🎉 VSEC Core 1.0.0 and VSEC Test v4.3.4 are now live! Release Notes ↗
Open Source

Open Source

The Breakwater CLI is open source

Breakwater is the part of VSEC Test that does the testing. It runs on every Bench, talks to the Device Under Test over CAN and Ethernet/IP, and executes the Test Cases in a Test Run.

Its command line tool, bw_cli, runs Test Cases directly on a Bench. See Breakwater CLI.

bw_cli is open source, under the GNU General Public License, version 2 only (GPL-2.0-only). You can read exactly what each Test Case sends to your device, run Test Cases without VSEC, and change them to suit your own setup.

What is in the source

  • bw_cli itself.
  • The Test Cases. Every audit bw_cli can run, with the parameters it accepts and the frames or packets it sends.
  • Discovery, the code behind bw_cli discover and attack surface discovery.

Using the CLI with and without VSEC

A Bench created through VSEC Test installs Breakwater and keeps the Bench connected to your workspace. Nothing changes for existing Benches.

bw_cli also runs on its own. Install it from source on any supported Linux machine and run Test Cases locally, with no VSEC account. Test Plans, scheduled Test Runs, reports and remote access to the Bench need VSEC Test.

Only test hardware you own or are authorised to test. Several Test Cases can flood a bus, reset an ECU or write to its memory. That is the point of a security test, and it is also why it belongs on a bench, not in a vehicle on the road.

Source for earlier releases

The source corresponding to Breakwater releases 2.5.0 to 3.0.2 is published as Debian source packages in the Breakwater APT repository. After adding the repository as described in Updating Breakwater, which includes the deb-src line, fetch a release with:

apt-get source breakwater=3.0.2

Each source package names the release it corresponds to, lists every file with its SHA-256, and includes the source of each third-party component at the version used, with its licence.

Contributing and reporting security issues

Bug reports, new Test Cases and fixes are welcome as issues and pull requests on GitHub.

Please do not report security vulnerabilities in a public issue. Use our contact form instead.

Last updated on