Security Analysis of IoT Frameworks using Static Taint Analysis

Security Analysis of IoT Frameworks using Static Taint Analysis
复制标题

DOI:
10.1145/3508398.3511511
复制
发表时间:
2022-04
期刊:
Proceedings of the Twelfth ACM Conference on Data and Application Security and Privacy
影响因子:
--
通讯作者:
Tuba Yavuz;Christopher Brant
Tuba Yavuz;Christopher Brant
中科院分区:
其他
文献类型:
--
作者:
Tuba Yavuz;Christopher Brant

文献摘要

相似文献

物联网(IoT)框架旨在促进IoT设备的配置和安全操作。典型的物联网框架由各种软件层和组件组成,包括第三方库、通信协议栈、硬件抽象层(HAL)、内核和应用程序。由于其事件驱动的性质,物联网框架除了显式数据流之外还具有隐式数据流。在本文中,我们提出了一个静态的污点跟踪框架,IFLOW,有利于系统代码的安全性分析,使规范的数据流查询,可以参考各种软件实体。我们已经制定了各种安全相关的数据流查询,并使用IFLOW来分析几个流行的物联网框架的安全性:Amazon FreeRTOS SDK,SmartThings SDK和Google IoT SDK。我们的研究结果表明,IFLOW既可以检测到真实的错误,又可以将安全分析定位到物联网框架的相关组件。
Internet of Things (IoT) frameworks are designed to facilitate provisioning and secure operation of IoT devices. A typical IoT framework consists of various software layers and components including third-party libraries, communication protocol stacks, the Hardware Abstraction Layer (HAL), the kernel, and the apps. IoT frameworks have implicit data flows in addition to explicit data flows due to their event-driven nature. In this paper, we present a static taint tracking framework, IFLOW, that facilitates the security analysis of system code by enabling specification of data-flow queries that can refer to a variety of software entities. We have formulated various security relevant data-flow queries and solved them using IFLOW to analyze the security of several popular IoT frameworks: Amazon FreeRTOS SDK, SmartThings SDK, and Google IoT SDK. Our results show that IFLOW can both detect real bugs and localize security analysis to the relevant components of IoT frameworks.