Jul 2026· IEEE Internet of Things Journal· Vol abs/2607.07226, pp. 1-1· 0 citations· 46 references
Computer Science
TL;DR
This work presents a comprehensive security analysis for SDVs, focusing on software vulnerabilities, and combines systematic vulnerability discovery, leveraging public Common Vulnerabilities and Exposures databases, within a dockerized development environment that evaluates exploitability risks.
Abstract
Software-defined vehicles (SDVs) are revolutionizing transportation by integrating complex, interconnected hardware, and software systems. This evolution introduces significant security challenges. We present a comprehensive security analysis for SDVs, focusing on software vulnerabilities. We note that existing vulnerability assessment tools fall short in addressing operating systems vulnerabilities, particularly when it comes to efficiently analyzing diverse software stacks in realistic environments. We present and release a vulnerability assessment solution that efficiently addresses these limitations. Our approach combines systematic vulnerability discovery, leveraging public Common Vulnerabilities and Exposures (CVE) databases, within a dockerized development environment that evaluates exploitability risks. The results reveal both breadth of potential threats and the practical constraints we faced during exploitation. We discuss the implications for industry and research, and propose directions for building more resilient SDVs.
A survey of automotive software vulnerabilities and associated attack vectors and analyzes the significant changes in security trends is presented and several security recommendations for software engineering teams are provided based on the findings.
Srijita Basu, Miroslaw Staron, M. Almgren et al.· Software quality journal· 0 citations
This article describes and categorize embedded systems, highlights the challenges posed by embedded systems for taint analysis, examine state-of-the-art techniques, and categorize dozens of tools in this field.
This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk.
Shruti Agarwal, S. Sharma· DMPedia Lecture Notes in Com...· 1 citation
A novel NSSA framework based on process tree modeling and dynamic service-chain orchestration that significantly outperforms PCA and Basic Evolution in terms of true positive and false positive rates, while the dynamic service-chain mechanism ensures efficient resource utilization and rapid threat containment.
Si-Wei Li, Xiao-Dong Wei· International Journal of Com...· 0 citations
VEX-Bench is introduced, the first benchmark for evaluating LLM agents'ability to assess the exploitability of software supply chain vulnerabilities, and contains 75 real-world cases mined from GitHub and labeled by security experts, covering Python, Java, and Go.
Jia-Hao Shi, Edward Tsien, Yi-Feng Di et al.· 0 citations
Software supply chain security has become increasingly critical due to the widespread reliance on third-party dependencies and the growing attack surface of modern software ecosystems. However, existing quantitative, measurement-based analysis and vulnerability management approaches remain largely fragmented and ecosys...
Sarah Meriem Ourari· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.