FINESSE: intrusion detection for road and rail
From July 2022 to December 2025, six partners built the continuous detection chain for vehicle fleets, from the sensor in the vehicle through the transmission path to the security operations centre at the operator. Yekta IT brought the SOC knowledge from critical infrastructure and developed the VATT&EK attack classification.
Who, when, out of what
Duration
July 2022 to December 2025.
Funding
The German Federal Ministry of Research, Technology and Space, formerly the BMBF. Funding reference 16KIS1584K.
Partners
INCYDE as consortium lead, with DB Systemtechnik, ETAS of the Bosch group, Fraunhofer SIT, the University of Passau and Yekta IT.
Field of application
Road and rail vehicles, from the control unit in the vehicle to the operator's security operations centre.
Our part
The SOC architecture for vehicle fleets, the VATT&EK attack classification, and the two demonstrators YekCar and YekTrain.
Published
Four papers at ACM CSCS, IEEE CNS, SECURWARE and in the Springer LNCS.
Road and rail on a common basis
In automotive the building blocks are more mature: IDS sensors for CAN and Ethernet, the AUTOSAR IDS manager, and in UN R155 a fleet-wide obligation to detect attacks. For rail there was no comparable approach. Rail brings constraints of its own: detection has to work without reacting on the bus, and a vehicle stays in service for 30 to 40 years.
FINESSE puts attack classification, detection rules and event formats for both domains onto a common basis. A detection pattern from road transport thereby becomes usable on rail. We call that exchange mobility threat intelligence. The results rest on open components and interfaces and feed into standardisation.
A language for attacks on vehicles
MITRE ATT&CK describes attacks on classic IT. For vehicles with control units, field buses and real-time requirements, the techniques are missing from it. VATT&EK (Vehicle Adversarial Tactics, Techniques & Expert Knowledge) fills that gap with 14 tactic classes, from CAN injection through radio attacks to GNSS spoofing.
We formalised and published the model with Dominik Spychalski (INCYDE) and Prof. Stefan Katzenbeisser (University of Passau) at the ACM Computer Science in Cars Symposium. The extension to the UDS diagnostic protocol (ISO 14229) came about with Nicolas Loza, Jens Gramm and Michael Peter Schneider of ETAS: 27 UDS services analysed, 50 attack techniques derived from them across nine tactics, checked against 33 published vulnerability reports. Two thirds of the techniques were already documented in the field; the rest uncovered attack vectors nobody had researched until then.
The SOC, carried over to vehicle fleets
Yekta IT builds and runs security operations centres for operators of critical infrastructure. In FINESSE we carried that knowledge from the OT world over into the vehicle world.
On board, a security event centre aggregates and correlates the reports of the individual sensors and allows fast local response. In the backend the data comes together fleet-wide in a vehicle security operations centre, enriched with the VATT&EK classification and threat intelligence. We extended the AUTOSAR event formats by forensic fields, rule ID, severity and confidence, and defined structurally compatible formats for rail for the first time. Pseudonymisation under the GDPR is part of the model from the start.
For the operator that means: what stands out becomes visible across a whole fleet, gets placed, and is documented in a way that can be followed, while operations continue.
Live on a moving train
In the advanced TrainLab of DB Systemtechnik we ran the monitoring on a real vehicle. We tap the train's MVB and CAN communication without reacting on the bus and transmit it by UDP to a separate rail PC.
The manipulated MVB telegrams were injected into that transport path. The safety-critical vehicle bus itself stayed untouched. Our MVB IDS detected the attacks and reported them to the security event centre; in the rail SOC the events came together centrally. Working without reacting on the bus is mandatory in rail operation: a detection system must not influence a safety-relevant field bus. We met that requirement on a real vehicle, supported by DB Systemtechnik, the University of Passau and INCYDE.
From a real component to an attack you can watch
Out of the analysis of real vehicles, hardware and components came two rigs that show attack and detection side by side. We have demonstrated both publicly, among other places at the Nationale Konferenz IT-Sicherheitsforschung in 2025 and at IT-Sicherheitstag NRW.
What was published out of the project
- VATT&EK: Formalization of Cyber Attacks on Intelligent Transport Systems. A. R. Yekta, D. Spychalski, E. Yekta, C. Yekta, S. Katzenbeisser. ACM CSCS 2023. 10.1145/3631204.3631867
- UDS Attack Taxonomy: Systematic Classification of Vehicle Diagnostic Threats. A. R. Yekta, N. Loza, J. Gramm, M. P. Schneider, S. Katzenbeisser. IEEE CNS 2025. 10.1109/CNS66487.2025.11195020
- From ECU to VSOC: UDS Security Monitoring Strategies. A. R. Yekta et al. SECURWARE 2025. 10.48550/arXiv.2510.25375
- Towards a Holistic and Multi-Modal Vehicle Security Monitoring. A. R. Yekta, D. Spychalski, C. Yekta, M. Heinrich, C. Krauß, S. Katzenbeisser. Springer LNCS, link to follow.
- Vehicle Threat Matrix: vehicle-threat-matrix.com
All results in detail are in the FINESSE closing brochure, which is in German.
Where the results land in our consulting
The detection rules, the classification and the experience from the field trial are in our daily work.
Questions about vehicle monitoring?
We will say what of this transfers to your fleet or your plant, and what does not.