FINESSE at CPS-Sec 2025 in Avignon

Systematic Classification of UDS Attacks
At the 10th IEEE International Workshop on Cyber-Physical Systems Security (CPS-Sec 2025), part of the IEEE Conference on Communications and Network Security (CNS) 2025 in Avignon, the FINESSE consortium presented current research on vehicle diagnostic protocol security.
Paper: “UDS Attack Taxonomy: Systematic Classification of Vehicle Diagnostic Threats”
The paper was developed in collaboration between Ali Recai Yekta (Yekta IT), Nicolas Loza, Jens Gramm, and Michael Peter Schneider (ETAS), and Prof. Stefan Katzenbeisser (University of Passau) within the FINESSE research project.
Challenge: The increasing complexity and connectivity of modern vehicles leads to significant security challenges, particularly affecting the Unified Diagnostic Services (UDS) protocol – a communication standard used in the automotive industry for diagnostic and maintenance purposes.
VATT&EK Framework: The paper presents a comprehensive analysis of potential attack techniques targeting the UDS protocol. The research utilizes the VATT&EK Framework – a vehicle-specific adaptation of the well-known MITRE ATT&CK methodology. This approach systematically identifies and categorizes adversarial techniques for exploiting UDS vulnerabilities.
Practical Validation: The analysis demonstrates the taxonomy’s practical applicability by mapping it to existing attack scenarios from published literature. For nearly two-thirds of the identified techniques, concrete examples from real-world attack scenarios could be identified.
The presented taxonomy provides a structured approach for security assessments, incident response, and developing effective monitoring strategies for UDS-based communication. The results form an important foundation for developing protective measures and monitoring strategies in vehicle security for road and rail vehicles.
Paper DOI: Publication
The FINESSE project is funded by the German Federal Ministry of Research, Technology and Space (BMFTR).