Skip to main content
Research project

FINESSE: intrusion detection for road and rail

From July 2022 to December 2025, six partners built the continuous detection chain for vehicle fleets, from the sensor in the vehicle through the transmission path to the security operations centre at the operator. Yekta IT brought the SOC knowledge from critical infrastructure and developed the VATT&EK attack classification.

Angriffserkennung für Straße und Schiene Ein Auto und ein Triebkopf, beide mit Steuergeraeten an einem Bus und beide unter Angriff. Ueber den Uplink laufen ihre Meldungen in ein Vehicle Security Operations Center, das die ganze Flotte auf einer Lage zusammenfuehrt. ROAD CAN · ETHERNET · UDS RAIL MVB · CANOPEN · IEC 61375 UPLINK VEHICLE SOC ONE FLEET, ONE PICTURE USE CASES JE FAHRZEUGTYP FINESSE · ATTACK DETECTION FOR ROAD AND RAIL
Key facts

Who, when, out of what

Duration

July 2022 to December 2025.

Funding

The German Federal Ministry of Research, Technology and Space, formerly the BMBF. Funding reference 16KIS1584K.

Partners

INCYDE as consortium lead, with DB Systemtechnik, ETAS of the Bosch group, Fraunhofer SIT, the University of Passau and Yekta IT.

Field of application

Road and rail vehicles, from the control unit in the vehicle to the operator's security operations centre.

Our part

The SOC architecture for vehicle fleets, the VATT&EK attack classification, and the two demonstrators YekCar and YekTrain.

Published

Four papers at ACM CSCS, IEEE CNS, SECURWARE and in the Springer LNCS.

The approach

Road and rail on a common basis

Strasse und Schiene auf einer gemeinsamen Basis Fahrzeuge auf der Strasse und auf der Schiene melden in eine gemeinsame Angriffsklassifikation mit vierzehn Taktik-Klassen, von dort in ein SOC beim Betreiber. Der Rueckweg fuehrt ein Muster aus dem einen Bereich in den anderen. ROAD CAN · ETHERNET · UDS RAIL MVB · CANOPEN · IEC 61375 VATT&EK ONE CLASSIFICATION FOR BOTH 14 TACTIC CLASSES SOC AT THE OPERATOR CORRELATED FLEET-WIDE PSEUDONYMISED · GDPR FINESSE · MOBILITY THREAT INTELLIGENCE

In automotive the building blocks are more mature: IDS sensors for CAN and Ethernet, the AUTOSAR IDS manager, and in UN R155 a fleet-wide obligation to detect attacks. For rail there was no comparable approach. Rail brings constraints of its own: detection has to work without reacting on the bus, and a vehicle stays in service for 30 to 40 years.

FINESSE puts attack classification, detection rules and event formats for both domains onto a common basis. A detection pattern from road transport thereby becomes usable on rail. We call that exchange mobility threat intelligence. The results rest on open components and interfaces and feed into standardisation.

VATT&EK

A language for attacks on vehicles

VATT&EK und die UDS-Erweiterung Eine Matrix aus vierzehn Taktik-Spalten. Neun davon tragen die aus 27 UDS-Diensten abgeleiteten Techniken. Eine Angriffskette laeuft quer durch mehrere Taktiken. TACTICS TECHNIQUES 27 UDS SERVICES ANALYSED 50 TECHNIQUES · 9 OF 14 TACTICS CHECKED AGAINST 33 REPORTS ALREADY DOCUMENTED PREVIOUSLY UNEXAMINED VATT&EK · 14 TACTIC CLASSES, ROAD AND RAIL

MITRE ATT&CK describes attacks on classic IT. For vehicles with control units, field buses and real-time requirements, the techniques are missing from it. VATT&EK (Vehicle Adversarial Tactics, Techniques & Expert Knowledge) fills that gap with 14 tactic classes, from CAN injection through radio attacks to GNSS spoofing.

