the company as well as graphic and photo material for download. Press Contact +49 89 991950-527 michael_eckstein@genua.eu Contact us Follow us on Latest press releases

Hitachi – A Fast Response Center for the Energy Transition

Case Study 21.11.2024 Remote Maintenance for the Energy Sector Hitachi Energy – A Fast Response Center for the Energy Transition The availability of energy technology equipment is becoming increasingly important for the energy industry. That's why operators and service providers have been working with remote maintenance for years. However, due to the increasing complexity of networks and the increasing threat of cyberattacks, the security of such systems is increasingly coming into focus. The example of Hitachi Energy's Grid Automation Service shows how remote maintenance can be operated safely and efficiently: Between 80 and 100 support cases are processed there per month, many of them with remote access. Headquartered in Switzerland, Hitachi Energy plans and implements substations, high-voltage direct current transmission connections, transformer stations and numerous other energy supply systems. Through its Grid Automation Service, the company also maintains energy technology facilities worldwide. Hitachi Energy uses genubox technology from genua GmbH for secure remote access to customer systems. Project Details The Customer: Hitachi Energy, headquartered in Switzerland, plans and realises high-voltage direct current transmission systems, substations, transformer stations and numerous other energy supply systems. The Task: Support for Hitachi customers worldwide who require support for alarms and malfunctions or machine monitoring, remote diagnostics or remote access scenarios. The Solution: The genubox secures remote access to the customer’s systems and allows the user complete connection control into his network. It is perhaps the first time since industrialization that an essential pillar of the economy in Germany has changed as dramatically as the energy landscape is currently doing. Several parallel drivers are accelerating the change: From the phase-out of nuclear energy, to the gas shortage at the beginning of the Russian war of aggression on Ukraine, to climate change, these events are leading to unprecedented growth in decentralized, energy sources and new, decentralized distribution grids. And with them, the demands on electricity producers, grid operators and suppliers are growing. A technology leader in the energy industry is Hitachi Energy. Headquartered in Switzerland, the company employs around 45,000 people in 90 countries and generate business volumes of around $13 billion USD. Customers in the energy, industrial and infrastructure sectors all face the same challenge: to drive the energy transition towards a climate-neutral future in an increasingly complex world without losing track. This can only be achieved with intelligent concepts, embedded in a secure, largely automated and digitized structure. "We are further developing our customers' energy systems to make them more sustainable, flexible and secure, while at the same time aligning them with economic, ecological and social values," says Michael Joos. He is head of the Collaborative Operations Center, or COC for short, in Baden in Switzerland. "Automation and flexibility are particularly important at our Grid Automation business unit. One aspect is becoming increasingly important for our customers: the availability of the systems and networks," adds Joos. To maximize this, Hitachi Energy's Grid Automation Service focuses on six performance areas: Intelligent spare parts supply and supply Software and firmware support Tailor-made training Tools and know-how for preventive maintenance Cyber security solutions and Fast and flexible support in the event of service. More than 40 engineering and service centers are strategically located around the globe to address these issues and keep the automation and communication systems of users from more than 140 countries running. Equipment and system training ensures that operating personnel can respond quickly and efficiently. Where this is not enough, Joos and his colleagues identify and analyze the causes of equipment failures and propose effective measures. They advise on spare parts, upgrades and retrofits, as well as cybersecurity issues. Short Response Times Required genubox XSi from Genua is a highly secure VPN solution that has been specially developed for use in sensitive Industry 4.0 environments. It enables secure networking and remote maintenance of machines and systems through encrypted data transmission. Time is money. Every user has this saying in the back of their minds when things get stuck in the system. At the heart of rapid troubleshooting and root cause analysis is the Customer Connect Center system, in which each customer is routed to the right advisor. Dragan Klisaric, Global COC Manager and thus responsible for all Collaborative Operations Centers worldwide, describes the structure: "Comparable to our COC here in Baden, there are six other centers that are located in the different time zones in such a way that our experts are