Research Paper on Computer Security Concerns: Threats, Attacks, and Assets

profileAK10
Sample_Research_Report.docx

Research Report

Cyber Security and Robotics

Table of Contents Chapter 1- Abstract 2 Introduction 3 Problem Statement and Purpose of Research 3 Relevance and Significance 4 Research Questions 4 Barriers and Issues 5 Chapter 2 - Review of the Literature 5 Chapter 3 - Approach/Methodology 7 Chapter 4: Findings, Analysis, and Summary of Results 9 Chapter 5: Conclusions 10 References 10

Chapter 1- Abstract

Robots whether those are military, surgical, or household are prone to face similar cybersecurity threats as any handheld device or a computer system have been facing. With the innovation of newer technology humans have been able to achieve rapid success in the field of robotics, but that has opened doors to many cyber threats on these robots.

Robots like vacuum cleaners or simple telephones could also pose privacy and safety threats to their owners. What will happen if these robots are hacked? This research paper emphasizes on the cybersecurity attacks associated with service robots and presents the risk faced by the user by bucketing them into two different categories, which are security and safety. The study presents that robot development phase is where there is greatest opportunity to foresee the type of potential threats the robot and in turn the user may face and the importance of robot security control in the development phase.

Keywords: cybersecurity, privacy, safety, robots, innovation, technology

Introduction

Robotics is one of the domains where cyber threat is being recognized as the major security and privacy risk.

Robots are being used in assembly lines, medical settings, entertainment, and households extensively nowadays, thus, it is clear that safety, security and privacy of robotic systems is critical. Mitigating cyber threats on robots is a complicated process, as it requires robot builders to focus on multiple areas starting from coding the algorithms right by the developers to maintaining the confidentiality of the device architecture and design. The security problems that arise could be categorized as “virtual” pertains to the compromised data or communication and the other is on the physical side that concerns the user as well as the robot. Together these can me referred as “Cyber-physical security” to include both virtual and physical threats. In this study I am focusing on only the safety and privacy side and aims at gathering recent studies and surveys conducted in this area. There are many existing studies that focus on the importance of security and privacy of robotics systems in this rapidly growing technological era.

The survey presented in this study tries to gather information on the outcomes of previous research conducted. The different areas in this research paper are organized as follows. Chapter 1 presents a general overview of cybersecurity risks to different service robots and provides a taxonomy for the risks. Chapter 2 presents details on the focus areas of the research to build the foundation and justify results. Chapter 3 and 4 outlines the methodology employed and any supported data analysis and summarizes them. Finally, Chapter 5 summarizes the work done in this research paper.

Problem Statement and Purpose of Research

Cyber threats are affecting robotics operations in a negative way virtually. Hackers can modify the information gathered, stored or transmitted by the robot. These threats have effects on both external and internal entities. Some of these threats could have real potential to cause significant harm to innocent people, disrupt services, harm products and steal important information. Many robots are being used in autonomous weapon systems, industrial setup, medical procedures and in armed forces where they work side-by-side with humans. Thus, there is a genuine need to mitigate cyber security threats. In this study, we have focused on two particular cases: safety and privacy.

Relevance and Significance

Robots are actively involved in people’s daily lives at each aspect. May it be inside the house using robotic vacuum cleaners for house hold work or outside using an autonomous car, an entertainment robot or drone. Cyber threats have been increasing exponentially as people all over the world are rapidly using newer robots and technology. They are connected using robots, may it be for communication, entertainment, military or any other miscellaneous digital means. The Robotics and automation industry is expected to grow from $62 billion to $1.2 trillion in the next one decade. These numbers shed some light on the importance of safety and security in this industry.

The main objectives of this paper are to:

· Analyze several cyber-physical security threats, which indirectly target clients or users.

· Improve safety and security of the robotic systems, raise awareness and increase understanding of the emerging threats on the robotic platforms.

The study outlined in this paper focusses on how to have a safer and more secure robotic systems by addressing one or more of the following issues:

· identification of possible security and privacy threats against many modalities of robotic systems;

· evaluation of impact of the identified threats in a systematic manner; and

· prevention and mitigation of the threats.

Research Questions

· How to categorize the possible security and privacy threats faced by different robotic systems.

· Understanding the impact, the type of user, domestic vs business vs governmental have on type of threats.

