Applied Research

We permanently work on current security topics by systematic and continuous further education in our test laboratory. On the one hand we use what we learn from our security assessments, on the other hand we issue technology articles that we publish through our TIGER-INFO mailing list.

Our technology studies are an important component of Compass strategy. We place special emphasis on practical experience rather than limiting ourselves to the study of RFCs and white papers. Our versatile laboratory enables us to carry out extensive tests on many operating systems.

Furthermore, we develop our own security tools that are partly available for download free of charge, or else are intended for internal use only. This software engineering allows us to maintain our know-how in the area of source code analysis.

Projects in technology-transfer between the University of Applied Sciences Rapperswil and Compass Security:http://hsr.csnc.ch

 

Security Topics:

 

2008

Universal Windows Proxy
E-Banking VMWare Appliance
Windows Mobile Malicious Code
IPv6 - Teredo
VMWare Exploiting

2007

Firefox Observation Plugin
Flash InSecurity
Paros Smartcard
QR Code Reader
WiFi Driver Exploits

2006

Browser Security
SIP Fuzzing
SmartCard
Layer II Security
Phishing
HTTPS SSO
VoIP Security Test Tool

 

2005

Detect IP addresses for port security
Test reporting suite
Phishing warning system
.NET security demo applikation

2004

DNS tunnel test-suite
Mail security test
VPN bypass security
Port security
Time stamping authority

2003

BlueTooth security
SOAP firewall prototype
Client proxy for SOAP firewall
WebSSH
Apache webentry project (SingleSignOn)
Distributed wireless honeypot
Management dashboard

2002

Vulnerabilities in webservers
Application security testing
Certificate based Outlook WebAccess
Buffer overflows under Windows, study and tools
Process monitor for Windows systems
Process analyzer (API monitor for Windows programs)
HTTP-session management

2001

DNS security (dns packet assembler)
Kevin Mitnick attacking toolkit
PDA security analyze
SMS authentication - Login service by SMS

2000

Windows Snort Intrusion Detection Management Console
SSLProxy/sniffer
Wardialer for Linux using MySQL and advanced technique
S-Tools (Info Gathering)
SecurityCheck via ActiveX

1999

IDS market analysis
Knowledge Management System

News

Compass invites to the Security Event 2010
6/7/10 - On Thursday, September 09, 2010 Compass Security AG organise their annual "Compass Event". For this seminar the ICT security service provider invites customers and other interested persons to the auditorium of the HSR University of Applied Sciences in Rapperswil / Switzerland. From 08:30 to 17:00 the participants benefit from the latest findings and experiences about ITC security in the frame of presentations, Live-Hacking demonstrations and speeches. A red-hot topic is brought up by Nicolas Seriot in his guest speech "iPhone-Hacking".

New at Compass: "FileBox" as an Appliance
5/25/10 - Compass Security AG have further developed their Web based transfer solution "File Box" and launched an appliance. Companies keep thus complete control of their data as the appliance is located on their own premises. The multitenant solution addresses mainly target groups who are dependent on a safe data transfer with customers or business partners, such as banks, insurance companies, chartered accountants, trustees, lawyers or medical doctors.

Hacking-Lab Remote: Rent a Professional IT Security Lab
4/13/10 - For imparting knowledge on IT security topics such as the OWASP TOP 10, OSSTMM and other attacking respectively defence measures in a practical way, high schools and companies no longer need to invest in their own security lab. Using the Hacking-Lab of Compass Security AG users have access via Internet to an interactive lab environment. The ICT security service provider makes students and employees more familiar with current cyber threats, attacking strategies and defence measures.

Evening event of ISSS on "Cyber Crime in Switzerland"
2/23/10 - Ivan Bütler, Compass managing director, is organizing the "1st ISSS St Gall conference" together with Dr. Lukas Ruf. On Thursday, April 29, 2010, interested people are meeting in order to gain an up-to-date overview in the field of computer crime an to become familiar with the developments.

Compass hacks live at CeBIT
2/22/10 - Marco Di Filippo, Regional Director Germany of Compass Security AG takes on the role of the hacker at CeBIT and puts modern technologies to the test. On the CeBIT platforms of the media partner Network Computing and of the anti virus specialist Avira he is going to x-ray data centers and mobile devices such as iPhone, Blackberry, etc. regarding their safety compliance.