Skip to main content
Research project

FINESSE: intrusion detection for road and rail

From July 2022 to December 2025, six partners built the continuous detection chain for vehicle fleets, from the sensor in the vehicle through the transmission path to the security operations centre at the operator. Yekta IT brought the SOC knowledge from critical infrastructure and developed the VATT&EK attack classification.

Attack detection for road and rail A car and a power car, both with ECUs on a bus and both under attack. Over the uplink their reports run into a Vehicle Security Operations Center that brings the whole fleet onto one picture. ROAD CAN · ETHERNET · UDS RAIL MVB · CANOPEN · IEC 61375 UPLINK VEHICLE SOC ONE FLEET, ONE PICTURE USE CASES JE FAHRZEUGTYP FINESSE · ATTACK DETECTION FOR ROAD AND RAIL
Key facts

Who, when, out of what

Duration

July 2022 to December 2025.

Funding

The German Federal Ministry of Research, Technology and Space, formerly the BMBF. Funding reference 16KIS1584K.

Partners

DB Systemtechnik, ETAS of the Bosch group, Fraunhofer SIT, INCYDE, the University of Passau and Yekta IT.

Field of application

Road and rail vehicles, from the control unit in the vehicle to the operator's security operations centre.

Our part

The SOC architecture for vehicle fleets, from the Security Event Center on board to the Vehicle Security Operations Center in the backend. The VATT&EK attack classification. The MVB IDS and the field trial in DB Systemtechnik's Advanced TrainLab, on a moving train. The demonstrators YekCar and YekTrain.

Published

Four papers at ACM CSCS, IEEE CNS, SECURWARE and CRITIS.

The approach

Road and rail on a common basis

Road and rail on a common basis Vehicles on the road and on the rails report into a shared attack classification with fourteen tactic classes, and from there into a SOC at the operator. The return path carries a pattern from one domain into the other. ROAD CAN · ETHERNET · UDS RAIL MVB · CANOPEN · IEC 61375 VATT&EK ONE CLASSIFICATION FOR BOTH 14 TACTIC CLASSES SOC AT THE OPERATOR CORRELATED FLEET-WIDE PSEUDONYMISED · GDPR FINESSE · MOBILITY THREAT INTELLIGENCE

In automotive the building blocks are more mature: IDS sensors for CAN and Ethernet, the AUTOSAR IDS manager, and in UN R155 a fleet-wide obligation to detect attacks. For rail there was no comparable approach. Rail brings constraints of its own: detection has to work without reacting on the bus, and a vehicle stays in service for 30 to 40 years.

FINESSE puts attack classification, detection rules and event formats for both domains onto a common basis. A detection pattern from road transport thereby becomes usable on rail. We call that exchange mobility threat intelligence. The results rest on open components and interfaces and feed into standardisation.

VATT&EK

A language for attacks on vehicles

VATT&EK and the UDS extension A matrix of fourteen tactic columns. Nine of them carry the techniques derived from 27 UDS services. One attack chain runs across several tactics. TACTICS TECHNIQUES 27 UDS SERVICES ANALYSED 50 TECHNIQUES · 9 OF 14 TACTICS CHECKED AGAINST 33 REPORTS ALREADY DOCUMENTED PREVIOUSLY UNEXAMINED VATT&EK · 14 TACTIC CLASSES, ROAD AND RAIL

MITRE ATT&CK describes attacks on classic IT. For vehicles with control units, field buses and real-time requirements, the techniques are missing from it. VATT&EK (Vehicle Adversarial Tactics, Techniques & Expert Knowledge) fills that gap with 14 tactic classes, from CAN injection through radio attacks to GNSS spoofing.