available around the clock. In the support network, everyone works together, we exchange know-how with each other and work together according to the follow-the-sun concept." Many customers, especially those in critical infrastructure, use service level agreements that define very fast response times. Depending on the contract, this can be one or two hours, up to a first response of 15 minutes. "In order to achieve such response times, various conditions must be met. First of all, we work together with the local units. You already know the systems very well and do not have to spend a lot of time familiarizing yourself with them. When a customer calls us, we don't have to look up what they might have bought from us. Instead, we know exactly who is on the other side, what their system is and where the problems could lie," says Klisaric. The View into the Complex Dragan Klisaric (right) is Global Manager of the Collaborative Operations Center and Michael Joos (center), Head of the COC in Baden, Switzerland. Numerous remote maintenance processes for Hitachi Energy customers are managed from here with the help of the genubox. In order to be able to help users quickly in the event of an emergency, the engineers and technicians in support depend on getting information very quickly. What does it look like in the system, what alarms are there, how loud events in logbooks, can information be downloaded quickly, log files, fault recorder entries – these are typical questions that used to have to be clarified by phone and e-mail. "Fortunately, those days are over," says Joos, adding: "The crucial thing is that we now have a secure way to access the customer system directly. Our service level agreements define who can access, when can be accessed, which systems can be accessed. Our partner genua ensures that the whole thing runs safely with the genubox." The subsidiary of the German Bundesdruckerei Group is an IT security company and expert when it comes to protecting complex and critical digital infrastructures. In addition to consulting and software applications, it is also special hardware that can be used to securely implement remote access to systems. "genubox is the answer to our customers' legitimate security questions," says Joos. "It solves our challenges in terms of remote engineering, cyber security, remote asset access, or connection to the Internet. We use it as a service box and as a platform for different functionalities." If all maintenance connections run through the genubox, the system is safe and users retain full control. Access from the outside is carried out on a port- or application-specific basis to the target system, which is isolated from the rest of the system. Dedicated rendezvous points are available. They are located, for example, in the cloud or in the so-called demilitarized zone. These are computers that lie between two networks and separate them from each other by strict access rules. All Accesses Always at a Glance The structure of remote maintenance setup at Hitachi Energy: Without the genua solution, secure external access to customer systems would not be possible. Between 80 and 100 support cases are processed each month - around 5 % of them remotely. Nevertheless: "When talking to customers, the question arises again and again: Is this safe enough? Even in cases where we have been able to convince our partners that the system is secure and that there are significant benefits, uncertainty often remains. This goes so far that plant access is limited to individual Hitachi Energy colleagues, otherwise no one is allowed to enter the plant remotely," says Joos. Here, too, the software and authentication logic used offers a solution: Common identity and access management systems can be connected and thus users and their rights can be managed easily and centrally. In addition to connection control, monitoring is helpful for very sensitive areas: With the help of genubox, users can follow all maintenance work live via the user interface and create video recordings for revision-optimized documentation. This means that the maintenance action, access time, destination and accessing instance are monitored in real time and documented at all times. "We are very satisfied with the genua technology and the cooperation with our colleagues. By using it, we ensure to our customers that remote access is only provided by authorized personnel and can show a rapid response that deserves the name 'rapid response'," says Klisaric. With the help of genubox, Hitachi Energy's Grid Automation business unit can tailor its service agreements to the needs of its customers. In emergencies or planned business interruptions, repairs are carried out quickly so that the affected system can quickly take its place in the power grid and the energy transition. Author: Frank Jablonski, mylk+honey, Würzburg. Read more about our Remote Service Solution genubox . Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Remote Maintenance Critical Infrastructure Share Article Related Links Remote Service Solution genubox Secure service access to sensitive networks supports Zero-Trust concepts Back to Overview

