In the Star Wars universe, there is a light side and a dark side (also, just like duct tape). This duality can be represented in almost any area of technology – things designed to be good for humanity can also be turned bad by different people. Time and again, we’ve seen cyberattacks, security breaches and shutdowns caused by people exploiting systems that were designed initially to help people.
The Internet was built with a promise of unlimited information available at everyone’s fingertips, a truly egalitarian and noble concept. But along with the good it continues to provide, the Internet spawned dangers such as the dark web, spam, phishing, fake news and disinformation that spreads via social media and other sites.
The Internet was built with a promise of unlimited information available at everyone’s fingertips, a truly egalitarian and noble concept. But along with the good it continues to provide, the Internet spawned dangers such as the dark web, spam, phishing, fake news and disinformation that spreads via social media and other sites.
Robotics is not immune to this moral ambiguity. In several cases, we’ve seen this technology used to disrupt air travel, such as the use of drones at Gatwick Airport a few years ago and other more sinister threats. Reports of automotive hacking aside, a high-profile incident is likely a matter of when, not if.
Traditionally, many robot deployments in factories have been disconnected from the Internet. But this often provides a false sense of security. The outdated thinking is that isolation is sufficient to keep threats away, but this discounts evidence that many cyberattacks work through someone on the inside – either a disgruntled employee or someone inadvertently enabling outside access through social engineering. We have seen organizations with the highest security needs embrace the cloud, and also use it to improve security through best practices. This is known as DevSecOps.
Many of the mobile robots being deployed in warehouses and other locations today rely on Wi-Fi or LTE networking in order to operate and report data back to a centralized service. Making sure these networks are secure usually requires collaboration between the robotics maker and an enterprise IT team. Security practices of today’s cloud vendors in many ways offer superior protection of critical data than even pure on-premise solutions.
Security and safety threats in robotics are dual concerns that are often intertwined. While safety is concerned with limiting potential physical or economic harm to others, security is primarily concerned with protecting the robot from unauthorized use, it is easy to see how unauthorized use could lead to personal or property damage.
This was a recent discussion topic at a meeting of the Robot Operations Group, where security expert (and white hat hacker) Aaron Turner spoke to the members about how technologies that are aimed to help people can be turned into weapons under the right circumstances.
“There’s a whole wide range of things that can go wrong in the computing world that you need to think about,” said Turner. “You need to find someone who has been raked through the coals … who can do threat modeling for you. Thinking about the worst case scenario for your robot can help you make a plan to secure that scenario from ever occurring.”
Some key takeaways:
As operations experts, we at InOrbit understand the security and safety concerns that customers have about cloud-based software and robotics. Strong security considerations are an integral part of effective RobOps, and as part of that we help bring DevSecOps best practices to robotics. That's why we designed the InOrbit architecture from the ground up with security as a top priority. Some security measures include, but are not limited to:*
We believe that the job of securing a robotics deployment is everyone’s responsibility, which is why we are happy to discuss our security position with robot developers and people interested in deploying robots within their enterprise.
At InOrbit we’re committed to continue providing reliably secure RobOps tools and services and driving awareness around best practices for the rapidly growing robotics market.
*More details are available in our Technical Brief on InOrbit End-to-End Security.