Stock Abbreviation : Topsec      Stock Code : 002212
7*24 hour service: 400-777-0777

Topsec Alpha Lab

Monitoring and warning of cyberspace security vulnerabilities, mining and research of IT infrastructure product vulnerabilities, analysis and research of IoT and industrial network product threats, reverse analysis and protection research of software and hardware products, security risk research of mobile applications, and malicious code tracking analysis.

Lab Overview

Topsec Alpha Lab was established in 2011. Since the establishment, this lab has been adhering to the concept of "attack and defense integration" and has gathered together many professional and technical researchers to engage in research on attack and defense technologies and continue their efforts in forward-looking technologies in the security field. As the support team for Topsec's professional security products and services, the superb professional technical level and rich suppression experience of this lab have provided strong technical support for development and upgrade of Topsec products, major national security projects, and customer services.

Attack and defense technology search for IoT

This lab has a professional software and hardware reverse research team, which studies the vulnerability exploitation methods for IoT devices with different architectures and the wireless communication protocols commonly used by IoT devices. Its team members exploit vulnerabilities in various IoT devices such as routers, smart door locks, NAS, and smart home appliances, detect multiple high-risk vulnerabilities, assist IoT device manufacturers (such as TP-Link, NETGEAR, QNAP, Huawei, and Xiaomi) in fixing the vulnerabilities, and have received public acknowledgment from the manufacturers. They also study the IoV security, exploit the vulnerabilities of vehicle communication protocols, devices, systems, and wireless vehicle keys, and detect and submit multiple vehicle and T-box vulnerabilities.

Attack and defense technology search for mobile terminals

This lab has a number of mobile security researchers, mainly engaged in the security technology research for mainstream mobile platforms such as Android and iOS. The researchers focus on app reverse analysis, anti-reverse protection confrontation, malicious code analysis, and privacy leakage threats and assessment of app security. They help a number of well-known manufacturers fix app security vulnerabilities and have received public acknowledgment from the manufacturers. They also assist relevant regulatory agencies in detecting privacy leakage risks of many well-known apps.

Binary reverse research

This lab has a professional software and hardware reverse research team, which has been engaged in reverse analysis for many years. Its team members focus on reverse analysis, anti-analysis confrontation, code restoration, and code auditing. They continuously carry out malicious code identification and analysis to detect a variety of advanced attack technologies, exploit and submit multiple high-risk vulnerabilities in mainstream products such as operating systems, databases, and readers, and have received public acknowledgment from software and hardware product suppliers including Apple, IBM, and Adobe many times.

Emergency response to vulnerabilities

With security vulnerabilities as a key factor affecting cybersecurity, the importance of relevant intelligence is self-evident. This lab establishes a complete set of vulnerability emergency response mechanism and develops an automatic vulnerability intelligence collection and analysis platform. This platform can collect data from many channels in a wide range to capture high-risk vulnerability intelligence in a timely and accurate manner through smart screening supplemented by manual judgment. Over the years, this lab has released emergency and major security vulnerability threat intelligence in the first time several times to help customers avoid security risks, and has been commended by relevant national institutions for many times.

Original vulnerability research

Since its establishment, this lab has always adhered to original vulnerability research to assist manufacturers in mining and fixing vulnerabilities in various CMSs, network devices, industrial control devices, web sites, and apps. The researchers have continuously released more than 2,000 original vulnerabilities to Common Vulnerabilities and Exposures (CVE), China National Vulnerability Database (CNVD), China Industrial Control System Vulnerability Database (CICSVD), China National Vulnerability Database of Information Security (CNNVD), National Vulnerability Database (NVDB), and public Security Response Centers (SRCs) of major manufacturers. They assist the country in building the cyberspace order and strengthen cybersecurity defense.

Attack and defense technology research

This lab has a number of senior penetration testing engineers, who mainly engage in the research of web attack and defense technologies and provide support for internal and external penetration testing. Internally, they are responsible for the launch and upgrade security of Topsec's internal products. Externally, they assist the national security department in combating illegal and criminal activities to safeguard major national activities.

Breakthrough in Important Core Technologies

Topsec Alpha Lab has participated in and undertaken many national, provincial, and ministerial key cybersecurity scientific research projects, including the National High-tech Research and Development Program (863 Program), the Torch Program, and several national-level technology breakthrough projects. It provides a large amount of technical support and technology breakthrough for the Cyberspace Administration of China, the CNCERT/CC, the China Information Technology Security Evaluation Center, the Ministry of Public Security, Ministry of State Security, and the military. During the major state-level meetings, this lab has completed the guarantee tasks for major national information security for many times in accordance with the requirements of the superior departments. It has received a letter of thanks from the CNCERT/CC, nominating and commending its researchers.

Vulnerability Research and Acknowledgment

In terms of vulnerability exploring and analysis, Topsec Alpha Lab has submitted more than 2,000 original vulnerabilities of various types to platforms including CNVD, CNNVD, CICSVD, NVDB, and CVE accumulatively over a period of time. This lab has been granted with the following honor certificates: Outstanding Contribution Organization for Original Vulnerability Report, Top Level Excellent Technical Support Organization, Annual CNNVD Excellent Support Organization, Outstanding Organization in Emergency Vulnerability Response, and CICSVD Excellent Member Organization. Since 2008, this lab has reported hundreds of CVE vulnerabilities in products of internationally renowned manufacturers and has received acknowledgment from international manufacturers such as Apple, Adobe, Oracle, Google, and Huawei.

Honor Certificates