Monitoring Vulnerabilities in Next-Generation Automotive Operating Systems
Dimitri Simon, Badis Hammi, Joaquin Garcia-Alfaro, Hervé Debar
cs.CR
Submitted: 2026-07-08
Journal ref: IEEE Internet of Things Journal,2026
DOI: 10.1109/JIOT.2026.3711962
Code: https://github.com/EternalDreamer01/vera
Project page: https://eclipse-score.github.io
License: http://creativecommons.org/licenses/by/4.0/
The gist: Software-defined vehicles (SDVs) are revolutionizing transportation by integrating complex, interconnected hardware, and software systems.
Terminology
Abstract
Software-defined vehicles (SDVs) are revolutionizing transportation by integrating complex, interconnected hardware, and software systems. This evolution introduces significant security challenges. We present a comprehensive security analysis for SDVs, focusing on software vulnerabilities. We note that existing vulnerability assessment tools fall short in addressing operating systems vulnerabilities, particularly when it comes to efficiently analyzing diverse software stacks in realistic environments. We present and release a vulnerability assessment solution that efficiently addresses these limitations. Our approach combines systematic vulnerability discovery, leveraging public Common Vulnerabilities and Exposures (CVE) databases, within a dockerized development environment that evaluates exploitability risks. The results reveal both breadth of potential threats and the practical constraints we faced during exploitation. We discuss the implications for industry and research, and propose directions for building more resilient SDVs.
Sources
- Vexed by VEX tools: Consistency evaluation of container vulnerability scanners
- Advancing Security in Software-Defined Vehicles: A Comprehensive Survey and Taxonomy
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs