<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>COLINS-</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Combining Experimental and Analytical Methods Penetration Testing of AI-Powered Robotic Systems for</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>National Aerospace University «Kharkiv Aviation Institute»</institution>
          ,
          <addr-line>Chkalova, str. 17, Kharkiv, 61070</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2023</year>
      </pub-date>
      <volume>7</volume>
      <fpage>20</fpage>
      <lpage>21</lpage>
      <abstract>
        <p>AI-powered robotic systems (RS) are increasingly vulnerable to cyber-attacks targeting their software and hardware. To evaluate the risks of successful cyber-attacks, it is necessary to apply various assessment techniques. This study aims to propose a risk-oriented approach to assess the cyber security and safety of the RS and choose countermeasures to prevent critical failures. The proposed approach includes a classification table for complex analytical techniques such as Intrusion (Failure) Modes and Effect Criticality Analysis (I(F)MECA), Attack Tree Analysis (ATA), and Risks and Vulnerabilities assessment (R&amp;VA), as well as experimental methods such as Penetration Testing (PT) and F&amp;VIT (Faults and Variabilities Injection Testing). The approach also involves combining these methods with PT to reduce execution time, improve completeness and trustworthiness, and decrease the costs of assessment. The paper focuses on RS architecture, using a collaborative robot as an example.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Robotics</kwd>
        <kwd>safety</kwd>
        <kwd>cybersecurity</kwd>
        <kwd>penetration testing</kwd>
        <kwd>IMECA</kwd>
        <kwd>AI-powered robots</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        Robotic systems (RS) are used daily in manufacturing to increase the efficiency, speed, and accuracy
of production processes. The increasing use of RS obliges manufacturers to prioritize safety and
cybersecurity issues during the development, deployment, and operation of these systems. Safety is a
key factor in the development and use of the RS. These systems can cause serious injuries to workers
in case of malfunction or improper use. In addition to safety risks, cybersecurity is also a critical issue
for RS, especially in cases where the components of these systems are connected to a single network.
RS must be safe and well-protected. If not, they can become dangerous tools capable of causing chaos
and significant harm to their environment and the people they provide services to. [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] Humanity has
already faced some of the consequences of serious cybersecurity problems with IoT devices that have
caused damage to companies and businesses, as well as to individual users. Problems with the safety
and cybersecurity of the RS can have a much greater impact. There have been notable incidents
involving robots, such as:
• A security robot at the Stanford Shopping Centre in Silicon Valley hit a child, fortunately,
the child was not seriously injured.
• A Chinese-made robot crashed at a trade show in Shenzhen, breaking a shop window and
injuring a person who was nearby.
• In 2007, a malfunctioning robotic gun killed nine soldiers and seriously injured 14 others
during the shooting.
• According to recent research, robotic surgery is associated with 144 deaths in the United
      </p>
      <p>States.</p>
      <p>Indeed, these incidents demonstrate how dangerous compromised or hacked RS can be. Despite the
obvious need for ensuring the safety and cybersecurity of the RS, the heterogeneity of these systems,
as well as their large numbers and resource constraints, hinder the implementation of powerful security
measures.</p>
      <p>
        Moreover, robots powered by AI are being used by industries to bridge the gap between humans and
technology, solve issues, and adapt business strategies to changing customer expectations. Robots with
AI capabilities operate in shared environments to keep employees safe in industrial workplaces.
Additionally, they work independently to complete complicated operations such as cutting, grinding,
welding, and inspection [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Here is a sum-up of the different applications where AI can be used in the
RS:
• Machine learning allows RS to learn from their environment and experiences. It enables
robots to adapt and improve their performance over time. For instance, a robot may learn to
recognize objects in its environment by analyzing images from a camera.
• Computer vision is another area of AI that is extensively used in robotics. It involves
teaching robots to interpret visual data from cameras, sensors, and other sources. Robots can
use this information to navigate their environment, identify objects, and avoid obstacles.
• Natural language processing (NLP) is the field of AI that deals with teaching robots to
understand human language. This enables robots to interact with humans more effectively.
For example, a robot may be trained to understand spoken commands and respond
appropriately.
• Autonomous navigation: Autonomous navigation is the ability of RS to move around in
their environment without human intervention. This is achieved through a combination of
sensors, machine learning, and other AI techniques. Autonomous navigation is particularly
important in applications such as self-driving cars and drones.
• Predictive maintenance involves using AI to predict when a robot or its components are
likely to fail. This enables preventive maintenance to be performed, which can help to
reduce downtime and repair costs.
