PFirewall: Semantics-Aware Customizable Data Flow Control for Home Automation Systems

10/17/2019
by   Haotian Chi, et al.
0

Emerging Internet of Thing (IoT) platforms provide a convenient solution for integrating heterogeneous IoT devices and deploying home automation applications. However, serious privacy threats arise as device data now flow out to the IoT platforms, which may be subject to various attacks. We observe two privacy-unfriendly practices in emerging home automation systems: first, the majority of data flowed to the platform are superfluous in the sense that they do not trigger any home automation; second, home owners currently have nearly zero control over their data. We present PFirewall, a customizable data-flow control system to enhance user privacy. PFirewall analyzes the automation apps to extract their semantics, which are automatically transformed into data-minimization policies; these policies only send minimized data flows to the platform for app execution, such that the ability of attackers to infer user privacy is significantly impaired. In addition, PFirewall provides capabilities and interfaces for users to define and enforce customizable policies based on individual privacy preferences. PFirewall adopts an elegant man-in-the-middle design, transparently executing data minimization and user-defined policies to process raw data flows and mediating the processed data between IoT devices and the platform (via the hub), without requiring modifications of the platform or IoT devices. We implement PFirewall to work with two popular platforms: SmartThings and openHAB, and set up two real-world testbeds to evaluate its performance. The evaluation results show that PFirewall is very effective: it reduces IoT data sent to the platform by 97

READ FULL TEXT

page 1

page 14

research
01/26/2021

PFirewall: Semantics-Aware Customizable Data Flow Control for Smart Home Privacy Protection

Internet of Things (IoT) platforms enable users to deploy home automatio...
research
06/11/2020

Sovereign: User-Controlled Smart Homes

Smart homes made up of Internet of Things (IoT) devices have seen wide d...
research
04/16/2022

A User Study to Evaluate a Web-based Prototype for Smart Home Internet of Things Device Management

With the growing advances in the Internet of Things (IoT) technology, Io...
research
05/14/2018

LUCON: Data Flow Control for Message-Based IoT Systems

Today's emerging Industrial Internet of Things (IIoT) scenarios are char...
research
02/08/2019

Privacy Leakage in Smart Homes and Its Mitigation: IFTTT as a Case Study

The combination of smart home platforms and automation apps introduces m...
research
02/09/2018

Running Distributed and Dynamic IoT Choreographies

IoT systems are growing larger and larger and are becoming suitable for ...
research
12/04/2018

A Study of Data Store-based Home Automation

Home automation platforms provide a new level of convenience by enabling...

Please sign up or login with your details

Forgot password? Click here to reset