A Mutation Framework for Evaluating Security Analysis tools in IoT Applications

10/11/2021
by   Manar H. Alalfi, et al.
0

With the growing and widespread use of Internet of Things (IoT) in our daily life, its security is becoming more crucial. To ensure information security, we require better security analysis tools for IoT applications. Hence, this paper presents an automated framework to evaluate taint-flow analysis tools in the domain of IoT applications. First, we propose a set of mutational operators tailored to evaluate three types of sensitivity analysis, flow, path and context sensitivity. Then we developed mutators to automatically generate mutants for those types. We demonstrated the framework on a subset of mutational operators to evaluate three taint-flow analyzers, SaINT, Taint-Things and FlowsMiner. Our framework and experiments ranked the taint analysis tools according to precision and recall as follows: Taint-Things (99 Recall, 100 (100 the first framework to address the need for evaluating taint-flow analysis tools and specifically those developed for IoT SmartThings applications.

READ FULL TEXT

page 24

page 30

research
02/07/2022

An Automated Approach for Privacy Leakage Identification in IoT Apps

This paper presents a fully automated static analysis approach and a too...
research
11/30/2021

A Mathematical Framework for Evaluation of SOAR Tools with Limited Survey Data

Security operation centers (SOCs) all over the world are tasked with rea...
research
09/19/2021

A domain-specific modeling and analysis environment for complex IoT applications

To cope with the complexities found in the Internet of Things domain, de...
research
07/19/2023

Analyzing IoT Hosts in the IPv6 Internet

Users and businesses are increasingly deploying Internet of Things (IoT)...
research
07/29/2022

Effectiveness of Transformer Models on IoT Security Detection in StackOverflow Discussions

The Internet of Things (IoT) is an emerging concept that directly links ...
research
08/10/2018

A Security Analysis of IoT Encryption: Side-channel Cube Attack on Simeck32/64

Simeck, a lightweight block cipher has been proposed to be one of the en...
research
11/03/2021

IoT to monitor people flow in areas of public interest

The unexpected historical period we are living has abruptly pushed us to...

Please sign up or login with your details

Forgot password? Click here to reset