      </p>
      <p>
        AI is playing an increasingly important role in robotics, enabling robots to perform tasks that would
have been impossible or difficult to achieve without it. But the use of AI entails potentially new threats
to RS. For example, AI technologies can be targeted to bypass AI-based threat detection systems. [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]
As a result, it is very important to build not only a functionally powerful, but also a safe and secure
AIpowered RS that is ready not only for traditional cyberattacks but also for AI-powered attacks. To meet
this requirement properly planned and executed measures may help ensure the safety and cybersecurity
of the RS. Evaluation of the readiness of the RS for unusual situations and cyberattacks, as well as
testing of safety and cybersecurity, should be conducted at every stage of the RS life cycle, from design
and development to implementation and operation.
      </p>
      <p>The readiness assessment may include an evaluation of potential threats, identification of critical
components and processes that need to be protected, and identification of strategies for detecting and
recovering RS after an incident.</p>
      <p>Safety and cybersecurity testing can be conducted through various analytical and experimental
methods, such as penetration testing (PT), risk and vulnerability assessment (R&amp;VA), Attack Tree
Analysis (ATA), Intrusion (Failure) Modes, and Effect Criticality Analysis (I(F)MECA) and
Variabilities Injection Testing (F&amp;VIT) as well as a combination of these methods to expand the test
coverage and improve the quality of testing.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Related works</title>
      <p>Our study collected and analyzed existing works in the development and use of methods for ensuring
the safety and cybersecurity of the RS.</p>
      <p>
        The authors of the article [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] propose a standardized methodology for conducting security
assessments in robotics. They also emphasize the importance of cybersecurity in robotics as robots
become increasingly autonomous and connected to other devices. This paper presents the Robot
Security Framework (RSF), which consists of a set of guidelines and procedures for identifying,
analyzing, and mitigating security risks in robotic systems. The RSF is designed to be flexible and
adaptable to different types of robots and environments. The article provides a detailed overview of the
RSF and demonstrates its application. According to the authors, RSF can improve the safety of robotics
and facilitate the development of safe and reliable robots.
      </p>
      <p>
        The article [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] discusses the importance of conducting Robot Operating System (ROS) PT to identify
and mitigate possible security risks. The authors provide a detailed overview of the ROS architecture
and its security features, as well as common vulnerabilities that may be present in ROS-based systems.
The article also offers a case study of the PT approach for ROS-based robots, including tools and
techniques used to test and identify security weaknesses. The main idea of the article is that conducting
regular PT on ROS-based systems is extremely important to ensure their security and protection against
possible cyberattacks.
      </p>
      <p>
        In this paper [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] a security assessment was conducted for the collaborative robot (cobot) Franka
Emika Panda. The authors analyzed the potential areas of cyberattacks and their potential impact on the
security and cybersecurity of the cobot. The study is based on the basics of The Open-Source Security
Testing Methodology (OSSTM) and the recommendations of The Open Worldwide Application
Security Project (OWASP).
      </p>
      <p>
        The authors of this informative paper [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] have covered a few RS from different manufacturers during
their practical research and identified critical issues related to the security and cybersecurity of these
systems. This paper also describes in detail the potential threats that a compromised RS may pose, as
well as the security and cybersecurity issues identified in these systems.
      </p>
      <p>
        In the study [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] another cobot model, Universal Robots UR3, was considered as the RS under study.
By using a simulator of this RS, the authors investigated the security of the cobot firmware update
process. This analysis revealed four hitherto unknown vulnerabilities in the software update process
that could lead to a complete compromise of the cobot.
      </p>
      <p>
        In addition, the authors of [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] theoretically and experimentally investigated the challenges and
security implications of the modern RS. The authors of this paper reviewed the standard architecture of
the IRS and analyzed it from the point of view of system safety and cybersecurity. An attacker model
was also proposed, with the help of which the authors showed how an attacker can compromise the
cobot controller and gain full control over it, which can lead to significant changes in the production
process, which may result in manufacturing defects. The authors also investigated the potential
consequences of such cyberattacks and experimentally assessed the resistance of widespread robots to
these types of attacks.
      </p>
      <p>
        Also, in this article [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] the authors summarized the results of some of the previously mentioned
studies in the field of security and cybersecurity of the RS and analyzed the main problems and
difficulties that hinder the development of robot security, among which were the lack of awareness of
manufacturers in the issue of security and cybersecurity of robotic systems, the lack of real test benches,
the weak security of firmware and communication protocols of RS, as well as the limited computing
resources of these systems.
