Designing security for robots

Robots are becoming more affordable and practical for everyday solutions, but the need for robust security is also important, according to security firm IOActive.

04/18/2017


There is no doubt robots are becoming more commonplace. After all, they will soon become a less expensive human replacement in conducting the more mundane aspects of the workplace.

While the manufacturing automation sector is experiencing growth in robot usage, what happens when their software and firmware end up affected by security vulnerabilities?

As electronic devices become smarter and the cost of cutting-edge technology decreases, we increasingly look to machines to help meet human needs, save lives, entertain, teach, and cure. That means the robot becomes an affordable and practical solution for today's business and personal needs, according to analysis conducted by security firm IOActive.

The evidence of robots going mainstream is compelling as large investments continue in the public and private sectors:

  • Reports forecast worldwide spending on robotics will reach $188 billion in 2020
  • South Korea is planning to invest $450 million in robotic technology over the next five years
  • Reports estimate venture capital investments reached $587 million in 20155 and $1.95 billion in 2016
  • SoftBank recently received $236 million from Alibaba and Foxconn for its robotics division
  • UBTECH Robotics raised $120 million in the past two years
  • Factories and businesses in the U.S. added 10% more robots in 2016 than in the previous year.

Along those lines, IOActive researchers analyzed home, industrial and business robots from six different vendors. The researchers conducted tests on their mobile applications, software and firmware. IOActive identified nearly 50 vulnerabilities in the tested components, but researchers said they did not conduct an in-depth analysis, which suggests the actual number of weaknesses could be higher.

The company published a paper providing a non-technical description of the vulnerabilities. Technical details will be available after vendors have had a chance to address the flaws. IOActive said the robots it reviewed suffer from vulnerabilities, including problems related to communications, authentication, authorization mechanisms, cryptography, privacy, default configurations, and open source components.

The flaws allow attackers to intercept communications between the robot and the application controlling it, remotely access critical services without a username and password, install malicious software, and extract sensitive information not encrypted properly. The vulnerabilities can end up being leveraged for spying via the robot's camera and microphone, steal personal or business data, and even take control of the machine and cause physical damage or harm.

Robots are already showing up in thousands of homes and businesses. All signs indicate robots will soon be everywhere, as toys for children, companions for the elderly, customer assistants at stores, and healthcare attendants. Robots will fill a dizzying array of service roles, as home and business assistants, manufacturing workers, and security and law enforcement.

As many of these "smart" machines have a self-propelled component, it is important they are secure, well protected, and not easy to hack. If not, instead of helpful resources they could quickly become dangerous tools capable of wreaking havoc and causing substantive harm to their surroundings and the humans they're designed to serve.

Gregory Hale is the editor and founder of Industrial Safety and Security Source (ISSSource.com), a news and information Website covering safety and security issues in the manufacturing automation sector. This content originally appeared on ISSSource.com. ISSSource is a CFE Media content partner. Edited by Chris Vavra, CFE Media, cvavra@cfemedia.com.

ONLINE extra

See related stories from ISSSourced linked below.



Top Plant
The Top Plant program honors outstanding manufacturing facilities in North America. View the 2017 Top Plant.
Product of the Year
The Product of the Year program recognizes products newly released in the manufacturing industries.
System Integrator of the Year
Each year, a panel of Control Engineering and Plant Engineering editors and industry expert judges select the System Integrator of the Year Award winners in three categories.
February 2018
2017 Product of the Year winners, retrofitting a press, IMTS and Hannover Messe preview, natural refrigerants, testing steam traps
March 2018
SCCR, 2018 Maintenance study, and VFDs in a washdown environment.
Jan/Feb 2018
Welding ergonomics, 2017 Salary Survey, and surge protection
April 2018
ROVs, rigs, and the real time; wellsite valve manifolds; AI on a chip; analytics use for pipelines
February 2018
Focus on power systems, process safety, electrical and power systems, edge computing in the oil & gas industry
December 2017
Product of the Year winners, Pattern recognition, Engineering analytics, Revitalize older pump installations
April 2018
Implementing a DCS, stepper motors, intelligent motion control, remote monitoring of irrigation systems
February 2018
Setting internal automation standards
December 2017
PID controllers, Solar-powered SCADA, Using 80 GHz radar sensors

Annual Salary Survey

Before the calendar turned, 2016 already had the makings of a pivotal year for manufacturing, and for the world.

There were the big events for the year, including the United States as Partner Country at Hannover Messe in April and the 2016 International Manufacturing Technology Show in Chicago in September. There's also the matter of the U.S. presidential elections in November, which promise to shape policy in manufacturing for years to come.

But the year started with global economic turmoil, as a slowdown in Chinese manufacturing triggered a worldwide stock hiccup that sent values plummeting. The continued plunge in world oil prices has resulted in a slowdown in exploration and, by extension, the manufacture of exploration equipment.

Read more: 2015 Salary Survey

The Maintenance and Reliability Coach's blog
Maintenance and reliability tips and best practices from the maintenance and reliability coaches at Allied Reliability Group.
One Voice for Manufacturing
The One Voice for Manufacturing blog reports on federal public policy issues impacting the manufacturing sector. One Voice is a joint effort by the National Tooling and Machining...
The Maintenance and Reliability Professionals Blog
The Society for Maintenance and Reliability Professionals an organization devoted...
Machine Safety
Join this ongoing discussion of machine guarding topics, including solutions assessments, regulatory compliance, gap analysis...
Research Analyst Blog
IMS Research, recently acquired by IHS Inc., is a leading independent supplier of market research and consultancy to the global electronics industry.
Marshall on Maintenance
Maintenance is not optional in manufacturing. It’s a profit center, driving productivity and uptime while reducing overall repair costs.
Lachance on CMMS
The Lachance on CMMS blog is about current maintenance topics. Blogger Paul Lachance is president and chief technology officer for Smartware Group.
Maintenance & Safety
The maintenance journey has been a long, slow trek for most manufacturers and has gone from preventive maintenance to predictive maintenance.
Industrial Analytics
This digital report explains how plant engineers and subject matter experts (SME) need support for time series data and its many challenges.
IIoT: Operations & IT
This digital report will explore several aspects of how IIoT will transform manufacturing in the coming years.
Randy Steele
Maintenance Manager; California Oils Corp.
Matthew J. Woo, PE, RCDD, LEED AP BD+C
Associate, Electrical Engineering; Wood Harbinger
Randy Oliver
Control Systems Engineer; Robert Bosch Corp.
Data Centers: Impacts of Climate and Cooling Technology
This course focuses on climate analysis, appropriateness of cooling system selection, and combining cooling systems.
Safety First: Arc Flash 101
This course will help identify and reveal electrical hazards and identify the solutions to implementing and maintaining a safe work environment.
Critical Power: Hospital Electrical Systems
This course explains how maintaining power and communication systems through emergency power-generation systems is critical.
click me