Secure Remote Maintenance for Critical Infrastructure

Case Study 18.04.2021 A Secure Solution, Comparable to the Analogue World Remote Maintenance for Critical Infrastructure: Made Possible through Security Remote maintenance for critical infrastructure? A sensitive matter. The IT systems of the German Pension Insurance Association process medical and social data and are classified as critical infrastructure. The German Pension Insurance Association shows how remote maintenance that needs to satisfy the highest security requirements can be achieved. Parts of the IT systems of the German Pension Insurance Association are classified as critical infrastructure and have especially high protection requirements. "In our organizational area, approximately 50 different manufacturers would like to access installed systems via the Internet to perform remote maintenance. Under critical infrastructure conditions, this is a major challenge with respect to security," says Tobias Birk, Director of Security of the German Pension Insurance Association Baden-Württemberg (Dt.Re.Vers.), as he describes the initial situation. The administrators of the German Pension Insurance Association (specifically: Northern Bavaria, Bavaria South, Swabia, Rhineland-Palatinate, Hesse, Saarland, Baden-Württemberg) operate a joint computer center in Würzburg. This supplies the administrators, spread over five federal states, with a number of regional centers, branch offices, socio-medical services as well as rehabilitation clinics and therapy centers. A wide range of different IT and technology solutions are operated at these locations, from the laboratory equipment in the clinics to the elevator controls in the building technology and office IT for the administration of the insured. "We need a secure solution, comparable to that in the analog world," says Birk, as he describes the challenge. He explains this using the once-common on-site deployment of service technicians as an example. The technician first had to register in person at the reception desk. An IT employee of the German Pension Insurance Association checked his identity and authorization and accompanied him to the system. Every step of the technician was personally monitored. "Unauthorized persons had no chance. Even if they made it from the parking lot to the reception desk, they could not enter the well-secured building unsupervised,” formulates the IT security specialist, explaining the need for a secure remote maintenance solution. Requirements of a Critical Infrastructure Company "Remote maintenance over external networks or by third parties is especially critical," according to the German Federal Office for Information Security (BSI) in chapter "Securing remote maintenance" of the IT-Baseline-Protection Catalog (IT-Grundschutz-Katalog). The law for increasing the security of information technology systems (IT Security Act), which went into effect in 2015, prescribes how critical infrastructure operators implement IT security in accordance with the "state of the art." The BSI specifies the basic rules for securing remote maintenance access points and describes the necessary security functions that should be fulfilled. "The BSI rules were for us the basis of the functional specification of the remote maintenance solution. We placed special emphasis on the tamper-proof recording – including by video – and the implementation of a four-eyes principle. In addition, our employee should be able to interrupt the remote maintenance session at any time," says Birk as he lists the requirements. First, a market analysis and evaluation of relevant remote maintenance solutions was performed with the involvement of an external, neutral service provider. In the end, two providers were left to choose from. In a proof of concept, the solutions of both providers were simulated under real conditions with three clients and intensively tested for approximately three months. The PoC was performed according to the typical cooperation method in the joint computer center of the German Pension Insurance Association in Würzburg together by the IT from the German Pension Insurance Association Baden-Württemberg and the specialists of the German Pension Insurance Association Rhineland-Palatinate and Bavaria South. The decision was made in favor of the remote maintenance solution of the German IT security company genua GmbH. The tests confirmed that the solution satisfied all essential criteria and also proved effective in operation. The central security element of the solution from genua is the so-called rendezvous concept. With this approach, no unilateral remote maintenance access is permitted into the network of the German Pension Insurance Association. All external connections are made via a rendezvous server that is installed in a demilitarized zone (DMZ) next to the firewall. Both the external maintenance technician and the internal employee of the German Pension Insurance Association establish connections to the server at an agreed time. These are created as strongly encrypted and authenticated point-to-point connections via a VPN tunnel. A direct maintenance connection is created only once the rendezvous has been established on the server. No direct network coupling occurs. Through the rendezvous solution, the German Pension Insurance Association retains full control of the maintenance access in its networks. The remote maintenance solution was implemented together with genua and was set up within two weeks. The preconfigured and tested elements from the proof-of-concept could be used in the solution. "With the genucenter as a management station, we administrate all remote maintenance elements from a central point. As a result, it is relatively simple to keep an eye on the status or to integrate additional hardware," reports Tobias Birk. The IT security specialist works in Stuttgart, the computer center is in Würzburg and the systems that are to undergo remote maintenance are in Bavaria, Baden-Württemberg, Rhineland-Palatinate, Saarland and Hesse. For these distributed structures, the German Pension Insurance Association required a differentiated role concept to satisfy the needs of multiple legally independent users. In the event of an audit, the various security officers should only obtain access to the data of their client. To complete the remote maintenance solution, the German Pension Insurance Association had still further remote desktop requirements. These included the possibility of making the option of a data transfer configurable so as to be flexible here. "genua accepted the change requests and implemented them according to our wishes," says Birk. "The assistance and support from genua are good. If necessary, we always have a contact person and not just an anonymous web-ticket system. If it is urgent, we can use additional escalation levels." The participating employees from the German Pension Insurance Association first had to familiarize themselves with the new system. The consensus was ultimately very positive because the new solution is uniform for all applications. There is no longer a range of different methods and user interfaces. In addition, each admin can adapt the necessary details for his area. The SSH connection can thereby be established using tools such as Putty or a viewer from genua. The external maintenance access can also be restricted to certain areas or individual systems via the central management station. With respect to time, use can also be restricted to certain times of day. Lastly, it is possible to limit the remote maintenance session in terms of duration. "This is equivalent to the inspections once performed by a guard service. We define an electronic guard book and know at all times who is still present and what they are doing," Birk says in summary. This central solution is operated within the South-Southwest region of the German Pension Insurance Association / in the Würzburg computer center (RZW-Verbund) according to the cooperation model that prevails here. In concrete terms, this means that the German Pension Insurance Association Baden-Württemberg and the German Pension Insurance Association Rhineland-Palatinate share the operation. Contact to the external manufacturers and service providers is made available via a single point of contact. The concept is fully transparent. All authorized users are registered in an order database. The respective authorizations of each user are also stored here. The external partners initially responded very apprehensively to the new solution. Once reference was made to the critical infrastructure requirements, however, there was more understanding. Ultimately, the extremely streamlined solution could convince. "Manufacturers and IT service providers do not need to install any additional software. They download a "portable client," load the predefined configuration provided by the German Pension Insurance Association and the client is functional. And that’s it," says Birk. A Secure Solution for All Critical Infrastructure Requirements This solution with the rendezvous concept for integrating external access has proven in practice to be fast, reliable and secure for the German Pension Insurance Association. The security from the analog world could be successfully transferred to the critical infrastructure. "The remote maintenance solution is simple and secure. And when it’s simple, it’s also accepted. Even if a laptop belonging to an external service technician is stolen, the thief will make it only as far as the parking lot in front of the building. The interior of the building itself remains secure. This is security by default," says the head of the German Pension Insurance Association competence team in positive assessment of the security solution. Photo credits: German Pension Insurance Association, Press Office; graphic: genua GmbH Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Public Sector Critical Infrastructure Remote Maintenance Share Article Related Links Remote Service Solution genubox Secure service access to sensitive networks supports Zero-Trust concepts Central Management Station genucenter Convenient and efficient administration of IT security solutions Back to Overview

