Cross-App Threats in Smart Homes: Categorization, Detection and Handling

08/06/2018
by   Haotian Chi, et al.
0

A number of Internet of Things (IoTs) platforms have emerged to enable various IoT apps developed by third-party developers to automate smart homes. Prior research mostly concerns the overprivilege problem in the permission model. Our work, however, reveals that even IoT apps that follow the principle of least privilege, when they interplay, can cause a unique type of threats, named Cross-App Interference (CAI) threats. We describe and categorize the new threats, showing that unexpected automation and security and privacy issues may be caused by such threats, which cannot be handled by existing IoT security mechanisms. To address the problem, we present HOMEGUARD, a system for appified IoT platforms to detect and cope with CAI threats. A symbolic executor module is built to precisely extract the automation semantics from IoT apps. The semantics of different IoT apps are then considered collectively to evaluate their interplay and discover CAI threats systematically. A user interface is presented to users during IoT app installation, interpreting the discovered threats to help them make decisions. We evaluate HOMEGUARD via a proof-of-concept implementation on Samsung's SmartThings, and discover many threat instances among apps in the SmartThings public repository. The evaluation shows that it is precise, effective and efficient.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/06/2018

Cross-App Interference Threats in Smart Homes: Categorization, Detection and Handling

A number of Internet of Things (IoTs) platforms have emerged to enable v...
research
06/29/2020

IoTGaze: IoT Security Enforcement via Wireless Context Analysis

Internet of Things (IoT) has become the most promising technology for se...
research
06/13/2023

SoK: Decoding the Super App Enigma: The Security Mechanisms, Threats, and Trade-offs in OS-alike Apps

The super app paradigm, exemplified by platforms such as WeChat and AliP...
research
11/24/2019

Real-time Analysis of Privacy-(un)aware IoT Applications

Users trust IoT apps to control and automate their smart devices. These ...
research
02/09/2018

The Effect of IoT New Features on Security and Privacy: New Threats, Existing Solutions, and Challenges Yet to Be Solved

The future of Internet of Things (IoT) is already upon us. IoT applicati...
research
03/08/2022

Analyzing the Security of the Business Collaboration Platform App Model

Business Collaboration Platforms like Microsoft Teams and Slack enable t...
research
06/05/2023

Sustainable Adaptive Security

With software systems permeating our lives, we are entitled to expect th...

Please sign up or login with your details

Forgot password? Click here to reset