Metasploit for Cyber-Physical Security Testing with Real-Time Constraints

被引:1
|
作者
Shrestha, Sulav Lal [1 ]
Lee, Taylor [1 ]
Fischmeister, Sebastian [1 ]
机构
[1] Univ Waterloo, Waterloo, ON, Canada
来源
关键词
Cyber-physical systems; Security; Controller area network;
D O I
10.1007/978-3-031-17551-0_17
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Metasploit is a framework for cybersecurity testing. The Metasploit Framework provides the Hardware Bridge API to enable security testing of cyber-physical systems. Cyber-physical systems and tests/attacks on the systems are subject to real-time constraints. Hence, this research aims to study the timing characteristics of tests implemented using the framework. Several factors, such as the programming language used to write tests, overhead added by the framework, scheduling policies etc., affect the latency and jitter. This paper considers the Controller Area Network used in automotive systems to study the effect of those factors on the timing characteristics. The study evaluates (i) latency and jitter for transmission and reception of the messages in the network and (ii) the jitter in the periodicity in periodic transmission of messages. Based on the results, the study determines the best combination of the factors to minimize the latency and jitter in the tasks considered. The paper performs a case study on actual tests/attacks subject to real-time constraints and analyses the suitability of executing the tests using Metasploit. The study analyses the performance of tasks implemented as Metasploit modules and shows how choices of some factors can significantly improve the temporal characteristics without modifying the Metasploit Framework. The experimental results show some interesting findings related to Ruby and the Metasploit Framework.
引用
收藏
页码:260 / 275
页数:16
相关论文
共 50 条
  • [21] A Real-time Cyber-Physical System for Indoor Environment Monitoring
    Mi, Weihong
    Zhou, Nanshu
    Jin, Yaohui
    2016 INTERNATIONAL CONFERENCE ON MANUFACTURING SCIENCE AND INFORMATION ENGINEERING (ICMSIE 2016), 2016, : 379 - 385
  • [22] Real-time detection of deception attacks in cyber-physical systems
    Feiyang Cai
    Xenofon Koutsoukos
    International Journal of Information Security, 2023, 22 : 1099 - 1114
  • [23] Real-Time Temperature Field State Observer and Digital Replica to Support Cyber-Physical Testing
    Salmeron, M.
    Montoya, H.
    Silva, C. E.
    Dyke, S. J.
    EXPERIMENTAL TECHNIQUES, 2024,
  • [24] Seamless validation of cyber-physical systems under real-time conditions by using a cyber-physical laboratory test field
    Jacobitz, Sven
    Gollner, Marian
    Zhang, Jie
    Yarom, Or Aviv
    Liu-Henke, Xiaobo
    IEEE INTERNATIONAL CONFERENCE ON RECENT ADVANCES IN SYSTEMS SCIENCE AND ENGINEERING (IEEE RASSE 2021), 2021,
  • [25] Integrating Cyber-Attack Defense Techniques into Real-Time Cyber-Physical Systems
    Hao, Xiaochen
    Lv, Mingsong
    Zheng, Jiesheng
    Zhang, Zhengkui
    Yi, Wang
    2019 IEEE 37TH INTERNATIONAL CONFERENCE ON COMPUTER DESIGN (ICCD 2019), 2019, : 237 - 245
  • [26] Real-time cyber/physical interplay in scheduling for peak load optimisation in Cyber-Physical Energy Systems
    De Martini, Daniele
    Benetti, Guido
    Facchinetti, Tullio
    INTELLIGENT SYSTEMS WITH APPLICATIONS, 2024, 22
  • [27] Predictable Application Mapping for Manycore Real-Time and Cyber-Physical Systems
    Kanduri, Anil
    Rahmani, Amir-Mohammad
    Liljeberg, Pasi
    Tenhunen, Hannu
    2015 IEEE 9TH INTERNATIONAL SYMPOSIUM ON EMBEDDED MULTICORE/MANYCORE SYSTEMS-ON-CHIP (MCSOC), 2015, : 135 - 142
  • [28] Cyber-physical structural optimization using real-time hybrid simulation
    Zhang, Ruiyang
    Phillips, Brian M.
    Fernandez-Caban, Pedro L.
    Masters, Forrest J.
    ENGINEERING STRUCTURES, 2019, 195 : 113 - 124
  • [29] Real-Time Cyber-Physical Systems Transatlantic Engineering Curricula Framework
    Grega, Wojciech
    Kornecki, Andrew J.
    PROCEEDINGS OF THE 2015 FEDERATED CONFERENCE ON COMPUTER SCIENCE AND INFORMATION SYSTEMS, 2015, 5 : 755 - 762
  • [30] Dependable Scheduling for Real-Time Workflows on Cyber-Physical Cloud Systems
    Zhou, Junlong
    Sun, Jin
    Zhang, Mingyue
    Ma, Yue
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2021, 17 (11) : 7820 - 7829