SOS 2023

Schedule

(Time in UTC)

7:00 AM
(UTC)
Welcome Session
30 mins
Show More...
7:30 AM
(UTC)
KEYNOTE: Looking back to the future of automotive cybersecurity
1 hour

This talk looks back at the maturation of cybersecurity in the automotive industry from early anti-theft systems to the use of technical measures to protect electronic vehicle systems up to today’s requirements regarding technical and organizational measures to protect current vehicles against attacks. The talk reports on experiences from this maturing process as well as current and future challenges. Technical but also organizational trends will be highlighted and discussed in the conflict resulting from an increasing rigidity of concrete (regulatory) requirements on the one hand and the required degree of freedom for the development of alternative solutions on the other hand. Empirical success criteria and high dynamics regarding environmental conditions for automotive cybersecurity will be one focus area of the discussion.

Show More...
Dr. Joern Eichler
Head of Security Engineering Volkswagen Passenger Cars

Joern is responsible for security architectures of vehicle platforms, secure product development processes and methods as well as related standardization activities within the Technical Development of Volkswagen Passenger Cars. His research is focused on the development of secure systems and he is giving lectures on Security Engineering at Freie Universität Berlin. Joern has more than 20 years of experience as a researcher, developer, architect, and manager in different industries and research organizations, including 15 years in the security domain. Joern holds a Ph.D. in Computer Science from the Technical University of Munich and an MSc in Business Economics from the Freie Universität Berlin.

Show More...
8:30 AM
(UTC)
A Practical Transformation Proposal between Attack Potential based and CVSS based Attack Feasibility
45 mins

ISO/SAE 21434:2021 discusses the calculation of the Attack Feasibility Rating through various methods, including the CVSS-based approach and the Attack Potential (AP)-based approach.

During the concept and development phases (e.g., TARA), the more detailed Attack Potential approach finds widespread use. Conversely, the CVSS-based approach continues to dominate continual cybersecurity activities due to the availability of public vulnerability database ratings based on CVSS. As both CVSS and Attack Potential approaches have their respective advantages and applications, it is evident that the coexistence of these methods will persist.

However, our concrete project experiences have revealed that the application of different approaches does not consistently yield identical results, even when considering the same attack paths. This disparity becomes particularly problematic when trying to integrate CVSS-based information into Risk Value calculations originally designed for the Attack Potential-based approach. Until this issue is addressed in upcoming releases of ISO/SAE 21434, the industry requires a solution to maintain a holistic product cybersecurity risk and vulnerability management approach throughout the entire product lifecycle. Therefore, there is a pressing need for a stable and consistent conversion methodology between the Attack Potential and CVSS-based approaches.

This presentation aims to explain the differentiation between the CVSS-based and Attack Potential approaches, highlighting their individual advantages and disadvantages. It also acknowledges the continued significance of both approaches in Road Vehicles Cybersecurity Engineering and proposes conversion methods. These are then elaborated with detailed calculations, and examples are provided to demonstrate the consistency of the results.

Show More...
Orhun Süzer
Independent Consultant

Masters in Embedded Systems
More than 7 years of experience in Automotive Cybersecurity
ISTQB, IREB, RE@Agile, ASPICE Certifications

Show More...
8:30 AM
(UTC)
Automating End-to-End Security Testing in the Automotive Industry
45 mins

This talk will explore the challenges and benefits of integrating automated end-to-end security testing into the automotive development lifecycle. It will discuss solutions for infrastructure, asynchronous messages, fast-changing backends, and emerging technologies to meet UN R155 criteria.

Show More...
Alon Ashkenazi
Solution Incubator Manager, Cymotive

15 years of experience in both cyber security and R&D projects at various companies.

For the past 4 years I have been working in Cymotive, a company that is providing cyber security services for the automotive industry and working mainly with VW and its brands.

I have intensive experience in architecture design, risk analysis for automotive, and R&D.

I have invented a product for end to end automated security testing for automotive, which is unique in its way of analyzing asynchronous messaging and its impact on various IoTs and have a team of developers including myself developing this for the past 2 years as part of my role in Cymotive.

Show More...
9:15 AM
(UTC)
GoGoBark:Interference Attacks on UWB Ranging for IEEE 802.15.4z Standard
45 mins

The industry generally acknowledges that Ultra Wide Band (UWB) technology can theoretically mitigate relay attacks targeting traditional Low Frequency (LF) and Bluetooth Passive Keyless Entry (PKE) systems. UWB localization technology has been increasingly incorporated into the latest digital car key systems, so the functionality of UWB ranging is directly tied to the car’s susceptibility to relay attacks and the proper operation of the car key. However, during a security test project at GoGoByte, we discovered that merely adhering to the IEEE 802.15.4z and Car Connectivity Consortium (CCC) Digital Key standards does not ensure the reliable performance of the UWB ranging function. We have proposed a “sniper” jamming attack on High Rate Pulse (HRP) UWB ranging. For confidentiality reasons, we used the iPhone 14 and AirTag as demonstration devices and created an attack device called GoGoBark. Once GoGoBark is activated, the UWB-based ranging function of the iPhone fails, with a success rate of 99%. This attack method impacts not only Apple smartphones but also digital car keys that utilize IEEE 802.15.4z HRP UWB ranging.

Show More...
Zhongjie Wu
9:15 AM
(UTC)
Tragedy of the Commons: Software Security in the Software-Defined Car
45 mins

This talk paints the picture of the challenges the automotive industry is facing in the era of software-defined vehicles (SDVs) where software security suffers from the tragedy of the commons. Coverage-guided fuzzing has proven to be very effective in finding security-relevant bugs in software. Despite a large slew of open-source tools, applying coverage-guided fuzzing to automotive software still has a high entry barrier for adoption. To alleviate the challenge, this talk presents system and module-level fuzzing approaches to lower the entry barrier for fuzzing automotive software. To make the approaches tangible, short live demonstrations of the system and module fuzzing approaches will be presented.

Show More...
Khaled Yakdan

Khaled Yakdan is the Chief Scientist and Co-Founder at Code Intelligence. Holding a Ph.D. in Computer Science and having spent over 9 years in academia, Khaled now oversees the implementation of research outcomes in AI, usable security, and vulnerability detection into Code Intelligence’s products. He worked and contributed to research in reverse engineering, vulnerability finding, and concolic executions. His papers are published at top-tier international security conferences.

Show More...
Rakshith Amarnath

Rakshith is currently the Director for Embedded and Automotive Solutions at the German startup Code Intelligence. In his current role, he oversees the future expansion of service offerings from Code Intelligence in these sectors and handles client projects from the perspective of customer success. Rakshith brings more than a decade of experience in the automotive sector where he previously worked as R&D project lead at Robert Bosch to secure connectivity based products. Rakshith completed his M.Sc. degree in Embedded Systems with honors from the Delft University of Technology. He actively engages with the community via invited keynote talks and as an industry chair for IEEE conferences.

Show More...
10:00 AM
(UTC)
Security of Over-the-Air Software Update towards SDV
45 mins

Over-the-Air Software Update is widely used by Car OEMs to ensure maintenance of Vehicles Software through regular updates containing either bug fixes, vulnerability patches or introduction of new features or functionalities throughout vehicle serial-life on Connected Vehicles.

Introduction of ISO/SAE-21434 standard and UNR.155/UNR.156 regulations have largely contributed to helping OEMs and Suppliers at standardizing methodologies within engineering flows and processes while impacting security architecture. This initial step could largely be extended in the future and become even more beneficial to Vehicle end-users since security serves common objectives for all OEMs and automotive suppliers with ultimate winners being end-users with more secure products running in our streets. Knowledge sharing should be encouraged to continue to strive for continuous improvements.

Goal of this session is to share current strategies & methodologies used at Renault to enhance Security Architecture on future SDV platforms and cope with the challenges of updating very frequently multiple execution environments including sensitive automotive functions while still controlling security risks.

Show More...
Cédric Vamour
Cybersecurity Architect at Renault

Cedric Vamour is Cybersecurity Architect at Renault Software Factory in Sophia-Antipolis (France). His fields of operations are the end-to-end Cyber-Security of Software Update on Renault Vehicles, V2X C-ITS (Intelligent Transportation Systems) for Assistance/Autonomous Driving functions, Cryptography and Key Managment. He worked previously as a Senior/Staff Engineer for Intel and Texas Instruments on embedded and wireless systems.

Show More...
10:00 AM
(UTC)
TABLE TOP EXERCISE: Incident Response - Live Tabletop
1 hour

This presentation will be a live demonstration of an incident response Tabletop Exercise, designed to outline the benefits of conducting exercises within businesses and governments and provide attendees with firsthand experience of what an event like this would entail.

The exercise will be interactive with the audience, relying on them to help drive the incident through each stage of the process:

Identify
Triage
Validate
Mitigate
Disclose

This will be a fictional incident for a fictional company/device not targeted to the automotive industry, with some actionable tips to enhance or establish incident response tabletops within private and public organizations.

Show More...
Sean McKeever
Senior Security Researcher GRIMM

Sean McKeever Is a Security Researcher at GRIMM, previously he worked as a Cybersecurity Architect at global automotive OEM where he secured advanced transportation mobility platforms and served as the company’s Bug Bounty Program Manager. Outside of Sean’s employment, he co-founded the Detroit chapter of the Automotive Security Research Group (ASRG), developed the RoboCar Platform, and contributes to CTFs at DEFCON, GRRCon, Converge and BSides Detroit.

Show More...
11:20 AM
(UTC)
Falling Backwards Into Automotive Security
45 mins

Having been involved in the automotive cybersecurity industry since early 2017, Kamel has gotten to experience the growth of the field firsthand. Over the years, the industry has changed greatly, with industry standards and legislation coming to completion, the emergence of different groups and organizations, books specific to the subject of automotive security published, and more. In this talk, Kamel will recount his time in the industry, answering many of the most common questions he receives from newcomers to the industry eager to find guidance on how to navigate it.

Show More...
Kamel Ghali
ASRG Japan Lead

Kamel Ghali is a veteran of the automotive cybersecurity industry and car hacking community. He has spent over five years watching the industry mature from many points of views including professional car hacker, reverse engineering expert, vehicle penetration tester, and legislation compliance auditor. He contributes to many cybersecurity communities – especially those focused on automotive security – by giving talks and training at events around the world, hosting the Car Hacking CTF at the annual DEFCON Car Hacking Village, and being an active member of the Automotive Security Research Group (ASRG) and other similar organizations. His hobbies include cooking and commentating competitive fighting games!

Show More...
11:20 AM
(UTC)
SDVs and Beyond: Upstream's H1'2023 Automotive Cyber Trend & Impact Report
45 mins

For the last six years, Upstream has been carefully monitoring and analyzing automotive and smart mobility cybersecurity incidents and risks.

