Metasploit for Cyber-Physical Security Testing with Real-Time Constraints

被引:1
|
作者
Shrestha, Sulav Lal [1 ]
Lee, Taylor [1 ]
Fischmeister, Sebastian [1 ]
机构
[1] Univ Waterloo, Waterloo, ON, Canada
来源
SCIENCE OF CYBER SECURITY, SCISEC 2022 | 2022年 / 13580卷
关键词
Cyber-physical systems; Security; Controller area network;
D O I
10.1007/978-3-031-17551-0_17
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Metasploit is a framework for cybersecurity testing. The Metasploit Framework provides the Hardware Bridge API to enable security testing of cyber-physical systems. Cyber-physical systems and tests/attacks on the systems are subject to real-time constraints. Hence, this research aims to study the timing characteristics of tests implemented using the framework. Several factors, such as the programming language used to write tests, overhead added by the framework, scheduling policies etc., affect the latency and jitter. This paper considers the Controller Area Network used in automotive systems to study the effect of those factors on the timing characteristics. The study evaluates (i) latency and jitter for transmission and reception of the messages in the network and (ii) the jitter in the periodicity in periodic transmission of messages. Based on the results, the study determines the best combination of the factors to minimize the latency and jitter in the tasks considered. The paper performs a case study on actual tests/attacks subject to real-time constraints and analyses the suitability of executing the tests using Metasploit. The study analyses the performance of tasks implemented as Metasploit modules and shows how choices of some factors can significantly improve the temporal characteristics without modifying the Metasploit Framework. The experimental results show some interesting findings related to Ruby and the Metasploit Framework.
引用
收藏
页码:260 / 275
页数:16
相关论文
共 50 条
  • [1] Secure Reboots for Real-Time Cyber-Physical Systems
    Banerjee, Vijay
    Hounsinou, Sena
    Olufowobi, Habeeb
    Hasan, Monowar
    Bloom, Gedare
    PROCEEDINGS OF THE 4TH WORKSHOP ON CPS & IOT SECURITY AND PRIVACY, CPSIOTSEC 2022, 2022, : 27 - 33
  • [2] Using Soft Real-Time Simulation in a Hybrid Environment for Cyber-Physical Security Experiments
    Genge, Bela
    Siaterlis, Christos
    2011 20TH IEEE INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES (WETICE), 2011, : 285 - 290
  • [3] Distributed Real-Time Software for Cyber-Physical Systems
    Eidson, John C.
    Lee, Edward A.
    Matic, Slobodan
    Seshia, Sanjit A.
    Zou, Jia
    PROCEEDINGS OF THE IEEE, 2012, 100 (01) : 45 - 59
  • [4] Design Procedure for Real-Time Cyber-Physical Systems Tolerant to Cyberattacks
    Paredes, Carlos M.
    Castro, Diego Martinez
    Potes, Apolinar Gonzalez
    Piedrahita, Andres Rey
    Junquera, Vrani Ibarra
    SYMMETRY-BASEL, 2024, 16 (06):
  • [5] Decentralized Real-Time Anomaly Detection in Cyber-Physical Production Systems under Industry Constraints
    Goetz, Christian
    Humm, Bernhard
    SENSORS, 2023, 23 (09)
  • [6] Real-Time Data Retrieval in Cyber-Physical Systems with Temporal Validity and Data Availability Constraints
    Fu, Chenchen
    Liu, Qiangqiang
    Wu, Peng
    Li, Minming
    Xue, Chun Jason
    Zhao, Yingchao
    Hu, Jingtong
    Han, Song
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2019, 31 (09) : 1779 - 1793
  • [7] Real-time detection of deception attacks in cyber-physical systems
    Feiyang Cai
    Xenofon Koutsoukos
    International Journal of Information Security, 2023, 22 : 1099 - 1114
  • [8] Real-time detection of deception attacks in cyber-physical systems
    Cai, Feiyang
    Koutsoukos, Xenofon
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 22 (05) : 1099 - 1114
  • [9] Seamless validation of cyber-physical systems under real-time conditions by using a cyber-physical laboratory test field
    Jacobitz, Sven
    Gollner, Marian
    Zhang, Jie
    Yarom, Or Aviv
    Liu-Henke, Xiaobo
    IEEE INTERNATIONAL CONFERENCE ON RECENT ADVANCES IN SYSTEMS SCIENCE AND ENGINEERING (IEEE RASSE 2021), 2021,
  • [10] Real-Time Attack-Recovery for Cyber-Physical Systems Using Linear Approximations
    Zhang, Lin
    Chen, Xin
    Kong, Fanxin
    Cardenas, Alvaro A.
    2020 IEEE 41ST REAL-TIME SYSTEMS SYMPOSIUM (RTSS), 2020, : 205 - 217