Cross-App Interference Threats in Smart Homes: Categorization, Detection and Handling

Cross-App Interference Threats in Smart Homes: Categorization, Detection and Handling
复制标题

DOI:
10.1109/dsn48063.2020.00056
复制
发表时间:
2018-08
期刊:
2020 50th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
通讯作者:
Haotian Chi;Qiang Zeng;Xiaojiang Du;Jiaping Yu
Haotian Chi;Qiang Zeng;Xiaojiang Du;Jiaping Yu
中科院分区:
其他
文献类型:
--
作者:
Haotian Chi;Qiang Zeng;Xiaojiang Du;Jiaping Yu

文献摘要

被引文献

相似文献

物体互联网平台繁荣家庭自动化应用程序(应用程序)。先前的研究涉及应用程序内安全性。我们的工作表明,自动化应用程序甚至单独保护,在相互作用时仍会引起威胁家庭,称为跨应用干扰(CAI)威胁。我们会系统地对这些威胁进行分类,并使用满意度模型理论(SMT)对其进行编码。我们介绍了HomeGuard,这是一种用于检测和处理实际部署中CAI威胁的系统。构建符号执行者是为提取规则语义的构建,并利用仪器在应用程序安装过程中捕获配置。根据SMT模型检查规则和配置,其解决方案表明存在相应的CAI威胁。我们进一步结合了应用程序功能,设备属性和CAI类型,以标记CAI实例的风险水平。在我们的评估中,HomeGuard发现了146个智能市场应用程序中的663个CAI实例,在安装时施加了较小的延迟,并且没有运行时开销。
Internet of Thing platforms prosper home automation applications (apps). Prior research concerns intra-app security. Our work reveals that automation apps, even secured individually, still cause a family of threats when they interplay, termed as Cross-App Interference (CAI) threats. We systematically categorize such threats and encode them using satisfiability modulo theories (SMT). We present HomeGuard, a system for detecting and handling CAI threats in real deployments. A symbolic executor is built to extract rule semantics, and instrumentation is utilized to capture configuration during app installation. Rules and configuration are checked against SMT models, the solutions of which indicate the existence of corresponding CAI threats. We further combine app functionalities, device attributes and CAI types to label the risk level of CAI instances. In our evaluation, HomeGuard discovers 663 CAI instances from 146 SmartThings market apps, imposing minor latency upon app installation and no runtime overhead.