In addition to an extensive report published annually, last year we added a new mid-year version of the report – focusing on major trends we identified recently that drive new attack vectors and risks.

In our latest H1’2023 report we identified three significant trends that directly derive from the SDV transformation the industry is undergoing:

1. Steep rise in backend server attacks – enabling access to sensitive vehicle data and controls
2. The critical role of continuous SBOM analysis (dynamic TARA) and how it can be utilized to boost threat intelligence
3. Agriculture, construction, and heavy machinery vehicles – new targets by malicious are being targeted by threat actors – these SDVs are more susceptible than ever to cybersecurity threats

In this session, we’ll dive deep into the opportunities delivered by SDVs, and help assess the emerging cybersecurity threats. We’ll provide insights on recent incidents and discovered vulnerabilities in 2023, and how OTA – which are at the heart of SDV transformation – are also a very effective mitigation tool.

Show More...
Giuseppe Serio
VP Market Development, Upstream

With more than two decades of experience in the automotive industry, Giuseppe Serio is responsible for global and strategic initiatives at Upstream, serving as the VP Market Development.

Prior to joining Upstream, he helped clients succeed in their digital transformation related to connected cars as well as their risks associated with cybersecurity, serving as the Global Industry Solution Leader Connected Vehicle & Automotive Cybersecurity at IBM. Giuseppe has been a thought leader, featured speaker and panelist on automotive security topics around the world and one of the first proponents of the idea of a vehicle security operations center for connected and autonomous vehicles (vSOC).

Show More...
12:05 PM
(UTC)
Challenges in Automotive Vulnerability Disclosure
45 mins

As the automotive industry embraces cutting-edge technology, the need for robust security measures becomes paramount. This presentation delves into our research, which involved successfully hacking thousands of heavy vehicles and shines a spotlight on the significant challenges encountered during the vulnerability disclosure process.

Show More...
Ramiro Pareja
Principal Security Consultant at IOActive

Ramiro Pareja is Principal Security Consultant at IOActive. He has a large experience on hardware security and he specializes on Embedded Systems and SoC security. In the last years, Ramiro has developed his interest and expertise in the automotive industry, where he applied successfully attacks like fault injection and side channel attacks – very common in other markets like smartcards or content protection – to the automotive electronic systems.

If it has chips, he can break it 😉

Show More...
Yashin Mehaboobe
Security Consultant

Yashin Mehaboobe is a security consultant at Xebia and has more than 8 years experience in the embedded systems security domain. His primary areas of interest is blackbox vulnerability analysis and pentesting of common IoT devices with focus on Internet facing scalable attacks. He’s also identified several fault injection attacks in open source embedded software and modern microcontrollers. In his spare time he likes to travel, take photographs, bake and read.

Show More...
12:05 PM
(UTC)
Fault Injection Attacks on Secure Automotive Bootloaders
45 mins

In this talk, we present a novel method for exploiting vulnerabilities in secure embedded bootloaders, which are the foundation of trust for modern vehicle software systems. Specifically, we demonstrate the feasibility of code execution attacks by leveraging a combination of software and hardware weaknesses in the secure software update process of electronic control units (ECUs), which is standardized across the automotive industry. Our method utilizes an automated approach, eliminating the need for static code analysis, and utilizes a novel algorithm for identifying fault injection parameters, enabling code execution in a matter of minutes to hours. Additionally, we demonstrate the ability to perform information leakage and program execution tracing through fault injection on PowerPC and ARM processors, which are commonly used in safety-critical applications. These experiments were conducted using electromagnetic fault injection techniques, without any hardware modifications to the targeted systems. Our results indicate that the standardized secure software update process currently used in the automotive industry is in need of revision in light of the security risks demonstrated.

Show More...
Dr. Nils Weiss

Dr. Nils Weiss, researcher in Automotive Security with over 7 years of experience, currently spearheading dissecto GmbH, a spin-off from the Laboratory for Safe and Secure Systems (las3.de) at the University of Applied Sciences in Regensburg. Dr. Weiss’s passion for Automotive Security was ignited during his internship at the industry giant, Tesla Motors, which eventually led him to embark on a journey toward revolutionizing the field of automotive security research. During his bachelor’s and master’s programs, he delved into the world of penetration testing and explored the vulnerabilities in entire vehicles. In addition to his contributions towards penetration testing of automotive systems, Dr. Weiss has also been actively involved in developing open-source penetration testing frameworks for automotive systems such as the revolutionary Scapy.

Show More...
Enrico Pozzobon

Enrico has worked as an automotive penetration tester since 2016. Together with Nils Weiss, he built the automotive security research lab at the OTH Regensburg and worked with several automotive manufacturers and insurance companies to find vulnerabilities and build exploit demonstrations.

Show More...
12:50 PM
(UTC)
Cybersecurity in the Driver's Seat: SBOMs for Automobiles
45 mins

This presentation explores the crucial role of Software Bill of Materials (SBOMs) in automobile cybersecurity, given the increased vulnerability due to connected cars and autonomous vehicles. SBOMs help identify security risks and vulnerabilities in the software supply chain of vehicles. We discuss challenges in obtaining SBOMs, contractual issues, and suppliers’ limited knowledge. We showcase tools for SBOM management/generation and draw lessons from successful implementations in other industries. Targeted at cybersecurity professionals, automobile industry leaders, and policymakers, this session highlights the significance of SBOMs in enhancing automobile cybersecurity.

Show More...
David Leichner
CMO at Cybellum

David started his career in network security at one of the leading banks on Wall Street followed by a similar role at TRW Space and Defense. Since moving to the vendor side, David has 25 years of executive management and consulting experience garnered from leading vendors including cybersecurity companies such as Cynet, Morphisec and Cybellum. David is also a member of the Board of Trustees of the Jerusalem College of Technology where he was instrumental in establishing the Cyber Elite Training Program. In addition, David is a mentor and guest lecturer to students in the MBA program at Hebrew University. David has authored many articles and blogs and has presented at conferences around the globe on the topic of cybersecurity.

Show More...
12:50 PM
(UTC)
How an automotive security researcher had his car stolen via 'CAN Injection 🚘💉'
45 mins

The story of the investigation into the device that I believe was used to steal my 2021 Toyota RAV4 and how easy it is to do using ‘CAN Injection ‘ most details are in the following blog post-https://kentindell.github.io/2023/04/03/can-injection/

Show More...
Dr. Ken Tindell
CTO Canis Automotive Labs

Dr. Ken Tindell is a veteran of the automotive industry, co-founding startups that were later sold to Bosch and to Mentor Graphics. He has developed various CAN technologies, including timing analysis, novel CAN controller architectures, and the CAN-HG augmentation of the CAN protocol and co-founded Canis Labs to provide security products for CAN bus.

Show More...
Ian Tabor
Automotive Cybersecurity Consultant

Automotive security consultant that has a passion for car hacking, found vulnerabilities in his own car and private Car bug bounties. Now runs Car Hacking Village UK and is part of the team behind CHV at defcon. Has created #Value-pasta-auto which is an open source ‘Car in a case’ and has also created the nano-can pcb and software, which can allow potential car hackers to build a cheap OBD2 (<£20) car hacking device.

Show More...
1:55 PM
(UTC)
KEYNOTE: Automotive Cybersecurity Map – Today and Tomorrow
1 hour

This presentation aims to give you an overview of the various initiatives that are propelling automotive cybersecurity forward. We will provide a roadmap of important topics and the organizations necessary to be successful.

During our discussion, we will explore the efforts made in the field of automotive cybersecurity, emphasizing their importance and the effects they have. We will also look at the latest advancements and industry trends, discussing how they are shaping the future of automotive security. Furthermore, we will stress the essential steps that the community needs to take in order to proactively prepare for the constantly changing threat landscape.

Show More...
Dr. Andre Weimerskirch
VP Platform SOFTWARE, Cybersecurity and Functional Safety Lear Corporation

Dr. André Weimerskirch is Vice President for Platform Software, Cybersecurity and Functional Safety at Lear Corporation. Before that, André was with the University of Michigan Transportation Research Institute (UMTRI) and co-founded the security company ESCRYPT. Andre is active in the SAE/ISO 21434 standardization, adjunct at UMTRI, and advisory board member at Block Harbor Cybersecurity.

Show More...
2:55 PM
(UTC)
PANEL DISCUSSION: Maturity of Cybersecurity Management Systems in Automotive: Insights from Auditors
1 hour

In this panel, we will explore the maturity for CSMS implementations across the automotive industry, and how it varies in different markets. We will discuss the most common process gaps and key challenges that OEMs and Suppliers face during audits, and how they can better prepare for them. Our high-profile Panelists will share their insights and experiences from an auditor’s perspective.

PANEL MODERATOR:
Dr. Jetzabel M. Serna-Olvera is the CEO and Co-founder of SAPAR GmbH, bringing over 18 years of global cybersecurity expertise. With a PhD in cybersecurity from the Universitat Politécnica de Catalunya, BarcelonaTech, she has excelled in various roles. Dr. Serna-Olvera began as a software engineer at the Tijuana City Council and went on to become a security researcher at esCERT-UPC. She further contributed as a senior security intelligence researcher at LaCaixa Bank and an assistant professor at the Goethe University of Frankfurt. In the automotive industry, she made strides as a cybersecurity strategist, advisor, and security culture lead at leading companies including Continental, Robert Bosch GmbH, and Geely. Her focus areas encompass Vulnerability Management, Incident Response, Threat Intelligence, and fostering a Cybersecurity Culture. Additionally, her extensive knowledge of privacy-enhancing technologies, GDPR compliance, and privacy-centric machine learning drives her mission of simplifying cybersecurity and privacy, cultivating expertise, and integrating them into core business operations.

Show More...
Jako Fritz

Jako holds a Bachelor in Telematics and a Master of Science in Computer Science with a focus on cybersecurity. His professional background includes work on network intrusion detection methods, penetration testing of payment products, and work on payment and automotive cybersecurity standards. Currently at UL Solutions he is responsible for its certification programs around ISO/SAE 21434 and ISO 24089 as well as the R155/R156 vehicle type approval services. As an expert he also actively contributes to the development of cybersecurity standards and regulations.

 

Show More...
Dirk Ruberg

Since June 2019, I have been employed at the Institute for Mobility (IFM) of TÜV Nord. Here I am responsible for the topics of cybersecurity, safety, and software update in the automotive sector. Within the scope of these activities, I have accompanied the development of the regulations on UN-R155 and UN-R156 and actively participated in the development of the test procedures for auditing cybersecurity management systems according to UN-R155 and software update management systems according to UN-R156 at IFM. I have the signature authority of the KBA to perform audits and have performed them at several OEMs. Prior to that, I worked for more than 18 years as an application engineer for communication chips in the semiconductor industry at Infineon and Lantiq.

