Jul 2026· IEEE Internet of Things Journal· Vol abs/2607.07226, pp. 1-1· 0 citations· 46 references
Computer Science
TL;DR
This work presents a comprehensive security analysis for SDVs, focusing on software vulnerabilities, and combines systematic vulnerability discovery, leveraging public Common Vulnerabilities and Exposures databases, within a dockerized development environment that evaluates exploitability risks.
Abstract
Software-defined vehicles (SDVs) are revolutionizing transportation by integrating complex, interconnected hardware, and software systems. This evolution introduces significant security challenges. We present a comprehensive security analysis for SDVs, focusing on software vulnerabilities. We note that existing vulnerability assessment tools fall short in addressing operating systems vulnerabilities, particularly when it comes to efficiently analyzing diverse software stacks in realistic environments. We present and release a vulnerability assessment solution that efficiently addresses these limitations. Our approach combines systematic vulnerability discovery, leveraging public Common Vulnerabilities and Exposures (CVE) databases, within a dockerized development environment that evaluates exploitability risks. The results reveal both breadth of potential threats and the practical constraints we faced during exploitation. We discuss the implications for industry and research, and propose directions for building more resilient SDVs.
The increased level of connectivity for vehicles leads to sophisticated and challenging software security concerns for automotive Original Equipment Manufacturers (OEMs) and suppliers. With a Connected Vehicle (CV) communicating with multiple entities (road infrastructure, other vehicles, OEMs, cloud, etc.), new attack...
Srijita Basu, Miroslaw Staron, M. Almgren et al.· Software quality journal· 0 citations
Embedded systems are plagued by various security vulnerabilities that can lead to severe attacks. Therefore, it is crucial to detect and mitigate these vulnerabilities quickly and accurately. In this article, we survey existing research on vulnerability detection in embedded systems, with taint analysis as the central...
This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk.
Shruti Agarwal, S. Sharma· DMPedia Lecture Notes in Com...· 1 citation
A novel NSSA framework based on process tree modeling and dynamic service-chain orchestration that significantly outperforms PCA and Basic Evolution in terms of true positive and false positive rates, while the dynamic service-chain mechanism ensures efficient resource utilization and rapid threat containment.
Si-Wei Li, Xiao-Dong Wei· International Journal of Com...· 0 citations
The software supply chain has become an increasingly exposed attack surface because of its reliance on intricate yet fragile dependencies. Existing defenses such as GitHub Dependabot often raise many false alerts because their coarse-grained matching cannot determine whether a vulnerable dependency is actually exploita...
Jia-Hao Shi, Edward Tsien, Yi-Feng Di et al.· 0 citations
Software supply chain security has become increasingly critical due to the widespread reliance on third-party dependencies and the growing attack surface of modern software ecosystems. However, existing quantitative, measurement-based analysis and vulnerability management approaches remain largely fragmented and ecosys...
Sarah Meriem Ourari· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.