Metasploit for Cyber-Physical Security Testing with Real-Time Constraints

被引:1
|
作者
Shrestha, Sulav Lal [1 ]
Lee, Taylor [1 ]
Fischmeister, Sebastian [1 ]
机构
[1] Univ Waterloo, Waterloo, ON, Canada
来源
SCIENCE OF CYBER SECURITY, SCISEC 2022 | 2022年 / 13580卷
关键词
Cyber-physical systems; Security; Controller area network;
D O I
10.1007/978-3-031-17551-0_17
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Metasploit is a framework for cybersecurity testing. The Metasploit Framework provides the Hardware Bridge API to enable security testing of cyber-physical systems. Cyber-physical systems and tests/attacks on the systems are subject to real-time constraints. Hence, this research aims to study the timing characteristics of tests implemented using the framework. Several factors, such as the programming language used to write tests, overhead added by the framework, scheduling policies etc., affect the latency and jitter. This paper considers the Controller Area Network used in automotive systems to study the effect of those factors on the timing characteristics. The study evaluates (i) latency and jitter for transmission and reception of the messages in the network and (ii) the jitter in the periodicity in periodic transmission of messages. Based on the results, the study determines the best combination of the factors to minimize the latency and jitter in the tasks considered. The paper performs a case study on actual tests/attacks subject to real-time constraints and analyses the suitability of executing the tests using Metasploit. The study analyses the performance of tasks implemented as Metasploit modules and shows how choices of some factors can significantly improve the temporal characteristics without modifying the Metasploit Framework. The experimental results show some interesting findings related to Ruby and the Metasploit Framework.
引用
收藏
页码:260 / 275
页数:16
相关论文
共 50 条
  • [41] Introduction to the Special Issue on Real-Time, Embedded and Cyber-Physical Systems
    Chang, Li-Pin
    Kuo, Tei-Wei
    Gill, Chris
    Nakazawa, Jin
    ACM TRANSACTIONS ON EMBEDDED COMPUTING SYSTEMS, 2014, 13
  • [42] Decentralized Real-Time Safety Verification for Distributed Cyber-Physical Systems
    Hoang-Dung Tran
    Luan Viet Nguyen
    Musau, Patrick
    Xiang, Weiming
    Johnson, Taylor T.
    FORMAL TECHNIQUES FOR DISTRIBUTED OBJECTS, COMPONENTS, AND SYSTEMS (FORTE 2019), 2019, 11535 : 261 - 277
  • [43] A PERSONALIZED CYBER-PHYSICAL LABORATORY FOR A REAL-TIME SYSTEMS INTERFACING COURSE
    Kinsner, Witold
    Li, Hongru
    Reid, Siobhan
    Vu, Vinh
    Zhou, Zhou
    Lambeta, Michael
    Shevchenko, Oleg
    Kolansky, Glen
    2021 IEEE CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING (CCECE), 2021,
  • [44] Design Procedure for Real-Time Cyber-Physical Systems Tolerant to Cyberattacks
    Paredes, Carlos M.
    Castro, Diego Martinez
    Potes, Apolinar Gonzalez
    Piedrahita, Andres Rey
    Junquera, Vrani Ibarra
    SYMMETRY-BASEL, 2024, 16 (06):
  • [45] Self-reconfiguration of real-time communication in cyber-physical systems
    Jatzkowski, Jan
    Kleinjohann, Bernd
    MECHATRONICS, 2016, 34 : 72 - 77
  • [46] Correction: Real-time detection of deception attacks in cyber-physical systems
    Feiyang Cai
    Xenofon Koutsoukos
    International Journal of Information Security, 2023, 22 : 1383 - 1383
  • [47] Real-time Simulation of Electric Vehicle Powertrain: Hardware-in-the-Loop (HIL) Testbed for Cyber-Physical Security
    Yang, Bowen
    Guo, Lulu
    Ye, Jin
    2020 IEEE TRANSPORTATION ELECTRIFICATION CONFERENCE & EXPO (ITEC), 2020, : 63 - 68
  • [48] A real-time cyber modeling approach in MTConnect-based cyber-physical production environment
    Kang, Hyoung Seok
    Lee, Ju Yeon
    51ST CIRP CONFERENCE ON MANUFACTURING SYSTEMS, 2018, 72 : 462 - 467
  • [49] Distributed Architecture for Real-Time Cyber-Physical System, Time-Sensitive Networks
    Kovacshazy, Tamas
    2018 19TH INTERNATIONAL CARPATHIAN CONTROL CONFERENCE (ICCC), 2018,
  • [50] MegaSense: Cyber-Physical System for Real-time Urban Air Quality Monitoring
    Rebeiro-Hargrave, Andrew
    Motlagh, Naser Hossein
    Varjonen, Samu
    Lagerspetz, Eemil
    Nurmi, Petteri
    Tarkoma, Sasu
    PROCEEDINGS OF THE 15TH IEEE CONFERENCE ON INDUSTRIAL ELECTRONICS AND APPLICATIONS (ICIEA 2020), 2020, : 1 - 6