datenhain GmbH: IT Security Services for Companies

Case Study 27.10.2020 Real-time monitoring of network traffic Keep a Close Watch on Internal Network Traffic Simple IT security solutions used up to now often have weaknesses and cyber attacks remain undiscovered for longer periods of time. IDS/IPS systems therefore make sense but they are complex and costly to administer. The Berlin-based IT service provider datenhain GmbH takes a different approach: With the practical cognitix Threat Defender from genua, data traffic is monitored in real time to detect and defend against dangers within networks, thereby providing additional IT security from behind the perimeter firewalls. "Previous security concepts place the primary focus on keeping attackers out of one's own network. The internal network, on the other hand, is trusted and network traffic is only rarely monitored and analyzed" André Hermbusch , General Manager, datenhain GmbH datenhain GmbH: IT Security Services for Companies For more than 10 years, datenhain GmbH has been advising and supporting small- and medium-sized enterprises on the topics of IT infrastructure and IT security. The problem: increasingly sophisticated and well-concealed attack methods frequently use standard protocols, are often encrypted and not detected by signature-based systems with static rules. Malware can thereby spread in the internal network. This is a current topic in particular for critical infrastructures, development-intensive companies and other highly sensitive areas. "Many of our customers must satisfy compliance regulations with increased security requirements. We therefore searched for a practical and easy-to-integrate solution that would also allow us to keep an eye on internal network traffic," says André Hermbusch. Real-Time Network Traffic Monitoring and Automatic Defense The IT service provider had been searching for a state-of-the-art solution for network analysis. Based on datenhain's experiences, normal network sniffers were no longer adequate for the increasingly complex network relationships and rapidly growing network traffic. The solution needed to above all monitor communication of the end devices with the internet, with internal servers and devices among one another. "We need machine logic that analyzes the network traffic, identifies dangers in real time and automatically implements rules for defending against attacks. Customers often want graphically prepared overviews so that they can immediately zoom in on points of interest," says the General Manager, describing his requirements. While intrusion detection systems (IDS) and intrusion prevention systems (IPS) can detect anomalies in network traffic and automatically prevent attacks, many companies lack the resources and the time to intensively deal with such tools. Real-time reporting with a traffic-light system provides messages about potential danger cognitix Threat Defender Uses Data Analytics and Threat Intelligence The IT service provider became aware of cognitix Threat Defender from genua through a test performed by heise.de. The software solution combines the IDS approach with prevention functions. Using data analytics and threat intelligence, cognitix Threat Defender detects attacks in real time and also offers a platform for the use of AI technologies. "We tested cognitix Threat Defender and were surprised how quickly we received the first real-time overview of the network traffic. Following the base installation of the software, a standard set of rules is already available that provides an overview of the network and the installed devices," says André Hermbusch, describing his first impression. datenhain typically uses cognitix Threat Defender for applications such as detecting the horizontal propagation of malware, e.g., encryption trojans, in normal office networks. In factory halls with technical devices from many different manufacturers, monitoring is performed to determine whether devices contact one another in the event that this deviates from normal behavior. Moreover, the network traffic is divided into classes so as to prevent undesired protocols or to detect undesired traffic such as YouTube or Facebook. Behavioral patterns detection of the network devices cognitix Threat Defender detects the behavioral patterns of the network devices and assigns them defined rules. Previously separate functions, such as network analysis, intrusion prevention, asset tracking and a dynamic policy engine, are thereby merged into a single system. Security Defined Networking Guarantees a High Protection Level Cognitix Threat Defender sets up a self-monitoring, secure network ( Security Defined Networking ) that detects the behavioral patterns of the network devices and assigns defined rules. Previously separate functions, such as network analysis, intrusion prevention, asset tracking and a dynamic policy engine, are thereby merged into a single system. cognitix Threat Defender analyzes the network traffic according to IP and MAC addresses, ports, protocols and applications of OSI layers 2 to 7. Traffic is thereby checked for problematic addresses, domains or file signatures which should be detected and blocked. In addition, an asset database of all devices in the network is created and the communication relationships of the devices examined. The devices are assigned behavioral rules and these are monitored. Any new devices that appear are immediately reported. Real-time reporting with a traffic-light system provides messages about a possible potential danger. Using drill-down reporting, suspicious areas can be considered in greater detail by clicking on a graphical representation of the network traffic. Information such as the live data from the filtered area is thereby available with a one minute advance to examine the participating devices and target addresses. Simple Integration in the Network without Sacrificing Performance "When we come into a company, we first examine the current state of the network to obtain an overview of the existing infrastructure,” reports André Hermbusch. During this process, the network traffic is initially scanned passively and a picture of the "normal state" made. By taking a starting inventory of the network in this way, general weak points and security holes are detected that could be caused, e.g., by configuration errors, network problems or outdated device software. Compared to other IDS systems, the General Manager describes the installation of the software and the integration in the network as being uncomplicated. Integration can be performed without needing to make changes to the network topology. Rules about the "normal behavior" of the network traffic are defined on the basis of the starting inventory. A policy engine manages the rules. They determine how to respond to undesired behavior or acute dangers. If, for example, a device establishes a connection with more than ten hosts within one minute, a rule can ensure that the device is isolated. Based on datenhain's experience, the continuous monitoring of network traffic is a big challenge for performance: "cognitix Threat Defender is a pure software solution. In terms of hardware, all that is needed is – depending on the application – a cigarette pack-sized mini-PC or a powerful server for the real-time analysis of 40 Gbit/s network traffic. The network analysis has only a minimal affect on latency. cognitix Threat Defender achieves nearly switch-level performance." Increased Security: Detect and Eliminate Undesired and Dangerous Traffic André Hermbusch reports that during the initial analysis of the communication relationships, unexpected details regularly emerge. As an example, he mentions a television that establishes a connection with its manufacturer in China every morning or an old production system that has received no security updates in eight years and would be easy to attack. A Windows PC that has not been used in a long time, on the other hand, would be identified as being infected due to its unusual traffic. Also visible was the banned private use of Facebook within a company, which cognitix Threat Defender can prevent through policy rules or greatly slow down in network traffic. André Hermbusch also comments positively on the short release cycles for cognitix Threat Defender for the implementation of customer requests. cognitix Threat Defender takes a big step in early 2020. genua will then offer the security platform on its own hardware which can easily be inserted in networks as an appliance. Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Industry Network Security Threat Detection Share Article Related Links IDS & IPS cognitix Threat Defender High-performance attack detection for reliable protection of IT and OT networks Back to Overview