Show More...
Thomas Thurner
Johana Constante Pérez

Diplom Engineer Telecommunication Engineering
Master of Electrical Engineering and Information Technology

ISO 27001 Certified Internal Auditor,
CISSP- Certified Information Systems Security Professional
Active participation in the ISO 21434 working group, former German TARA working group co-chair
Consulting and auditing on Automotive and Automation Cybersecurity activities over the complete security lifecycle, Managing the Cybersecurity activities involving different OEMs and products, performing threat Analysis and Risk Assessment, analyze requirements, standardization and regulation activities including active participation in the ISO 21434 working group, Information Security, Vulnerability Analysis, Networking, Communication Protocols, Project Management,
Currently Teamleader Cybersecurity TÜV SÜD Rail Automation. Focus: assessment, training and certification of Automotive and Industrial Cybersecurity.

Show More...
Dr. Jetzabel M. Serna-Olvera

Dr. Jetzabel M. Serna-Olvera is the CEO and Co-founder of SAPAR GmbH, bringing over 18 years of global cybersecurity expertise. With a PhD in cybersecurity from the Universitat Politécnica de Catalunya, BarcelonaTech, she has excelled in various roles. Dr. Serna-Olvera began as a software engineer at the Tijuana City Council and went on to become a security researcher at esCERT-UPC. She further contributed as a senior security intelligence researcher at LaCaixa Bank and an assistant professor at the Goethe University of Frankfurt. In the automotive industry, she made strides as a cybersecurity strategist, advisor, and security culture lead at leading companies including Continental, Robert Bosch GmbH, and Geely. Her focus areas encompass Vulnerability Management, Incident Response, Threat Intelligence, and fostering a Cybersecurity Culture. Additionally, her extensive knowledge of privacy-enhancing technologies, GDPR compliance, and privacy-centric machine learning drives her mission of simplifying cybersecurity and privacy, cultivating expertise, and integrating them into core business operations.

Show More...
3:55 PM
(UTC)
Data Trails: MBUX NTG6 & DLT Files - Forensic & Cybersecurity Research
45 mins

The talk focuses on the discovery of invaluable data captured in infotainment modules suspected of crashing, which can aid serious crime or collision investigations. This data is often found in Diagnostic Log Trace (DLT) files associated with the AUTOSAR (Automotive Open System Architecture) standardisation initiative for automotive electronic control units (ECUs).

The AUTOSAR framework enables modular development and software component reuse across different automotive platforms, reducing development costs and improving system quality and safety. The DLT file format within AUTOSAR logs and traces diagnostic and software event information in ECUs, providing a standardised way of analysing and diagnosing issues.

The DLT files have been observed to contain data such as entered destinations, tracklogs (GPS fixes), connected devices, connected phonebooks, connection times, engine on/off events, and odometer readings. However, the conditions under which these DLT files are created and their exact sources remain unclear to the Vehicle Systems Forensics community.

The presenter shares their personal experience with one vehicle equipped with systems capable of storing DLT files. They acquired data from the infotainment system using various techniques and are currently conducting ongoing testing to understand the creation and content of these files fully.

The ultimate goal of this research is to enable vehicle systems forensics investigators to better comprehend DLT files and the associated data for existing vehicles and ongoing criminal investigations. Additionally, it aims to raise awareness among automotive cybersecurity professionals about the potential risks of personal data captured within infotainment systems via this protocol and the need for enhanced data security in the future.

Show More...
Noel Lowdon
Vehicle systems Forensics Investigator

I am a Vehicle Systems Forensics Investigator and since 2016 have owned my own company that specialise in Vehicle Systems Forensics Investigations which supports Law Enforcement Investigations. I have developed a training programme for those wishing to learn more about Vehicle Systems Forensics and set up The Vehicle Network App for people with an interest in vehicle related investigations to provide information and resources in educating people in this ever evolving area. I was previously employed by West Yorkshire Police where I was both a qualified Detective and Forensic Collision Investigator for 17 years responsible for investigating serious collisions and crimes involving vehicles. I am on the National Crime Agencies Expert Advisers Database with regards to vehicle related investigations in the UK.

Show More...
3:55 PM
(UTC)
Mining for relevant vulnerabilities in connected devices
45 mins

We will discuss strategies to automatically generate the Software Bill of Materials (SBOM) of connected devices as a foundation for effective vulnerability management. SBOMs provide a comprehensive list of all software components and their dependencies in a given system – a prerequisite to identifying vulnerabilities and their potential impact. Additionally, we will delve into some intricacies and challenges when dealing with SBOM.

To avoid alert fatigue, we will further demonstrate effective strategies to automate impact assessments of vulnerabilities to filter false positives and increase the relevance of reported vulnerabilities using both open-source solutions as well as commercial services.

Attendees will gain insight into how automated SBOM generation and management can improve vulnerability management processes, reduce risks, and increase the efficiency of the product security lifecycle.

Show More...
Florian Lukavsky
CTO, ONEKEY

Florian Lukavsky started his hacker career in early ages, bypassing parental control systems. Since then, he has reported numerous zero-day vulnerabilities responsibly to software vendors and has conducted hundreds of pentests and security reviews of connected devices as a CREST certified, ethical hacker. After building offensive cyber-security teams in Singapore, Malaysia, Thailand, and Switzerland, he founded ONEKEY.
Today, Florian Lukavsky aids organizations with SBOM, security & compliance automation for connected devices as CTO of ONEKEY, the leading European product security platform.

Show More...
5:00 PM
(UTC)
How to establish a cybersecurity culture in automotive development work: Guidance beyond ISO/SAE 214
45 mins

Culture, a word without hard facts, it is more about feeling. So, what is meant by that? When it comes to the specific establishment of a cybersecurity culture, we are talking about quite an unclear challenge. ISO/SAE 21434:2021 presupposes the fostering and maintenance of a strong cybersecurity culture as one of the prerequisites for developing cyber secure products. But the standard leaves the implementation of that requirement open. Additionally, it affects not only the cybersecurity team but also the whole organization. This means completely different company divisions and teams with very different backgrounds and work spheres, often distributed across many locations, are involved.

The purpose of this presentation is to show how cybersecurity culture can be addressed in different phases of the product lifecycle and propose concrete measures to strengthen that in your company.

In conclusion, the presentation discusses how to measure a proper culture and provide evidence to an auditor or technical service.

Show More...
Manuel Sandler
Partner, CYRES Consulting

Mr. Manuel Sandler is Partner of CYRES Consulting, headquartered in Munich, Germany. After graduating with Bachelor and Master degrees in Mathematics from the University of Bayreuth, his long career in the automotive industry started as a development engineer for Functional Safety at ITK Engineering AG.
Responsible for resource planning in international functional safety development projects at leading OEMs and tier-1 suppliers, he was able to develop an early understanding of the balancing act between compliance with standards and regulations on the one hand and the complexity of cross-organizational development projects on the other.
Later on that, he was first Functional Safety Manager at Autoliv and then Process Manager, responsible among other things for supporting the global engineering cybersecurity management at Veoneer, the automotive technology spinoff.
In addition to conceptual responsibility for the global engineering process landscape with a focus on systems engineering and cybersecurity, he was responsible for identifying, evaluating, piloting and rolling out best practices.
This included the launch of a globally rolled-out competency management and training initiative focused on role- and function-based automotive cybersecurity training.
After joining CYRES Consulting, one of the leading consultancies for strategic design and operational implementation of automotive cybersecurity, as an Associate Partner, he now leads as a Partner the international teams that ensure the implementation of cybersecurity requirements for OEMs, Tier-N-Suppliers as well as new technology providers from all over the world. He continues to balance the intensive efficiency requirements of the automotive industry with the ever-increasing demands of new standards and regulations, such as ISO/SAE 21434 Road Vehicles – Cybersecurity Engineering.
Manuel Sandler is a highly requested speaker for advanced automotive cybersecurity keynotes as well as co-author of The Essential Guide to ISO/SAE 21434 (published by CYRES Consulting, 2021), which is the world’s first officially ISO/DIN licensed technical publication on the ISO/SAE 21434 standard.”

Show More...
5:00 PM
(UTC)
Securing Connected Cars Against Full-Chain Attacks and Advanced Automotive Vulnerabilities
45 mins

The technologies in hacking connected cars have not only advanced but also become more accessible to cybercriminals recently. They can now purchase “black box” tools that allow them to quickly overcome anti-theft technologies incorporated in modern vehicles without fully understanding CAN bus and other, similar communication protocols.

As demonstrated in Pwn2Own Vancouver 2023, malicious actors could level up by staging a complex attack scenario by combining multiple vulnerabilities — such as a time-of-check to time-of-use (TOCTOU) issue and a heap overflow and out-of-bounds write zero-day vulnerability in the in-vehicle infotainment (IVI) system — to control a Tesla Model 3 remotely.2 Compared to already known exploits on weak key fob cryptography and relay attacks, malicious activities like this are far more advanced and underscore the importance of further securing today’s vehicles against such imminent threats.

In this presentation, we will address the following questions:

– What has driven cybercriminals to be more brazen and attacks to be more sophisticated?

– How will cybercriminals monetize these advanced automo=ve vulnerabilities?

– Where could the next stages of cyberattacks come from emerging trends in automotive vulnerabilities, new attack vectors, and future targets?

– What are the industry’s counterattacks to stay ahead of a rapidly changing automotive threat
landscape?

Show More...
Vít Šembera
Security Researcher, Vic One

Vit Šembera has a master’s in computer science from Brno University of Technology in the Czech Republic. He is an IT enthusiast who has a broad interest in technology. One of his strengths is reverse-engineering IoT devices. In the last four years, he has focused on automotive technologies.

Show More...
5:45 PM
(UTC)
End-to-end derivation of cybersecurity requirements in different levels of the V-model using TARA me
45 mins

Combination of TARAs on different levels (system and software). How to perform on those levels, using the example of architectural vulnerability analysis for Electronic Steering Column Lock function to identify cybersecurity controls.

Show More...
Dr. Thomas Liedtke
Vector Consulting Services GmbH – consulting manager

Dr. Thomas Liedtke is manager consulting of Vector Consulting Services GmbH and member of the national DIN AK Cybersecurity and intacs advisory board.

– is leading the Cybersecurity SPICE – an intacs® add-on for Automotive SPICE® working group.

– is very experienced with the TARA method and guided and integrated the development of the cybersecurity materials in INTACS.

– studied Computer Science/ Mathematics at the University of Stuttgart

– In addition to his many years of practical experience, he relies above all on common standards/ regulations such as ISO/SAE 21434, UNECE, ISO 27001, ISO 5112, TISAX, and others.

Show More...
5:45 PM
(UTC)
Walking Through Walls: The Real-World Approach to Vehicle Security Assessment
45 mins

Car hacking has been a hot topic in the security community since 2015. In the years since, vehicle OEMs and suppliers put significant effort towards protecting vehicle users from cyber security incidents. However, the journey towards secure cars is far from the end, as modern vehicles’ complexity and connectivity introduce new challenges.

