MAGIC addresses forensic investigations across three operational phases: pre-operation (design & development), on-operation (vehicle in use), and post-operation (after an incident). Two cross-cutting work packages handle management and dissemination.
1
Project Management
Overall project management, dissemination, and reporting activities. The project leader oversees coordination among all partners, financial reporting, and delivery of project status reports. The vice project leader provides academic guidance and supports delegated dissemination activities.
- Project status reports
- Coordination across all consortium partners
- Financial and administrative oversight
2
Use Cases & Literature Review
Identification of industrial needs and use cases, state-of-the-art analysis, and gap identification in current ADF practices.
- T2.1: Identification and prioritization of industrial use cases through stakeholder interviews (accident investigators, OEM engineers, law enforcement).
- T2.2: Literature review covering ADF, IoT, CPS, and avionics — with gap analysis and future guidelines.
3
Pre-Operation — ADF Architecture
Design of a reference architecture for forensically enabled vehicles, covering secure logging, secure storage, and software update mechanisms.
- T3.1: Reference architecture and guidelines — defining vital components, requirements, and interplay between ADF, Hybrid IDS, secure logging, secure storage, and OTA updates. Guidelines for ADF data management and governance, focused on GDPR compliance and the CIA security triad.
4
On-Operation — Threat Detection & Data Collection
Forensic soundness, real-time threat detection via AI-driven IDS, and forensically sound data collection during vehicle operation.
- T4.1: Forensic soundness and data collection strategies — anomaly and tampering detection, anti-forensic protection, ISO/IEC 27037:2012 compliance, bandwidth and data integrity management.
- T4.2: Enhanced IDS methodologies — real-time adaptation, automatic rule generation via OTA, XAI for transparency, adversarial training, event correlation matrices.
5
Post-Operation — Digital Evidence Management
Management and analysis of digital forensic evidence, IDS maintainability, and adaptive cyber-resilience mechanisms post-incident.
- T5.1: Forensically sound management of digital evidence — identification, collection, acquisition, and preservation per ISO/IEC 27037:2012.
- T5.2: ADF and IDS maintainability — online adaptation, OTA update management, data lifecycle management.
- T5.3: Resilient ADF mechanisms and metrics — evaluation of resilience under cyber-attacks.
6
Dissemination & Proof of Value
Demonstrating the practical value of MAGIC's ADF solutions and disseminating results to academia, industry, and policymakers.
- Proof of Value (PoV) demonstrations on real-world use cases
- Workshops at major international conferences (e.g., IEEE/IFIP DSN, AutoSec)
- Publication of results in leading academic venues
- Education: at least 2 Ph.D. students and 6 master's students
- Engagement with regulatory bodies and standardization organizations