Satisfied Customers from high security Remote Maintenance Service

Case Study 25.02.2011 Satisfied Customers from Remote Maintenance Service – KASTO Maschinenbau KASTO, a manufacturer of metal saws and storage systems provides rapid service via the Internet with their high security remote maintenance solution Remote maintenance service - KASTO Maschinenbau Their teeth cut through the hardest steel: KASTO metal saws cut steel girders with rapid, precise cuts; aluminium blocks and sheet steel are cut exactly to shape at high speed. The raw materials – which can weigh tons – are fed to the saws directly from fully automatic storage systems. The KASTO Maschinenbau company, based in Achern in Baden-Wuerttemberg, Germany, is specialized in the sawing and storage of metal – from compact systems for small businesses up to full automatics with integrated storage systems – and is the world-wide market leader with over 140,000 customer installations. When customers purchase a powerful sawing machine or a custom storage system they expect rapid service from the manufacturer at all times in order to guarantee problem-free operation. KASTO, which is a mid-sized engineering company with 700 employees, provides this service world-wide – using remote maintenance access via the Internet. This remote maintenance solution allows regular monitoring, quick reaction times and often removes the need for a technician to be deployed on-site. In addition, the solution implemented meets two other important requirements: it is simple to administer and ensures the security of KASTO’s customers’ IT. KASTO produces their sawing machines and storage systems in Germany; the world-wide distribution takes place through foreign subsidiaries. The circle closes once again at the headquarters in Achern, where the customer service for the installed systems is based. Customer queries are taken on and processed by support staff in the central service center. During this procedure customers can choose between three service levels: from a normal maintenance contract over extended support with shortened reaction times – eventually outside normal hours of business – up to "teleservice" with remote maintenance access via the Internet. "With the teleservice, our specialists access the machine control systems by remote access and look for the problem. This can then be resolved immediately in 80 percent of all incidents. And our customers value this quick and cost-effective service without the deployment of a technician on site", explained Josef Schneider, Head of Service at KASTO. A Standardized Solution Replaces a Conglomerate of Remote Maintenance Systems genubox: compact remote maintenance solution KASTO implemented their first remote maintenance connections between their service center and customers’ machines using analogue modems or ISDN, data transfer was encrypted with various VPN (Virtual Private Network) appliances from a number of manufacturers. This led to a conglomerate of different solutions that were time-consuming to operate and administer. The frequency with which errors occurred increased with the complexity and the connections used were slow and expensive. This situation motivated KASTO to introduce a standard solution for the remote maintenance. The central requirements in the specification were: quicker and less expensive data transfer via the Internet reliable IT security for data transfer and access to customer networks simple operation and administration of a large number of connections Tenders were then obtained from a number of manufacturers and evaluated and tested, with the final choice being the remote maintenance solution from genua. The company, which is based in Kirchheim near Munich in Germany, is a specialist in remote maintenance systems and high security firewalls. "The solution from genua met all the specified requirements and could acquire important additional plus points in the area of IT security. The company has many years of experience in this field and as KASTO has to access customers’ networks during remote maintenance, a high degree of security gives the customers the trust they require", explains Thomas Zeller, Managing Director of BWG Informationssysteme. BWG Informationssysteme has supported KASTO for more than 20 years with the implementation and security of their IT infrastructure. The key to the selected solution is the Remote Service Appliance genubox. The system runs on compact, maintenance-free hardware and is installed at the end-points of the maintenance connection; i.e. one appliance at the machine being maintained and one as a central access point at the manufacturer’s service center. A connection via the Internet is then established between the appliance at the machine and the service center appliance. This connection is quick, inexpensive and uses encryption technology to ensure that data transmissions cannot be read by third parties. Secure Access to the Customer’s Network Vollautomatische Lagersysteme werden per Fernzugriff überwacht und gewartet Although the connection via the Internet is reliably protected, access to the customer’s network still touches the sensitive subject of IT security: the sawing machine and the automatic storage system themselves are integrated in the customer’s LAN and KASTO therefore is accessing this network to carry out the maintenance. Dogged resistance from those responsible for the customer’s IT security is to be expected here as every access to the LAN from outside brings with it the risk that it will be misused from malicious third parties. The maintenance concept from genua, however, solves this problem as the direction in which the connection is made is reversed: i.e. all maintenance connections are initiated from the customer’s appliance via the Internet to the service center. It is only after these connections have been established that they can be used by KASTO in the other direction for maintenance access. Many customers leave connections established in this manner permanently open, others only open them for the time-frame in which the maintenance access is to take place. However, it is always the customer who initiates the connection, not KASTO. This is important as it is always easier for customers to know which outgoing connections are being established and therefore this approach is more secure than allowing external access to their network. A further security feature of the genua solution is the encryption procedure used. Communication between the customer’s remote maintenance appliance and the appliance at KASTO uses SSH. In contrast to the widely used IPSec, that basically couples networks, SSH allows communication to be restricted to specific services. This means that with IPSec all computers in network A are generally able to communicate with all computers in network B. However, with SSH, data transfer can be restricted to taking place between the remote machine and the service center – communication with other computers in either network is not possible. Full Access Control for Remote Maintenance Customers All maintenance steps carried out by the service provider are recorded by the genubox and clearly shown on the customer’s local GUI. This means that the customer knows at all times exactly when the teleservice has used the connection and which systems were worked on. "The security of our remote maintenance customers’ IT is not weakened and customers always have control over access. Even customers that have to follow very strict security policies accept this solution and allow us into their networks with the remote maintenance box", says Gerhard Lambertz, Software Developer at KASTO. The genubox solution is comfortable for the maintenance specialists from KASTO to operate. They are able to use a standardized GUI to log in to the genubox before proceeding to the control systems of the sawing machines or storage systems. Operational data is then called up with a variety of tools, analysis carried out and errors corrected if required. The genuboxes also have to be administered. This is carried out using a central management server at KASTO, where the service staff are able to monitor the status of all customer genuboxes that are active. "The ease of operation and high security provided by this remote maintenance system enables us to offer a world-wide service that in turn makes a considerable contribution to the satisfaction of our customers", explains Josef Schneider, KASTO’s Head of Service. Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Remote Maintenance Predictive Maintenance Industry Share Article Related Links Remote Maintenance Remote Maintenance We support companies when setting up secure remote maintenance access – at all relevant stations of the value creation chain. Remote Service Solution genubox Secure service access to sensitive networks supports Zero-Trust concepts Back to Overview

