论文标题
ROS可以安全地用于行业吗?红色团队Ros-Istrial
Can ROS be used securely in industry? Red teaming ROS-Industrial
论文作者
论文摘要
随着行业的日益增长,ROS迅速成为机器人技术的标准。尽管ROS 2中的发展表现出希望,但行业中采用缓慢的收养周期将从现在起广泛的ROS 2工业收养年。 ROS在此期间将占上风:即使其起源不考虑它,ROS是否可以安全地用于工业用例?本研究通过在涉及ROS工业和ROS包装的合成工业用例中进行有针对性的进攻安全练习来实验分析这个问题。我们的练习导致四组攻击能够损害ROS计算图,除了所有攻击图外,所有攻击都可以控制欲望时大多数机器人端点。据我们所知,并鉴于我们的设置,结果不利于当今行业中的ROS的安全使用,但是,我们设法确认某些机器人终点的安全性保持不变,并对确保ROS工业部署保持乐观。
With its growing use in industry, ROS is rapidly becoming a standard in robotics. While developments in ROS 2 show promise, the slow adoption cycles in industry will push widespread ROS 2 industrial adoption years from now. ROS will prevail in the meantime which raises the question: can ROS be used securely for industrial use cases even though its origins didn't consider it? The present study analyzes this question experimentally by performing a targeted offensive security exercise in a synthetic industrial use case involving ROS-Industrial and ROS packages. Our exercise results in four groups of attacks which manage to compromise the ROS computational graph, and all except one take control of most robotic endpoints at desire. To the best of our knowledge and given our setup, results do not favour the secure use of ROS in industry today, however, we managed to confirm that the security of certain robotic endpoints hold and remain optimistic about securing ROS industrial deployments.