Security Considerations on Three CPSs in Evolution: ROS, SCADA and OPC UA
Ivan Cibrario Bertolotti, Flavio LombardiOver the last few years, cyber-physical systems (CPSs) have come to play a central role in critical infrastructures, manufacturing, transport, and robotics. As a consequence, their lack of security increasingly affects the physical world, possibly causing material damage, environmental harm, and even loss of life. This paper reviews the evolution of CPSs over the last decade and highlights their main security issues and remedies. Some particularly relevant software infrastructures and communication protocols are analyzed in detail, such as the Robot Operating System (ROS), Supervisory Control and Data Acquisition (SCADA), and OPC Unified Architecture (OPC UA). The most important vulnerabilities are described, for instance, the ones affecting the Data Distribution Service (DDS) of ROS version 2, as well as the extent of insecure ROS and OPC UA deployment on the Internet. Moreover, the role and impact of Artificial Intelligence (AI) as an offensive and defensive tool is also discussed. Finally, we argue that the transition towards memory-safe and verifiable programming languages, such as Rust, and the use of model-based design (MBD) methods and tools might help prevent entire classes of attacks in the future.