Skip to main content

Three and a half years of research into cybersecurity for road and rail

A rail vehicle runs for 30 to 40 years. The fleet that has to be secured is long since in service, and it cannot be swapped for secure new vehicles. Cars and trains today run software, are connected, and tie in external services. Attacks therefore have to be detected in the vehicles that exist, during operation, and without disturbing the safety-critical technology.

Yekta IT at the Nationale Konferenz IT-Sicherheitsforschung 2025

For operators of critical infrastructure, attack detection has been a legal requirement in Germany since the IT-Sicherheitsgesetz 2.0. Automotive has the first building blocks for it; rail had no comparable approach. FINESSE brings the two together so that road and rail can learn from each other.

FINESSE (cyber protection systems for vehicles and infrastructure on road and rail) ran from July 2022 to December 2025 and builds the complete chain of attack detection for vehicle fleets, from the sensor in the vehicle through the transmission path to the security operations centre at the operator, with rule-based and machine-learning analysis and partly automated response. Automotive has the more mature components here: IDS sensors for CAN and Ethernet, the AUTOSAR IDS manager (IdsM), and with UN R155 a fleet-wide obligation to detect attacks. Rail had no such approach, and it brings its own constraints: detection that cannot react back on the system, and vehicle lifetimes of 30 to 40 years. The value lies in the exchange between the two. Attack classification, detection rules and event formats sit on a shared basis for road and rail, so that a detection pattern from one domain becomes usable in the other, an exchange we call mobility threat intelligence. The results rest on open components and interfaces and feed into standardisation.

The consortium: DB Systemtechnik, ETAS (Bosch group), Fraunhofer SIT, INCYDE (consortium lead), the University of Passau and Yekta IT. Funded by the German Federal Ministry of Research, Technology and Space (BMFTR, formerly BMBF), grant number 16KIS1584K.

Real attacks on road and rail

For cars, the 2015 Jeep Cherokee hack shows the reach: Charlie Miller and Chris Valasek took remote control through the connected Uconnect system, as far as the transmission and the brakes. Fiat Chrysler recalled 1.4 million vehicles, the first product recall caused by a cyber vulnerability (SecurityWeek). In 2018, Tencent Keen Security Lab demonstrated comparable attack chains reaching into BMW vehicle networks.

In rail, the risk often sits in the radio. In April 2026 a student stopped four Taiwan High Speed Rail trains by analysing the railway radio with a software defined radio and sending a forged general alarm to the control centre (Taipei Times). In Poland in 2023, unencrypted tones on an analogue VHF frequency were enough to trigger the radio-stop emergency braking on more than 20 trains; a simple transmitter sufficed (The Record). We model radio attacks of this kind in VATT&EK as a technique of their own.

Some of the risk sits in the software itself. In 2023, at 37C3, Dragon Sector uncovered hidden lock-out logic in Newag multiple units, built in by the manufacturer, which disabled vehicles after a visit to an independent workshop (37C3 talk). Without watching what your own vehicle software does, an attack cannot be told apart from a malfunction or from a manufacturer lock-out.

From an expensive intrusion into the vehicle network to a cheap radio attack: none of these was a hack that took seconds. Detection has to cover the whole span, and that starts with a clean classification.

VATT&EK: one vocabulary for attacks on vehicles

In classic IT, MITRE ATT&CK does this work. For vehicles with ECUs, field buses and real-time requirements it is not enough. We built the vehicle-specific answer: VATT&EK (Vehicle Adversarial Tactics, Techniques & Expert Knowledge), an adaptation for road and rail with 14 tactic classes, from CAN injection through radio attacks to GNSS spoofing. Our own analysis went into it, along with the exchange with manufacturers, suppliers and security specialists.

We formalised and published VATT&EK with Dominik Spychalski (INCYDE) and Prof. Stefan Katzenbeisser (University of Passau) at the ACM Computer Science in Cars Symposium.

The extension to the UDS diagnostic protocol (Unified Diagnostic Services, ISO 14229) we took forward with Nicolas Loza, Jens Gramm and Michael Peter Schneider (all ETAS) and Prof. Stefan Katzenbeisser. We analysed all 27 UDS services and derived 50 attack techniques across nine tactics from them, checked against 33 published vulnerability reports. Two thirds of the techniques were already documented in the wild; the rest surfaced attack vectors nobody had examined. Published at IEEE CNS 2025.

Our core competence: the SOC, now for vehicles

Yekta IT has built and run security operations centres for operators of critical infrastructure for years. In FINESSE we carried that OT SOC knowledge into the vehicle world.

On board, a Security Event Center (SEC) aggregates and correlates the reports from individual sensors and allows fast local responses. In the backend the data comes together fleet-wide in a Vehicle Security Operations Center (VSOC), enriched with VATT&EK classification and threat intelligence. We extend the AUTOSAR event formats with forensic fields such as rule ID, severity and confidence, and define structurally compatible formats for rail for the first time. GDPR-compliant pseudonymisation is part of the model from the start.

For an operator that means attacks and anomalies become visible across an entire fleet, classified and documented in a way that can be followed afterwards, without disturbing operation.

Demonstrators: from a real component to an attack you can watch

We analysed real vehicles, hardware and components and built two demonstrators from that work.

YekCar reproduces the security architecture of a connected car: real ECUs, CAN and UDS communication, an OBD-II interface, an attacker dashboard and a real-time monitor for the IDS. Live attacks on CAN, UDS and keyless entry are carried out and detected as they happen.

YekTrain reproduces the same chain for rail. From the analysis of real MVB implementations (Multifunction Vehicle Bus to IEC 61375, with the class 605 / ICE TD as reference) came a virtual MVB simulator covering all nine critical vehicle systems, a compromised DMI component (driver machine interface, the display and control unit in the cab) for injecting forged safety telegrams, an MVB-IDS for detection, and a rail SOC with live visualisation.

We have shown both demonstrators publicly, among others at the Nationale Konferenz IT-Sicherheitsforschung 2025 and at IT-Sicherheitstag NRW.

Live on a real train: the Advanced TrainLab

At DB Systemtechnik’s Advanced TrainLab (aTL) we demonstrated our monitoring on a moving vehicle.

We tap the train’s MVB and CAN communication without reacting back on it and transmit it over UDP to a separate RailPC. Into that transport path we injected manipulated MVB telegrams, producing attacks without touching the safety-critical vehicle bus. Our MVB-IDS detected them and reported them to the SEC; in the rail SOC the events came together centrally. The whole chain, from detection to situational display, ran live on a real vehicle. DB Systemtechnik, the University of Passau and our consortium partner INCYDE supported the work.

Not reacting back on the system is mandatory in rail operation: a detection system may not influence safety-relevant field buses. We met that requirement on a real train.

What remains

The FINESSE results feed into standardisation, into real rail platforms such as the Advanced TrainLab, and into our daily SOC and consulting work. Road and rail benefit from each other: detection patterns from automotive sharpen rail monitoring, and the other way round.

Our thanks to the BMFTR for the funding and to our partners DB Systemtechnik, ETAS, Fraunhofer SIT, INCYDE and the University of Passau for three and a half years of working together.

Publications from the project

The full results are in the FINESSE closing brochure.

View the FINESSE closing brochure

The project: FINESSE, attack detection for road and rail

Questions about this?

Talk to our consultants.