Delay Wreaks Havoc on Your Smart Home: Delay-based Automation Interference Attacks
Haotian Chi, Chenglong Fu, Qiang Zeng, Xiaojiang Du
Abstract
With the proliferation of Internet of Things (IoT) devices and platforms, it becomes a trend that IoT devices associated with different IoT platforms coexist in a smart home, demonstrating the following characteristics. First, a smart home may use more than one platform to support its devices and automation. Second, IoT devices of a home may transmit messages over different paths. By selectively delaying IoT messages, our study finds that two issues, inconsistency and disorder, can be exacerbated by attackers significantly. We then explore how these issues can be exploited and present seven types of exploitation, collectively referred to as Delay-based Automation Interference (DAI) attacks. DAI attacks cause home automation to yield incorrect interaction results, placing the IoT devices and smart home in insecure, unsafe, or unexpected states. It is worth highlighting that DAI attacks do not depend on any IoT implementation vulnerabilities or leaked keys/tokens, and they do not trigger alarms at any layers of the IoT protocol stack. To demonstrate and evaluate the new attacks, we set up two real-world testbeds, where commercial IoT devices and apps are deployed. The week-long experiments from both testbeds show that an attacker has adequate opportunities to launch DAI attacks that cause security or safety issues.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 8ca42482-9075-4aa6-b9b3-b499d11a4b0aCited by top-tier papers8
- From One Thousand Pages of Specification to Unveiling Hidden Bugs: Large Language Model Assisted Fuzzing of Matter IoT DevicesXiaoyue Ma, Lannan Luo, Qiang ZengUSENIX Security 2024 · 49 citations
- Federated IoT Interaction Vulnerability AnalysisGuangjing Wang, Hanqing Guo, Anran Li, Xiaorui Liu et al.ICDE 2023 · 20 citations
- Make Your Home Safe: Time-aware Unsupervised User Behavior Anomaly Detection in Smart Homes via Loss-guided MaskJingyu Xiao, Zhiyao Xu, Qingsong Zou, Qing Li et al.KDD 2024 · 12 citations
- Graph Learning for Interactive Threat Detection in Heterogeneous Smart Home Rule DataGuangjing Wang, Nikolay Ivanov, Bocheng Chen, Qi Wang et al.SIGMOD 2023 · 12 citations
- Perils and Mitigation of Security Risks of Cooperation in Mobile-as-a-Gateway IoTXin'an Zhou, Jiale Guan, Luyi Xing, Zhiyun QianCCS 2022 · 9 citations
Related papers
- Discovering and Understanding the Security Hazards in the Interactions between IoT Devices, Mobile Apps, and Clouds on Smart Home PlatformsWei Zhou, Yan Jia, Yao Yao, Lipeng Zhu et al.USENIX Security 2019 · 160 citations
- Detecting and Handling IoT Interaction Threats in Multi-Platform Multi-Control-Channel Smart HomesHaotian Chi, Qiang Zeng, Xiaojiang DuUSENIX Security 2023
- Discovering and Exploiting IoT Device Hidden Attributes: A New Vulnerability in Smart HomesXuening Xu, Chenglong Fu, Xiaojiang Du, Bo LuoCCS 2025
- Security Checking of Trigger-Action-Programming Smart Home IntegrationsLei Bu, Qiuping Zhang, Suwan Li, Jinglin Dai et al.ISSTA 2023 · 7 citations
- IoTSafe: Enforcing Safety and Security Policy with Real IoT Physical Interaction DiscoveryWenbo Ding, Hongxin Hu, Long ChengNDSS 2021
