Enhancing Security of Unmanned Aerial Vehicle Through Vulnerability Assessment and Penetration Testing: A Case Study on Parrot AR Drone 2.0
摘要
As Unmanned Aerial Vehicles (UAVs), or drones, increasingly permeate future societal frameworks, safeguarding them from malign entities becomes crucial for their integration into essential daily operations. Forecasts by (Stanković et al., Drones 5:49, 2021) suggest the drone market will swell to USD 60 billion by 2025, signifying their expansive adoption and the technological advancements they bring to various industries (Hamdi et al., Drone Forensics: A Case Study on DJI Phantom 4. In 2019 IEEE/ACS 16th International Conference on Computer Systems and Applications [AICCSA], 2019). However, the widespread deployment of UAVs also escalates security dilemmas, such as unauthorized access and cyber-physical attacks (Bouafif et al., Drone Forensics: Challenges and New Insights. In 2018 9th IFIP International Conference on New Technologies, Mobility and Security [NTMS], 2018). The Parrot AR Drone 2.0, celebrated for its affordability and simplicity, is particularly prone to exploits that threaten data's confidentiality, integrity, and availability (Astaburuaga et al., Vulnerability Analysis of AR.Drone 2.0, an Embedded Linux System. In 2019 IEEE 9th Annual Computing and Communication Workshop and Conference [CCWC], 2019). This research targets these vulnerabilities through detailed vulnerability assessment and penetration testing, focusing on identifying and mitigating security flaws in the Parrot AR Drone 2.0’s communication protocols and its unsecured FTP and Telnet connections. The findings aim to contribute to the UAV security domain, ensuring the safe integration of drones into critical infrastructures.