Labor Informationssicherheit und Complience (ISC)
Refine
Year of publication
Document Type
Language
- English (30)
Is part of the Bibliography
- no (30)
Keywords
- Internet of Things (7)
- Automotive (3)
- IoTAG (3)
- Penetration Testing (2)
- device identification (2)
- safety-critical infrastructure (2)
- security rating (2)
- Activating Learning (1)
- Artificial Intelligence (1)
- Automotive Security (1)
Institute
Begutachtungsstatus
- peer-reviewed (11)
- begutachtet (1)
The current transformation in the automotive industry is leading to new technologies with a higher software content, a higher degree of networking, and connections to cloud services. This development leads to an increase in the attack surface and the potential extent of damage. ISO/SAE 21434 and UNECE WP.29/R155 were published to address this development. The ISO/SAE 21434 proposes fuzz testing as a measure. In fuzzing, so-called fuzz data is generated and transmitted to a device under test to identify previously unknown and known vulnerabilities. This approach is already being used very successfully in other industries. But in the automotive sector, some challenges arise when testing hardware-related electronic control units. These include the fact that the internal system structures are often poorly known or not known, as well as the severely restricted access and hardware limitations for monitoring. One way to solve these challenges is to use side-channel information to monitor the device under test. Such information includes power consumption, temperature, and noise levels, for example. In this paper, we present a fuzz testing experiment to determine anomalies, data, and requirements for analyzing various side channels. Basic procedures were used to generate the fuzz data. Monitoring of the device under test was performed manually at the beginning. In addition, a side-channel measurement system with various measurement devices and a test setup are presented. Based on the identified fuzz messages, the behavior of the respective side channels during the abnormal behavior is analyzed and described.
As autonomous driving becomes increasingly feasible, the German government has introduced a legal framework to enable the operation of vehicles with Level 4 automated
driving functionality. A key requirement is the maintenance of a continuous connection between such vehicles and a remote technical supervisor. If this link is lost, the vehicle must transition into a safe state by bringing itself to a controlled stop. To mitigate the risk of connection loss, accurate forecasting of mobile network availability along routes is essential. This paper describes a spatio-temporal analysis of mobile network signal quality metrics along a fixed rural route based on 48 repeated measurement drives. The route was segmented into 320 spatial reference sections to enable consistent cross-trip comparison and stability assessment. A classification into usable and non-usable connectivity states reveals that more than half of the sections show pronounced trip-to-trip variability. The results show that mobile network quality is not only dependent on geographic location but is also influenced by environmental conditions. While global correlations between weather parameters and raw signal metrics remain weak, moderate relationships can be seen when analyzing the share of functionally usable connectivity in spatially unstable sections. A walk-forward forecasting model demonstrates that the inclusion of temperature in the model reduces prediction
error compared to a purely historical baseline in 73.7% of evaluated trips. The findings show the importance of feature selection and also the limitations of linear modeling approaches.
Rather than acting as deterministic predictors of signal strength, contextual parameters primarily modulate connectivity uncertainty in spatially unstable regions. These findings underscore the importance of contextual information and localized modeling
to predict network availability for safety-critical systems, such as autonomous vehicles.
The ongoing development of autonomous vehicles requires introducing advanced technologies and protocols to ensure road safety and efficiency. Conventional data recording devices in standard vehicles have limitations in data storage and accessibility, which hinders efficient information sharing and analysis. In addition, connected vehicles are vulnerable to targeted attacks that can lead to potential data breaches. EU regulation 2019/2144 has mandated the introduction of standardised data recording systems from 2024 to address these challenges. Based on this, we propose a standardised event detection and response system for autonomous vehicles introducing a Client2X architecture to improve data collection, storage and analysis. This architecture enables efficient machine learning-based event analysis, faster data retrieval and data integrity. An external monitoring system complements the in-vehicle data storage and ensures comprehensive data analysis. The proposed system aims to accelerate incident resolution and improve vehicle safety and data management.
Cyber Threat Intelligence (CTI) is a key component of modern security operations, yet existing systems struggle to integrate heterogeneous intelligence sources and to provide contextualized, organization-aware analysis. Knowledge-graph-based approaches offer structured and explainable representations of threats, while Large Language Models (LLMs) enable flexible semantic analysis of unstructured information. However, these paradigms are typically applied in isolation and fail to support continuous, context-driven threat modeling. This paper proposes an Agentic Graph Retrieval-Augmented Generation (GraphRAG) architecture for CTI analysis. The approach integrates structured and unstructured CTI into a persistent knowledge state consisting of a cybersecurity knowledge graph, a document store, and a vector index. Graph-first retrieval is combined with agentic orchestration to iteratively assemble bounded, task-relevant context for LLM-based reasoning, enabling grounded, explainable, and organization-specific threat analysis. We present a layered reference architecture and a detailed methodology describing knowledge construction, graph-first retrieval, agentic analysis workflow, and grounded reasoning. The proposed approach is designed to support security analysts and automated security workflows in operational CTI environments and provides a foundation for adaptive and explainable CTI systems that combine structured knowledge representation with flexible AI-driven analysis.