We formalised and published the model with Dominik Spychalski (INCYDE) and Prof. Stefan Katzenbeisser (University of Passau) at the ACM Computer Science in Cars Symposium. The extension to the UDS diagnostic protocol (ISO 14229) came about with Nicolas Loza, Jens Gramm and Michael Peter Schneider of ETAS: 27 UDS services analysed, 50 attack techniques derived from them across nine tactics, checked against 33 published vulnerability reports. Two thirds of the techniques were already documented in the field; the rest uncovered attack vectors nobody had researched until then.

Our part

The SOC, carried over to vehicle fleets

Yekta IT builds and runs security operations centres for operators of critical infrastructure. In FINESSE we carried that knowledge from the OT world over into the vehicle world.

On board, a security event centre aggregates and correlates the reports of the individual sensors and allows fast local response. In the backend the data comes together fleet-wide in a vehicle security operations centre, enriched with the VATT&EK classification and threat intelligence. We extended the AUTOSAR event formats by forensic fields, rule ID, severity and confidence, and defined structurally compatible formats for rail for the first time. Pseudonymisation under the GDPR is part of the model from the start.

For the operator that means: what stands out becomes visible across a whole fleet, gets placed, and is documented in a way that can be followed, while operations continue.

Field trial

Live on a moving train

Monitoring im Advanced TrainLab Die Bus-Kommunikation eines Zuges wird ohne Rueckkanal abgegriffen und per UDP an einen abgesetzten RailPC uebertragen. Der Angriff wird in diesen Transportpfad eingespielt, das IDS erkennt ihn und meldet an das SEC und weiter ins Rail-SOC. TRAIN MVB CANOPEN UDP TAP WITHOUT A RETURN PATH RAILPC MVB-IDS SEC ON BOARD MANIPULATED MVB TELEGRAMS RAIL-SOC DETECTED, REPORTED ADVANCED TRAINLAB · ON A MOVING VEHICLE

In the advanced TrainLab of DB Systemtechnik we ran the monitoring on a real vehicle. We tap the train's MVB and CAN communication without reacting on the bus and transmit it by UDP to a separate rail PC.

The manipulated MVB telegrams were injected into that transport path. The safety-critical vehicle bus itself stayed untouched. Our MVB IDS detected the attacks and reported them to the security event centre; in the rail SOC the events came together centrally. Working without reacting on the bus is mandatory in rail operation: a detection system must not influence a safety-relevant field bus. We met that requirement on a real vehicle, supported by DB Systemtechnik, the University of Passau and INCYDE.

Demonstrators

From a real component to an attack you can watch

Out of the analysis of real vehicles, hardware and components came two rigs that show attack and detection side by side. We have demonstrated both publicly, among other places at the Nationale Konferenz IT-Sicherheitsforschung in 2025 and at IT-Sicherheitstag NRW.

Publications

What was published out of the project

  • VATT&EK: Formalization of Cyber Attacks on Intelligent Transport Systems. A. R. Yekta, D. Spychalski, E. Yekta, C. Yekta, S. Katzenbeisser. ACM CSCS 2023. 10.1145/3631204.3631867
  • UDS Attack Taxonomy: Systematic Classification of Vehicle Diagnostic Threats. A. R. Yekta, N. Loza, J. Gramm, M. P. Schneider, S. Katzenbeisser. IEEE CNS 2025. 10.1109/CNS66487.2025.11195020
  • From ECU to VSOC: UDS Security Monitoring Strategies. A. R. Yekta et al. SECURWARE 2025. 10.48550/arXiv.2510.25375
  • Towards a Holistic and Multi-Modal Vehicle Security Monitoring. A. R. Yekta, D. Spychalski, C. Yekta, M. Heinrich, C. Krauß, S. Katzenbeisser. Springer LNCS, link to follow.
  • Vehicle Threat Matrix: vehicle-threat-matrix.com

All results in detail are in the FINESSE closing brochure, which is in German.

Next step

Questions about vehicle monitoring?

We will say what of this transfers to your fleet or your plant, and what does not.

Telephone
0231 39814905
Mon–Fri · 9am–5pm CET
Email
info@yekta-it.de
PGP key available
Location
Dortmund
Ruhrallee 9 · 44139