Cybersecurity in robotics is an emerging topic that has gained significant traction. Researchers have demonstrated some of the potentials and effects of cyber attacks on robots lately. This implies safety related adverse consequences causing human harm, death or lead to significant integrity loss clearly overcoming the privacy concerns in classical IT world. In cybersecurity research, the use of vulnerability databases is a very reliable tool to responsibly disclose vulnerabilities in software products and raise willingness of vendors to address these issues. In this paper we argue, that existing vulnerability databases are of insufficient information density and show some biased content with respect to vulnerabilities in robots. This paper presents the Robot Vulnerability Database (RVD), a directory for responsible disclosure of bugs, weaknesses and vulnerabilities in robots. This article aims to describe the design and process as well as the associated disclosure policy behind RVD. Furthermore the authors present preliminary selected vulnerabilities already contained in RVD and call to the robotics and security communities for contribution to the endeavour of eliminating zero-day vulnerabilities in robotics.
翻译:在网络安全研究中,使用脆弱程度数据库是一个非常可靠的工具,可以负责地披露软件产品的脆弱性,提高供应商解决这些问题的意愿。在这份文件中,我们认为,现有的脆弱程度数据库信息密度不足,在机器人的脆弱性方面显示出一些偏颇的内容。本文介绍了机器人脆弱性数据库,这是一个负责披露机器人中的错误、弱点和弱点的目录。这一文章旨在描述设计和过程以及RVD背后的相关披露政策。此外,作者还介绍了RVD中已经包含的一些初步选定的脆弱性,并呼吁机器人和安全界为努力消除机器人零天脆弱性作出贡献。