Security Checking of Trigger-Action-Programming Smart Home Integrations
Lei Bu, Qiuping Zhang, Suwan Li, Jinglin Dai, Guangdong Bai, Kai Chen, Xuandong Li
Abstract
Internet of Things (IoT) has become prevalent in various fields, especially in the context of home automation (HA). To better control HA-IoT devices, especially to integrate several devices for rich smart functionalities, trigger-action programming, such as the If This Then That (IFTTT), has become a popular paradigm. Leveraging it, novice users can easily specify their intent in applets regarding how to control a device/service through another once a specific condition is met. Nevertheless, the users may design IFTTT-style integrations inappropriately, due to lack of security experience or unawareness of the security impact of cyber-attacks against individual devices. This has caused financial loss, privacy leakage, unauthorized access and other security issues. To address these problems, this work proposes a systematic framework named MEDIC to model smart home integrations and check their security. It automatically generates models incorporating the service/device behaviors and action rules of the applets, while taking into consideration the external attacks and in-device vulnerabilities. Our approach takes around one second to complete the modeling and checking of one integration. We carried out experiments based on 200 integrations created from a user study and a dataset crawled from ifttt.com. To our great surprise, nearly 83% of these integrations have security issues.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 8fa5330d-c36a-4b7e-b701-437b8f9a3d05Cited by top-tier papers1
Ask how each one uses itRelated papers
- Temporal Specification Oriented Fuzzing for Trigger-Action-Programming Smart Home IntegrationsJinglin Dai, Yifan Xiong, Lezhi Ma, Shangqing Liu et al.ICSE 2026
- Charting the Attack Surface of Trigger-Action IoT PlatformsQi Wang, Pubali Datta, Wei Yang, Si Liu et al.CCS 2019 · 162 citations
- Identifying privacy weaknesses from multi-party trigger-action integration platformsKulani Mahadewa, Yanjun Zhang, Guangdong Bai, Lei Bu et al.ISSTA 2021 · 25 citations
- If This Then What?: Controlling Flows in IoT AppsIulia Bastys, Musard Balliu, Andrei SabelfeldCCS 2018 · 119 citations
- TAPFixer: Automatic Detection and Repair of Home Automation Vulnerabilities based on Negated-property ReasoningYinbo Yu, Yuanqi Xu, Kepu Huang, Jiajia LiuUSENIX Security 2024 · 6 citations