Anomaly Detection Protects Internal Data Traffic | Genua GmbH

Case Study 03.12.2020 Anomaly Detection Protects Internal Data Traffic Classic IT security protection with firewalls, IDS- or IPS-systems has a serious shortcoming. The systems are not able to detect a change in the communication behavior of network components that have been manipulated and, for example, send malicious code to other clients in the network. Stadtwerke Bad Reichenhall KU, a municipal enterprise, has therefore set up an anomaly detection system to defend against the threat. Gaps in traditional IT security systems Stadtwerke Bad Reichenhall KU is a regional service company that provides its customers with power, natural gas and local public transport as well as Internet, telephone and cable television. As critical infrastructure, Stadtwerke places special focus on IT security. The company is certified according to the international IT security standard 27001 and operates an information security management system (ISMS). Shortcomings of the classic IT security systems Regular audits and penetration tests confirmed that the security measures taken in accordance with the ISMS standard are effective. "The tests are, however, just a snapshot in time. If security gaps are exploited through social engineering and other, increasingly professional attacks, we want to be prepared. Up until now, we have been lacking anomaly detection as a permanent, real-time control that would also allow us to detect attacks in the internal data traffic early on," reports Carsten Viell, IT Director at Stadtwerke. Intrusion detection systems (IDS) and intrusion prevention systems (IPS) for monitoring office networks have proven themselves for years. A major disadvantage of these systems is that they are not designed for anomalies in the internal data stream. A workstation that previously only had connections with the login server and file server suddenly communicating with other computers within the network is not detected. If a workstation establishes connections to many ports in a short amount of time (network scan) or a printer contacts other devices in the network and attempts to download code from the network, that also initially remains undetected. IDS- and IPS systems do not check whether these network components are authorized to do this and whether the behavior is unusual. Attackers are thereby able to take over devices in the network without it being immediately noticed. "We looked for a solution to monitor the internal network using anomaly detection and became aware of the cognitix Threat Defender from genua. Because we have long been very satisfied with the products and services from genua, we were excited about this solution," explains the IT Director. Stadtwerke was looking for an intelligent system that independently scans the network components and analyzes their behavior. "We didn't want to enter thousands of rules by hand and then constantly update them manually," says Carsten Viell. The IT monitoring system also needed to be easy to administer for a medium-sized system such as that of Stadtwerke. Anomaly detection as permanent real-time control "The anomaly detection is very stable and performs well. On a separate screen, we can follow the traffic and used services in real time," says the IT Director, who is very satisfied with the day-to-day operation. The cyber security recommendation of the BSI (BSI-CS 134) places special emphasis on anomaly detection as a means for protecting networks: "It enables the detection of atypical behavior and, thus, in addition to technical error states and incorrect configuration, the detection of previously unknown forms of attack on such networks. This distinguishes anomaly detection from other measures that are based on the detection of already-known attacks." With its anomaly detection, the cognitix Threat Defender closes the security gap of IDS and IPS systems. It monitors all network traffic and also analyzes the behavior of the network components (assets). It sets up a monitored, secure network by recognizing the behavior patterns of the network devices and assigning defined rules. Focus is not on an individual device or an individual network connection but rather on the communication in the entire network and the behavior of all network participants. Previously separate functions, such as network analysis, intrusion detection, asset tracking and a dynamic policy engine, are thereby merged into a single system. ""The introduction of the system went surprisingly smooth. We were very well supported by genua's support staff and received direct assistance in setting up and scaling the system. Moreover, our suggestions for improvement were addressed and quickly implemented," says the IT Director, describing the introductory phase. An initial asset tracking with real-time analysis was performed at the start. During this process, an asset database with all 700 devices in the network, including WLAN networks, was created and a network status in the "base state" created. During this learning phase, it was determined what devices are in the network and what desired network traffic takes place in this base state. If new devices are added, they are immediately detected and must be released and the defined rules assigned. Administration of a system for anomaly detection "The anomaly detection is very stable and performs well. The system is well positioned for real-time tracking. On a separate screen, we can follow the traffic and used services in real time. We receive a warning message if anomalies are detected. Following the learning phase, the detection rate is now good and error messages (false positives) are increasingly rare," says the IT Director, who is very satisfied with the day-to-day operation. He experiences the system as easy-to-operate and self-explanatory. Attacks and anomalies in the network traffic have not occurred up to now. The attacks produced by the administrators were correctly detected and output as warning messages. In such instances, the affected client can be immediately decoupled, e.g., to prevent the further spread of an encryption Trojan. If necessary, the administrator can also issue an alarm via mobile telephony. Stadtwerke anticipates also using the expanded automation functions of the cognitix Threat Defender after a year of regular operation. Unusual patterns and patterns that deviate from the standard behavior (anomalies) in the data stream then result in the automatic interruption of the communication without the administrator needing to intervene. Benefits of the solution The IT Director of Stadtwerke gives the cognitix Threat Defender good marks in a summary: "We operate the solution on eight-year old hardware and are surprised at the system's good performance. There is little configuration work and the integration in the network was easier than expected." Due to the good experiences made in the office network, Stadtwerke has, with the control network, started work on incorporating the communication network for power supply in the anomaly detection system. Carsten Viell confirms the good price-performance ratio of the solution: "There's a great deal of intelligence in the system. Without any additional manual effort, we have permanent 24/7 monitoring of the network traffic. Our network operation has yet again become significantly more secure against increasingly complex attacks." Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Critical Infrastructure Threat Detection Share Article Related Links IDS & IPS cognitix Threat Defender High-performance attack detection for reliable protection of IT and OT networks Back to Overview

