Skip to main content

Yekta IT presents UDS paper at CPS-Sec 2025 in Avignon

At the 10th IEEE International Workshop on Cyber-Physical Systems Security (CPS-Sec 2025), part of the IEEE Conference on Communications and Network Security (CNS) 2025 in Avignon, we presented our latest work on the security of vehicle diagnostic protocols.

Our paper: "UDS Attack Taxonomy: Systematic Classification of Vehicle Diagnostic Threats"

Yekta IT at CPS-Sec 2025 in Avignon

Ali Recai Yekta presented our paper, written with ETAS (Nicolas Loza, Jens Gramm, Michael Peter Schneider) and the University of Passau (Prof. Stefan Katzenbeisser) as part of the FINESSE project.

The problem

Modern vehicles are more complex and more connected every year, and that brings real security problems with it. One of them concerns the Unified Diagnostic Services (UDS) protocol, the communication standard used for diagnostics and servicing in the automotive industry. Protecting vehicles against attack requires a systematic understanding of what the attack surface actually looks like.

We analysed potential attack techniques against UDS using the VATT&EK framework, our vehicle-specific adaptation of the MITRE ATT&CK methodology from earlier work. With it we identified and categorised adversarial techniques for exploiting UDS weaknesses.

To show that the taxonomy holds up in practice, we mapped it onto attack scenarios from published literature. For close to two thirds of the identified techniques we found concrete examples from real scenarios.

The taxonomy gives a structure for three things:

  • Security assessments: systematic security reviews of UDS implementations
  • Incident response: faster identification of and reaction to incidents
  • Security monitoring: building detection that works for UDS-based communication

The results feed directly into our further work on vehicle security, in particular the intrusion detection systems and monitoring strategies we are developing in FINESSE.

CPS-Sec 2025 was a useful venue for work on security in cyber-physical systems. Our systematic classification of UDS attacks is one contribution towards making modern vehicles harder to attack.

Our thanks to the workshop organisers Tooska Dargahi (Manchester Metropolitan University), Mohammad Ashiqur Rahman (Florida International University) and Alessandro Brighente (University of Padua).

Paper: DOI: 10.1109/CNS66487.2025.11195020

The project: FINESSE, attack detection for road and rail

Questions about this?

Talk to our consultants.