[en] Abstract—In this paper we propose ROS-Defender, a holistic
approach to secure robotics systems, which integrates a Security
Event Management System (SIEM), an intrusion prevention system
(IPS) and a firewall for a robotic system. ROS-Defender combines
anomaly detection systems at application (ROS) level and
network level, with dynamic policy enforcement points using
software defined networking (SDN) to provide protection against
a large class of attacks. Although SIEMs, IPS, and firewall
have been previously used to secure computer networks, ROSDefender
is applying them for the specific use case of robotic
systems, where security is in many cases an afterthought.
Centre de recherche :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > Services and Data management research group (SEDAN)
Disciplines :
Sciences informatiques
Auteur, co-auteur :
RIVERA, Sean ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
LAGRAA, Sofiane ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
STATE, Radu ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Nita-Rotaru, Cristina; Northeastern University > Khoury College of Computer Sciences
A. Akhunzada, E. Ahmed, A. Gani, M. K. Khan, M. Imran, and S. Guizani. Securing software defined networks: taxonomy, requirements, and open issues. IEEE Communications Magazine, 53(4):36-44, April 2015.
B. Breiling, B. Dieber, and P. Schartner. Secure communication for the robot operating system. pages 1-6, April 2017.
J. Chu. Army robotics in the military. https://insights.sei.cmu.edu/sei blog/2017/06/army-robotics-in-the-military.html. Accessed: August 02, 2018.
B. Dieber, B. Breiling, S. Taurer, S. Kacianka, S. Rass, and P. Schartner. Security for the robot operating system. Robot. Auton. Syst., 98:192-203, Dec. 2017.
P. Dorfinger, G. Panholzer, and W. John. Entropy estimation for realtime encrypted traffic identification (short paper). In J. Domingo-Pascual, Y. Shavitt, and S. Uhlig, editors, Traffic Monitoring and Analysis, pages 164-171, Berlin, Heidelberg, 2011. Springer Berlin Heidelberg.
F. Furrer, M. Burri, M. Achtelik, and R. Siegwart. Robot Operating System (ROS): The Complete Reference (Volume 1), chapter RotorS-A Modular Gazebo MAV Simulator Framework, pages 595-625. Springer International Publishing, Cham, 2016.
A. Giaretta, M. D. Donno, and N. Dragoni. Adding salt to pepper: A structured security assessment over a humanoid robot. CoRR, abs/1805.04101, 2018.
S. Hong, R. Baykov, L. Xu, S. Nadimpalli, and G. Gu. Towards sdndefined programmable BYOD (bring your own device) security. 2016.
S.-Y. Jeong, I.-J. Choi, Y.-J. Kim, Y.-M. Shin, J.-H. Han, G.-H. Jung, and K.-G. Kim. A study on ros vulnerabilities and countermeasure. In Proceedings of the Companion of the 2017 ACM/IEEE International Conference on Human-Robot Interaction, HRI '17, pages 147-148, New York, NY, USA, 2017. ACM.
D. Kreutz, F. M. Ramos, and P. Verissimo. Towards secure and dependable software-defined networks. In Proceedings of the Second ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking, HotSDN '13, pages 55-60, New York, NY, USA, 2013. ACM.
S. Lagraa, M. Cailac, S. Rivera, F. Beck, and R. State. Real-time attack detection on robot cameras: A self-driving car application. In IEEE International Conference on Robotic Computing (IRC), 2019.
F. Martn, E. Soriano, and J. M. Caas. Quantitative analysis of security in distributed robotic frameworks. Robotics and Autonomous Systems, 100:95-107, 2018.
R. Rahimi, C. Shao, M. Veeraraghavan, A. Fumagalli, J. Nicho, J. Meyer, S. Edwards, C. Flannigan, and P. Evans. An industrial robotics application with cloud computing and high-speed networking. In IEEE International Conference on Robotic Computing (IRC), pages 44-51, 2017.
S. Rivera, S. Lagraa, and R. State. Rosploit: Cybersecurity tool for ros. In IEEE International Conference on Robotic Computing (IRC), 2019.
The Open Networking Foundation. OpenFlow Switch Specification, Jun. 2012.
R. Toris, C. Shue, and S. Chernova. Message authentication codes for secure remote non-native client connections to ros enabled robots. pages 1-6, April 2014.
V. Varadharajan, K. K. Karmakar, and U. Tupakula. Securing communication in multiple autonomous system domains with software defined networking. In 2017 IFIP/IEEE Symposium on Integrated Network and Service Management (IM), pages 195-203, 2017.
R. White, H. I. Christensen, and M. Quigley. SROS: securing ROS over the wire, in the graph, and through the kernel. CoRR, abs/1611.07060, 2016.