The model is formalised and peer-reviewed as “VATT&EK: Formalization of Cyber Attacks on Intelligent Transport Systems” at the ACM Computer Science in Cars Symposium. The extension to the UDS diagnostic protocol (ISO 14229) followed as “UDS Attack Taxonomy: Systematic Classification of Vehicle Diagnostic Threats” at the IEEE Conference on Communications and Network Security: 27 UDS services analysed, 50 attack techniques derived from them across nine tactics, checked against 33 published vulnerability reports. Two thirds of the techniques were already documented in the field; the rest uncovered attack vectors nobody had researched until then.

Our part

The SOC, carried over to vehicle fleets

Yekta IT builds and runs security operations centres for operators of critical infrastructure. In FINESSE we carried that knowledge from the OT world over into the vehicle world.

On board, a security event centre aggregates and correlates the reports of the individual sensors and allows fast local response. In the backend the data comes together fleet-wide in a vehicle security operations centre, enriched with the VATT&EK classification and threat intelligence. We extended the AUTOSAR event formats by forensic fields, rule ID, severity and confidence, and defined structurally compatible formats for rail for the first time. Pseudonymisation under the GDPR is part of the model from the start.

For the operator that means: what stands out becomes visible across a whole fleet, gets placed, and is documented in a way that can be followed, while operations continue.

Field trial

Live on a moving train

Monitoring in the Advanced TrainLab A train's bus communication is tapped without a return path and transmitted by UDP to a remote RailPC. The attack is injected into that transport path; the IDS detects it and reports to the SEC and on into the rail SOC. TRAIN MVB CANOPEN UDP TAP WITHOUT A RETURN PATH RAILPC MVB-IDS SEC ON BOARD MANIPULATED MVB TELEGRAMS RAIL-SOC DETECTED, REPORTED ADVANCED TRAINLAB · ON A MOVING VEHICLE

In the advanced TrainLab of DB Systemtechnik we ran the monitoring on a real vehicle. We tap the train's MVB and CAN communication without reacting on the bus and transmit it by UDP to a separate rail PC.

The manipulated MVB telegrams were injected into that transport path. The safety-critical vehicle bus itself stayed untouched. Our MVB IDS detected the attacks and reported them to the security event centre; in the rail SOC the events came together centrally. Working without reacting on the bus is mandatory in rail operation: a detection system must not influence a safety-relevant field bus. We met that requirement on a real vehicle, supported by DB Systemtechnik, the University of Passau and INCYDE.

Demonstrators

From a real component to an attack you can watch

Out of the analysis of real vehicles, hardware and components came two rigs that show attack and detection side by side. We have demonstrated both publicly, among other places at the Nationale Konferenz IT-Sicherheitsforschung in 2025 and at IT-Sicherheitstag NRW.

Publications

What was published out of the project

  • VATT&EK: Formalization of Cyber Attacks on Intelligent Transport Systems. A. R. Yekta, D. Spychalski, E. Yekta, C. Yekta, S. Katzenbeisser. ACM CSCS 2023. 10.1145/3631204.3631867
  • UDS Attack Taxonomy: Systematic Classification of Vehicle Diagnostic Threats. A. R. Yekta, N. Loza, J. Gramm, M. P. Schneider, S. Katzenbeisser. IEEE CNS 2025. 10.1109/CNS66487.2025.11195020
  • From ECU to VSOC: UDS Security Monitoring Strategies. A. R. Yekta et al. SECURWARE 2025. 10.48550/arXiv.2510.25375
  • Towards a Holistic and Multi-Modal Vehicle Security Monitoring. A. R. Yekta, D. Spychalski, C. Yekta, M. Heinrich, C. Krauß, S. Katzenbeisser. CRITIS 2025, 20th International Conference on Critical Information Infrastructures Security. Springer LNCS, link to follow.
  • Vehicle Threat Matrix: vehicle-threat-matrix.com

All results in detail are in the FINESSE closing brochure, which is in German.

Next step

Questions about vehicle monitoring?

We will say what of this transfers to your fleet or your plant, and what does not.

Telephone
0231 39814905
Mon–Fri · 9am–5pm CET
Location
Dortmund
Ruhrallee 9 · 44139