Automated Flaw Detection for Industrial Robot RESTful Service


연구 분야: Safety



학회: International Conference on Verification, Model Checking, and Abstract Interpretation


초록

As industrial robots become an integral part of Industry 4.0 in the manufacturing sector, their interconnection and interoperability introduce significant security challenges. RESTful Web services have emerged as the preferred method for network communication due to their simplicity and ease of use. However, the effective detection of security flaws in RESTful services for industrial robots still faces three key challenges: high-quality test case generation, high-throughput testing, and anomaly detection. Unlike traditional applications deployed within cloud services, limited computational resources, unique controller states, and unclear API specifications in robots further complicate the resolution of these challenges. Consequently, a large number of security flaws persist in real and deployed devices, with some flaws even posing the risk of physical damage. To address these challenges, we propose a novel testing technique named ROBREST specifically designed for emerging RESTful services in the context of robotic systems. In test case generation, ROBREST analyzes description fields extracted from the OpenAPI specification, ensuring the generation of high-quality test cases. During abnormality observation, ROBREST combines both cyber and physical space states to identify anomalies in the target service. Additionally, ROBREST automatically customizes each testing request to the service, minimizing resource usage within the robot controller and bypassing the quantity restrictions present in the controller. Applying ROBREST to industrial robots, we identified a total of 19 system flaws (4 vulnerabilities and 15 bugs), and 2 of them have been assigned CVE IDs. Exploiting them can affect a multitude of industrial robots in the physical world.


Author Profile
Yuncheng Wang

Beijing Key Laboratory of IOT Information Security Technology Institute of Information Engineering Chinese Academy of Sciences Beijing China

British Indian Ocean Territory
Author Profile
Puzhuo Liu

School of Cyber Security University of Chinese Academy of Sciences Beijing China

China
Author Profile
Yaowen Zheng

Tsinghua University Beijing China

China

📄 논문 정보

발행 연도 2025년
인용수 0
출판 국가 British Indian Ocean Territory, China
사이트 Springer
좋아요 수 0

연관 논문 목록 (410건)