Mixed-Reality Remote Maintenance in Networks with Classification Level "German VS-NfD"

Case Study 03.05.2022 Remote Maintenance in VS-NfD Networks Remote Maintenance in Networks with Classification Level "German VS-NfD": Mixed-Reality Collaboration in Real Time for German Armed Services and Defense Technology In a field camp, at sea, in disaster areas: Defense technology is often maintained and repaired at the deployment location to ensure that the urgently needed high-tech equipment is ready for operation at all times. Technical support of the highly complex systems requires experts with specialized knowledge – such experts are a relatively rare commodity. With the remote support system "T-Maintenance XR" and the genua rendezvous remote maintenance solution, technicians on site can work collaboratively with an expert directly, intuitively and securely over any distance using mixed reality. Defense technology is often maintained and repaired at the deployment location The Challenge The main objective of all maintenance and repair measures in defense technology is to ensure that the German Armed Services are ready for deployment at all times. This task primarily takes place not in the workshop but at the deployment location, i.e., in field camps, logistic facilities or even on ships on international missions. Modern military systems are becoming ever more complex and need to be maintained by a comparatively small number of experts with specialized knowledge. This means that the rare expert knowledge must be quickly made available at a wide variety of different locations, often just for a short time and for important details. Modern mixed-reality technologies make this possible. However, secure remote support by experts places high demands on IT security, requires simple integration in existing networks as well as reliable and transparent monitoring options. The Solution: Mixed-Reality Collaboration with T-Maintenance XR "T-Maintenance XR" is a remote support system that allows technicians to be supported remotely on site by experts quickly and at low cost. A special feature is the mixed-reality collaboration during maintenance. Via a secure audio/video connection in combination with real-time interaction and document exchange, remote experts can intuitively get a picture of the situation on the ground and work together with the on-site maintenance technician. Here, head-mounted displays (HMDs) for mixed reality, e.g., Microsoft HoloLens 2, are used to enable two-handed maintenance with audio-visual support. A camera with remotely controllable focus and zoom function provides an overall view of the scenario. What happens in a remote support session? 1. The maintenance technician calls the support desk to request an expert. 2. The support desk organizes a remote session for the maintenance technician. 3. The maintenance technician joins the session via the XR application on HoloLens 2. 4. The expert joins the session via a web application. 5. The expert sees the system to be maintained from the viewpoint of the technician and can provide support by means of audio communication. The expert can provide documents and set markers. 6. The maintenance technician carries out the maintenance with the aid of the expert and ends the session. Rendezvous for Secure Connection Setup and Exchange It is easy to see why remote access in military settings is a sensitive issue in terms of the protection of classified government information. Remote support requires a highly secure, classified network to be partially opened up in a potentially insecure external network. This is why T-Maintenance XR in combination with the rendezvous remote maintenance solution from genua is used, which is based on components approved for classification level "German VS-NfD" by the German Federal Office for Information Security (BSI). Special features of the rendezvous approach are: Communication is monitored and takes place only within an agreed maintenance window via a connection that is encrypted for classification level "German VS-NfD" A rendezvous server acts as a secure mediator between the maintenance technician in the field and the internal restricted network, i.e., the support desk For the remote session, the field technician sets up an IPsec tunnel to the remote peer via a highly secure, restricted-level-approved end device The remote maintenance connection must always be authorized and set up internally, i.e., by the service desk An SSH VPN, which only grants access to certain applications/services (ports), is used for setting up the direct connection All network access is configured, controlled, monitored and recorded using a central management solution The communication partner in the internal, classified network retains control of the communication connection at all times The Result: Highly Secure Remote Support for Classification Level "German VS-NfD" T-Maintenance XR in combination with the genua rendezvous remote maintenance system provides a solution to the problem whereby dedicated special knowledge of experts who are not available on site is necessary for the maintenance of technically highly complex military or civil systems in the field. By using mixed reality, experts and field technicians can work on resolving the problem remotely, collaboratively and in real time. This increases the availability of the systems and avoids unnecessary travel costs. Special features of the solution are: The remote maintenance solution is easy to integrate in existing networks, easy to learn and easy to use It supports the intuitive exchange of expert knowledge in real time Through a BSI-approved WLAN connection and the rendezvous remote maintenance concept with components approved for classification level "German VS-NfD", it is suitable for deployment in military settings and for the protection of classified information T-Maintenance XR is portable, self-contained and can be used directly at the deployment location using the communication connections of the customer or optionally via mobile telephony The solution can be operated in a cloud or on-premise in a datacenter. If Microsoft HoloLens 2 is used, the solution is possible without connection to Microsoft Azure Cloud. More information about the remote maintenance solution from genua . Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Remote Maintenance Secrecy Protection Public Sector Share Article Related Links Remote Service Solution genubox Secure service access to sensitive networks supports Zero-Trust concepts Back to Overview

