Any security professional would recommend that you lock down your home or facility with a video monitoring system. Likewise, they would likely point out that protecting your online network with a firewall is common sense. But what about the other computerized, connected devices that are often overlooked? With technology playing a part in almost everything we do these days, security threats are now looming in places that we may not suspect at all. Anything with a computer brain and connectivity, whether via the internet or bluetooth, runs the risk of vulnerability to a cyber attack. This could be anything from a factory machine to an Amazon Echo. While the consequences of such an attack vary in degrees of severity depending on the nature of the device, one thing is certain: as cyber attacks become a bigger threat, tech manufacturers and users must demonstrate greater caution and vigilance in order to avoid them.
Interestingly, researchers have recently identified robotics as a developing field with a plethora of vulnerabilities to cyber attack. Security firm IOActive recently conducted a study intended to analyze the security vulnerabilities in a variety of products that rely on robotics technology. In the study, IOActive examined 10 robots with diverse purposes ranging from factory assembly to home entertainment. Results revealed several recurring security vulnerabilities, including unprotected communications, no authorisations and gutless cryptography.
So, why all the security lapses in robotics? What could happen? What can be done to protect robots from cyber attack?
Let’s start with the first question.
Why all the security lapses?
For one thing, many robotics developers rely on widely used open source codes. While shared codes can be advantageous when used in a secure environment, in many instances in robotics, open source codes are being shared between developers without adequate regard for security. According to ITProPortal contributor Kayla Matthews, this kind of code-sharing culture in robotics development could lead to vulnerable and compromised codes being shared in much the same way a virus spreads among humans.
What could happen?
As was previously stated, the nature of the device in question is a major factor in determining the nature of the consequences of an attack. But, just to illustrate the kind of disastrous results that could loom, image you are the owner of a factory that uses a robotic machine to assemble parts for a product. You have employees on the floor with the machine, operating the computer and working virtually arm in arm with the machine to ensure that the product is assembled correctly. Now think of the physical safety concerns that could arise in the factory as a result of the machine being hacked by an outside source.
Recently, The German Federal Agency Network issued a warning to parents regarding security concerns with Genesis Toy’s My Friend Cayla doll. The report indicated that the doll’s insecure bluetooth feature could be used as a channel through which hackers could listen to children talk, and even talk back to them. The use of a bluetooth-enabled doll as a surveillance device unavoidably elicits concerns about any insecure computerized product with a microphone or camera.
Now consider that some of the most sensitive information in your life, including information regarding your finances, personal identity, business/work dealings, medical information and even GPS location, is in some way connected to a computerized device, which may or may not rely on robotics technology. With this kind of information potentially on the line, consequences of a cyber attack on a device with sub-par security measures threaten to be catastrophic.
So to sum it up, whether you’re dealing with a high-tech setup with a hybrid cloud system and the likes or a simple toy with bluetooth capabilities, never count out the possibility of a cyber attack.
What can be done to protect robots from cyber attack?
The answer to this question is two-fold. First, developers must tighten up on security measures. One obvious way to do this would be to treat computer codes used to develop robotics products with greater care. Additionally, industry publications have pointed out that incorporating a tool called Secure Software Development Life Cycle (SSDLC) the development process could greatly lessen the risk cyber attack. SSDLC would essentially mitigate some of the security concerns that we are currently facing today from the very start.
Outside of what can be done to create safer devices, there are several ways that users can protect themselves. Consumers can avoid purchasing vulnerable devices by simply researching the security liabilities of devices before purchase. Additionally, experts say that changing passwords and updating software are both ways to make it more difficult to hack into their devices. Finally, users should take a look at the settings on their device. Sometimes the default settings are not the best for security. For example, if it is not necessary to have the device connected to the internet, disconnecting it could be one way of amping up security.