      </p>
      <p>
        Previously, we considered the issue of conducting PT of IoT systems in [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ] and proposed a model
for conducting such testing for the RS using the semi-formal IMECA method as a tool for assessing the
criticality of the impact of identified threats, vulnerabilities, and potential cyberattacks on the RS in
[
        <xref ref-type="bibr" rid="ref11">11</xref>
        ].
      </p>
      <p>This work is the next step in our research in the field of RS penetration testing. The purpose of this
study is to develop a comprehensive method for ensuring the safety and cybersecurity of the RS that
will provide maximum test coverage, considering the detection of design anomalies of evolution
systems and the evolution of sets and types of vulnerabilities at each level of development, deployment,
and use of RS.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Methods</title>
      <p>During our study, we have researched various methods of safety &amp; cybersecurity assessment. These
methods’ classification by the type of method is summarized in Table 1. In the safety and cybersecurity
field, the analytical method might involve using mathematical models or logical frameworks to identify
potential safety or security risks and to develop risk management strategies. For example, an analyst
might use attack tree analysis (ATA) to identify potential threats in a safety-critical system and to
develop strategies for preventing those threats. The experimental method might involve conducting
controlled experiments to evaluate the effectiveness of safety or security measures or to test the
performance of safety-critical systems. For example, an experiment might involve possible system
vulnerability exploitation (in the context of PT) testing to assess system response to such actions. The
analytical-experimental method might involve combining elements of both approaches to develop and
test new safety or security technologies or to refine existing ones. For example, an analyst might use
data from experiments to refine a mathematical model of a safety-critical system and to identify
potential improvements to the system.</p>
    </sec>
    <sec id="sec-4">
      <title>Attack Tree Analysis</title>
      <p>
        Attack Tree Analysis (ATA) provides a formal, methodical way of describing the security of
systems, based on varying attacks. It represents attacks against a system in a tree structure, with the
goal as the root node and different ways of achieving that goal as leaf nodes [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. The stages of ATA
are:
•
      </p>
      <p>Define the scope and goal of the analysis: The first step is to clearly define the system or
organization being analyzed and the goal of the analysis. This will help to focus the analysis
on the most important threats.</p>
      <p>Identify the potential threats: The next step is to brainstorm all the potential threats that
could occur against the system or organization. This can be done through various methods
such as brainstorming sessions or by analyzing historical attack patterns.</p>
      <p>Create an AT: The AT is a hierarchical diagram that shows the different stages of an attack,
from the initial point of entry to the final objective of the attacker. The tree is built by
breaking down the attack scenario into smaller, more manageable pieces.</p>
      <p>Analyze each node: Once the AT is created, each node is analyzed to determine the
likelihood and impact of the attack occurring. This helps to prioritize the threats and
determine which ones require the most attention.</p>
      <p>Develop countermeasures: After the analysis is complete, countermeasures are developed
to address the identified threats. These can range from technical controls such as firewalls
and access controls to procedural controls such as training and awareness programs.
Test and validate the countermeasures: Finally, the effectiveness of the countermeasures is
tested and validated to ensure that they are effective in addressing the identified threats. This
can be done through various methods such as PT or scenario-based exercises.</p>
    </sec>
    <sec id="sec-5">
      <title>Intrusion (Failure) Modes and Effect Criticality Analysis</title>
      <p>
        System analysis is aimed at showing the characteristics of the system as availability, security, and
vulnerability through using two techniques the IMECA (for intrusion) and FMECA (for failure) [
        <xref ref-type="bibr" rid="ref14 ref15">14,15</xref>
        ].
The main stages of an I(F)MECA include:
• System/Process Analysis: In this stage, the system or process is broken down into its
components or steps, and each is analyzed to identify potential intrusion/failure modes.
• Intrusion/Failure Mode Analysis: Once potential intrusion/failure modes are identified, they
are analyzed to determine their effects on the system or process. This stage looks at how
each intrusion/failure mode could affect the performance, reliability, safety, cybersecurity,
or other critical aspects of the system/process.
• Criticality Analysis: After analyzing the effects of each intrusion/failure mode, the next
stage is to determine the criticality of each intrusion/failure mode. This involves assigning
a score to each intrusion/failure mode based on factors such as the likelihood of occurrence,
the severity of impact, and detectability.
• Risk Mitigation: Finally, based on the criticality scores, risk mitigation strategies are
developed to address the most critical intrusion/failure modes. This may involve redesigning
the system or process, implementing additional safeguards or redundancy, or developing
contingency plans.