· Once attacks are identified, how someone can mitigate the risks.

· How to model risks based on the type of threats experienced in the past.

Barriers and Issues

The robotics field is vast and due to the different types of robots and their uses the type of threats experienced are also different. Thus, it’s difficult to generalize the type of threats and remedies. Threats could have been generated accidentally due to some malfunctioning in robot resulting in transmission of confidential data or with malicious intent from the third party. The former ones are easier to control where the development team can take possible measures if faced during manufacturing and testing phase of the robot but the later is difficult to detect as well as control.

Chapter 2 - Review of the Literature

Below are some of the needs for modeling risks that helped build a foundation to justify the research problem i.e, need to improve the safety and security of robotics systems irrespective of the area of use.

To model risk, research uses security risk analysis that is performed on two factors: likelihood of a successful attack against an asset, and the consequence of such an attack. There are studies that show cybersecurity threats have targeted industrial environments more than that of service robots at home in the past. Cyber threats could be classified in general into three fields: confidentiality, integrity, and availability of information. In addition to this there are physical damages caused by cyber threats. In the research, risks associated with an attack are modeled in terms of the final user of the robot. The three identified robot users are - domestic users, commercial ones, and high-level organization.

Below are some of the threats experienced in the past by domestic and industrial robot users:

1. Economic risks, which takes into account the expenses incurred to fix the robot or the associated environment after the attack.

2. Physical, Reputational and Psychological if any damage to humans happens.

3. Economic damage, national security problems and any political risks in case the robot is being used by a public corporation.

The type of potential damage depends on the different levels of physical attacks to the robot: destruction, partial damage, degradation, disruption, or substitution of their elements.

Table below shows the summarization of threats identified using numbers 1-4 based on a survey conducted on the physical elements of the robot, with 4 being the severe scale of attack. The rows of the table indicate the different levels of physical attacks which are- destruction, partial damage, degradation, disruption, or substitution of their elements. Columns of below table indicate the different types of users of service like the domestic, commercial, or public administration/governmental.

These also depend on the type of user. The damages attack different users in a different ways, and users’ perception about the relevance of these risks is also different. For instance, domestic users are more concerned about the privacy issues, whereas corporate users are more concerned about the reputation of the corporation or their personal reputation in the corporation. Same applies to safety issues; domestic users are more concerned about the economic damage that robots can cause in their belongings, whereas corporate users are more worried about reputational damages or potential lawsuits. From my point of view, attacks on privacy are the one of most relevant risks that service robots could bring both to homes and to business.

The leak of information in a threat can cause severe damages. So, in the next section the research focuses on privacy threats.

Privacy risks characterization Robots can go places humans cannot go, see things humans cannot see, and do things humans cannot do. These characteristics have made the robots very useful in some domains like space exploration, rescue missions, hazardous materials manipulation, etc. where use of humans could be dangerous and life threatening. The entertainment robots/gadgets sometimes come with built-in cameras, microphones and speakers, which could be controlled using a remote either hand held or audio command based. Some of the online cyber attackers get control of the mobile Wi-Fi robot toys that kids are using and could pose a risk to families with children. For example, the Wall Street Journal reported that after an investigation into Cayla doll,1 Germany’s Federal Network has issued an order for all parents to find the doll and destroy her. Parents who ignore the order to destroy Cayla could face a fine of up to €25,000 and up to 2 years in prison. On its website, the agency posted a template for a destruction certificate that should be filled in, signed by a waste-management company, and sent to the agency as proof of destruction. Cayla doll is just an example.

Chapter 3-Approach/ Methodology

Before the analysis of any risks and threats, we have an urge to model the scenarios that may define or develop to be a part of cybersecurity for robots. This paper will attempt to execute a generalized research, hence avoiding any particular scenario. This approach and methodology will be divided into multiple layers, that is pictorially represented in Fig 1.

The origin of any threat can be fragmented into 3 main buckets:

a. Accident – An accepted scenario where there are no perfect situations created in the laboratories. This means that planning for such situations is close to impossible. This may include the risk of third party APK malfunction, logic developed by open source developers, etc.

b. Natural – A natural disaster that may compromise the physical integrity of the robot. This may cause partial damage, degraded performance, unexpected behavior, disruption of components, etc.

c. External – Attacks that can be attempted by external users. This can include altering control parameters, tampering logic in production, tampering calibration parameters, altering signals generated by the robots for control, etc.

