On the (In)Security of Secure ROS2
Gelei Deng, Guowen Xu, Yuan Zhou, Tianwei Zhang, Yang Liu
摘要
Robot Operating System (ROS) has been the mainstream platform for research and development of robotic applications. This platform is well-known for lacking security features and efficiency for distributed robotic computations. To address these issues, ROS2 is recently developed by utilizing the Data Distribution Service (DDS) to provide security support. Integrated with DDS, ROS2 is expected to establish the basis for trustworthy robotic ecosystems. In this paper, we systematically study the security of the current ROS2 implementation from three perspectives. By abstracting the key functions from the ROS2 native implementation, we first formally describe the ROS2 system communication workflow and model it using a concurrent modeling language. Second, we verify the model with some key security properties through a model checker, and successfully identify four security vulnerabilities in ROS2's native security module: Secure ROS2 (SROS2). To validate these flaws, we set up simulation and physical multi-robot testbeds running different real-world workloads developed by Open Robotics and Amazon AWS Robotics. We demonstrate that an adversary can exploit these vulnerabilities to totally invalidate the security protection offered by SROS2, and obtain unauthorized permissions or steal critical information. Third, to enhance the security of ROS2, we propose a general defense solution based on the private broadcast encryption scheme. We run different workloads and benchmarks to show the efficiency and security of our defense. Our findings have been acknowledge by ROS2 official, and the suggested mitigation has been implemented in the latest SROS2 version.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Detecting Temporal Misalignment Attacks in Multimodal Fusion for Autonomous DrivingMd Hasan Shahriar, Md Mohaimin Al Barat, Harshavardhan Sundar, Ning Zhang 等ICLR 2026
- Decentralized Information-Flow Control for ROS2Nishit V. Pandya, Himanshu Kumar, Gokulnath Pillai, Vinod GanapathyNDSS 2024
它引用的顶会 Paper6
- FAME: Fast Attribute-based Message EncryptionShashank Agrawal, Melissa ChaseCCS 2017 · 被引用 243 次
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 被引用 225 次
- Exposing Congestion Attack on Emerging Connected Vehicle based Traffic Signal ControlQi Alfred Chen, Yucheng Yin, Yiheng Feng, Z. Morley Mao 等NDSS 2018 · 被引用 107 次
- Breaking the Decisional Diffie-Hellman Problem for Class Group Actions Using Genus TheoryWouter Castryck, Jana Sotáková, Frederik VercauterenCRYPTO 2020 · 被引用 29 次
- Automated Discovery of Denial-of-Service Vulnerabilities in Connected Vehicle ProtocolsShengtuo Hu, Qi Alfred Chen, Jiachen Sun, Yiheng Feng 等USENIX Security 2021 · 被引用 18 次
相关 Paper
- An Analytical Latency Model of the Data Distribution Service in ROS 2Hyungseok Park, Sanghoon Lee, Doosik Um, Hyunho Ryu 等INFOCOM 2025 · 被引用 3 次
- Response time analysis for dynamic priority scheduling in ROS2Abdullah Al Arafat, Sudharsan Vaidhun, Kurt M. Wilson, Jinghao Sun 等DAC 2022 · 被引用 38 次
- Enhancing ROS System Fuzzing through Callback TracingYuheng Shen, Jianzhong Liu, Yiru Xu, Hao Sun 等ISSTA 2024 · 被引用 7 次
- Modeling and Analysis of Inter-Process Communication Delay in ROS 2Xiantong Luo, Xu Jiang, Nan Guan, Haochun Liang 等RTSS 2023 · 被引用 10 次
- Multi-Dimensional and Message-Guided Fuzzing for Robotic Programs in Robot Operating SystemJia-Ju Bai, Haoxuan Song, Shimin HuASPLOS 2024 · 被引用 6 次