      </p>
    </sec>
    <sec id="sec-6">
      <title>Penetration Testing</title>
      <p>
        PT is a widely used methodological approach, that allows assessing the security of a system by
simulating a real attack [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. Qualitatively conducted testing allows you to determine the level of
security of the system and the presence of vulnerabilities in it, identify the most likely ways to violate
the established security policy, and determine how well the complexity of security features of such a
system works. [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ] Several methodological approaches to PT have been discussed in detail in [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ].
Usually, PT includes the next 5 stages:
• Planning and reconnaissance: This stage involves gathering information about the target
system, such as its network topology, IP addresses, and applications, to identify potential
entry points and vulnerabilities.
• Scanning: In this stage, various scanning tools are used to identify and map out the target
system's vulnerabilities, such as open ports, services, and potential vulnerabilities in the
application or operating system.
• Gaining access: Once potential vulnerabilities have been identified, attempts are made to
exploit them to gain access to the system or application.
• Maintaining access: If access is successfully gained, the penetration tester attempts to
maintain access to the system for as long as possible, to further evaluate its security.
• Analysis and reporting: Finally, the results of the PT are analyzed, and a report is generated,
which details the vulnerabilities that were identified, the methods used to exploit them, and
recommendations for addressing and mitigating these vulnerabilities.
      </p>
    </sec>
    <sec id="sec-7">
      <title>Faults and Variabilities Injection Testing</title>
      <p>FVI testing is a commonly used experimental technique to assess the dependability of
microprocessor-based systems [18] such as RS also. The general stages of FVI testing are as follows:
• Planning: The FVI testing strategy is defined in this stage. This includes identifying the
system components to be tested, selecting the types of faults and variabilities to be
introduced, and determining the testing environment.
• Injection: This stage involves introducing faults and variabilities into the system. The types
of faults and variabilities that can be injected include hardware faults (such as memory errors
and disk failures), software faults (such as coding errors and logic errors), and environmental
variabilities (such as network latency and power fluctuations).
• Observation: In this stage, the system's response to the injected faults and variabilities is
observed. This involves monitoring system behavior, gathering performance metrics, and
identifying any unexpected behaviors or errors.
• Analysis: In this stage, the data gathered during observation is analyzed to identify patterns
and root causes of faults and variabilities. This helps determine areas of the system that need
improvement and identify potential solutions.
• Reporting: Finally, a report is generated that summarizes the findings of the FVI testing.</p>
      <p>The report may include recommendations for improving the system's resilience and
dependability, as well as any identified areas for further testing and analysis.</p>
    </sec>
    <sec id="sec-8">
      <title>Modeling methods combinations</title>
      <p>During our study, we analyzed each stage of all these methods and developed a combined safety &amp;
cybersecurity assessment cycle shown in Figure 6. We summarized similar stages and grouped them,
for example, we noticed that all 5 methods have an initial stage when testers perform a pre-processing
task/activity without direct interaction with the target system like planning, identifying the assets, etc.
We simply named this stage a Pre-processing stage.</p>
      <p>Most parts of the other stage were processed in the same way, but we also highlighted the such type
of possible testing stages like System Preparation which describes the additional steps to be done (for
example, vulnerabilities injection) before the start of the assessment process.</p>
    </sec>
    <sec id="sec-9">
      <title>4. Experiment</title>
      <p>
        The choice of method depends on the specific problem being addressed and the resources available.
Using a combination of approaches can help to ensure that safety and security risks are effectively
identified and managed and that safety-critical systems are reliable and effective. In our previous
research [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] we already tried to combine PT with I(F)MECA to assess the criticality of possible RS
threats. During this work, we want to analyze a few more options of existing safety and cybersecurity
assessment methods to be combined with PT. As an object of study, we will keep using the RS
architecture, as we did before, but this time we will use a black-box view described in Figure 7.
      </p>
      <p>
        The programmer or the operator issues high-level commands to the controller (e.g., via a REST API,
with a program on the HRI interface, moving the joystick). The controller translates such commands
into low-level inputs for the actuators (e.g., end effectors, servo motors) through dedicated I/O
interfaces. The controller is also reachable through a remote-access interface. [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] Also, cobots can be
equipped with AI-powered components such as 2D cameras, force sensors, etc. [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
      </p>
    </sec>
    <sec id="sec-10">
      <title>Analytical and experimental methods combinations</title>
      <p>In this section, we described 4 analytical and experimental methods combinations. The goal
of this combination is to reduce PT execution time, improve its completeness and trustworthiness,
and decrease the costs of safety and cybersecurity assessment.</p>
    </sec>
    <sec id="sec-11">
      <title>4.1.1. I(F)MECA-PEN Stages</title>
      <p>Such methods combination is fully applicable for a safety-cybersecurity-critical system such as RS.
