Research and knowledge
Our own OT lab and applied security research.
Research that stands in the lab and comes back in tests
We run our own OT lab with demonstrators from several sectors. We play attacks and defences through on real hardware there, not in theory and not in simulation.
Part of that work ran from July 2022 to December 2025 in a federally funded joint project on cyber protection systems for vehicles and infrastructure in road and rail transport, together with partners from rail, the automotive industry, Fraunhofer and a university. Our sub-project carried the funding reference 16KIS1588. What came out of it flows straight back into our tests and training.
Three components that did not exist before
From the joint project, documented publicly in the project report.
Intrusion detection for the vehicle bus in a train
Vendor-neutral detection for the Multifunction Vehicle Bus to IEC 61375. Recordings from two systems of different origin and a virtual environment of our own run through adapters into a common data model. Detection is hybrid, rule-based and learning-based.
Intrusion detection for vehicle diagnostics
Common detection on the vehicle bus reads only frame structures and does not understand the diagnostic protocol. Ours interprets it: session states, service identifiers and access levels are evaluated in order to detect reading out, memory scanning and attacks on the security access.
A security event centre in the vehicle
Individual detection systems each see only their own technology. The security event centre collects and correlates events from all sources on board, making attack chains across technologies visible, and is at the same time the interface to fleet-wide analysis.
From the controller to the fleet, in five levels
Security events arise in very different places, and they need different response times. So we laid the architecture out as a hierarchy: raw data in control units and network components, above it the monitoring of individual control units, above that the monitoring of whole vehicle domains with their respective protocols, above that the consolidation within the vehicle, and at the top the cross-vehicle analysis in operation.
The lower levels allow immediate local response; the top one allows connections across the fleet. For the event formats we extended an existing automotive standard by the fields that were missing for analysis that holds up.
Trialled on a research train
The advanced TrainLab of DB Systemtechnik served as the test platform under real operating conditions. Vehicle buses are tapped on board and transmitted to a computer with a security module. The sensors run in containers, normalise the incoming data and check it for manipulation.
Because the mobile connection of a moving train is limited, the sensors pre-filter: only what is security-relevant is transmitted. If the link to the analysis drops, the security event centre buffers on board until it is back. Those are the constraints that separate a train from a data centre.
What was published from it
The results are peer-reviewed and published, not only in project reports:
- VATT&EK: Formalization of Cyber Attacks on Intelligent Transport Systems. A TTP based approach for Automotive and Rail. 7th ACM Computer Science in Cars Symposium, 2023. The model sorts adversary behaviour into fourteen tactic classes, from manipulating the environment through initial access to impact, and so covers what the common IT model leaves open for vehicles.
- UDS Attack Taxonomy. Systematic classification of vehicle diagnostic threats. IEEE Conference on Communications and Network Security, 2025.
- From ECU to VSOC. UDS Security Monitoring Strategies. SECURWARE, 2025. Three categories of detection strategy, from patterns in the vehicle protocol through assessment in the context of vehicle state to the inclusion of public vulnerability information.
- Towards a Holistic and Multi-modal Vehicle Security Monitoring. Critical Information Infrastructures Security, 20th International Conference.
- Multi-modales Intrusion Detection System. Angriffserkennung für Mobilitätssysteme. Signal + Draht 117 (2025) 3.
- KI auf Schienen. Beschleunigung der digitalen Transformation des Bahnbetriebs. Signal + Draht 116 (2024) 4, pages 15 to 21, also published in English.
A public matrix accompanies the taxonomy, in which the tactics and techniques can be looked up.
Research is not a marketing word here
The detection rules we write in client projects come from the same work. The training sessions in which participants attack things themselves run on the same rigs. And the testing procedures we apply in a plant have been played through on our own hardware first.
What we find and learn we share on the blog, in publications, and in security advisories of our own with coordinated disclosure.
Research that stands in the lab.
We run our own OT lab with real demonstrators from several sectors. Three points describe the work.
Real hardware
We play attacks and defences through on real hardware, not in theory and not in simulation.
Funded projects
Part of that work ran until December 2025 in the FINESSE joint project. What comes out of the research flows straight back into our tests and training.
We pass it on
What we find and learn we share on the blog, in planned white papers and in security advisories of our own.
Four ways into our work.
From the running lab to planned publications. One sentence to place each; the detail follows on its own page.
- YekCity Built from the analysis of real attacks on power and utility networks: a model city with real controllers, on which those attacks can be replayed, detected and practised.
- YekTrain Vehicle systems on MVB and CANopen, built from recordings of real trains. Attacks and their detection can be shown on it reproducibly.
- YekCar Emulated control units with CAN, UDS and keyless entry, with an attacker dashboard and an IDS monitor in the same case.
- YekIntel Threat intelligence and attack simulation across all demonstrators.
White papers
In-depth articles on OT and IT security. In preparation.
CVEs and security advisories
Vulnerabilities we found ourselves, with coordinated disclosure. In preparation.
The demonstrators are the evidence.
Three demonstrators from different sectors, on which attacks and countermeasures can be shown reproducibly. They are the basis of our tests, our training and our live demos.
YekCity
Built from the analysis of real attacks on power and utility networks: a model city with real controllers, on which those attacks can be replayed, detected and practised.
YekTrain
Vehicle systems on MVB and CANopen, built from recordings of real trains. Attacks and their detection can be shown on it reproducibly.
YekCar
Emulated control units with CAN, UDS and keyless entry, with an attacker dashboard and an IDS monitor in the same case.
What we work on.
Our research is embedded in funding programmes and a lab of our own.
BMFTR
Funded by the German Federal Ministry of Research, Technology and Space, formerly the BMBF.
FINESSE project
Applied security research in a funded joint project.
OT lab
Real demonstrators from several sectors as the basis of the work.
See the lab up close.
Arrange a first conversation or ask for a live demo. We will show the demonstrators and what can be tested on them.