This talk will communicate the specific experience of the PCAutomotive team conducting vehicle security research, covering all the steps starting with intelligence gathering to the vulnerability disclosure process. The talk will tell our story – the way we perform our black-box research, using the latest SKODA SUPERB III car, as an example.

The specific vulnerabilities found and covered in the talk will include unintended debug functionality, hard-coded passwords, weak protection of the diagnostic services, as well as information disclosure issues in the backend server API. The talk will demonstrate how insufficient protection of in-vehicle diagnostic services may result in safety issues for drivers.

The purpose of the talk is to share our experience with manufacturers and their internal security teams, automotive developers, and the general car security community – all to further secure our streets.

Show More...
Danila Parnishchev
Head of Security Assessment at PCAutomotive

Danila is an application security engineer and a bug bounty hunter with more than 8 years of experience in security assessment of automotive, industrial, banking, networking solutions, as well as desktop applications. His favourite projects are those implying a bit of soldering and hardware analysis, and a lot of heavy reverse engineering, all to find impactful bugs hiding in the depths of embedded devices, solutions, and technologies.
At his current job, Danila oversees the development of new security services, leading various security evaluations, documenting and presenting research results, conducting responsible vulnerability disclosures, and sharing knowledge with his colleagues and the community.
Danila has previously spoken at various hacking conferences, including Recon Brussels, Positive Hack Days, SyScan360, and Standoff.

Show More...
6:30 PM
(UTC)
A Fully Trained Jedi, You Are Not
45 mins

As automotive software organizations push security earlier in the development processes, what can or should regular software or operations engineers know about security? Taking as given that we need them to build secure systems, that demands a shared understanding of the security issues that might come up, and agreement on what that body of knowledge might entail. Without this knowledge, they’ll keep building insecure systems. With them, we can have fewer recurring problems that are trivially attackable.

Show More...
Adam Shostack
Adam is a leading expert on threat modeling, and a consultant, entrepreneur, technologist, author and game designer.

Adam is a member of the BlackHat Review Board, and helped create the CVE and many other things. He currently helps many organizations improve their security via Shostack & Associates, and helps startups become great businesses as an advisor and mentor. While at Microsoft, he drove the Autorun fix into Windows Update, was the lead designer of the SDL Threat Modeling Tool v3 and created the “Elevation of Privilege” game. Adam is the author of Threat Modeling: Designing for Security, and the co-author of The New School of Information Security.

Show More...
6:30 PM
(UTC)
The road to regulation: cybersecurity requirements for modern vehicles
45 mins

This session will detail the latest UNECE cybersecurity regulations, comparing the automotive sector to other industry benchmarks. However, regulation is not a fix-all solution and its limitations will also be highlighted – alongside an introduction into the technologies on the market which can help achieve compliance and a strong cybersecurity posture.

Show More...
Hollie Hennessy
Senior Analyst, IoT Cybersecurity, Omdia

Hollie provides insight into the fascinating and fast-moving domain of IoT cybersecurity for vendor, service provider and enterprise audiences. She regularly contributes to industry publications and frequently speaks at industry events.
Hollie has a range of experience in research. She began her career in the legal sector, writing and researching for expert witness reports on the labor market. She then moved into product testing, with a consumer protection focus. In this role, she was responsible for managing comparative tests of various technology products, as well as regular testing and investigative work into the security of these products.

Show More...
7:15 PM
(UTC)
Closing Remarks
10 mins
Show More...
John Heldreth
ASRG Founder
7:25 PM
(UTC)
Networking
Show More...
12:30 PM
(UTC)
1:00 PM
(UTC)
KEYNOTE: Central E/E Arch (‘single SoC’), How to ensure security & safety of hyperconverged SDV's?
1 hour

Merging several functions (including safety-related vision and infotainment) into a single piece of silicon is the next SDV trend. Those approaches have many benefits but also raise significant security & safety challenges.

Ampere will dig into the details of the market offering, in an unprecedented overview of next-gen system-on-chip architectures, and will explain a few examples of security defects in such architectures, leading to life-threatening safety issues.

Let’s see what technological alignments are still needed for those solutions to be beneficial, without compromising the safety of road users.

Show More...
Frederic Ameye
Frederic Ameye
Cybersecurity Lead, Ampere (Renault Group) France

Frederic Ameye is a cybersecurity expert at Ampere (Renault Group). After having worked in the defense and medical industries, Frederic now helps Ampere define the SDV architectures of tomorrow, while keeping the solutions safe & secure. Ensuring leading-edge secure software solutions, preparing the path towards post-quantum cryptography, and designing safe E/E centralized architectures are his day-to-day activities.

Show More...
2:05 PM
(UTC)
TAF as Steel - A practical example for applying Targeted Attack Feasibility in an ECU Project
45 mins

This presentation aims to provide an explanation and practical interpretation on the topic of Targeted Attack Feasibility (TAF, specified by ISO/SAE AWI PAS 8475). TAF is a concept that serves as a harmonized approach for managing cyber risks in the vehicle industry with security controls differing from a standard solution for any reason (e.g. usage of special technologies, or securing legacy architecture). For this reason, the presentation will provide useful insight into this topic for any participant of the transportation industry supply chain.

Show More...
Janos Kovacs
Cyber Risk Analyst, Cymotive Budapest, Hungary

I have spent the last decade with defining secure processes and designing secure products for automotive companies – for OEMs and Tier1s all around the world. I am an enthusiast of the cybersecurity profession.

Show More...
(UTC)
Tales from a Penetration Testing Team - Insights on Recent Zero-Day Automotive Vulnerabilities
45 mins

We’re all familiar with the term “Zero-Day Vulnerabilities” but have you ever wondered what kinds are found in real-time embedded automotive systems today? Our penetration testing team reverse-engineers many ECUs from clients, uncovering zero-day vulnerabilities in components like TCUs, BCMs, Instrument Clusters, Airbags, and other safety-critical systems. In this talk, we will present and detail four distinct vulnerabilities we found and disclosed, highlighting the complexity and variety of security issues, and concluding with lessons learned and strategies for mitigation.

Show More...
Amit Geynis
Amit Geynis
Security Research Team Leader, PlaxidityX Israel

Amit Geynis is a Security Researcher & Team Lead at PlaxidityX (Formerly Argus).

In his role, Amit dedicates his time researching automotive embedded security and is responsible for penetration testing, vulnerability research, security code reviews and reverse engineering. Amit also implements and designs Argus’ interface fuzzing solutions.

Prior to joining PlaxidityX, Amit held the position of a Security Researcher at IBM Cyber Security Center of Excellence (CCoE), part of a global innovation team, under the IBM Security CTO office. Amit also served as a Firmware Developer at Broadcom Corporation. During his military service, Amit led a Signal Research Team at the Israeli Defense Forces (IDF) Cyber Intelligence Unit – 8200.

Amit holds a B.Sc. Cum Laude in Communication Systems Engineering from Ben-Gurion University of the Negev.

Show More...
2:35 PM
(UTC)
EVSE Security and the need for collaboration
30 mins

Explore the unique cybersecurity challenges faced by Electric Vehicle Supply Equipment (EVSE) and why traditional approaches fall short. This session will highlight the necessity for a collaborative strategy to address evolving threats and enhance the security of EV infrastructure. Discover the innovative approaches needed to secure this crucial component of the electric vehicle ecosystem.

Show More...
Adam Laurie
Adam Laurie
Chief Product Security Officer, ALPITRONIC GMBH Bolzano, Italy
2:55 PM
(UTC)
Exploiting EV Charging Networks: Pathways to Potential Blackouts
45 mins

This talk explores the recent vulnerabilities in EV charging networks, focusing on how threat actors could exploit these weaknesses to cause large-scale blackouts. By examining critical issues in EV chargers, Charging Station Management Systems (CSMS), and external integrations, we aim to guide EV charging site operators, manufacturers, regulators, and security professionals in implementing robust cybersecurity measures to safeguard our grid infrastructure around the world.

Show More...
Lionel R. Saposnik
Lionel R. Saposnik
VP of Security Research, SaiFlow

Lionel is an experienced security researcher with 13 years of experience in red teaming, penetration testing, and SDLC consulting. Lionel led operations of adversary simulation for complex systems and successfully demonstrated potential damage to critical infrastructure such as OT networks and EV charging sites. In the pursuit to help organizations better prepare for a security incident, Lionel joined a team of incident responders during the peak time of organizations moving to the Cloud. Working from a different point of view, Lionel was in charge of simulating attacks on different SaaS and Cloud environments and improving detection capabilities to give investigators better forensics capabilities, understand the attack vector, and contain the breach. Lionel later continued his journey to the energy sector, especially on distributed energy management and EV charging infrastructure with SaiFlow as a VP of Security Research. Lionel and his team discovered multiple vulnerabilities in EV chargers and management services which could potentially disrupt charging services, perform energy theft, or worse, cause blackouts. Lionel is passionate about exploring how different systems work and finding ways to exploit them while helping its clients raise their security posture.

Show More...
(UTC)
Securing the Keys to the Future: Robust Authentication for Next-Gen Vehicles
45 mins

This presentation addresses solutions for mitigating critical vulnerabilities in automotive keyless entry systems. Our approach combines challenge-response authentication with timestamp verification to prevent relay and replay attacks that enable vehicle theft. We introduce the theoretical foundations of this concept, which builds upon existing techniques and is still in the idea stage.

Show More...
Carlo Bauer
Carlo Bauer
Student, HS Mannnheim Germany

Cyber Security Student

Show More...
Fabian Maas
Student, HS Mannnheim Germany

Cyber security student at Hochschule Mannheim – University of Applied Sciences

Show More...
Gesa Müller
Student, UAS Mannheim Germany

09/2021 – now: Cyber Security Student at the University of Applied Sciences in Mannheim

Show More...
Orell Schwarzbach
Orell Schwarzbach
Student, UAS Mannheim Germany

2021-2024 Cyber Security (B. Sc.) Student

Show More...
3:45 PM
(UTC)
From regulation to practice: Frameworks for Cybersecurity Manager to enable better cybersecurity.
45 mins

Why a systematic empowerment of the Cybersecurity Manager is more beneficial than just randomly targeting personal and company certifications. Real-world approaches that combine cybersecurity with leadership principles, people management, education, and processes.

Show More...
Manuel Sandler
Independent Automotive Consultant Germany

Manuel Sandler is recognized worldwide as one of the world’s leading minds on applied automotive cybersecurity. Today, as an independent consultant, he advises vehicle manufacturers, Tier N suppliers and technology providers from all over the world on the strategic design and operational implementation of cybersecurity in vehicle development.