All the possible attack surfaces (marked in the dashed oval in Fig.7), such as robot/service networks,
controllers, or a program task, can be assessed using this method’s combination. I(F)MECA-PEN
allows the pentester to assess and perform Intrusion/Failure analysis and assess findings
(threats/vulnerabilities/attacks) criticality after PT phases such as scanning, gaining access, and
maintaining access. Figure 8 describes the way how I(F)MECA stages can be integrated into the PT
flow.</p>
    </sec>
    <sec id="sec-12">
      <title>4.1.2. ATA-PEN Stages</title>
      <p>ATA is very often used technique as an addition to the PT activities, especially after the Scanning
stage. The stages of ATA-PEN are described in Figure 9.</p>
    </sec>
    <sec id="sec-13">
      <title>4.1.3. R&amp;VA-PEN Stages</title>
      <p>This combination of methods is so widespread that sometimes PT is confused with VA and vice
versa. R&amp;VA-PEN is a very large-scale and long-time-consuming process that covers not only safety
&amp; cybersecurity assessment, but also vulnerability monitoring and reporting activities. The stages of
R&amp;VA-PEN are described in Figure 10.</p>
    </sec>
    <sec id="sec-14">
      <title>4.1.4. FVI-PEN Stages</title>
      <p>The unique stage of the FVI-PEN method is the Injection stage. This technique may be useful to test
the completeness and trustworthiness of the PT process. The idea is that the development team injects
certain known vulnerabilities before starting the testing phase, and pen-testers must check how the RS
will react to their appearance and what exactly they can lead to. Unfortunately, this method is quite
risky, because fault or vulnerability injection can lead to unexpected RS behavior, so it is not
recommended to perform it on a real existing system. The stages of FVI-PEN are described in Figure
11. Gaining &amp; maintaining access might be an optional step.</p>
    </sec>
    <sec id="sec-15">
      <title>Methods combinations advantages and disadvantages</title>
      <p>We compared and discussed method combinations and summarized their advantages and
disadvantages in the tables 2-5.</p>
    </sec>
    <sec id="sec-16">
      <title>4.2.1. I(F)MECA-PEN advantages and disadvantages</title>
      <p>Advantages Disadvantages
+ Pentester can predict the impact of - Vulnerabilities can be “known” issues that refer
vulnerabilities he found without exploitation of the pentester to the vulnerabilities databases
these findings. In cases when the goal is like NVD with already assigned CVE, assessed
assessing the impact of possible threats, this criticality level, and described steps to exploit
method’s combination can save a lot of time by and there is no critical need for criticality
excluding the low criticality scenarios from the analysis before the exploitation.
testing scope.
+ When access to the RS is gained, the - If access to the system is gained for a very short
pentester can redo the I(F)MECA analysis again period pentester might have no time to perform
to identify the most critical threats and begin an I(F)MECA analysis.
the exploitation process from them.
+ Might be very helpful also after regression
testing to understand the level of risk
mitigation.</p>
    </sec>
    <sec id="sec-17">
      <title>4.2.2. ATA-PEN advantages and disadvantages</title>
      <p>Advantages Disadvantages
+ This helps the pentester to identify possible - Requires extra time for creating attack trees.
attack vectors on the RS like robot/service
networks, controller, or a program task, and
analyze their components to understand the
way to perform an intrusion to the RS.
+ Applied countermeasures can be validated
using ATA-PEN methods combinations.</p>
    </sec>
    <sec id="sec-18">
      <title>4.2.3. R&amp;VA-PEN advantages and disadvantages</title>
      <p>Advantages Disadvantages
+ The method has the largest testing coverage. - Cost- and time-consuming method.
+ Simplifies mitigation of the “false-positive”
findings by verifying them using exploitation
activities.</p>
    </sec>
    <sec id="sec-19">
      <title>4.2.4. FVI-PEN advantages and disadvantages</title>
      <p>Advantages Disadvantages
+ This method’s combination allows for the - Risky if used in a real RS condition.
assessment of the quality of pentesters’ work.
+ By using this method development team can - Time-consuming method.
see how RS will work in unexpected/critical
situations.
- Requires robotic simulators to be used for
testing.
