Metasploit for Cyber-Physical Security Testing with Real-Time Constraints

被引:1
作者
Shrestha, Sulav Lal [1 ]
Lee, Taylor [1 ]
Fischmeister, Sebastian [1 ]
机构
[1] Univ Waterloo, Waterloo, ON, Canada
来源
SCIENCE OF CYBER SECURITY, SCISEC 2022 | 2022年 / 13580卷
关键词
Cyber-physical systems; Security; Controller area network;
D O I
10.1007/978-3-031-17551-0_17
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Metasploit is a framework for cybersecurity testing. The Metasploit Framework provides the Hardware Bridge API to enable security testing of cyber-physical systems. Cyber-physical systems and tests/attacks on the systems are subject to real-time constraints. Hence, this research aims to study the timing characteristics of tests implemented using the framework. Several factors, such as the programming language used to write tests, overhead added by the framework, scheduling policies etc., affect the latency and jitter. This paper considers the Controller Area Network used in automotive systems to study the effect of those factors on the timing characteristics. The study evaluates (i) latency and jitter for transmission and reception of the messages in the network and (ii) the jitter in the periodicity in periodic transmission of messages. Based on the results, the study determines the best combination of the factors to minimize the latency and jitter in the tasks considered. The paper performs a case study on actual tests/attacks subject to real-time constraints and analyses the suitability of executing the tests using Metasploit. The study analyses the performance of tasks implemented as Metasploit modules and shows how choices of some factors can significantly improve the temporal characteristics without modifying the Metasploit Framework. The experimental results show some interesting findings related to Ruby and the Metasploit Framework.
引用
收藏
页码:260 / 275
页数:16
相关论文
共 50 条
  • [21] Methods for real-time simulation of Cyber-Physical Systems: application to automotive domain
    Faure, Cyril
    Ben Gaid, Mongi
    Pernet, Nicolas
    Fremovici, Morgan
    Font, Gregory
    Corde, Gilles
    2011 7TH INTERNATIONAL WIRELESS COMMUNICATIONS AND MOBILE COMPUTING CONFERENCE (IWCMC), 2011, : 1105 - 1110
  • [22] MegaSense: Cyber-Physical System for Real-time Urban Air Quality Monitoring
    Rebeiro-Hargrave, Andrew
    Motlagh, Naser Hossein
    Varjonen, Samu
    Lagerspetz, Eemil
    Nurmi, Petteri
    Tarkoma, Sasu
    PROCEEDINGS OF THE 15TH IEEE CONFERENCE ON INDUSTRIAL ELECTRONICS AND APPLICATIONS (ICIEA 2020), 2020, : 1 - 6
  • [23] Real-Time Misbehavior Detection and Mitigation in Cyber-Physical Systems Over WLANs
    Cao, Xianghui
    Liu, Lu
    Shen, Wenlong
    Laha, Aurobinda
    Tang, Jin
    Cheng, Yu
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2017, 13 (01) : 186 - 197
  • [24] Real-Time Task Scheduling for Machine Perception in Intelligent Cyber-Physical Systems
    Liu, Shengzhong
    Yao, Shuochao
    Fu, Xinzhe
    Shao, Huajie
    Tabish, Rohan
    Yu, Simon
    Bansal, Ayoosh
    Yun, Heechul
    Sha, Lui
    Abdelzaher, Tarek
    IEEE TRANSACTIONS ON COMPUTERS, 2021, 71 (08) : 1770 - 1783
  • [25] Real-Time Controller Reconfiguration for Delay-Resilient Cyber-Physical Systems
    Kim, Sangjun
    Lee, Sanghoon
    Park, Kyung-Joon
    IEEE ACCESS, 2022, 10 : 101220 - 101228
  • [26] Real-Time Adaptive Sensor Attack Detection in Autonomous Cyber-Physical Systems
    Akowuah, Francis
    Kong, Fanxin
    2021 IEEE 27TH REAL-TIME AND EMBEDDED TECHNOLOGY AND APPLICATIONS SYMPOSIUM (RTAS 2021), 2021, : 237 - 250
  • [27] Security in Cyber-Physical Systems
    Dsouza, Joanita
    Elezabeth, Laura
    Mishra, Ved Prakash
    Jain, Rachna
    PROCEEDINGS 2019 AMITY INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE (AICAI), 2019, : 840 - 844
  • [28] Cyber-physical systems security: A systematic review
    Harkat, Houda
    Camarinha-Matos, Luis M.
    Goes, Joao
    Ahmed, Hasmath F. T.
    COMPUTERS & INDUSTRIAL ENGINEERING, 2024, 188
  • [29] Designed-in Security for Cyber-Physical Systems
    Peisert, Sean
    Margulies, Jonathan
    Nicol, David M.
    Khurana, Himanshu
    Sawall, Chris
    IEEE SECURITY & PRIVACY, 2014, 12 (05) : 9 - 12
  • [30] Cyber-Physical Security of a Smart Grid Infrastructure
    Mo, Yilin
    Kim, Tiffany Hyun-Jin
    Brancik, Kenneth
    Dickinson, Dona
    Lee, Heejo
    Perrig, Adrian
    Sinopoli, Bruno
    PROCEEDINGS OF THE IEEE, 2012, 100 (01) : 195 - 209