CHAPTER 5. SUMMARY AND FUTURE WORK
5.1 Future Work
Future research could focus on several different paths. First, there are other types of network attacks to consider, such as denial of service attacks. These
attacks, which could include wireless traffic jamming, exploitation of the application itself to tax the system or crash it all together, or tampering with the pre-shared keys to prevent communication from succeeding.
The efficiency of the cryptosystem implemented in this research could also be improved so that devices with low computing power can still communicate
effectively as HARMS actors. This might include porting the HARMS system into a lower level programming language, such as C.
Although timestamps were introduced as a security mechanism to help prevent replay attacks, other types of checks could also be implemented to further increase security of communication. Global positioning could be used to provide geographic or localization data in the message, to better help prevent a situation similar to the MiG-in-the-middle attack, where actors are very far away from each other in space.
As mentioned in Section 4.4, the implementation of multicast and broadcast messages also has room for improvement. This problem introduces the concept of shared secrets or some form of group key management, a new cryptographic hurdle to overcome. However, if solved, this could lead to improvements in overall
performance and cut down on total network traffic.
Finally, applying this research to a real-world scenario that requires
firefighting robots would be of particular interest, now that this proof-of-concept has been put in place.
LIST OF REFERENCES
Amano, H. (2002). Present status and problems of fire fighting robots. In SICE 2002. proceedings of the 41st SICE annual conference (Vol. 2, pp. 880–885).
Anderson, R. (2008). Security engineering: A guide to building dependable distributed systems (Second ed.). Indianapolis, IN: Wiley Publishing, Inc.
Biryukov, A., Dunkelman, O., Keller, N., Khovratovich, D., & Shamir, A. (2009).
Key recovery attacks of practical complexity on AES variants with up to 10 rounds. Cryptology ePrint Archive, Report 2009/374.
Bless, E. (2006). Anna konda: the firefighting snakebot. Engadget. Retrieved from www.engadget.com/2006/07/23/anna-konda-the-firefighting-snakebot Boneh, D. (1998). The decision Diffie-Hellman problem. In Algorithmic number
theory (pp. 48–63). Springer.
Bradshaw, A. (1991). The UK security and fire fighting advanced robot project. In Advanced robotic initiatives in the UK, IEE colloquium on (pp. 1–4).
Brenner, B. (2012). ICS-CERT alert: Natural gas pipelines under attack. Retrieved from www.csoonline.com/article/2135157/
critical-infrastructure/ics-cert-alert--natural-gas-pipelines-under-attack.html Cherry, S. (2011). Sons of stuxnet. IEEE Spectrum. Retrieved from
spectrum.ieee.org/podcast/telecom/security/sons-of-stuxnet
Ciancamerla, E., Minichino, M., & Palmieri, S. (2013). Modeling cyber attacks on a critical infrastructure scenario. In Information, intelligence, systems and applications (IISA), 2013 fourth international conference on (pp. 1–6).
The Clinton administration’s policy on critical infrastructure protection:
Presidential directive 63 (Tech. Rep.). (1998, May 22). White House.
Retrieved from fas.org/irp/offdocs/pdd/pdd-63.htm
Davis, T. (2015). Propane tank truck fire shuts down interstate 20 in Arlington.
NBCDFW . Retrieved from nbcdfw.com/news/local/
18-Wheeler-Fire-Shuts-Down-Interstate-20-in-Arlington-287324761.html Dubel, W., Gongora, H., Bechtold, K., & Diaz, D. (2003). An autonomous
firefighting robot. Department of Electrical and Computer Engineering, Florida International University, Miami, FL, USA.
Esmaeili, A., Mozayani, N., & Motlagh, M. (2014, Feb). Multi-level holonification of multi-agent networks. In Intelligent systems (ICIS), 2014 iranian conference on (p. 1-5).
Goldman, D. (2013). Hacker hits on U.S. power and nuclear targets spiked in 2012.
CNN Money. Retrieved from money.cnn.com/2013/01/09/
technology/security/infrastructure-cyberattacks/
Grant, C. (2014). Creating the research roadmap for smart fire fighting. Fire Protection Research Foundation.
Heller, W. (2011). Firefighting robots in japan. Robotland . Retrieved from robotland.blogspot.com/2011/03/firefighting-robots-in-japan.html
Higgins, F., Tomlinson, A., & Martin, K. M. (2009). Survey on security challenges for swarm robotics. In Autonomic and autonomous systems, 2009. ICAS’09.
fifth international conference on (pp. 307–312).
Homeland security presidential directive 7 (Tech. Rep.). (2003, Dec 17). White House. Retrieved from
www.dhs.gov/homeland-security-presidential-directive-7
Is your HVAC (air conditioning) the next SCADA target? (2013). Cyber Defense Magazine. Retrieved from www.cyberdefensemagazine.com/
is-your-hvac-air-conditioning-the-next-scada-target/
Kaliski, B. (2000). PKCS #5: Password-based cryptography specification version 2.0 (RFC No. 2898). RFC Editor. Internet Requests for Comments. Retrieved from www.rfc-editor.org/rfc/rfc2898.txt
Kaufman, C., Hoffman, P., Nir, Y., Eronen, P., & Kivinen, T. (2014). Internet key exchange protocol version 2 (IKEv2) (RFC No. 7296). RFC Editor. Internet Requests for Comments. Retrieved from www.rfc-editor.org/rfc/rfc7296.txt Kobayashi, A., & Nakamura, K. (1983). Rescue robots for fire hazards. In
Proceedings of the 1983 international conference on advanced robotics (pp.
91–98).
