攻击者通过恶意软件窃取机器人安全密钥,实现对自动驾驶系统的伪装控制。
Supply Chain Exploitation of Secure ROS 2 Systems: A Proof-of-Concept on Autonomous Platform Compromise via Keystore Exfiltration
- 在Debian包中植入木马,窃取ROS 2生成的安全密钥并通过DNS外传
- 利用窃取密钥可伪装成合法节点,成功注入伪造控制或感知消息
- 适用于所有使用SROS 2的机器人系统,适合安全研究人员参考
本文针对安全版ROS 2(SROS 2)框架提出一种供应链攻击的验证性案例,实验平台为Quanser QCar2自动驾驶车辆。恶意感染的Debian包修改核心ROS 2安全命令,将新生成的密钥库凭证以base64编码分块形式通过DNS发送至攻击者控制的域名服务器。获取这些凭证后,攻击者可作为已认证节点重新加入SROS 2网络,并发布未被识别的伪造控制或感知消息。我们在配置有Intel RealSense相机的SROS 2 Humble测试环境中验证该能力,执行四路口标志物导航任务。实验结果表明,控制主题注入可引发强制刹车、持续高速加速及循环转向;感知主题欺骗可制造虚假停车标志或屏蔽真实检测。该攻击可推广至任何基于DDS且使用SROS 2的机器人系统,凸显了保障供应链完整性和运行时语义验证的必要性,以防范内部威胁与身份冒用。
原文摘要 · Abstract (English)
This paper presents a proof-of-concept supply chain attack against the Secure ROS 2 (SROS 2) framework, demonstrated on a Quanser QCar2 autonomous vehicle platform. A Trojan-infected Debian package modifies core ROS 2 security commands to exfiltrate newly generated keystore credentials via DNS in base64-encoded chunks to an attacker-controlled nameserver. Possession of these credentials enables the attacker to rejoin the SROS 2 network as an authenticated participant and publish spoofed control or perception messages without triggering authentication failures. We evaluate this capability on a secure ROS 2 Humble testbed configured for a four-stop-sign navigation routine using an Intel RealSense camera for perception. Experimental results show that control-topic injections can cause forced braking, sustained high-speed acceleration, and continuous turning loops, while perception-topic spoofing can induce phantom stop signs or suppress real detections. The attack generalizes to any data distribution service (DDS)-based robotic system using SROS 2, highlighting the need for both supply chain integrity controls and runtime semantic validation to safeguard autonomous systems against insider and impersonation threats.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。