These elements need to be vetted and planned for, before deploying into a physical environment.

Software flaws, intentional or unintentional can be presented into the following categories:

a. Software flaws

b. Security malfunction

c. Feature misuse

While these risks cannot be avoided totally, there are several approaches to cope with these threats. This will be briefly explained in the next section.

Integrity

Confidentiality

Privacy

Availabilitydent

Safetydent

Internal and external users

Disruption

Degradation

Destructiondent

Physical & Cyber

cyber

Cyber

Physical

Natural

Attack

Accident

Risk

Impact

Target

Origin

Chapter 4 – Analysis

While there are always several actors involved in implementation of these systems (namely - final users, business users, robot vendors, independent developers) the impact of each threat on different actor will differ.

A domestic user can be concerned about the economic impact of the damage or even physical damage that it may cause to a human. On the other hand, a business user will be concerned with the following:

a. Theft of intellectual property

b. Reputation amongst the public.

c. Regulatory problems, sometimes involving legal actions.

To avoid or prepare for these threats, we need to analyze the methods of attacks in the cyber infrastructure. The following may be a list of the most common attacks (not a complete list):

a. Malware – A software that may be developed to cause damage to a single component or an entire network. This may or may not be structured. This includes worms, torjans and viruses. The attack may render the robot (software or hardware) inoperable or even grant the attacker root access, enabling them to control the network remotely.

b. Phishing – A method used by an attacker to fool the user into taking harmful actions. These actions may be as simple as reveling the passwords, usually an outcome of a successful phishing page.

c. Denial of Service (DOS) – Typically a brute force attack to stop the service from working entirely. This attack, when prolonged for a long time may cause severe damage to the repetition of the firm/ business involved

d. Man in the middle (MITM) – An attack involving the attacker to interpose secretly between the user and the service. A successful MITM attack may equip the attacker with sensitive information and relaying false information to the destination at the same time.

Common methods to avoid cyber attacks –

a. End point protection

b. Firewall

c. Access management

d. Data backup for rollbacks

e. Data Encryption

i. AES 256(Advanced Encryption Standard)

ii. RSA(Rivest-Shamir-Adleman)

iii. Triple DES

Chapter 5: Conclusions

This study has shed light on the security and safety risks caused by cyber attackers on robotic systems. The study has proposed taxonomy for the attack on service robots. The study has used the type of robots, type of users of the robot and the asset being compromised to create the taxonomy. In case of a virtual attack, assets of type data, information, confidentiality could be compromised and in case of physical attacks it can impose physical threats to the human or robots involved. This classification could be used while deciding on whether to purchase the robot or not for the service required and highlights the potential risks that the buyer could encounter. The study has considered the different types of sensors that are equipped by the service robots and the type of information they can gather during a cyber-attack. This info can be used to configure robots depending on their use and the type of user. The database of type of threats that have been faced in the past plays a major role in the risk modeling and thus helps to foresee and mitigate associated risks. Finally, the importance of mitigating these risks and taking measure during the development phase of the robot is highlighted, using standard protocols, algorithms, hardware and good practices are a key.

References

1. https://www.therobotreport.com/cyber-attacks-on-robots-a-real-threat-new-report-shows-ease-of-hacking/

2. https://www.researchgate.net/publication/321638514_Cybersecurity_of_Robotics_and_Autonomous_Systems_Privacy_and_Safety

3. https://www.csoonline.com/article/3237324/what-is-a-cyber-attack-recent-examples-show-disturbing-trends.html

4. https://capcoverage.com/index.php/10-ways-to-prevent-cyber-attacks/

5. https://leaf-it.com/10-ways-prevent-cyber-attacks/

6. https://www.getapp.com/resources/common-encryption-methods/

7. Calo RM. Robots and privacy. In: Bekey P, Abney G, Lin K, editor. Robot Ethics: The Ethical and Social Implications of Robotics. Boston: MIT Press; 2011

8. Humayed A, Lin J, Li F, Luo B. Cyber-Physical Systems Security - A Survey [Internet]. 2017. arXiv preprint. arXiv:1701.04525

2