VMCAI 2025
Mon 20 - Tue 21 January 2025 Denver, Colorado, United States
co-located with POPL 2025

This program is tentative and subject to change.

Mon 20 Jan 2025 17:00 - 17:30 at Hopscotch - Applications

As industrial robots become an integral part of Industry 4.0 in the manufacturing sector, their interconnection and interoperability introduce significant security challenges. RESTful Web services have emerged as the preferred method for network communication due to their simplicity and ease of use. However, the effective detection of security flaws in RESTful services for industrial robots still faces three key challenges: high-quality test case generation, high-throughput testing, and anomaly detection. Unlike traditional applications deployed within cloud services, limited computational resources, unique controller states, and unclear API specifications in robot further complicate the resolution of these challenges. Consequently, a large number of security flaws persist in real and deployed devices, with some flaws even posing the risk of physical damage.

To address these challenges, we propose a novel testing technique named RobRest specifically designed for emerging RESTful services in the context of robotic systems. In test case generation, RobRest analyzes description fields extracted from the OpenAPI specification, ensuring the generation of high-quality test cases. During abnormality observation, RobRest combines both cyber and physical space states to identify anomalies in the target service. Additionally, RobRest automatically customizes each testing request to the service, minimizing resource usage within the robot controller and bypassing the quantity restrictions present in the controller. Applying RobRest to industrial robots, we identified a total of 19 system flaws (4 vulnerabilities and 15 bugs), and 2 of them have been assigned CVE IDs. Exploiting them can affect a multitude of industrial robots in the physical world.

This program is tentative and subject to change.

Mon 20 Jan

Displayed time zone: Mountain Time (US & Canada) change

16:00 - 17:30
ApplicationsVMCAI 2025 at Hopscotch
16:00
30m
Talk
ExpectAll: A BDD Based Approach for Link Failure Resilience in Elastic Optical Networks
VMCAI 2025
Gustav S. Bruhns Aalborg University, Martin P. Hansen Aalborg University, Rasmus Hebsgaard Aalborg University, Frederik M. W. Hyldgaard Aalborg University, Jiri Srba Aalborg University
16:30
30m
Talk
Constructing Trustworthy Smart Contracts
VMCAI 2025
Devora Chait-Roth New York University, Kedar Namjoshi Nokia Bell Labs
17:00
30m
Talk
Automated Flaw Detection for Industrial Robot RESTful Service
VMCAI 2025
Yuncheng Wang Institute of Information Engineering, Chinese Academy of Sciences; School of Cyber Security, UCAS Beijing, China, Puzhuo Liu Tsinghua University, Yaowen Zheng Institute of Information Engineering at Chinese Academy of Sciences, Dongliang Fang Beijing Key Laboratory of IOT Information Security Technology, Institute of Information Engineering, CAS, China; School of Cyber Security, University of Chinese Academy of Sciences, China, Zhiwen Pan Institute of Information Engineering, Chinese Academy of Sciences; School of Cyber Security, UCAS Beijing, China, Shuaizong Si Institute of Information Engineering, Chinese Academy of Sciences; School of Cyber Security, UCAS Beijing, China, Weidong Zhang Institute of Information Engineering, Chinese Academy of Sciences; School of Cyber Security, UCAS Beijing, China, Limin Sun Institute of Information Engineering at Chinese Academy of Sciences; University of Chinese Academy of Sciences