Internet Access for German Government (IVBB)

Case Study 11.09.2011 Teamwork in Clusters Internet Access for German Government (IVBB) Data zips quickly and securely to and fro between all top-level German federal agencies along the government's Bonn-Berlin information network, the IVBB. Gateways between this and the public Internet are subject to demanding performance and security requirements. These needs are met using firewall clusters. View of the Chancellery in Berlin When the German seat of government moved from Bonn to Berlin, offices of a number of ministries remained in the former capital. So that information could flow quickly and without obstruction between the two locations, the government created the Bonn-Berlin information network, the IVBB. This data highway connects all offices of top-level federal government agencies, from the Office of the Federal President, the Chancellery and all ministries through to the Federal Court of Audit. Exacting Demands on Firewalls At its central nodes, the IVBB also links into the Internet, giving all government agencies access to the World Wide Web. The crossover points between the government intranet and the public Internet must meet the highest standards in terms of security technology: Security certified to stringent ITSEC or Common Criteria (CC) international standards Guaranteed 99.93 percent system availability High data throughput to provide all top-level federal agencies with fast Internet access Cluster-ready for flexible upgrading to higher performance needs After in-depth practical demonstrations in the lab, the Federal Office for Information Security (BSI) opted for a solution from genua, a German IT security company. The genugate firewalls fully meet the challenging requirements. One Solution, Two Firewalls The genugate security system combines two different firewalls – an application -level gateway and a packet filter – in one compact solution. The two firewalls work in series, meaning that all data packets must pass two separate tests before they can cross the Internet/IVBB interface. The application-level gateway checks the content of received data, sifting out spam, viruses and other undesirables. The packet filter makes sure connection requests are legitimate based on formal criteria such as IP address and protocol type. The strong security guaranteed by this two-stage system is borne out by high-level certification: ITSEC E3/High for genugate versions 4.0 and 5.0, and CC EAL 4+ for version 6.0. As the firewall attains even higher security standards in terms of selfprotection, genugate additionally carries a Highly Resistant rating – the only firewall in the world to do so. Teamwork in Clusters genugate satisfies the demanding availability and throughput requirements by teamwork: All tasks are shared among clusters of firewalls. If one system fails, others in the same cluster immediately take over. The clusters are infinitely scaleable and so can be upgraded to higher performance requirements at any time. Sales Contact Sales + 49 89 991950-902 sales@genua.eu Topics Public Sector Critical Infrastructure Firewalls & Gateways Share Article Related Links High Resistance Firewall genugate Complete data analysis for maximum network security Back to Overview

1 2 3 4 5 6 7 8 9 10 11 12 13 14
Contact
+ 49 89 991950-0
+ 49 89 991950-999
info(at)genua.de
  • Genua Security made in Germany Logo
  • Genua Tüv certificate
  • Genua Tüv Rheinland Zertifikat
  • Genua Tüv Zertifikat
  • © 2026 genua
  • GCC
  • Imprint
  • Data Protection and Privacy
  • Whistleblowing System
  • Terms of use
genua bdr signet