AutoSec Fuzz Testing Lab
Break protocols before attackers do
Build and operate fuzzing campaigns against automotive protocol stacks, with instrumentation, triage and defect reporting that fits a validation programme.
Primary objectives
- Design a protocol fuzzing campaign
- Instrument targets for crash detection
- Triage and de-duplicate findings
- Integrate fuzzing into a validation pipeline
Overview
What This Lab Is For
Fuzzing finds the defects that review and manual testing do not. This lab builds the capability as a repeatable programme rather than a one-off campaign — designed scope, instrumented targets, triage that survives hundreds of findings and evidence in a format a type-approval assessor will accept.
Build and operate fuzzing campaigns against automotive protocol stacks, with instrumentation, triage and defect reporting that fits a validation programme.
Learning goals
- Operate a repeatable automotive fuzzing programme
- Produce evidence that satisfies validation requirements
Technology stack
- UDS
- DoIP
- SOME/IP
- CAN
- Coverage instrumentation
Tools used
Hardware, Software and Security Tooling
Production-representative equipment and the toolchains engineers use on the job — not simulators standing in for them.
Hardware
Physical targets and instrumentation you will work on directly.
- Instrumented target ECUCoverage-instrumented build for crash detection
- DoIP and Automotive Ethernet benchRig
- Debug probe for crash captureDebugger
Security tools
Analysis, testing and cryptographic tooling applied to the targets.
- Protocol fuzzing framework
- Target instrumentation harness
- Crash triage tooling
Exercises
2 Assessed Exercises
Each exercise is assessed rather than demonstrated. Durations are indicative and vary with cohort experience.
UDS service fuzzing
intermediateFuzz diagnostic services and triage the resulting faults.
- Duration
- 3 hours
Automotive Ethernet stack fuzzing
advancedCampaign against SOME/IP and DoIP handling with coverage feedback.
- Duration
- 4 hours
Learning outcomes
What You Can Demonstrate Afterwards
An at-a-glance summary — each item is expanded in the sections above and below.
- Skills acquired
2
Assessed competencies, listed in full under Overview above.
- Capability levels
- L4 · ValidationL5 · OffensiveL6 · Leader
- Programs supported
4
Listed with their capability level in the next section.
Capability framework
Where This Lab Sits in the Framework
All six levels, and this lab’s relationship to each — including the ones it deliberately does not cover.
- Not covered
Level 1 · Awareness
Cybersecurity Awareness
Covered by other labs in the estate
- Not covered
Level 2 · Compliance
Compliance Practitioner
Covered by other labs in the estate
- Not covered
Level 3 · Secure Developer
Secure Developer
Covered by other labs in the estate
- Supported
Level 4 · Validation
Master TARA, security validation, fuzz testing and architecture review.
- Supported
Level 5 · Offensive
Develop automotive penetration testing, red team and exploit research capabilities.
- Supported
Level 6 · Leader
Lead CSMS transformation, security governance and enterprise capability programmes.
Common questions
AutoSec Fuzz Testing Lab FAQ
What engineers and their managers ask before booking lab time.
- Do I need prior fuzzing experience?
- No. The lab starts from campaign design principles. It does assume embedded or validation engineering background — you should be comfortable instrumenting a target and reading a crash dump.
- Why is instrumentation emphasised so heavily?
- Because an uninstrumented target survives faults silently. A campaign that runs for a week and reports nothing usually means the harness could not detect a failure, not that the stack is sound.
- Does the lab cover CI integration?
- Yes, in the final exercise. You leave with a gating model, a triage workflow that de-duplicates at scale and an evidence format that fits an existing validation process.
Get Your Engineers Into the AutoSec Fuzz Testing Lab
Lab access is included with the programs above, and can be delivered onsite, remotely or as part of a corporate academy.