4.3.</p>
    </sec>
    <sec id="sec-20">
      <title>Methods comparison</title>
      <p>Based on the analysis of possible options for combining existing methods of ensuring the safety and
cyber security of RS and a review of the advantages and disadvantages of these methods, it is possible
to build a generalized matrix of influence on certain aspects of PT.</p>
      <p>We evaluated the impact methods combining on the PT metrics (completeness, trustworthiness,
execution time, cost) using the scale from -2 to 2, where -2 is a significant decrease in the metric, -1 is
a slight decrease in the metric, 0 means that the value of the metric doesn’t change, 1 is a slight increase
in the metric, 2 is a significant increase in the metric. Before the evaluation, all the metrics score values
are equal to 0. The results are summarized in Table 6.</p>
      <p>I(F)MECA-PEN doesn’t significantly increase the execution time and cost of PT but incomparably
improves its completeness and trustworthiness. Meanwhile, the ATA-PEN combination also raises PT
execution time and cost but also slightly improves its completeness and trustworthiness. R&amp;VA is a
very cost- &amp; time-consuming method combination, but it significantly improves PT completeness.
FVIPEN is a method combination, which requires an additional environment to be used for PT, but this
method can significantly improve RS dependability.</p>
    </sec>
    <sec id="sec-21">
      <title>5. Conclusions</title>
      <p>
        During this study, we analyzed a few analytical and experimental methods of safety and
cybersecurity assessment to be combined with PT and evaluated them. As a preliminary result, we have
determined that the combination of I(F)MECA with PT [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] is the best of the considered ones but
requires practical confirmation in the conditions of application in a real RS or its emulator.
      </p>
      <p>Future research can be dedicated to, firstly, the addition of other methods and analysis of their
extended combination, and secondly, simulation and field investigation of the RS cyber security
assessment using the suggested approach. Finally, it would be interesting to continue research on
cybersecurity analysis and assurance issues for the Internet of Robots as a part of IoT systems [19,20].</p>
    </sec>
    <sec id="sec-22">
      <title>6. References</title>
      <p>[18] A. Aponte-Moreno, J. Isaza-GonzÃlez, A. Serrano-Cases, A. Martínez-Álvarez, S.
CuencaAsensi, and F. Restrepo-Calle, Evaluation of fault injection tools for reliability estimation of
microprocessor-based embedded systems, Microprocessors and Microsystems 96 (2023), doi:
10.1016/j.micpro.2022.104723.
[19] M. Kolisnyk, Vulnerability analysis and method of selection of communication protocols for
information transfer in Internet of Things systems, Radioelectronic and Computer Systems, 1
(2021), pp. 133–149, doi: 10.32620/reks.2021.1.12.
[20] O. Morozova, A. Nicheporuk, A. Tetskyi, and V. Tkachov, Methods and technologies for ensuring
cybersecurity of industrial and web-oriented systems and networks, Radioelectronic and Computer
Systems, 4 (2021), pp. 145–156, doi: 10.32620/reks.2021.4.12.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>IOActive.Com</surname>
          </string-name>
          , Hacking Robots before Skynet, url: https://ioactive.com/pdfs/Hacking-RobotsBefore-Skynet.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>A.</given-names>
            <surname>Borboni</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.V.V.</given-names>
            <surname>Reddy</surname>
          </string-name>
          , I. Elamvazuthi,
          <string-name>
            <given-names>M.S.</given-names>
            <surname>AL-Quraishi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Natarajan</surname>
          </string-name>
          and
          <string-name>
            <given-names>S.S.</given-names>
            <surname>Azhar</surname>
          </string-name>
          <string-name>
            <surname>Ali</surname>
          </string-name>
          ,
          <article-title>The Expanding Role of Artificial Intelligence in Collaborative Robots for Industrial Applications: A Systematic Review of Recent Works</article-title>
          ,
          <source>Machines</source>
          <volume>11</volume>
          (
          <issue>111</issue>
          ) (
          <year>2023</year>
          ), doi: 10.3390/machines11010111.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>O.</given-names>
            <surname>Veprytska</surname>
          </string-name>
          and
          <string-name>
            <given-names>V.</given-names>
            <surname>Kharchenko</surname>
          </string-name>
          ,
          <article-title>AI-powered attacks against AI-powered protection: classification, scenarios and risk analysis</article-title>
          ,
          <source>in: Proceedings of the IEEE Conference on Dependable Systems, Services and Technologies</source>
          ,
          <string-name>
            <surname>DESSERT</surname>
          </string-name>
          ,
          <year>2022</year>
          , doi: 10.1109/DESSERT58054.
