ContexloT: Towards Providing Contextual Integrity to Appified IoT Platforms

ContexloT: Towards Providing Contextual Integrity to Appified IoT Platforms
复制标题

DOI:
10.14722/ndss.2017.23051
复制
发表时间:
2017
期刊:
--
影响因子:
--
通讯作者:
Yunhan Jia;Qi Alfred Chen;Shiqi Wang;Amir Rahmati;Earlence Fernandes;Z. Morley Mao;A. Prakash
Yunhan Jia;Qi Alfred Chen;Shiqi Wang;Amir Rahmati;Earlence Fernandes;Z. Morley Mao;A. Prakash
中科院分区:
其他
文献类型:
--
作者:
Yunhan Jia;Qi Alfred Chen;Shiqi Wang;Amir Rahmati;Earlence Fernandes;Z. Morley Mao;A. Prakash

文献摘要

被引文献

相似文献

物联网(IoT)已迅速发展到一个新的应用化时代,第三方开发者可以使用编程框架为物联网平台编写应用程序。与其他应用化平台(例如智能手机平台)一样,权限系统在平台安全中起着重要作用。然而,近期有报道称当前物联网平台权限模型存在设计缺陷,使用户面临诸如入室盗窃等重大危害。为了解决这些问题,当前和未来的物联网平台都需要一种新的访问控制模型。在本文中,我们提出了ContexIoT,这是一种用于应用化物联网平台的基于情境的权限系统,它通过支持对敏感操作进行细粒度的情境识别以及提供带有丰富情境信息的运行时提示来帮助用户进行有效的访问控制,从而提供情境完整性。ContexIoT中的情境定义处于过程间控制和数据流级别,我们表明它比之前针对智能手机平台的基于情境的权限系统更全面。ContexIoT被设计为向后兼容,因此可被当前的物联网平台直接采用。我们在三星SmartThings平台上对ContexIoT进行了原型设计,并开发了一种自动应用程序补丁机制以支持未修改的商品SmartThings应用程序。为了评估该系统的有效性,我们通过重现已报道的物联网攻击并基于智能手机恶意软件类别构建新的物联网攻击,对应用化物联网平台可能遭受的攻击进行了首次广泛研究。我们根据生命周期和攻击者技术对这些攻击进行分类,并构建了第一个分类的物联网攻击应用数据集。在该数据集上对ContexIoT进行评估,我们发现它能够有效区分所有测试应用程序的攻击情境。对283个商品物联网应用程序的性能评估表明,应用程序补丁对事件触发延迟增加的延迟几乎可以忽略不计,并且权限请求频率远低于被认为可能使用户习惯或厌烦的阈值。
The Internet-of-Things (IoT) has quickly evolved to a new appified era where third-party developers can write apps for IoT platforms using programming frameworks. Like other appified platforms, e.g., the smartphone platform, the permission system plays an important role in platform security. However, design flaws in current IoT platform permission models have been reported recently, exposing users to significant harm such as break-ins and theft. To solve these problems, a new access control model is needed for both current and future IoT platforms. In this paper, we propose ContexIoT, a context-based permission system for appified IoT platforms that provides contextual integrity by supporting fine-grained context identification for sensitive actions, and runtime prompts with rich context information to help users perform effective access control. Context definition in ContexIoT is at the inter-procedure control and data flow levels, that we show to be more comprehensive than previous context-based permission systems for the smartphone platform. ContexIoT is designed to be backward compatible and thus can be directly adopted by current IoT platforms. We prototype ContexIoT on the Samsung SmartThings platform, with an automatic app patching mechanism developed to support unmodified commodity SmartThings apps. To evaluate the system’s effectiveness, we perform the first extensive study of possible attacks on appified IoT platforms by reproducing reported IoT attacks and constructing new IoT attacks based on smartphone malware classes. We categorize these attacks based on lifecycle and adversary techniques, and build the first taxonomized IoT attack app dataset. Evaluating ContexIoT on this dataset, we find that it can effectively distinguish the attack context for all the tested apps. The performance evaluation on 283 commodity IoT apps shows that the app patching adds nearly negligible delay to the event triggering latency, and the permission request frequency is far below the threshold that is considered to risk user habituation or annoyance.