In his role as Knowledge Management Advisor for the CYEQT Knowledge Base, operator of the world’s leading automotive cybersecurity learning database for, he continues to develop the Automotive Cybersecurity Professional competence management framework he co-developed, as well as associated training programmes for role- and function-based automotive cybersecurity enablement.

With a bachelor’s and master’s degree in mathematics from the University of Bayreuth, he began his long career in the automotive industry as a development engineer for functional safety at ITK Engineering AG. As the person responsible for resource planning in international functional safety development projects at leading OEMs and Tier 1 suppliers, he developed an early understanding of the balancing act between compliance with standards and regulations on the one hand and the complexity of cross-organizational development projects on the other. He then worked at Autoliv, first as Functional Safety Manager and then as Process Manager, where he was responsible for supporting global engineering cybersecurity management at Veoneer, the automotive technology spin-off. In addition to conceptual responsibility for the global engineering process landscape with a focus on systems engineering and cybersecurity, he was responsible for the identification, evaluation, piloting and implementation of best practices.

Most recently, he was a partner for many years at CYRES Consulting, one of the leading consulting firms for the strategic design and operational implementation of cybersecurity in the automotive sector, which was fully acquired by an Italian stock-listed company at the beginning of 2024.

Manuel Sandler is an internationally sought-after speaker for practice-oriented cybersecurity keynotes in the automotive industry and author of The Essential Guide to ISO/SAE 21434 (2021), the world’s first technical publication on the ISO/SAE 21434 standard officially licensed by ISO/DIN and the ISO/SAE 21434:2021 Workbook (2023) with guidance and best practices for sustainable cybersecurity engineering.

Show More...
(UTC)
Shifting Left Vulnerability Management
45 mins

As the automotive industry undergoes a paradigm shift towards software-defined vehicles, the imperative for robust software security becomes obvious. This talk explores the nuanced landscape of identifying, managing, and preventing vulnerabilities early in the product lifecycle from the perspective of an OEM software company. The talk also highlights the role of standardized formats like software bill of materials (SBOMs) and anticipates future challenges such as crypto agility and the use of cryptographic bills of materials (CBOMs).

Show More...
Andreas Weichslgartner
Andreas Weichslgartner
Senior Technical Security Engineer, CARIAD SE Germany

Andreas Weichslgartner is currently working as a Senior Technical Security Engineer at CARIAD SE in the security department.

Joining the Volkswagen Group in 2017, he since then has been developing an embedded intrusion detection system, evaluating security testing technologies, managing vulnerabilities, enabling crypto agility, and working with machine learning in the area of security.
Before, he had been a researcher at the Department of Computer Science, Friedrich-Alexander University Erlangen-Nürnberg (FAU), Germany, from 2010 to 2017. He received his diploma degree (Dipl.-Ing.) in Information and Communication Technology and his Ph.D. (Dr.-Ing.) in Computer Science from the FAU, Germany, in 2010 and 2017, respectively.

Show More...
Vineeth B. Prasanna
Vineeth B. Prasanna
Senior Technical Security Engineer, CARIAD SE Germany

Mr. Vineeth Bharadwaj Prasanna is currently working as a Senior Technical Security Engineer at CARIAD SE in the product security department.

Vineeth joined the Volkswagen Group in 2018, as a security engineer for Audi AG. Since 2020, he has been a member of the offensive security team and has also been working on building up the vulnerability management system, end-to-end security engineering for China GB-T homologation project for the new PPE/PPC platform for the new Audi and Porsche cars at CARIAD SE.
Vineeth received his Master’s degree in Simulation Science from RWTH Aachen University in 2019 with special focus on optimization, and artificial intelligence.

Show More...
4:50 PM
(UTC)
Redefining OEM Supplier Dynamics: Powerful TARA Updates for Effective Requirements Specifications
45 mins

Understanding and mitigating weak links in the automotive supply chain is crucial for comprehensive vehicle cybersecurity. This presentation explores the necessity of Threat Analysis and Risk Assessment (TARA) at all supply chain levels and offers practical guidance for enhancing collaboration and security integration across OEMs and suppliers.

Show More...
Falk Mayer
Falk Mayer
Co-Founder & Managing Director, BreachLabz Munich, Germany

Falk Mayer is co-founder and managing director of BreachLabz, a renowned expert team of penetration testers for the automotive industry based in Munich, Germany. BreachLabz is a successful spin-off of CYRES Consulting, one of the world’s leading cybersecurity consultancies for the automotive industry, where Falk Mayer was previously a Senior Technical Cybersecurity Expert responsible for security risk assessments for international OEMs and Tier N suppliers. As a trained cybersecurity expert with a bachelor’s and master’s degree in physics from the University of Heidelberg, he professionalised early on with in-depth knowledge and genuine passion in the field of information, IoT and automotive technology security. In his versatile professional career, from Software Engineering at Robert Bosch to System Administration, he has already gained extensive experience, especially in the areas of testing, vulnerability management, risk assessments and others. In his role as a Senior Technical Expert for the strategic operationalisation and implementation of cybersecurity in vehicle development, he has gained extensive experience in the management of risk assessments, the development of security concepts for automotive systems, requirements engineering, security testing and, last but not least, as a software lead for system developments. As part of the growing BreachLabz team, Falk stands for the facilitation of knowledge and community exchange, not least with dedicated automotive penetration testing trainings, which he co-develops and conducts as a senior trainer, but also for bridging the gap between the left and right side of the V-model by developing sustainable security testing concepts.

Show More...
(UTC)
Risk assessment along the supply chain. From OEM to Tier 1 to Tier 2 – how does it all fit together?
45 mins

In a typical situation, a supplier (Tier-1, Tier-2, …) is asked to perform “own” TARAs on their level. In the end, the results have to be consistent with the vehicle TARA. Cybersecurity requirements coming from customers have to be evaluated against Cybersecurity Requirements derived from supplier TARA. Approaches of the structural view will be presented.

Show More...
Thomas Liedtke
Thomas Liedtke
Senior Cyber Security Manager , Magility Cyber Security GmbH Germany

Consultant and expert for Cybersecurity, functional Safety, Automotive SPICE, Privacy, Auditor and Assessor

Show More...
5:20 PM
(UTC)
Driving Efficiency: Validating Your Security Posture With Sector Relevant Intelligence
30 mins

As connected and autonomous vehicles advance, the automotive industry faces increasingly complex cyber threats.
This presentation highlights today’s most common threats and explores how to effectively integrate Cyber Threat Intelligence (CTI) into security operations. Our live demo during this session will also showcase how OpenCTI enhances security posture, streamlines incident response, and drives efficiency.

Show More...
Jermain Njemanze
Jermain Njemanze
EMEA Lead Solution Engineer, Filigran France

Delivering CTI software solutions for 8 years and happy to resolve your cyber pains with Filigran soltuions.

Show More...
5:40 PM
(UTC)
An Investigation into Retrievable PII Data from a Mercedes-Benz NTG6 IVI Module
45 mins

This presentation explores the technique employed to perform a forensic acquisition of a publicly obtained Mercedes-Benz NTG6 infotainment module, the methods used to analyse data, revealing Personally Identifiable Information (PII) such as connected devices, phonebook records, call logs, and navigation data, stored without encryption or authentication, resulting in the extraction of vehicle user information using custom Python programming, highlighting privacy concerns in connected vehicles, where PII information such as location history, driving behavior, contact lists and more could be misused. This project identifies the types and extent of PII retrievable from modern vehicles, analyses manufacturer practices, and assesses adherence to regulations. Finally, it recommends measures to enhance privacy safeguards in connected vehicles.

Show More...
Richard Harding
Richard Harding
Digital Forensics Student, University of South Wales United Kingdom

As a current MSc student in Digital Forensics and recent first-class honours graduate, my passion lies in applying my skills to the critical and rapidly evolving field of connected vehicles. While my background initially focused on web development, the analytical and problem-solving skills I honed have proven invaluable in navigating the complexities of connected vehicle data collection, retention, and storage. My ongoing research, which began as a BSc dissertation project, investigates the vulnerability of Personally Identifiable Information (PII) data in connected vehicles. I’m currently expanding this work by examining a wider range of vehicle manufacturer IVI systems to gain a more comprehensive understanding of PII data exposure. My goal is to collaborate with the automotive industry to find practical solutions, build consumer and industry awareness, and contribute to establishing regulations surrounding PII data in connected vehicles, like emerging trends being seen in the automotive industry.

Show More...
(UTC)
The Complex Regulatory Landscape of Automotive Cybersecurity: Challenges of National Standards
45 mins
Show More...
Janine Funke
Janine Funke
Lead Strategic Area Cybersecurity, UL Solutions, Software Intensive Systems Germany

Janine Funke is currently leading the strategic area of cybersecurity at Kugler Maag Cie by UL Solutions, where she is on the one hand responsible for internal business and knowledge development, and on the other hand, she is consulting and training OEMs and suppliers for automotive cybersecurity. Moreover, she is an auditor for Cybersecurity Management Systems and Software Update Management Systems.

Her academic journey began with a study in international business, culminating in a double degree from China and Germany. Early in her career, she immersed herself in the dynamic field of automotive cybersecurity, a passion that continues to grow. Actively participating in committees such as “”WG 11 Cybersecurity,”” she contributes to shaping industry standards. Furthermore, she is currently involved in the establishment of the “”ASRG Women”” network, dedicated to fostering a supportive community for women in automotive cybersecurity.

Show More...
6:30 PM
(UTC)
KEYNOTE:Raising the Cybersecurity bar: Seeking unconventional methods to solve conventional problems
1 hr

KEYNOTE PRESENTATION:

In the rapidly evolving automotive cybersecurity landscape, engineering teams face increasing security challenges, particularly with software-defined vehicles. Securing these complex, interconnected automotive systems is becoming more difficult as adversaries enhance their capabilities.

This talk explores critical automotive security challenges from three different perspectives: technical security, process compliance, and
human resources. We will discuss why merely meeting minimum- security standards is inadequate and why raising the bar is essential.
Best practices for achieving higher security will be shared across these three areas.

The talk will then explore the growing role of Generative AI in strengthening security efforts, accelerating the execution of the secure engineering lifecycle, and improving overall work quality, effectively raising the security bar. Finally, we will provide insights into the future of this technology and how the industry can stay ahead of emerging cybersecurity threats.

