Today’s society is becoming more and more connected, all in order to make the availability as user-friendly as possible. But what problems they can lead to if it is not done in a safe way is something that this thesis will test. In this thesis, a cyber security analysis of a connected product is performed. The product to be evaluated is a robot that is used by having conversations with the user. Robots are not uncommon today; it is something that has long been used in industry but today can be found in many different places in everyday life. The robot examined in this thesis will interact with its user via video and audio, and in addition to seeing how secure the robot is, the user’s integrity will also be examined against the robot’s possible vulnerabilities. The method of investigating this robot is first done with an analysis of potential threats by creating a threat model. After a threat model is created, the most critical vulnerabilities are tested with penetration testing. The focus on finding vulnerabilities was made regarding how the robot communicates over the network. Both how it works to load different programs to the robot and how the robot’s communication is done directly with the user of the robot. The vulnerability was found and could be exploited to some extent. Above all, the network communication between the robot and its API was not encrypted, so all communication could be read. Some parts of the robot have good safety in mind, while other parts show that safety has not been a top priority.
Dagens samhälle blir alltmer uppkopplat, allt för att användarvänligheten ska bara så enkel som möjligt. Men vilka problem de kan leda till ifall det inte görs på ett säkersätt är något som denna uppsats kommer att testa. I denna uppsats görs en cyber säkerhetsanalys av en uppkopplad produkt. Produkten som ska utvärderas är en robot som används genom att ha samtal med användaren. Robotar är idag inget ovanligt, det är något som har länge använts inom industrin men idag kan finnas på många olika ställen i vardagen. Roboten som undersöks i denna uppsats ska via video och ljud interagera med sin användare och förutom att se hur säker roboten är så kommer även användarens integritet att undersökas mot robotens möjliga sårbarheter. Metoden för att undersöka denna robot görs först med en analys av potentiella hot genom att skapa en hot modellering. Efter en hot modellering är skapad testas de mest kritiska sårbarheterna med penetrations testning. Fokusen för att hitta sårbarheter gjordes med anseende på hur roboten kommunicerar över nätverken. Både hur det fungerar för att ladda in olika program till roboten och hur robotens kommunikation görs direkt med användaren av roboten. Sårbarheten hittades och kunde utnyttjas till en viss grad. Framför allt var inte nätverkskommunikationen mellan roboten och dess API krypterat således kunde all kommunikation läsas av. Visa delar av roboten har ett bra säkerhets tänkt samtidigt som andra delar märks det att säkerhet inte har varit högst prioriterat.