Real-time Analysis of Privacy-(un)aware IoT Applications

11/24/2019
by   Leonardo Babun, et al.
0

Users trust IoT apps to control and automate their smart devices. These apps necessarily have access to sensitive data to implement their functionality. However, users lack visibility into how their sensitive data is used (or leaked), and they often blindly trust the app developers. In this paper, we present IoTWatcH, a novel dynamic analysis tool that uncovers the privacy risks of IoT apps in real-time. We designed and built IoTWatcH based on an IoT privacy survey that considers the privacy needs of IoT users. IoTWatcH provides users with a simple interface to specify their privacy preferences with an IoT app. Then, in runtime, it analyzes both the data that is sent out of the IoT app and its recipients using Natural Language Processing (NLP) techniques. Moreover, IoTWatcH informs the users with its findings to make them aware of the privacy risks with the IoT app. We implemented IoTWatcH on real IoT applications. Specifically, we analyzed 540 IoT apps to train the NLP model and evaluate its effectiveness. IoTWatcH successfully classifies IoT app data sent to external parties to correct privacy labels with an average accuracy of 94.25 Finally, IoTWatcH yields minimal overhead to an IoT app's execution, on average 105 ms additional latency.

READ FULL TEXT
research
06/06/2022

Longitudinal Analysis of Privacy Labels in the Apple App Store

In December of 2020, Apple started to require app developers to annotate...
research
08/06/2018

Cross-App Threats in Smart Homes: Categorization, Detection and Handling

A number of Internet of Things (IoTs) platforms have emerged to enable v...
research
04/26/2018

Enabling Trusted App Development @ The Edge

We present the Databox application development environment or SDK as a m...
research
11/20/2019

Privacy-Preserving Payment Splitting

Widely used payment splitting apps allow members of a group to keep trac...
research
06/16/2020

Bayesian Evaluation of User App Choices in the Presence of Risk Communication on Android Devices

In the age of ubiquitous technologies, security- and privacy-focused cho...
research
04/13/2021

The AppChk Crowd-Sourcing Platform: Which third parties are iOS apps talking to?

In this paper we present a platform which is usable by novice users with...
research
03/25/2022

Rapid prototyping and performance evaluation of MEC-based applications

Multi-access Edge Computing (MEC) will enable context-aware services for...

Please sign up or login with your details

Forgot password? Click here to reset