Show More...
Dr. Ahmad MK Nasser
Dr. Ahmad MK Nasser
Senior Manager | Lead Security Architect and Team Manager of DRIVE OS, NVIDIA United States

Dr. Ahmad MK Nasser is a seasoned expert in automotive cybersecurity with over two decades of experience in embedded software and hardware architectures. Starting as a Software Engineer at Vector CANtech in 2002 he honed his skills in CAN drivers, diagnostics protocols, and flash bootloaders across various microcontrollers. In that role, Ahmad interacted with numerous customers and consulted with them on troubleshooting complex software bugs. Ahmad subsequently joined Robert Bosch as a Technical Expert, focusing on automotive networking software, diagnostics, and HSM firmware in active safety systems. At Bosch, he was among the first engineers to implement cybersecurity requirements into a safety critical system (ABS/ESP) for major automotive manufacturers. Through the integration of the HSM firmware and enablement of secure onboard communication and secure diagnostics, Ahmad got firsthand experience about the challenges faced when enabling security in resource-constrained systems. He also saw firsthand the impact of security on legacy systems during both development and manufacturing. Around this time, Ahmad started his Ph.D. in the topic of securing safety critical systems at the University of Michigan-Dearborn. He later transitioned to Renesas, where he again helped numerous customers enable hardware security features using the Renesas microcontrollers and SoCs. He later became the team leader for the HSM firmware development team where he built a portable HSM solution that supported both MCU and SoC systems while following a secure software development lifecycle. During his tenure at Renesas, he was an active member of several standardization committees, contributing to key security standards such as SAE J3101, Uptane, and CAN XL-sec. Also, while at Renesas, Ahmad completed his Ph.D. with numerous publications around the topic of safety and security overlap as well as the security of resource constrained embedded systems.

Currently serving as a Lead Security Architect and Engineering Manager at NVIDIA, Ahmad oversees security operations for DRIVE OS, a multifaceted
software stack that powers autonomous driving applications. He consults with numerous teams on developing the secure software solution in compliance with ISO/SAE 21434. His latest work is focused on leveraging Generative AI to improve the efficiency of security analysis and cybersecurity work product generation
while working within the confines of a cybersecurity management system.
Throughout his career, Ahmad has conducted threat and risk analysis of
numerous vehicle architectures, ECUs, and smart sensors giving him firsthand experience about the challenges and opportunities of building secure vehicle platforms.

Show More...
7:35 PM
(UTC)
PANEL DISCUSSION: Automotive Privacy – Differentiator or Pain in the Neck?
1 hr

Let’s assume that privacy (the right to be left alone) is a fundamental human right. As we know, there is data protection regulations worldwide which are supposed to be reflected, specifically, in business models and application domains relying on personalization. In the automotive domain this causes conflicts of interests.

The panel gives an overview of the state of the art of personalization and the corresponding Personally Identifiable Information needed in automotive applications and mobility services and discusses the level of privacy which has been introduced so far. Since there is always room for improvement the panel also gives advice and recommendations for OEMs, Tier1s, service providers, and passengers across the data life cycle to meet compliance and beyond.

MODERATOR: Mario Hoffman
Group Lead Cyber Security, ARRK Engineering GmbH

PANELIST:
Andrea Amico
Founder & CEO, Privacy4Cars

Misha Rykov
Independent Investigative Researcher

PD Dr. Sebastian Pape
Security & Privacy Manager, Continental Automotive Technologies GmbH

Show More...
Misha Rykov
Misha Rykov
Independent Investigative Researcher Germany

Kyiv-native and Berlin-based, Misha is an independent investigative researcher. In 2021-2024, Misha was part of Mozilla’s privacy effort as a researcher at an award-winning *Privacy Not Included. Misha loves investigative storytelling and community activism.

Show More...
Mario Hoffman
Mario Hoffman
Group Lead Cyber Security, ARRK Engineering GmbH Germany

With more than 20 years of experience in Cyber Security, including 10+ years in team lead positions at Fraunhofer Institutes, Mario entered the automotive domain in 2016. From May 2016 to March 2022, he served as “”Global Head of Security & Privacy Consulting and Engineering”” at Continental AG, Frankfurt, Germany. In 2022 he took responsibility for homologation according to UNECE R.155/R.156 at Sono Motors, an OEM startup and EV solar pioneer in Munich. In Feb 2023 he joined ARRK Engineering in Munich where he now leads a group on Automotive Cyber Resilience including automotive privacy.

In Dec 2013, Mario was awarded “Privacy by Design Ambassador” by Kim Cavoukian, former Information & Privacy Commissioner Ontario, Canada. He is a member of International Association of Privacy Professionals (IAPP), ACM, Germany’s Gesellschaft für Informatik, Chaos Computer Club, and Digitalcourage.

Show More...
Andrea Amico
Founder & CEO, Privacy4Cars United States

Privacy4Cars founder & CEO. Driving Privacy through transparency, data protection, and real consent. Multiple patents and creator of first app-driven process to delete PI from cars and of VehiclePrivacyReport.com

Show More...
PD Dr. Sebastian Pape
Security & Privacy Manager, Continental Automotive Technologies GmbH Germany

Sebastian Pape is a security and privacy manager working at Continental Automotive Technologies GmbH. In his current role, he is coordinating security and privacy within a project and contributing to research within the AUTOPSY project. Sebastian is also a Privatdozent at Goethe University Frankfurt and (co-)founder and managing director of the Social Engineering Academy (SEA) GmbH.

Sebastian successfully completed diplomas in mathematics (Dipl.-Math.) and computer science (Dipl.-Inform.) at Darmstadt University of Technology, holds a doctoral degree (Dr. rer. nat.) from the University of Kassel, and holds a venia legendi for computer science from his habilitation at Goethe University Frankfurt. So far, he has published more than 50 scientific conference papers and 20 journal papers with most of them dealing with privacy, human factors and serious games.

Show More...
8:40 PM
(UTC)
Practical Transformation Proposal between CVSS 4.0 and ISO/SAE 21434 Attack Feasibility Rating
45 mins

Following our previous paper presented at the 2023 Secure our Streets (SoS), titled “A Practical Transformation Proposal between Attack Potential-based and CVSS-based Attack Feasibility Ratings,” we received significant positive feedback and numerous requests for an update incorporating the new CVSS 4.0 standard, which was released at the end of 2023. Recognizing the importance of this new standard, we propose a practical method to integrate CVSS 4.0 into the systematic analysis framework of ISO/SAE 21434. Given that CVSS 4.0 is not yet included in ISO/SAE 21434, our work aims to bridge this gap and provide a robust approach for enhancing attack feasibility assessments within the automotive cybersecurity domain.

Show More...
Oliver Huppenbauer
Oliver Huppenbauer
Global Cybersecurity Manager, Marquardt GmbH Germany

Oliver Huppenbauer, with over 10 years of experience at Marquardt Group, is the Global Head of Product Cybersecurity. He leads global cybersecurity management, incident response, and vulnerability management, ensuring compliance with ISO/SAE 21434 and UN ECE R155. Oliver oversees security methodologies for automotive systems and supply chains. Previously, he managed technical projects for keyless automotive systems, focusing on cybersecurity processes, vulnerability management, and continuous improvement within Automotive Spice and security frameworks.

Show More...
Orhun Süzer
Independent Consultant, Orhun Süzer | Masters in Embedded Systems Stuttgart, Germany

Masters in Embedded Systems
More than 7 years of experience in Automotive Cybersecurity
ISTQB, IREB, RE@Agile, ASPICE Certifications

Show More...
9:10 PM
(UTC)
Everything Everywhere All at Once: Towards Integrated Product Security for Software Defined Vehicle
30 mins

In today’s world, software-defined vehicles require continuous development even after production. Releasing feature and security enhancements via OTA updates is the new normal for many automotive OEMs. However, doing this efficiently while managing complexity and risk is often a struggle.

In this talk, we’ll cover how your organization can:

– Accelerate product development & minimize risks
– Ensure transparency in software development
– Enhance vulnerability analysis & risk management
– Build effective partnerships for innovation

Show More...
Jonathan Mohring
Jonathan Mohring
President, itemis Inc. United States

Jonathan Mohring is the President of itemis Inc. in the US. Prior to itemis, he spent over 20 years at Honda, Chrysler, and Daimler in Europe and the US driving innovation in the areas of engineering IT, software automation, and data strategy.

Show More...
Dirk Leopold
Dirk Leopold
Executive Vice President, Digital Engineering, Itemis AG Germany

Dirk Leopold is the EVP of Digital Engineering and a senior expert in automotive cybersecurity at itemis AG. For the past 7 years at items, he has been focusing on automotive cybersecurity risk management including related regulations, norms, services, and products.

Show More...
9:30 PM
(UTC)
The Missing Link - How we collect and leverage SBOMs
45 mins

There is some debate as to how SBOMs can enhance vulnerability management practices, and some believe that collecting SBOMs from internal teams or suppliers is too difficult and time-consuming. Learn how Schneider Electric has collected thousands of our product SBOMs and how we are leveraging the SBOMs as part of our corporate product CERT to quickly analyze and focus our attention when time is of importance. This presentation describes how we modified our policies and processes to collect, generate, and store thousands of SBOMs. You will hear how we have leveraged SBOMs during the Log4j and OpenSSL vulnerability events. Then we will conclude with key learnings, suggestions, and opportunities for improvement.

Show More...
Cassie Crossley
Cassie Crossley
VP, Supply Chain Security, Cybersecurity & Product Security Office, Schneider Electric United States

Cassie Crossley, Vice President, Supply Chain Security in the global Cybersecurity & Product Security Office at Schneider Electric, is an experienced cybersecurity technology executive in Information Technology and Product Development and author of “Software Supply Chain Security: Securing the End-to-End Supply Chain for Software, Firmware, and Hardware.” She has many years of business and technical leadership experience in supply chain security, cybersecurity, product/application security, software/firmware development, program management, and data privacy. Ms. Crossley has designed frameworks and operating models for end-to-end security in software development lifecycles, third party risk management, cybersecurity governance, and cybersecurity initiatives. She is a member of the CISA SBOM working groups and presents frequently on the topic of SBOMs and Supply Chain Security. Ms. Crossley has an M.B.A. from California State University, Fresno, and her Bachelor of Science degree in Technical and Professional Communication with a specialization in Computer Science.

Show More...
(UTC)
vSOC Risk Recharging: Dynamically Integrating TARA, Threat Intelligence and Live Monitoring
45 mins

This presentation addresses the critical need for dynamic risk analysis in automotive cybersecurity, focusing on emerging threats to connected vehicles and mobility ecosystems. Real-world examples will demonstrate the importance of integrating TARA, threat intelligence, and live monitoring in a continuous, proactive feedback loop across the automotive cybersecurity stack.

Show More...
Elad Robb
Elad Robb
Director of Cyber Threat Intelligence, Upstream Security Israel

Elad leads Upstream’s cyber threat intelligence solution, AutoThreat®, the first mobility purpose-built CTI service and platform. AutoThreat® collects, analyzes, and leverages mobility threat intel from multiple public, deep and dark web sources enabling stakeholders to gain domain-specific context of cyber threats impacting their assets and supply chain. Prior to joining Upstream, Elad established and led several CTI teams in the critical infrastructure, IT and corporate due-diligence sectors. Elad served in the Israeli Defense Force’s elite technological unit 8200 and holds an L.L.B in commercial law and is a certified attorney, member of the Israeli bar association. In his spare time he really never misses his weekly basketball training.

