Skip to content
Open access

Monitoring Vulnerabilities in Next-Generation Automotive Operating Systems

Jul 2026 · IEEE Internet of Things Journal · Vol abs/2607.07226, pp. 1-1 · 0 citations · 46 references
Computer Science

TL;DR

This work presents a comprehensive security analysis for SDVs, focusing on software vulnerabilities, and combines systematic vulnerability discovery, leveraging public Common Vulnerabilities and Exposures databases, within a dockerized development environment that evaluates exploitability risks.

Abstract

Software-defined vehicles (SDVs) are revolutionizing transportation by integrating complex, interconnected hardware, and software systems. This evolution introduces significant security challenges. We present a comprehensive security analysis for SDVs, focusing on software vulnerabilities. We note that existing vulnerability assessment tools fall short in addressing operating systems vulnerabilities, particularly when it comes to efficiently analyzing diverse software stacks in realistic environments. We present and release a vulnerability assessment solution that efficiently addresses these limitations. Our approach combines systematic vulnerability discovery, leveraging public Common Vulnerabilities and Exposures (CVE) databases, within a dockerized development environment that evaluates exploitability risks. The results reveal both breadth of potential threats and the practical constraints we faced during exploitation. We discuss the implications for industry and research, and propose directions for building more resilient SDVs.

Read PDF

Similar papers

Review Open access Sep 2026

Mapping the landscape of software vulnerabilities in connected vehicles

The increased level of connectivity for vehicles leads to sophisticated and challenging software security concerns for automotive Original Equipment Manufacturers (OEMs) and suppliers. With a Connected Vehicle (CV) communicating with multiple entities (road infrastructure, other vehicles, OEMs, cloud, etc.), new attack...

Srijita Basu, Miroslaw Staron, M. Almgren et al. · 0 citations
Review Open access Aug 2026

Detecting Vulnerabilities in Embedded Systems via Taint Analysis: A Survey

Embedded systems are plagued by various security vulnerabilities that can lead to severe attacks. Therefore, it is crucial to detect and mitigate these vulnerabilities quickly and accurately. In this article, we survey existing research on vulnerability detection in embedded systems, with taint analysis as the central...

Guo-Hao Wu, Hong-Liang Liang, Lu-Ming Yin et al. · 0 citations
Review Open access Jul 2026

Penetration Testing in System Security

This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk.

Shruti Agarwal, S. Sharma · 1 citation
Sep 2026

Implementing a Security Operations Baseline Through Process Tree Modeling for Network Security Situational Awareness

A novel NSSA framework based on process tree modeling and dynamic service-chain orchestration that significantly outperforms PCA and Basic Evolution in terms of true positive and false positive rates, while the dynamic service-chain mechanism ensures efficient resource utilization and rapid threat containment.

Si-Wei Li, Xiao-Dong Wei · 0 citations
#machine learning Preprint Sep 2026

VEX-Bench: Benchmarking LLM Agents for Assessing Exploitability of Software Supply Chain Vulnerabilities

The software supply chain has become an increasingly exposed attack surface because of its reliance on intricate yet fragile dependencies. Existing defenses such as GitHub Dependabot often raise many false alerts because their coarse-grained matching cannot determine whether a vulnerable dependency is actually exploita...

Jia-Hao Shi, Edward Tsien, Yi-Feng Di et al. · 0 citations
Preprint Sep 2026

Measuring the Security of the Evolving Software Supply Chain: a Research Agenda

Software supply chain security has become increasingly critical due to the widespread reliance on third-party dependencies and the growing attack surface of modern software ecosystems. However, existing quantitative, measurement-based analysis and vulnerability management approaches remain largely fragmented and ecosys...

Sarah Meriem Ourari · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.