As autonomous driving becomes increasingly feasible, the German government has introduced a legal framework to enable the operation with Level 4 automated driving functionality. A key requirement is the maintenance of a continuous connection between such vehicles and a remote technical supervisor. If this link is lost, the vehicle must transition into a safe state by bringing itself to a controlled stop. To mitigate the risk of connection loss, accurate forecasting of mobile network availability along routes is essential. This paper presents an Exploratory Data Analysis (EDA) based on 38 measurement runs collected over ten months along a rural 64 km route in Germany. The dataset includes passive mobile network signal quality parameters, Global Navigation Satellite System (GNSS) position and precision data, as well as contextual features, such as speed, driving direction, day of the week, weather, and distance to the connected base station. Although mean values capture overall tendencies for areas with consistently good or poor coverage, they fail to capture the variability necessary for reliable prediction on a per-trip basis. Notably, some route segments show high variance in signal quality across different measurement runs. This variability is assumed to result from changing environmental influences, such as weather or traffic conditions at different times. Our analysis reveals weak but statistically relevant correlations between several contextual features (e.g., temperature ≈ -0.2) and network quality indicators. The inclusion of weather parameters or the day of the week has been shown to lower the Mean Absolute Error (MAE) compared to a prediction based only on measurements from the past. These findings underscore the importance of contextual information and localized modeling to predict network availability for safety-critical systems, such as autonomous vehicles.
The digitization of almost all sectors of life and the quickly growing complexity of interrelationships between actors in this digital world leads to a dramatically increasing attack surface regarding both direct and also indirect attacks over the supply chain. These supply chain attacks can have different characters, e.g., vulnerabilities and backdoors in hardware and software, illegitimate access by compromised service providers, or trust relationships to suppliers and customers exploited in the course of business email compromise. To address this challenge and create visibility along these supply chains, threat-related data needs to be rapidly exchanged and correlated over organizational borders. The publicly funded project MANTRA is meant to create a secure and resilient framework for real-time exchange of cyberattack patterns and automated, contextualized risk management. The novel graph-based approach provides benefits for automation regarding cybersecurity management, especially when it comes to prioriization of measures for risk reduction and during active defense against cyberattacks. In this paper, we outline MANTRA’s scope, objectives, envisioned scientific approach, and challenges.
The paper presents a penetration testing framework for automotive IT security education and evaluates its realization. The automotive sector is changing due to automated driving functions, connected vehicles, and electric vehicles. This development also creates new and more critical vulnerabilities. This paper addresses a possible countermeasure, automotive IT security education. Some existing solutions are evaluated and compared with the created Automotive Penetration Testing Education Platform (APTEP) framework. In addition, the APTEP architecture is described. It consists of three layers representing different attack points of a vehicle. The realization of the APTEP is a hardware case and a virtual platform referred to as the Automotive Network Security Case (ANSKo). The hardware case contains emulated control units and different communication protocols. The virtual platform uses Docker containers to provide a similar experience over the internet. Both offer two kinds of challenges.
The first introduces users to a specific interface, while the second combines multiple interfaces, to a complex and realistic challenge. This concept is based on modern didactic theories, such as constructivism and problem-based/challenge-based learning.
Computer Science students from the Ostbayerische Technische Hochschule (OTH) Regensburg experienced the challenges as part of a elective subject. In an online survey evaluated in this paper, they gave positive feedback. Also, a part of the evaluation is the mapping of the ANSKo and the maturity levels in the Software Assurance Maturity Model (SAMM) practice Education & Guidance as well as the SAMM practice Security Testing. The scientific contribution of this paper is to present an APTEP, a corresponding learning concept and an evaluation method.
Automotive Original Equipment Manufacturer (OEM) and suppliers started shifting their focus towards the security of their connected electronic programmable products recently since cars used to be mainly mechanical products. However, this has changed due to the rising digitalization of vehicles. Security and functional safety have grown together and need to be addressed as a single issue, referred to as automotive security, in the following article. One way to accomplish security is automotive security education. The scientific contribution of this paper is to establish an Automotive Penetration Testing Education Platform (APTEP). It consists of three layers representing different attack points of a vehicle. The layers are the outer, inner, and core layers. Each of those contains multiple interfaces, such as Wireless Local Area Network (WLAN) or electric vehicle charging interfaces in the outer layer, message bus systems in the inner layer, and debug or diagnostic interfaces in the core layer. One implementation of APTEP is in a hardware case and as a virtual platform, referred to as the Automotive Network Security Case (ANSKo). The hardware case contains emulated control units and different communication protocols. The virtual platform uses Docker containers to provide a similar experience over the internet. Both offer two kinds of challenges. The first introduces users to a specific interface, while the second combines multiple interfaces, to a complex and realistic challenge. This concept is based on modern didactic theory, such as constructivism and problem-based learning. Computer Science students from the Ostbayerische Technische Hochschule (OTH)Regensburg experienced the challenges as part of a special topic course and provided positive feedback.
The ongoing digitization and digitalization entails the increasing risk of privacy breaches through cyber attacks. Internet of Things (IoT) environments often contain devices monitoring sensitive data such as vital signs, movement or surveil-lance data. Unfortunately, many of these devices provide limited security features. The purpose of this paper is to investigate how artificial intelligence and static analysis can be implemented in practice-oriented intelligent Intrusion Detection Systems to monitor IoT networks. In addition, the question of how static and dynamic methods can be developed and combined to improve net-work attack detection is discussed. The implementation concept is based on a layer-based architecture with a modular deployment of classical security analysis and modern artificial intelligent methods. To extract important features from the IoT network data a time-based approach has been developed. Combined with
network metadata these features enhance the performance of the artificial intelligence driven anomaly detection and attack classification. The paper demonstrates that artificial intelligence
and static analysis methods can be combined in an intelligent Intrusion Detection System to improve the security of IoT environments.
Learning centered teaching becomes an important factor in a global perspective of learning software engineering. The Just-in-Time Teaching approach is used in a Chinese-German empirical case study. In a one year terminated project we will analyze the performance of our students in an active learning scenario with Just-in-Time Teaching and Peer Instruction. We will contribute an inter-cultural comparison of achieved competencies by student’s self-assessment and teacher’s observation.