Understanding IoT Security from a Market-Scale Perspective

Understanding IoT Security from a Market-Scale Perspective
复制标题

DOI:
10.1145/3548606.3560640
复制
发表时间:
2022-11
期刊:
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Xin Jin;Sunil Manandhar;Kaushal Kafle;Zhiqiang Lin;Adwait Nadkarni
Xin Jin;Sunil Manandhar;Kaushal Kafle;Zhiqiang Lin;Adwait Nadkarni
中科院分区:
其他
文献类型:
--
作者:
Xin Jin;Sunil Manandhar;Kaushal Kafle;Zhiqiang Lin;Adwait Nadkarni

文献摘要

被引文献

相似文献

消费类物联网产品和服务无处不在;然而,如果不了解市场上的物联网产品,即没有市场规模的视角,对消费者物联网安全的适当描述是不可实现的。本文试图通过开发IoTSpotter框架来缩小这一差距,该框架自动构建移动物联网应用程序的市场规模快照,即用作物联网设备的伴侣或自动化提供商的移动应用程序。IoTSpotter还提取工件,使我们能够在物联网上下文中检查此快照的安全性(例如,应用程序支持的设备,物联网特定库)。使用IoTSpotter,我们从b谷歌Play中识别了37,783个移动物联网应用程序,这是迄今为止最大的移动物联网应用程序集,并揭示了该过程中的7个关键结果(1- 7)。我们利用此数据集执行三个关键的安全分析,从而得出10个有影响力的安全发现(F1-F10),这些发现展示了移动物联网应用程序的当前状态。我们的分析发现,94.11%(863/917)的移动物联网应用(每个安装量为100万)存在严重的加密违规行为,65个易受攻击的物联网特定库受到79个独特cve的影响,被40个流行应用使用,7887个应用受到Janus漏洞的影响。最后,对18个流行的移动物联网应用程序进行了案例研究,揭示了其中的漏洞对重要物联网工件和功能的关键影响,从而推动了物联网移动安全分析的发展。
Consumer IoT products and services are ubiquitous; yet, a proper characterization of consumer IoT security is infeasible without an understanding of what IoT products are on the market, i.e., without a market-scale perspective. This paper seeks to close this gap by developing the IoTSpotter framework, which automatically constructs a market-scale snapshot of mobile-IoT apps, i.e., mobile apps that are used as companions or automation providers to IoT devices. IoTSpotter also extracts artifacts that allow us to examine the security of this snapshot in the IoT context (e.g., devices supported by apps, IoT-specific libraries). Using IoTSpotter, we identify 37,783 mobile-IoT apps from Google Play, the largest set of mobile-IoT apps so far, and uncover 7 key results in the process (ℛ1-ℛ7). We leverage this dataset to perform three key security analyses that lead to 10 impactful security findings (F1-F10) that demonstrate the current state of mobile-IoT apps. Our analysis uncovers severe cryptographic violations in 94.11% (863/917) mobile-IoT apps with >1 million installs each, 65 vulnerable IoT-specific libraries affected by 79 unique CVEs, and used by 40 popular apps, and 7,887 apps that is affected by the Janus vulnerability. Finally, a case study with 18 popular mobile-IoT apps uncovers the critical impact of the vulnerabilities in them on important IoT artifacts and functions, motivating the development of mobile security analysis contextualized to IoT.