CANoe_TestPackage_EV_Security_PressRelease_202604_Graphic1.jpg

Security Testing

Vector is known for the full portfolio of testing tools. Vector Consulting also delivers external and independent Security Testing. We support companies worldwide , ranging from Architecture and Code Review, Static Code Analysis, to Unit tests, Fuzzing and Penetration Testing. Our novel Grey-Box Pentest techniques yield better vulnerability with lower cost. All test is also offered as remote activity.

Security Testing

Security_Testing.jpg

At Vector Consulting, we are using a specific methodology for risk-based testing. While brute-force testing might sound appealing to detect weakness at any place, it is expensive and not effective. No test is complete, and brute-force PenTest for sure will overlook specific feature correlations. Vector therefore has developed our own Grey-Box Security Testing suite where we conduct a mini-TARA and on this basis, identify the attack vectors and test focus based on assets and risks. It is grey-box because we follow the black-box security testing approach, while considering specific risks due to attacks and implementation. For instance, a specific architecture or protocol – when known – invites specific attacks, such as CAN with DOS attacks. On this well-founded methodological basis, the security items in scope of the security engineering process are identified and agreed.

Fuzz Testing

Frame Fuzzing

Frame fuzzing is used to check the general robustness of the device.  To detect any ‘silent’ services that may be available in the system but only activated upon receiving a CAN frame with a specific ID, a CAN-Frame Fuzzer is used which is able to generate random CAN frames within a configurable address range. 

Signal Fuzzing

Signal fuzzing is used on the database defined messages to target the application software of the DUT with forged signal data which may uncover unexpected behavior, like resets. Such behavior of the target may point to a software vulnerability which may be exploitable.

Pen Testing

Code Quality Analysis

Verification of the implemented architecture against the planned architecture

Identification of typical design weakness, verification of the source codes with regards to compliance with programming specifications or critical code areas.

Tool-supported analysis independent of suspicion on faulty or critical programming construction and maintenance risks.

Early identification of open-source components to check the legal requirements.

Your Benefits

  • Global knowhow with 20 years of cybersecurity excellence and best practices
  • Hands-on approach and immediate access to templates, process guidance and our benchmarks
  • Technology expertise with our own extensive Security Testing Lab
  • Competences of different standards and regulations, e.g. ISO 21434, UNECE
  • Advanced security engineering methods, such as Threat Analysis and Risk Assessment (TARA), vulnerability scanning
  • Architecture and code reviews, and static code analysis
  • Cryptography and Management of crypto material (key, certificates)
  • Experience with HW trust anchors (SHE, HSM, TPM) > Secure boot / Secure flash
  • Secure diagnostic concepts
  • Secure on-board and off-board communication
  • Intrusion detection and intrusion prevention systems
  • Usage of database and restbus simulation
  • Comprehensive black, grey and white box testing
Technical_Article_Highlight.jpg
Technical Article Highlight
Cybersecurity with Heuristics, Published on ATZ Electronics, 06/2023: This article presents heuristic methods in automotive cybersecurity, exemplified in penetration testing. Related improvements include security patterns, automatic traceability, targeted attack patterns, threat catalogs, and feedback-based fuzzing.

Feedback

"Vector Consulting Services is a good partner for Claas to implement cybersecurity. Claas had great benefits from the Vector team for TARA and Security Engineering."

- Alexander Grossmann, Manager, Claas

"Thanks for your supporting for IEM&IGM project. With Vector professional skills and experience on Penetration and Fuzzing test, our software has become more mature. Looking forward to the next collaboration between BorgWarner and Vector."

- Dis Wang, Borgwarner China

"Vector Consulting Services supported Panasonic with cybersecurity, demonstrating an outstanding level of expertise. The goal of a comprehensive TARA integrated into a security concept was achieved. The support was intense and very successful!"

- Michael Prantke, Project Manager, Panasonic

"Thanks a lot to Vector Consulting for your excellent handling of comprehensive security test. Completed testing tasks on time and gave professional advice! Good communication and technical expertise help us be recognized by the OEM. Looking forward to our next cooperation!"

- Xuexin Shao, Inovance

Hands-on Tutorial

Your Partner for Engineering Excellence
Vector Consulting Services
Team
Your Partner for Engineering Excellence
Let us build the ideal setup for your engineering challenges together. Reach out to our team to explore how our powerful coaching can seamlessly integrate into your existing workflows.