Robots are typically not created with security as a main concern. Contrasting to typical IT systems, cyberphysical systems rely on security to handle safety aspects. In light of the former, classic scoring methods such as the Common Vulnerability Scoring System (CVSS) are not able to accurately capture the severity of robot vulnerabilities. The present research work focuses upon creating an open and free to access Robot Vulnerability Scoring System (RVSS) that considers major relevant issues in robotics including a) robot safety aspects, b) assessment of downstream implications of a given vulnerability, c) library and third-party scoring assessments and d) environmental variables, such as time since vulnerability disclosure or exposure on the web. Finally, an experimental evaluation of RVSS with contrast to CVSS is provided and discussed with focus on the robotics security landscape.
翻译:与典型的信息技术系统相比,网络物理系统依赖安全来处理安全问题。根据前者,典型的评分方法,如共同脆弱度计分系统(CVSS)无法准确地捕捉到机器人脆弱性的严重性。目前的研究工作侧重于创建一个开放和免费的机器人脆弱度计分系统(RVSS),该系统考虑机器人中的主要问题,包括机器人安全方面,b)评估特定脆弱程度的下游影响,c)图书馆和第三方评分评估和d)环境变量,如脆弱性披露或网上曝光的时间。最后,提供并讨论与机器人安全景观相对的对机器人脆弱度计分系统(RVSS)的试验性评价。