In a society where robots are increasingly pervasive across diverse domains, their security has become a strategic priority, as their interaction with the physical world amplifies the potential impact of security breaches. The initial lack of built-in security mechanisms in the widely adopted ROS framework has significantly broadened the attack surface, leaving many systems directly exposed to the Internet. In this work we firstly present a systematic methodology to reliably fingerprint ROS 2 instances exposed on the Internet. Our multi-stage pipeline combines active probing and protocol-aware fingerprinting to effectively filter false positives and distinguish ROS 2 deployments from honeypots and generic services. We then show the application of this methodology conducting five Internet-wide IPv4 (/0) scans over a two-month period (November 2025-January 2026). Among approximately 800 k hosts completing the TCP threeway handshake on port 11811, we identify 18 of them that exhibit all the characteristics of publicly exposed ROS 2 instances. These findings reveal a concrete and non-trivial attack surface, potentially enabling adversaries to interact with and compromise real-world robotic systems.

A Large-Scale Experimental Analysis of ROS 2 Instances Exposed on the Internet / Stanco, G., Iardino, A., Botta, A.. - (2026), pp. 118-123. (32nd International Conference on Telecommunications, ICT 2026 grc 2026) [10.1109/ict70370.2026.11594798].

A Large-Scale Experimental Analysis of ROS 2 Instances Exposed on the Internet

Stanco, Giovanni;Botta, Alessio
2026

Abstract

In a society where robots are increasingly pervasive across diverse domains, their security has become a strategic priority, as their interaction with the physical world amplifies the potential impact of security breaches. The initial lack of built-in security mechanisms in the widely adopted ROS framework has significantly broadened the attack surface, leaving many systems directly exposed to the Internet. In this work we firstly present a systematic methodology to reliably fingerprint ROS 2 instances exposed on the Internet. Our multi-stage pipeline combines active probing and protocol-aware fingerprinting to effectively filter false positives and distinguish ROS 2 deployments from honeypots and generic services. We then show the application of this methodology conducting five Internet-wide IPv4 (/0) scans over a two-month period (November 2025-January 2026). Among approximately 800 k hosts completing the TCP threeway handshake on port 11811, we identify 18 of them that exhibit all the characteristics of publicly exposed ROS 2 instances. These findings reveal a concrete and non-trivial attack surface, potentially enabling adversaries to interact with and compromise real-world robotic systems.
2026
A Large-Scale Experimental Analysis of ROS 2 Instances Exposed on the Internet / Stanco, G., Iardino, A., Botta, A.. - (2026), pp. 118-123. (32nd International Conference on Telecommunications, ICT 2026 grc 2026) [10.1109/ict70370.2026.11594798].
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11588/1062850
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact