Security Verification Support Services

IS&S - Cybersecurity Engineering Support -

*Note: This service is provided exclusively within Japan. We do not conduct business or provide support overseas.

Security Countermeasure Testing Support

  • Target Industry : Automotive / FA / Robotics / Construction Machinery / Marine, etc.
  • Target Department : Embedded Software Development

Are you facing any of these current issues and challenges?

  • Understand the need to implement security measures, but do not know how to proceed
  • Fully occupied with conventional development and lacking sufficient resources

We provide support for your security countermeasure testing.

Security Verification Perspectives of This Service

  • Verification of tamper detection

  • Verification of invalid input resilience (Fuzzing)

  • Verification of DoS attack resilience

  • Verification of unspecified services

  • Verification of replay attack resilience

Verification Methods of This Service

  • ECU Penetration Testing

    We conduct penetration testing in accordance with external guidelines or perform testing using black-box methodologies.

  • Fuzz Testing

    We input large volumes of fuzz data (unexpected data) into the target system to confirm that it does not exhibit abnormal behavior, such as system halts or unexpected output values, thereby verifying system robustness.

  • Communication Interface Testing (Including CAN)

    We perform security testing externally via communication interfaces and evaluate whether communication data is properly protected.

ECU Penetration Testing

  • Select target threats (verification items) and execute penetration testing

  • Conduct gray-box/white-box testing based on information disclosed by the client

    • Analyze hardware to evaluate security issues, including sensitive data leakage
    • Perform external security testing on communication interfaces to evaluate whether communication data is protected
    • Analyze software to evaluate security deficiencies, including implementation flaws in authentication/authorization and secure boot

  • Penetration testing evaluation perspectives

    • Evaluate IoT devices from diverse perspectives

Fuzz Testing

  • Challenges in Executing Fuzz Testing

    • Preparation of fuzz data
    - Creating large volumes of data manually requires significant time and labor.
    - Setting up prepared data for use in the test execution environment takes substantial effort.

    • Preparation of test execution environment
    - When using target hardware, inputting fuzz data (unexpected data) carries a risk of unforeseen damage or failures.
    - Executing tests using a debugger requires high manpower and effort.

  • Fuzz Testing Using CoverageMaster winAMS (CMW) / Quality Town for Embedded grade (QTE)

    By conducting software fuzz testing using an MCU simulator with CMW/QTE—both proven tools in unit testing—high-accuracy verification that cannot be detected in a PC-native environment becomes possible.

  • Reference 1: Verifying that output values are not abnormal

  • Reference 2–1: Detection of access to unexpected memory – 1

  • Reference 2–2: Detection of access to unexpected memory – 2

Communication Interface Testing (Including CAN)

  • Evaluation Targets for Interface Testing

    • Network / Vehicle systems

  • Evaluation Perspectives for Interface Testing

    • Verification of unspecified services
    • Verification of invalid input resilience
    • Verification of TLS / Wi-Fi / Bluetooth / CAN / Ethernet settings

  • Relevant Guidelines

    • Test suites prepared in accordance with industry standards
    Implementation methodologies based on proprietary know-how

Deliverables of This Service

  • We execute these vulnerability tests on your behalf and submit a "Verification Result Report" as the deliverable.

Related Services & Tools

Co-creating unprecedented evolution through unstoppable technology.

Please feel free to contact us for details on our products and services or to request materials.