Watch Hackers Sabotage an Industrial Robot Arm

3 min read
Curated from wired.com →

When the cybersecurity industry warns of digital threats to the “internet of things,” the targets that come to mind are ill-conceived, insecure consumer products like hackable lightbulbs and refrigerators. But one group of researchers has shown how hackers can perform far more serious physical sabotage: tweaking an industrial robotic arm to cost millions of dollars worth of product defects, and possibly to damage the machinery itself or its human operator.

Researchers at the security firm Trend Micro and Italy’s Politecnico Milano have spent the last year and a half exploring that risk of a networked and internet-connected industrial robot. At the IEEE Security & Privacy conference later this month, they plan to present a case study of attack techniques they developed to subtly sabotage and even fully hijack a 220-pound industrial robotic arm capable of wielding gripping claws, welding tools, or even lasers. The ABB IRB140 they compromised has applications in everything from automotive manufacturing to food processing and packaging to pharmaceuticals.

In their tests, the researchers found a broad collection of security vulnerabilities in the controller computer that pilots that arm. Those security flaws allowed the team to pull off a range of attacks, like changing the roughly $75,000 machine’s operating system with a USB drive plugged into the computer’s ports, and subtly tampering with its data. More alarmingly, they also managed to load their own malicious commands onto the machine from anywhere on the internet. “If you upload your own code, you can change completely what it’s doing to the work piece, introduce defects, stop the production, whatever you want,” says Federico Maggi, who began the work with his fellow Politecnico Milano researchers before joining Trend Micro. “Once you find this, the only limit is your imagination.”

Since the researchers alerted ABB to the hackable bugs they’d discovered, the Swedish-Swiss firm has released security fixes for all of them, Maggi says. ABB didn’t immediately respond to WIRED’s request for comment. But Maggi notes the company’s admirable speed in fixing its flaws doesn’t solve the larger problem. If he and his colleagues were able to find so many basic security flaws in the IRB140, Trend Micro argues that other industrial robots among the 1.3 million the International Federation of Robotics expects to be deployed by 2018 will be vulnerable to similar attacks.

Once you find this, the only limit is your imagination Federico Maggi, Trend Micro

Since software updates for robots can often cause costly delays in manufacturing processes, factories often skip them, Maggi says. That means even known security flaws could linger in the robots for years. And he argues similar techniques would likely work on even larger, more powerful robots like ABB’s IRB 460, a robotic arm capable of moving hundreds of pounds. “Looking at only one vendor, we found textbook examples of vulnerabilities, very simple ones,” says Maggi. “All our attacks can be applied to other categories of robots as well.”

The flaws the researchers identified in ABB’s IRB140 would have given any potential robot-hackers plenty of inroads. Most seriously, they found that any remote attacker could use the internet-scanning tool Shodan to find exposed, accessible FTP servers connected to the robots, and upload files to them that would be automatically downloaded and run whenever the robot is next rebooted.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at wired.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.