          <year>2022</year>
          .
          <volume>10018770</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>V.</given-names>
            <surname>Vilches</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. Alzola</given-names>
            <surname>Kirschgens</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Calvo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Cordero</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R. Izquierdo</given-names>
            <surname>Pisón</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. Mayoral</given-names>
            <surname>Vilches</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. Muñiz</given-names>
            <surname>Rosas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G. Olalde</given-names>
            <surname>Mendia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. J. Usategui</given-names>
            <surname>San</surname>
          </string-name>
          , I. Ugarte,
          <string-name>
            <given-names>E.</given-names>
            <surname>Gil-Uriarte</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Tews</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A.</given-names>
            <surname>Peter</surname>
          </string-name>
          ,
          <article-title>Introducing the Robot Security Framework (RSF), A Standardized Methodology to Perform Security Assessments in Robotics (</article-title>
          <year>2018</year>
          ), url: https://arxiv.org/abs/
          <year>1806</year>
          .04042.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>B.</given-names>
            <surname>Dieber</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>White</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Taurer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Breiling</surname>
          </string-name>
          , G. Caiazza,
          <string-name>
            <given-names>H.</given-names>
            <surname>Christensen</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A.</given-names>
            <surname>Cortesi</surname>
          </string-name>
          ,
          <string-name>
            <surname>Penetration Testing</surname>
            <given-names>ROS</given-names>
          </string-name>
          ,
          <source>Studies in Computational Intelligence</source>
          <volume>831</volume>
          (
          <year>2019</year>
          ), doi: 10.1007/978-3-
          <fpage>030</fpage>
          -20190-
          <issue>6</issue>
          _
          <fpage>8</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>S.</given-names>
            <surname>Hollerer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Fischer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Brenner</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Papa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Schlund</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Kastner</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Fabini</surname>
          </string-name>
          , and
          <string-name>
            <given-names>T.</given-names>
            <surname>Zseby</surname>
          </string-name>
          ,
          <article-title>Cobot attack: a security assessment exemplified by a specific collaborative robot</article-title>
          ,
          <source>Procedia Manufacturing</source>
          <volume>54</volume>
          (
          <year>2021</year>
          ), pp.
          <fpage>191</fpage>
          -
          <lpage>196</lpage>
          , doi: 10.1016/j.promfg.
          <year>2021</year>
          .
          <volume>07</volume>
          .029.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>C.F.</given-names>
            <surname>Chan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.P.</given-names>
            <surname>Chow</surname>
          </string-name>
          , and
          <string-name>
            <given-names>T.</given-names>
            <surname>Tang</surname>
          </string-name>
          ,
          <article-title>Security Analysis of Software Updates for Industrial Robots, Critical Infrastructure Protection XV</article-title>
          .
          <article-title>ICCIP 2021</article-title>
          .
          <source>IFIP Advances in Information and Communication Technology</source>
          <volume>636</volume>
          (
          <year>2022</year>
          ), pp.
          <fpage>229</fpage>
          -
          <lpage>245</lpage>
          , doi: 10.1007/978-3-
          <fpage>030</fpage>
          -93511-5_
          <fpage>11</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>D.</given-names>
            <surname>Quarta</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Pogliani</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Polino</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Maggi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.M.</given-names>
            <surname>Zanchettin</surname>
          </string-name>
          , and
          <string-name>
            <given-names>S.</given-names>
            <surname>Zanero</surname>
          </string-name>
          ,
          <article-title>An Experimental Security Analysis of an Industrial Robot Controller</article-title>
          ,
          <source>in: Proceeding of the 2017 IEEE Symposium on Security and Privacy (SP)</source>
          ,
          <year>2017</year>
          , pp.
          <fpage>268</fpage>
          -
          <lpage>286</lpage>
          , doi: 10.1109/SP.
          <year>2017</year>
          .
          <volume>20</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>H.</given-names>
            <surname>Pu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>He</surname>
          </string-name>
          , P. Cheng, M. Sun, and
          <string-name>
            <given-names>J.</given-names>
            <surname>Chen</surname>
          </string-name>
          , Security of Industrial Robots: Vulnerabilities, Attacks, and Mitigations, IEEE Network (
          <year>2022</year>
          ), doi: 10.1109/MNET.116.2200034.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>A.</given-names>
            <surname>Abakumov</surname>
          </string-name>
          and
          <string-name>
            <given-names>V.</given-names>
            <surname>Kharchenko</surname>
          </string-name>
          ,
          <article-title>Penetration testing for ІoT systems: cyber threats, methods, and stages</article-title>
          ,
          <source>Electronic Modeling</source>
          <volume>44</volume>
          (
          <issue>4</issue>
          ) (
          <year>2022</year>
          ), pp.