Krawczyk, H., & Eronen, P. (2010). HMAC-based extract-and-expand key derivation function (HKDF) (RFC No. 5869). RFC Editor. Internet Requests for Comments. Retrieved from www.rfc-editor.org/rfc/rfc5869.txt
Krebs, B. (2014). Target hackers broke in via HVAC company. Krebs on Security.
Retrieved from
krebsonsecurity.com/2014/02/target-hackers-broke-in-via-hvac-company/
Kumar, V., Rus, D., & Singh, S. (2004). Robot and sensor networks for first responders. Pervasive Computing, IEEE , 3 (4), 24–33.
Lahr, D., Orekhov, V., Lee, B., & Hong, D. (2013). Early developments of a parallelly actuated humanoid, SAFFiR. In ASME 2013 international design engineering technical conferences and computers and information in
engineering conference (pp. 1–7).
Lewis, J., Matson, E. T., Wei, S., & Min, B.-C. (2013). Implementing HARMS-based indistinguishability in ubiquitous robot organizations.
Robotics and Autonomous Systems, 61 (11), 1186–1192.
Man-in-the-middle attack. (2014). OWASP. Retrieved from www.owasp.org/index.php/Man-in-the-middle attack
Matson, E. T., & Min, B.-C. (2011). M2M infrastructure to integrate humans, agents and robots into collectives. In Instrumentation and measurement technology conference (I2MTC), 2011 IEEE (pp. 1–6).
McDonald, G., Murchu, L. O., Doherty, S., & Chien, E. (2013). Stuxnet 0.5: The missing link. Symantec Report. Retrieved from
www.symantec.com/connect/blogs/stuxnet-05-missing-link
Min, B.-C., Matson, E. T., Smith, A., & Dietz, J. E. (2014). Using directional antennas as sensors to assist fire-fighting robots in large scale fires. In Sensors applications symposium (SAS), 2014 IEEE (pp. 360–365).
MVF-5. (n.d.). DOK-ING. Retrieved from dok-ing.hr/products/firefighting/mvf 5 Naghsh, A. M., Gancet, J., Tanoto, A., & Roast, C. (2008). Analysis and design of
human-robot swarm interaction in firefighting. In Robot and human interactive communication, 2008. RO-MAN 2008. the 17th IEEE international symposium on (pp. 255–260).
National strategy for homeland security (Tech. Rep.). (2002). Office of Homeland Security. Retrieved from
www.dhs.gov/sites/default/files/publications/nat-strat-hls-2002.pdf Nguyen, C. Q., Min, B.-C., Matson, E. T., Smith, A. H., Dietz, J. E., & Kim, D.
(2012). Using mobile robots to establish mobile wireless mesh networks and increase network throughput. International Journal of Distributed Sensor Networks, 2012 .
Office of infrastructure protection. (2014). Homeland Security. Retrieved from www.dhs.gov/office-infrastructure-protection
Plackett, B. (2012). Rescue me, robot: Machines ready for firefighting duty. Wired Magazine. Retrieved from www.wired.com/2012/10/fire-fighting-robots Rescorla, E. (1999). Diffie-Hellman key agreement method (RFC No. 2631). RFC
Editor. Internet Requests for Comments. Retrieved from www.rfc-editor.org/rfc/rfc2631.txt
Russell, S., & Norvig, P. (2009). Artificial intelligence: A modern approach (Third ed.). Upper Saddle River, NJ: Prentice Hall.
Schneier, B. (2008). Aspidistra. Schneier on Security. Retrieved from www.schneier.com/blog/archives/2008/11/aspidistra.html
Schneier, B. (2012). When will we see collisions for SHA-1? Schneier on Security.
Retrieved from
www.schneier.com/blog/archives/2012/10/when will we se.html
Schoen, S., & Galperin, E. (2011). Iranian man-in-the-middle attack against google demonstrates dangerous weakness of certificate authorities. Electronic Frontier Foundation. Retrieved from
www.eff.org/deeplinks/2011/08/iranian-man-middle-attack-against-google
Schumacher, M., McVay, S., & Landes, J. (1999). Pokey the fire-fighting robot.
Retrieved from www.ee.nmt.edu/∼wedeward/EE382/SP99/group7 fr.pdf Skoloff, B., & Cone, T. (2013). Firefighters use drones to battle Yosemite rim fire.
Huffington Post. Retrieved from
www.huffingtonpost.com/2013/08/28/drones-yosemite-fire n 3833528.html Smith, B. (2014). Are drones the future of firefighting? Washington Times.
Retrieved from www.washingtontimes.com/news/2014/jul/5/
are-drones-the-future-of-firefighting
Smith, D. L., Petroka, R. P., Yobs, R. L., Lewis, D., & McCarthy, W. (1985). A mechanical predesign project in robotic fire fighting (Tech. Rep.). Monterey, California. Naval Postgraduate School.
Thring, M. W. (1963). The domestic revolution. Journal of the Royal Society of Arts, 556–572.
Unisys. (2014). Unisys survey reveals nearly 70 percent of critical infrastructure providers have been breached in the past year. Unisys. Retrieved from www.unisys.com/offerings/security-solutions/NewsRelease/
Unisys-Survey-Reveals-Critical-Infrastructure-Providers-Breached
Weiss, G. (1999). Multiagent systems: A modern approach to distributed artificial intelligence. MIT press.
What is critical infrastructure? (2013). Homeland Security. Retrieved from http://www.dhs.gov/what-critical-infrastructure
Zetter, K. (2015). A cyberattack has caused confirmed physical damage for the second time ever. Wired Magazine. Retrieved from
www.wired.com/2015/01/german-steel-mill-hack-destruction
NOTES
Please note that parts of this thesis were included in a publication currently in review to the 12th International Conference on Mobile Systems and Pervasive Computing (MobiSPC 2015).