Show More...
Tom Kaplan
Tom Kaplan
Director of Data Analytics, Upstream Security Israel

Tom leads Upstream’s Data Analytics team, which is responsible for designing and efficiently executing data and analytics strategies to support a wide range of cybersecurity use cases for customers. Prior to joining Upstream, Tom served as an officer in the Israeli Defense Force’s elite technological unit 8200, where he led complex data-driven projects geared to provide unique insights on top of massive amounts of intelligence data. Tom is the lead singer of the Upstream band, and doesn’t skip his Crossfit workout in the morning before work.

Show More...
10:00 PM
(UTC)
CRISKLE: An Integrated Product Security Lifecycle Platform for Enhanced Safety & Security Analysis.
30 mins

In an era where mobility systems are rapidly evolving with advancements in technology, the integration of safety and security has become paramount. This presentation will delve into the critical need for a cohesive approach to safety and security analysis, addressing the challenges and opportunities in modern mobility systems. We will explore the latest innovations, methodologies, and best practices that are shaping the future of transportation safety. By driving forward the conversation on integrated safety and security, this presentation aims to equip stakeholders with the insights and tools necessary to build more resilient and secure mobility systems for the future.

Show More...
Saket Mohan
Saket Mohan
Founder and CEO, Secure Elements
10:20 PM
(UTC)
Enhancing Automotive Cybersecurity: Using Machine Learning techniques to Improve ISO/SAE 21434
45 mins

This presentation explores how machine learning (ML) techniques can transform ISO/SAE 21434’s reactive framework into a dynamic, proactive one. By leveraging ML algorithms for anomaly detection, predictive risk assessment, and automated threat detection, the framework can provide continuous, data-driven cybersecurity solutions.

ISO/SAE 21434 serves as a foundational standard in automotive cybersecurity, yet it suffers from gaps, including its reactive approach to identified threats, reliance on static risk assessments, and dependence on manual risk evaluations. These gaps expose vehicles to emerging cyber threats. This paper explores how machine learning (ML) techniques, such as Anomaly Detection, Predictive Risk Assessment, Automated Threat Detection can transform ISO/SAE 21434’s reactive framework into a dynamic, proactive one. By leveraging threat catalog, ML models can continuously learn from vehicle data, identifying anomalies and integrating external cybersecurity intelligence to predict and mitigate emerging threats. This integration not only enhances the ISO/SAE 21434 framework but also provides proactive, automated, and data-driven cybersecurity solutions. By embedding ML into the ISO/SAE 21434 framework, the automotive industry can fortify its resilience against evolving cyber risks, ensuring a safer and more secure vehicle environment.

Show More...
Atefeh Asayesh
Atefeh Asayesh
Vehicle Cybersecurity Analyst, Block Harbor Cybersecurity United States

Atefeh Asayesh serves as a vehicle cybersecurity analyst at Blokharbor Cybersecurity, having previously held the role of cybersecurity engineer at Magna Steyr. With six years of experience in cybersecurity, she has specialized in automotive security for two years. Atefeh’s interests lie in Cybersecurity Management Systems (CSMS) and Threat and Risk Assessment (TARA), and she possesses practical expertise in penetration testing. Currently, she is engaged in research focused on integrating ISO 21343 standards with machine learning techniques. Her recent paper on the application of ML for Over-the-Air (OTA) updates in autonomous vehicles was accepted at the Percom conference (rank A), with additional papers currently undergoing review.

Show More...
Minha Mir
Vehicle Cybersecurity Manager, Block Harbor Cybersecurity United States

Minha holds a Master’s degree in Cybersecurity and has spent the past four years at Block Harbor Cybersecurity, initially contributing to the VSOC team before transitioning to manage the TARA team. Under her leadership, the TARA team has successfully conducted over 300 Threat Analysis and Risk Assessments (TARAs) at scale for major OEMs and Tier 1 suppliers.

Show More...
(UTC)
Secure Isolation
45 mins

This presentation elaborates on secure isolation as a substantial element of a secure architecture. It especially focuses on the realization of isolation in software using operating systems and hypervisors and the challenges of providing HSM services to multiple VMs.

Show More...
Ionut Racaru
Ionut Racaru
Senior Expert, Elektrobit Romania

I joined Elektrobit in august 2014 and in the past 10 years I held a plethora of roles and responsibilities, all leading to my current Senior Expert position level. During my technical activity at Elektrobit, I experienced the steepest growth between 2016 and 2021 when I was working extensively on our company’s cybersecurity offering. This is a topic dear to me and I turn to it with every chance I get.

Show More...
Gabriel Byman
Gabriel Byman
Senior Cybersecurity Product Manager, Elektrobit Automotive Oulu, Finland

Gabriel Byman is a seasoned cybersecurity expert in the field of automotive cybersecurity with a background from defence and telecommunication security. As the Senior Cybersecurity Product Manager at Elektrobit, Gabriel has been at the forefront of ensuring the safety and security of modern vehicles.

His expertise lies in balancing cybersecurity with the need for speed to market in the automotive sector encompassing threat analysis, system security architecture, and the integration of cutting-edge security measures into automotive technology. Gabriel has actively contributed to the development of security solutions for connected cars, addressing the challenges posed by cyber threats. His work aligns with emerging standards and regulations such as UN R155 and ISO/SAE-21434, which mandate robust cybersecurity practices throughout the vehicle lifecycle.

Show More...
Elisabeth Waitz
Elisabeth Waitz
Senior Expert Cybersecurity, Elektrobit Germany

Elisabeth Waitz is a cybersecurity expert and software architect for automotive systems at Elektrobit, where she has worked since graduating from Friedrich-Alexander university in Erlangen, Germany in 2008. At Elektrobit, Elisabeth has held a variety of positions over the past 15 years, all focused
on developing and bringing to market innovative automotive cybersecurity solutions. Her roles have been wide-ranging, including implementing cryptographic routines and applications, consulting on customer projects, and establishing a companywide cybersecurity management system. Since 2018, in the current position, her responsibilities are the definition of concepts/architecture/design of various cybersecurity features for Elektrobit’s products. It also includes interaction with customers on cybersecurity topics and the continuous improvement of Elektrobit’s cybersecurity management system and engineering.

Show More...
11:10 PM
(UTC)
Application of GenAI LLM's for Threat Scenario Generation for TARA Assessments
45 mins

Performing Threat and Risk Assessments (TARA) while relying on static documentation poses challenges in addressing the evolving landscape of threats, characterised by increasingly sophisticated attackers and dynamic threat vectors. To address this issue, this presentation explores the utilisation of large language models (LLMs) to generate novel threat scenarios and corresponding mitigation techniques, to make TARA’s dynamic, based on attacks identified on in-vehicle networks and making them contextual.

Show More...
Saket Mohan
Saket Mohan
Founder and CEO, Secure Elements
Sampath Kalutharage
AI & Cybersecurity Engineer, Secure Elements
(UTC)
Automotive Bug Bounty Program and Lessons Learned
45 mins

During the inaugural Pwn2Own Automotive 49 unique zero-day vulnerabilities were discovered, affecting various connected car systems and components – including infotainment dashboards, operating systems, and electric vehicle (EV) chargers. We are discussing most common entry points, some details of the findings and how the industry should respond.

Show More...
Karl Schlauch
Karl Schlauch
Principal CyberSecurity, VicOne Germany

Karl Schlauch, aka Kalli, brings to VicOne over 20 years of infrastructure security expertise from Trend Micro, VicOne’s parent company. In his current role, Kalli works with global threat research teams and liaises with other business units and customers. He is a Certified Ethical Hacker (EC Council) and Incident Handler (GIAC).

Show More...
12:00 AM
(UTC)
Observing the Clouds: Lessons Learned from Cloud Vulnerabilities for HPCs and Software Containers
45 mins

Software containers should simplify updateability and create cost savings in the electrical and electronic (E/E) architecture. But does it provide the same or even stronger promises on cybersecurity?

Automotive functions are hosted in electronic control units (ECUs) and operated within a complex network within the vehicle. There are current efforts to centralize ECU functions from dedicated ECUs into centralized platforms. One driver is the UN regulation R156 with ISO 24089, which requires car manufacturers to address updateability.

The trend to restructure the E/E architecture to feature centralized high-performance computers (HPCs) can be observed in the industry. The HPC is intended to run several ECU functions in parallel on a common platform. Concepts like the Adaptive AUTOSAR enable vendors to host the functions in the form of processes on a POSIX platform. Using Linux as an operating system has also included cloud experts such as Red Hat and Canonical to enter the domain. Their reference architectures show HPCs running Linux, which can host vehicle functions in software containers.

This concept is not new and has already been executed in the IT domain for a magnitude of software solutions. In the past dedicated servers have been transformed into software containers running on centralized servers and later in distributed infrastructures of the clouds. This development was also accompanied by a high number of security vulnerabilities. Those vulnerabilities can be attributed to the software containers themselves as well as the orchestrator software such as Docker or Kubernetes.

The automotive use cases for container technologies also open up new challenges: the use of physical interfaces and non-IP bus systems, such as the CAN bus, is uncommon in the IT world and therefore new territory. Also, the communication from containers to on-board interfaces of the platform, such as SPI, could jeopardize the security system.

This talk gives an overview of past vulnerabilities in software containers as well as new challenges introduced by the automotive use cases. The outcome should be lessons learned in container security for suppliers and OEMs.

Show More...
Reinhard Kugler
Reinhard Kugler
MATRIS Applied Research Consulting, SBA Research Austria

Reinhard’s focus relies on security testing of IT and industrial cyber-physical systems. Based on his prior experience in cyber defense, he works with companies to develop security capabilities and secure products. Reinhard is an experienced instructor and develops tailored security trainings. His mission is to apply research methods (combinatorial security testing) to industrial applications, like automotive, embedded or cloud.

Show More...
(UTC)
PIVOT: Catalyzing the Community Around Collection and Sharing of Automotive Research Datasets
45 mins

In-vehicle and other data from connected, autonomous vehicles are critical to support research and applications in intelligent transportation. The University of Memphis, Colorado State University, and USC Information Sciences Institute, along with commercial telematics service provider Geotab, are building the Platform for Innovative use of Vehicle Open Telematics (PIVOT), a community-based platform intended to catalyze the production and consumption of automotive and heavy-duty datasets and associated tools to support the computer science, engineering, and other communities pursuing research in vehicle cybersecurity, intelligent transportation, and smart and connected communities. This talk will provide an overview of the PIVOT platform and summarize community feedback and key findings from a recent PIVOT workshop.

Show More...
David Balenson
David Balenson
Interim Director, NCD, USC-ISI, USC Information Sciences Institute United States

Computer Scientist at the University of Southern California Information Sciences Institute. He has broad-based experience and background in critical infrastructure security and resilience, computer and network security, applied cryptography, and R&D program and project management. His current research interests include cybersecurity for critical infrastructure and cyber-physical systems including automotive and autonomous vehicles, experimentation and test, technology transition, and multidisciplinary research.

