What is CycurFUZZ

UNECE WP.29 states that "both the OEM and the certification body (or technical service) must conduct security tests" in relation to cyber security measures. is required from OEMs to suppliers, security testing has become a very important and mandatory item. ISO 21434 also requires OEMs/suppliers to perform security testing to minimize unidentified weaknesses and vulnerabilities in their components.

Among the various security tests, the recommended one is the fuzz test, which inputs a large number of uncommon or invalid inputs to the target in order to cause unexpected behavior or anomalies that may lead to cyberattacks on the system. It is a method to Every year, the complexity of communication in in-vehicle systems (connectivity) increases, and in recent years, it is expected that nearly 70% of new light vehicles and trucks launched worldwide will have connectivity built-in. Various communications such as USB connectivity, connected entertainment, navigation systems, and wireless systems increase user convenience, but they also increase the vehicle's attack surface proportionally, allowing hackers to hijack systems and compromise the safety of occupants. The possibilities also increase. This is why cyber security testing in in-vehicle systems is so important. ESCRYPT CycurFUZZ is a powerful testing method to check the robustness of software and systems, fuzz testing software.

ESCRYPT CycurFUZZ is a test tool originally used for fuzz testing within ETAS.

Product Summary

Features

  • Conforms to GM CG4975 (fuzzing specification)
  • High performance and efficiency
  • Supports unlimited parallel CAN testing
  • Automatic reconnection with ECU and power cycle
  • Flexible licensing model (consultation required)
  • Automatic report creation
  • Fuzzing in virtual environments
  • AI fuzzing (improving efficiency through machine learning)
  • Simultaneous fuzzing for multiple ECUs

Unique strength of ETAS (1) Enhancement of fuzzing by artificial intelligence (AI)

CycurFUZZ enables instant learning of previously discovered vulnerabilities and the creation and execution of AI test cases using learning-based generative adversarial networks (GANs).

By doing so, we can optimize the fuzzing result and reduce the execution time.

ETAS unique strength ② Simultaneous fusing of multiple ECUs

CycurFUZZ enables fuzzing at the vehicle level by testing multiple vehicle components (system level) simultaneously on one communication bus.

It can reduce man-hours and fuzz test execution time. This innovative technology has been granted a US patent.

Fuzzing service

ETAS also provides a fuzzing service using CycurFUZZ, the above-mentioned in-house software. We have participated in numerous corporate projects and have contributed to the discovery of vulnerabilities and implementation errors. As a security testing expert, ETAS is well versed in embedded system fuzzing.

Inquiry

ETAS manufacturer information TOP

If you want to return to ETAS Manufacturer Information Top, please click below.