In a society where robots are increasingly pervasive across diverse domains, their security has become a strategic priority, as their interaction with the physical world amplifies the potential impact of security breaches. The initial lack of built-in security mechanisms in the widely adopted ROS framework has significantly broadened the attack surface, leaving many systems directly exposed to the Internet. In this work we firstly present a systematic methodology to reliably fingerprint ROS 2 instances exposed on the Internet. Our multi-stage pipeline combines active probing and protocol-aware fingerprinting to effectively filter false positives and distinguish ROS 2 deployments from honeypots and generic services. We then show the application of this methodology conducting five Internet-wide IPv4 (/0) scans over a two-month period (November 2025-January 2026). Among approximately 800 k hosts completing the TCP threeway handshake on port 11811, we identify 18 of them that exhibit all the characteristics of publicly exposed ROS 2 instances. These findings reveal a concrete and non-trivial attack surface, potentially enabling adversaries to interact with and compromise real-world robotic systems.
A Large-Scale Experimental Analysis of ROS 2 Instances Exposed on the Internet / Stanco, G., Iardino, A., Botta, A.. - (2026), pp. 118-123. (32nd International Conference on Telecommunications, ICT 2026 grc 2026) [10.1109/ict70370.2026.11594798].
A Large-Scale Experimental Analysis of ROS 2 Instances Exposed on the Internet
Stanco, Giovanni;Botta, Alessio
2026
Abstract
In a society where robots are increasingly pervasive across diverse domains, their security has become a strategic priority, as their interaction with the physical world amplifies the potential impact of security breaches. The initial lack of built-in security mechanisms in the widely adopted ROS framework has significantly broadened the attack surface, leaving many systems directly exposed to the Internet. In this work we firstly present a systematic methodology to reliably fingerprint ROS 2 instances exposed on the Internet. Our multi-stage pipeline combines active probing and protocol-aware fingerprinting to effectively filter false positives and distinguish ROS 2 deployments from honeypots and generic services. We then show the application of this methodology conducting five Internet-wide IPv4 (/0) scans over a two-month period (November 2025-January 2026). Among approximately 800 k hosts completing the TCP threeway handshake on port 11811, we identify 18 of them that exhibit all the characteristics of publicly exposed ROS 2 instances. These findings reveal a concrete and non-trivial attack surface, potentially enabling adversaries to interact with and compromise real-world robotic systems.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