Balenson co-leads and is the Community Outreach Director for the NSF-funded Open Community Platform for Sharing Vehicle Telematics Data for Research (PIVOT) project. He is also Community Outreach Director for the NSF-funded Security and Privacy Heterogeneous Environment for Reproducible Experimentation (SPHERE) project and he previously co-led the NSF-funded Innovation and Sharing Expertise and Artifacts for Reuse for Cybersecurity Community Hub (SEARCCH) and Cybersecurity Experimentation of the Future (CEF) projects.

Balenson is on the steering, organizing, and/or program committees for the Network and Distributed System Security (NDSS) Symposium, Annual Computer Security Applications Conference (ACSAC), Learning from Authoritative Security Experiment Results (LASER) Workshop, Cyber Security Experimentation and Test (CSET) Workshop, and the Vehicle Security and Privacy (VehicleSec) Symposium.

Prior to joining USC-ISI, Balenson was a senior computer scientist in the Computer Science Laboratory at independent, non-profit research institute, SRI International where he provided technical and programmatic support for the U.S. Department of Homeland Security Science and Technology Directorate (DHS S&T). Over his career, Balenson has worked for the Johns Hopkins University Applied Physics Laboratory, SPARTA, McAfee/Network Associates, Trusted Information Systems, and National Institute of Standards and Technology.

Show More...
12:45 AM
(UTC)
7:00 PM
(UTC)
WELCOME!
30 mins

Secure Our Streets 2025

Show More...
John Heldreth
ASRG Founder
7:30 PM
(UTC)
KEYNOTE: Product Cybersecurity in Practice: Aligning Standards, Contracts, and Industry Needs
60 mins

This presentation explores the evolution of product cybersecurity requirements in the automotive industry, highlighting the influence of emerging regulations such as UN ECE R.155 and standards like ISO/SAE 21434 on the cybersecurity landscape.

It also addresses the complexities and challenges arising from contractual obligations across the automotive value chain and offers practical recommendations for reducing this complexity through better alignment between regulatory, technical, and commercial requirements.

Show More...
Dr. Mathias Dehm
Chief Product Security & Privacy Officer, AUMOVIO Germany

Dr. Mathias Dehm is the Chief Product Security & Privacy Officer at AUMOVIO, one of the leading Tier-1 suppliers in the automotive industry. With over 14 years of experience in cybersecurity and privacy, he has held various leadership roles and built a strong track record across multiple sectors, including logistics, telecommunications, medical technology, defense, automotive, and startups.

Dr. Dehm holds a Ph.D. from Munster Technological University in Cork, Ireland, and brings a multidisciplinary perspective to product security, combining deep technical expertise with strategic business insight.

Show More...
8:35 PM
(UTC)
Post-Quantum Cryptography in Automotive: A Strategy Proposal
39 Mins

Asymmetric cryptography is now in widespread use, but algorithms that are secure today will be broken by the quantum computers of tomorrow. Most of todays and upcoming automotive security measures (e. g. ECU integrity protection, secure onboard communication, V2X, access control etc.) rely on classical cryptography that will be vulnerable. Although a breakthrough in quantum computing might be years away, companies need to prepare for the smooth transition to quantum-secure systems. Finding suitable post-quantum algorithms and migrating to quantum-secure systems can pose many challenges. This presentation aims to facilitate the understanding of challenges in the migration to post-quantum cryptography and describe viable solutions based on existing research. First, post-quantum algorithms and their impact on functions and protocols are analyzed under consideration of ongoing standardization processes and migration research projects. After that, the considerable differences between algorithms based on practical examples and benchmarks on common automotive hardware targets, e.g., Aurix TC375, are described. In the practical examples we focus on the lattice-based algorithms Falcon and Dilithium and briefly point out differences from other mathematical primitives. Furthermore, practical solutions for migration of Public Key Infrastructures (PKIs) are illustrated and respective advantages and disadvantages are discussed. The various categories of crypto agility are presented to highlight the wide scope of methods in this field. At the end, a general strategy for migration is proposed that considers the general uncertainty about the quantum threat by planning ahead and increases the trust in novel post-quantum algorithms by the implementation of suitable solutions.

Show More...
Dennis Naujoks
Consultant for Automotive Security, ETAS Germany

Dennis Naujoks is a cybersecurity consultant specializing in automotive security at ETAS. He holds a Bachelor’s and Master’s degree in IT-Security from Ruhr-University Bochum, where he developed a strong foundation in applied cryptography and embedded systems. During his Master’s thesis at TÜV IT, Dennis focused on post-quantum cryptography and side-channel analysis—key areas in securing next-generation embedded platforms. Since 2022, he has worked at the intersection of automotive systems and cybersecurity, helping clients navigate complex security challenges in connected and software-defined vehicles.

Show More...
8:35 PM
(UTC)
Enhancing Automotive IDPS with CHERI-based RISC Memory Protection for Improved Security
33

The rapid integration of connected technologies in modern vehicles has introduced significant cybersecurity challenges, particularly in securing critical systems against advanced threats such as IP spoofing and rule manipulation. This study investigates the application of CHERI (Capability Hardware Enhanced RISC Instructions) to enhance the security of Intrusion Detection Systems (IDSs) in automotive networks. By leveraging CHERI’s fine-grained memory protection and capability-based access control, the IDS ensures the robust protection of rule configurations against unauthorised access and manipulation. Experimental results demonstrate a 100% detection rate for spoofed IP packets and unauthorised rule modification attempts. The CHERI-enabled IDS framework achieves latency well within the acceptable limits defined by automotive standards for real-time applications, ensuring it remains suitable for safety-critical operations. The implementation on the ARM Morello board highlights CHERI’s practical applicability and low-latency performance in real-world automotive scenarios. This research underscores the potential of hardware-enforced memory safety in mitigating complex cyber threats and provides a scalable solution for securing increasingly connected and autonomous vehicles. Future work will focus on optimising CHERI for resource-constrained environments and expanding its applications to broader automotive security use cases.

Show More...
Saket Mohan
Founder and CEO, Secure Elements

Saket Mohan is the Founder and CEO of Secure Elements, a recognized leader in automotive cybersecurity. With over 15 years of experience in automotive telematics, connected cars, and cybersecurity, Saket has been instrumental in enhancing the cyber resilience of complex automotive systems. He has contributed to high-profile cybersecurity projects at leading organizations such as Jaguar Land Rover, ClearMotion, EDAG Engineering, and the Transport Research Laboratory. His passion for automotive cybersecurity led to the founding of Secure Elements, where he now leads a skilled team in developing innovative embedded cybersecurity software solutions that ensure the safety and security of software defined vehicles (SDV’s)

Show More...
Sampath Kalutharage
Cybersecurity and AI Lead Engineer, Secure Elements

Sampath Kalutharage is currently a Cybersecurity and AI Lead Engineer at Secure Elements. He is also a post-doctoral researcher at Lancaster University, specializing in embedded cybersecurity. With expertise in machine learning and Generative AI, Sampath has a solid foundation in the research and development of IoT cyber-critical systems. His career began as a Network Operations Centre Engineer, followed by various roles across network and cybersecurity sectors, including Zonal Technical Manager at NMI Infra and a significant tenure at Airtel. His passion for advancing cybersecurity knowledge led him to transition into academia. Sampath actively contributes to the cybersecurity community, regularly presenting at prestigious events and playing a crucial role in shaping the future of cybersecurity in automotive and critical systems.

Show More...
9:25 PM
(UTC)
Automotive Ethernet Security Revisited: New Protocols, New Attacks, and Advanced Scapy Techniques
46 Mins

Five years ago, we presented “Automotive Penetration Testing with Scapy” at TROOPERS19—a talk that quickly became one of the most-watched sessions on the TROOPERS YouTube channel. In the intervening years, the automotive domain has evolved significantly, particularly in the realm of **Automotive Ethernet** (e.g., 100/1000BASE-T1). Modern vehicles now rely heavily on protocols like **Diagnostics over IP (DoIP)**, **SOME/IP**, and **AUTOSAR PDUs**, combined with sophisticated security approaches and **Over-the-Air (OTA)** update mechanisms. In this fresh deep dive, we revisit the automotive Ethernet security landscape, illustrating how **Scapy** has adapted to accommodate these emerging protocols and testing scenarios. We will demonstrate advanced techniques, including restbus simulations for SOME/IP, emulating malicious OTA update servers, and exploring cutting-edge features in UDS—such as authentication services—all through carefully crafted packet injection and analysis.

Show More...
Dr. Nils Weiß
CEO & Co-Founder, dissecto GmbH

Dr. Weiß delved into penetration testing during his Bachelor’s and Master’s, exploring vulnerabilities in embedded systems and entire vehicles. Active in developing open-source penetration test frameworks like Scapy, he co-founded dissecto GmbH in 2022, focusing on simplifying security diagnostics and solutions for embedded systems.

Show More...
Jonas Horreis
Senior Penetration Tester dissecto GmbH

Jonas Horreis is a penetration tester at dissecto with a focus on automotive security. He started by automating ECU security tests for his bachelor’s thesis, expanded into securing EV-charging infrastructure and electric-vehicle architectures during his master’s research, and later investigated advanced fuzzing techniques as a university research assistant. Now he applies this knowledge to secure the ECUs of the future.

Show More...
9:25 PM
(UTC)
Automotive Threat Analysis and Risk Assessment: Data sharing using openXSAM format
33 Mins

This study examines the automation of converting Threat Analysis and Risk Assessment (TARA) data into the openXSAM format within the automotive industry, addressing the growing need for cybersecurity in modern, interconnected vehicles. By leveraging both qualitative and quantitative research methods, the study identifies challenges in data standardization, evaluates current practices, and explores the potential of automation to streamline processes and enhance compliance with ISO/SAE 21434 and UNECE Regulation No. 155. The findings demonstrate that automated data conversion could significantly improve efficiency, data integrity, and interoperability across the automotive supply chain, thereby supporting industry-wide cybersecurity objectives. This research offers valuable insights for automotive engineers, cybersecurity professionals, and policymakers, emphasizing the need for robust tools and collaborative efforts to standardize and automate TARA data processes.

Show More...
Sergio Scabar
Cybersecurity Manager, ZF Engineering Solutions

Brazilian professional with over 35 years of experience at ZF Group. Master’s degree in Computer Science with Cybersecurity from Wrexham Glyndwr University (UK), MBA in Strategic Business Management (Brazil), and BS in Mechanical Engineering (Brazil). Responsible for the Cybersecurity Engineering Service at ZF Engineering Solutions in the UK, delivering services for internal and external customer, including fuzz and pen testing.

Show More...