USENIX Security2021Top-tier venue
Capture: Centralized Library Management for Heterogeneous IoT Devices
Han Zhang, Abhijith Anilkumar, Matt Fredrikson, Yuvraj Agarwal
Abstract
With their growing popularity, Internet-of-Things (IoT) devices have become attractive targets for attack. Like most modern software systems, IoT device firmware depends on external third-party libraries extensively, increasing the attack surface of IoT devices. Furthermore, we find that the risk is compounded by inconsistent library management practices and delays in applying security updates-sometimes hundreds of days behind the public availability of critical patches-by device vendors. Worse yet, because these dependencies are "baked into" the vendor-controlled firmware, even security-conscious users are unable to take matters into their own hands when it comes to good security hygiene.
We present Capture, a novel architecture for deploying IoT device firmware that addresses this problem by allowing devices on a local network to leverage a centralized hub with third-party libraries that are managed and kept up-to-date by a single trusted entity. An IoT device supporting Capture comprises of two components: Capture-enabled firmware on the device and a remote driver that uses third-party libraries on the Capture hub in the local network. To ensure isolation, we introduce a novel Virtual Device Entity (VDE) interface that facilitates access control between mutually-distrustful devices that reside on the same hub. Our evaluation on a prototype implementation of Capture, along with 9 devices and 3 automation applets ported to our framework, shows that our approach incurs low overhead in most cases (<15% increased latency, <10% additional resources). We show that a single Capture Hub with modest hardware can support hundreds of devices, keeping their shared libraries up-to-date.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 528a9276-d240-400d-9525-548b5406a05eCited by top-tier papers4
- ModX: Binary Level Partially Imported Third-Party Library Detection via Program Modularization and Semantic MatchingCan Yang, Zhengzi Xu, Hongxu Chen, Yang Liu et al.ICSE 2022 · 43 citations
- Peekaboo: A Hub-Based Approach to Enable Transparency in Data Processing within Smart HomesHaojian Jin, Gram Liu, David Hwang, Swarun Kumar et al.S&P 2022 · 25 citations
- dSpace: Composable Abstractions for Smart SpacesSilvery Fu, Sylvia RatnasamySOSP 2021 · 11 citations
- Repurposing Neural Networks for Efficient Cryptographic ComputationXin Jin, Shiqing Ma, Zhiqiang LinNDSS 2025
Builds on10
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 428 citations
- SoK: Security Evaluation of Home-Based IoT DeploymentsOmar Alrawi, Chaz Lever, Manos Antonakakis, Fabian MonroseS&P 2019 · 411 citations
- FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process EmulationYaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song et al.USENIX Security 2019 · 279 citations
- HoMonit: Monitoring Smart Home Apps from Encrypted TrafficWei Zhang, Yan Meng, Yugeng Liu, Xiaokuan Zhang et al.CCS 2018 · 201 citations
Related papers
- Dominance as a New Trusted Computing Primitive for the Internet of ThingsMeng Xu, Manuel Huber, Zhichuang Sun, Paul England et al.S&P 2019 · 61 citations
- Bridge: High-Order Taint Vulnerabilities Detection in Linux-Based IoT FirmwareJiaqian Peng, Puzhuo Liu, Yicheng Zeng, Kai Cheng et al.S&P 2026 · 1 citation
- Security in the Air: Understanding IoT Vendor Practices and the Economics of Over-the-Air UpdatesHuancheng Hu, Christian DoerrUSENIX Security 2026
- Facilitating Non-Intrusive In-Vivo Firmware Testing with Stateless InstrumentationJiameng Shi, Wenqiang Li, Wenwen Wang, Le GuanNDSS 2024
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo et al.NDSS 2018 · 311 citations