          <fpage>79</fpage>
          -
          <lpage>104</lpage>
          , doi: 10.15407/emodel.44.04.079.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>A.</given-names>
            <surname>Abakumov</surname>
          </string-name>
          and
          <string-name>
            <given-names>V.</given-names>
            <surname>Kharchenko</surname>
          </string-name>
          ,
          <article-title>Combining IMECA analysis and penetration testing to assess the cybersecurity of industrial robotic systems</article-title>
          ,
          <source>in: Proceedings of the 12th IEEE Conference on Dependable Systems, Services and Technologies</source>
          ,
          <string-name>
            <surname>DESSERT</surname>
          </string-name>
          ,
          <year>2022</year>
          , doi: 10.1109/DESSERT58054.
          <year>2022</year>
          .
          <volume>10018823</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12] ECCouncil.org, Vulnerability Assessment: 6 Best Steps to Better Security, url: https://egs.eccouncil.org/wp-content/uploads/2020/12/Risk-and
          <article-title>-Vulnerability-Assessment-DoYou-Know-the-</article-title>
          <string-name>
            <surname>Other-Side</surname>
          </string-name>
          .pdf.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Md</surname>
            .
            <given-names>A. R.</given-names>
          </string-name>
          <string-name>
            <surname>Likhon</surname>
          </string-name>
          ,
          <source>Attack Trees: Cyber Security</source>
          ,
          <year>2020</year>
          , url: https://www.academia.edu/62051416/Attack_Trees_Cyber_Security.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>V.</given-names>
            <surname>Torianyk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Kharchenko</surname>
          </string-name>
          , and
          <string-name>
            <given-names>H.</given-names>
            <surname>Zemlianko</surname>
          </string-name>
          ,
          <source>IMECA Based Assessment of Internet of Drones Systems Cyber Security Considering Radio Frequency Vulnerabilities, in: Proceeding of the IntelITSIS'2021: 2nd International Workshop on Intelligent Information Technologies and Systems of Information Security</source>
          (
          <year>2021</year>
          ), url: https://ceur-ws.
          <source>org/</source>
          Vol-
          <volume>2853</volume>
          /paper50.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>V.</given-names>
            <surname>Pevnev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Torianyk</surname>
          </string-name>
          , and
          <string-name>
            <given-names>V.</given-names>
            <surname>Kharchenko</surname>
          </string-name>
          ,
          <source>Cyber Security of Wireless Smart Systems: Channels of Intrusions and Radio Frequency Vulnerabilities, Radioelectronic and Computer Systems</source>
          ,
          <volume>4</volume>
          (
          <issue>96</issue>
          ) (
          <year>2020</year>
          ), pp.
          <fpage>79</fpage>
          -
          <lpage>92</lpage>
          , doi: 10.32620/reks.
          <year>2020</year>
          .
          <volume>4</volume>
          .07.
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>M.</given-names>
            <surname>Denis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Zena</surname>
          </string-name>
          , and
          <string-name>
            <given-names>T.</given-names>
            <surname>Hayajneh</surname>
          </string-name>
          ,
          <article-title>Penetration testing: Concepts, attack methods, and defense strategies</article-title>
          ,
          <source>in: Proceedings of the 2016 IEEE Long Island Systems, Applications and Technology Conference (LISAT)</source>
          (
          <year>2016</year>
          ), doi: 10.1109/LISAT.
          <year>2016</year>
          .
          <volume>7494156</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>V.</given-names>
            <surname>Shelekhov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Barchenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Kalchenko</surname>
          </string-name>
          and
          <string-name>
            <given-names>V.</given-names>
            <surname>Obodyak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A Hierarchical</given-names>
            <surname>Fuzzy</surname>
          </string-name>
          <article-title>Quality Assessment of Complex Security Information Systems</article-title>
          ,
          <source>Radioelectronic and Computer Systems</source>
          ,
          <volume>4</volume>
          (
          <year>2022</year>
          ), pp.
          <fpage>106</fpage>
          -
          <lpage>115</lpage>
          , doi: 10.32620/reks.
          <year>2020</year>
          .
          <volume>4</volume>
          .10.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>