The reuse of technologies and inherent complexity of most robotic systems is increasingly leading to robots with wide attack surfaces and a variety of potential vulnerabilities. Given their growing presence in public environments, security research is increasingly becoming more important than in any other area, specially due to the safety implications that robot vulnerabilities could cause on humans. We argue that security triage in robotics is still immature and that new tools must be developed to accelerate the testing-triage-exploitation cycle, necessary for prioritizing and accelerating the mitigation of flaws. The present work tackles the current lack of offensive cybersecurity research in robotics by presenting a toolbox and the results obtained with it through several use cases conducted over a year period. We propose a modular and composable toolbox for robot cybersecurity: alurity. By ensuring that both roboticists and security researchers working on a project have a common, consistent and easily reproducible development environment, alurity aims to facilitate the cybersecurity research and the collaboration across teams.
翻译:技术的再利用和大多数机器人系统固有的复杂性日益导致机器人的出现,其攻击面广,潜在的脆弱性也多种多样。鉴于这些机器人在公共环境中的存在日益增加,安全研究比任何其他领域都越来越重要,特别是由于机器人脆弱性对人类的安全影响。我们认为,机器人的安全分层仍然不成熟,必须开发新的工具,以加速测试-再利用周期,这是确定和加快减少缺陷所必需的。目前的工作通过介绍一个工具箱和在一年中通过几个使用案例获得的结果来解决机器人目前缺乏攻击性网络安全研究的问题。我们提出了一个模块化和可兼容的机器人网络安全工具箱:高利度。通过确保从事一个项目的机器人和安全研究人员都有一个共同的、连贯的和容易复制的开发环境,高利度的目的是促进网络安全研究和跨团队的合作。