Security Verification Support Services
IS&S - Cybersecurity Engineering Support -
*Note: This service is provided exclusively within Japan. We do not conduct business or provide support overseas.
Security Countermeasure Testing Support
- Target Industry : Automotive / FA / Robotics / Construction Machinery / Marine, etc.
- Target Department : Embedded Software Development
Problem
Are you facing any of these current issues and challenges?
- Understand the need to implement security measures, but do not know how to proceed
- Fully occupied with conventional development and lacking sufficient resources
Solution
We provide support for your security countermeasure testing.
Security Verification Perspectives of This Service
-
Verification of tamper detection
-
Verification of invalid input resilience (Fuzzing)
-
Verification of DoS attack resilience
-
Verification of unspecified services
-
Verification of replay attack resilience
Verification Methods of This Service
-
ECU Penetration Testing
We conduct penetration testing in accordance with external guidelines or perform testing using black-box methodologies.
-
Fuzz Testing
We input large volumes of fuzz data (unexpected data) into the target system to confirm that it does not exhibit abnormal behavior, such as system halts or unexpected output values, thereby verifying system robustness.
-
Communication Interface Testing (Including CAN)
We perform security testing externally via communication interfaces and evaluate whether communication data is properly protected.
ECU Penetration Testing
-
Select target threats (verification items) and execute penetration testing
-
Conduct gray-box/white-box testing based on information disclosed by the client
• Analyze hardware to evaluate security issues, including sensitive data leakage
• Perform external security testing on communication interfaces to evaluate whether communication data is protected
• Analyze software to evaluate security deficiencies, including implementation flaws in authentication/authorization and secure boot -
Penetration testing evaluation perspectives
• Evaluate IoT devices from diverse perspectives
Fuzz Testing
-
Challenges in Executing Fuzz Testing
• Preparation of fuzz data
- Creating large volumes of data manually requires significant time and labor.
- Setting up prepared data for use in the test execution environment takes substantial effort.
• Preparation of test execution environment
- When using target hardware, inputting fuzz data (unexpected data) carries a risk of unforeseen damage or failures.
- Executing tests using a debugger requires high manpower and effort. -
Fuzz Testing Using CoverageMaster winAMS (CMW) / Quality Town for Embedded grade (QTE)
By conducting software fuzz testing using an MCU simulator with CMW/QTE—both proven tools in unit testing—high-accuracy verification that cannot be detected in a PC-native environment becomes possible.
-
Reference 1: Verifying that output values are not abnormal
-
Reference 2–1: Detection of access to unexpected memory – 1
-
Reference 2–2: Detection of access to unexpected memory – 2
Communication Interface Testing (Including CAN)
-
Evaluation Targets for Interface Testing
• Network / Vehicle systems
-
Evaluation Perspectives for Interface Testing
• Verification of unspecified services
• Verification of invalid input resilience
• Verification of TLS / Wi-Fi / Bluetooth / CAN / Ethernet settings -
Relevant Guidelines
• Test suites prepared in accordance with industry standards
Implementation methodologies based on proprietary know-how
Deliverables of This Service
-
We execute these vulnerability tests on your behalf and submit a "Verification Result Report" as the deliverable.
Co-creating unprecedented evolution through unstoppable technology.
Please feel free to contact us for details on our products and services or to request materials.