P-Verifier: Understanding and Mitigating Security Risks in Cloud-based IoT Access Policies

P-Verifier: Understanding and Mitigating Security Risks in Cloud-based IoT Access Policies
复制标题

DOI:
10.1145/3548606.3560680
复制
发表时间:
2022-11
期刊:
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Ze Jin;Luyi Xing;Yiwei Fang;Yan Jia;Bin Yuan;Qixu Liu
Ze Jin;Luyi Xing;Yiwei Fang;Yan Jia;Bin Yuan;Qixu Liu
中科院分区:
其他
文献类型:
--
作者:
Ze Jin;Luyi Xing;Yiwei Fang;Yan Jia;Bin Yuan;Qixu Liu

文献摘要

相似文献

现代物联网设备制造商正在利用托管平台即服务(PaaS)和云结构即服务(IaaS)物联网云(例如,AWS IoT、Azure IoT),以实现安全、便捷的物联网开发/部署。物联网访问控制是通过云指定的、云强制执行的物联网访问策略(云标准JSON文档,称为物联网策略)来实现的,这些策略声明了哪些用户可以在哪些约束条件下访问哪些物联网设备/资源。在本文中,我们对现代PaaS/IaaS物联网云上基于云的物联网访问策略的安全性进行了系统的研究。我们的研究表明,物联网语义和政策执行逻辑的复杂性为设备制造商提供了巨大的空间来编程有缺陷的物联网访问策略,引入了复杂的逻辑缺陷,这些缺陷是不可忽视的。除了设计领域的挑战/错误之外,令人惊讶的是,主流设备制造商在部署物联网策略时也普遍犯下严重错误,这要归功于PaaS/IaaS云提供的灵活性以及缺乏标准实践。我们对36家设备制造商和310个开源物联网项目的评估突出了问题的普遍性和严重性,这些问题一旦被利用,可能会对物联网用户的安全性,安全性和隐私产生严重影响。为了帮助制造商识别并轻松修复物联网策略缺陷,我们引入了P-Verifier,这是一种正式的验证工具,可以自动验证基于云的物联网策略。凭借评估的高效率和低性能开销,P-Verifier将有助于提升现代物联网部署和访问控制中的安全保证。我们负责任地向受影响的供应商报告了所有发现,并部署了修复程序或正在进行修复。
Modern IoT device manufacturers are taking advantage of the managed Platform-as-a-Service (PaaS) and Infrastructure-as-a-Service (IaaS) IoT clouds (e.g., AWS IoT, Azure IoT) for secure and convenient IoT development/deployment. The IoT access control is achieved by manufacturer-specified, cloud-enforced IoT access policies (cloud-standard JSON documents, called IoT Policies) stating which users can access which IoT devices/resources under what constraints. In this paper, we performed a systematic study on the security of cloud-based IoT access policies on modern PaaS/IaaS IoT clouds. Our research shows that the complexity in the IoT semantics and enforcement logic of the policies leaves tremendous space for device manufacturers to program a flawed IoT access policy, introducing convoluted logic flaws which are non-trivial to reason about. In addition to challenges/mistakes in the design space, it is astonishing to find that mainstream device manufacturers also generally make critical mistakes in deploying IoT Policies thanks to the flexibility offered by PaaS/IaaS clouds and the lack of standard practices for doing so. Our assessment of 36 device manufacturers and 310 open-source IoT projects highlights the pervasiveness and seriousness of the problems, which once exploited, can have serious impacts on IoT users' security, safety, and privacy. To help manufacturers identify and easily fix IoT Policy flaws, we introduce P-Verifier, a formal verification tool that can automatically verify cloud-based IoT Policies. With evaluated high effectiveness and low performance overhead, P-Verifier will contribute to elevating security assurance in modern IoT deployments and access control. We responsibly reported all findings to affected vendors and fixes were deployed or on the way.