M3-06

11.21(金) 15:15-15:55 | 展示会場内 RoomM

×

Special session

Supply Chain Security
- Visualizing Vulnerabilities and Automating Verification by Binary Analysis -

Presented byTOYO Corporation

In this session, we will introduce practical methods for supply chain security with an eye toward compliance with UN-R155/156 and ISO/SAE 21434. OEMs and Tier-1s face the challenge of verifying supplier deliverables. In response to this challenge, this session will introduce a method for visualizing security risks throughout the supply chain using Karamba Security's binary analysis tool, VCode. Specifically, based on the results of penetration tests conducted by Karamba for automotive suppliers, we will report on the trends and impact of vulnerabilities actually detected, such as unsigned firmware, encryption keys stored in plain text, and UDS implementation errors. We will also present case studies to demonstrate the risk reduction benefits and implementation benefits of automated verification using VCode.
  • Safety & Security
  • Automotive Software Expo
Speaker

TOYO Corporation

Software Solutions
Chief

Toshikazu Iwata

2007.04 Joined Toyo Corporation.Primarily engaged in sales and support in the field of materials analysis. 2017.04 Involved in an industry-academia collaboration project with Keio University. 2024.04 Involved in software static analysis and security-related work.

Inquiry

close