论文标题
Alurity,机器人网络安全的工具箱
alurity, a toolbox for robot cybersecurity
论文作者
论文摘要
技术的重复使用和大多数机器人系统的固有复杂性越来越多地导致机器人具有广泛的攻击表面和各种潜在的脆弱性。鉴于他们在公共环境中的存在越来越多,安全研究变得越来越重要,尤其是由于机器人脆弱性可能引起人类的安全性。我们认为,机器人技术的安全分类仍然不成熟,必须开发新的工具来加速测试 - 疏松探索周期,这对于确定和加速缓解缺陷所必需的必要条件。 目前的工作通过提出工具箱来解决机器人技术中目前缺乏进攻性网络安全研究,以及通过一年多的几种用例获得的结果。我们提出了一个用于机器人网络安全的模块化和可组合工具箱:蓝术。通过确保机器人主义者和从事项目的安全研究人员都具有共同的,一致且易于重现的开发环境,Alurity旨在促进网络安全研究和跨团队的协作。
The reuse of technologies and inherent complexity of most robotic systems is increasingly leading to robots with wide attack surfaces and a variety of potential vulnerabilities. Given their growing presence in public environments, security research is increasingly becoming more important than in any other area, specially due to the safety implications that robot vulnerabilities could cause on humans. We argue that security triage in robotics is still immature and that new tools must be developed to accelerate the testing-triage-exploitation cycle, necessary for prioritizing and accelerating the mitigation of flaws. The present work tackles the current lack of offensive cybersecurity research in robotics by presenting a toolbox and the results obtained with it through several use cases conducted over a year period. We propose a modular and composable toolbox for robot cybersecurity: alurity. By ensuring that both roboticists and security researchers working on a project have a common, consistent and easily reproducible development environment, alurity aims to facilitate the cybersecurity research and the collaboration across teams.