Identifying privacy weaknesses from multi-party trigger-action integration platforms
Kulani Mahadewa, Yanjun Zhang, Guangdong Bai, Lei Bu, Zhiqiang Zuo, Dileepa Fernando, Zhenkai Liang, Jin Song Dong
Abstract
With many trigger-action platforms that integrate Internet of Things (IoT) systems and online services, rich functionalities transparently connecting digital and physical worlds become easily accessible for the end users. On the other hand, such facilities incorporate multiple parties whose data control policies may radically differ and even contradict each other, and thus privacy violations may arise throughout the lifecycle (e.g., generation and transmission) of triggers and actions. In this work, we conduct an in-depth study on the privacy issues in multi-party trigger-action integration platforms (TAIPs). We first characterize privacy violations that may arise with the integration of heterogeneous systems and services. Based on this knowledge, we propose Taifu, a dynamic testing approach to identify privacy weaknesses from the TAIP. The key insight of Taifu is that the applets which actually program the trigger-action rules can be used as test cases to explore the behavior of the TAIP. We evaluate the effectiveness of our approach by applying it on the TAIPs that are built around the IFTTT platform. To our great surprise, we find that privacy violations are prevalent among them. Using the automatically generated 407 applets, each from a different TAIP, Taifu detects 194 cases with access policy breaches, 218 access control missing, 90 access revocation missing, 15 unintended flows, and 73 over-privilege access.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8fda2caa-87cb-4034-bd65-587978ae6014Cited by top-tier papers5
- Graph-based seed object synthesis for search-based unit testingYun Lin, You Sheng Ong, Jun Sun, Gordon Fraser et al.FSE 2021 · 34 citations
- Is It Safe to Share Your Files? An Empirical Security Analysis of Google WorkspaceLiuhuo Wan, Kailong Wang, Haoyu Wang, Guangdong BaiWWW 2024 · 6 citations
- Don't Bite Off More than You Can Chew: Investigating Excessive Permission Requests in Trigger-Action IntegrationsLiuhuo Wan, Kailong Wang, Kulani Mahadewa, Haoyu Wang et al.WWW 2024 · 4 citations
- CP-IoT: A Cross-Platform Monitoring System for Smart HomeHai Lin, Chenglong Li, Jiahai Yang, Zhiliang Wang et al.NDSS 2024
- Post-GDPR Threat Hunting on Android Phones: Dissecting OS-level Safeguards of User-unresettable IdentifiersMark Huasong Meng, Qing Zhang, Guangshuai Xia, Yuwei Zheng et al.NDSS 2023
Builds on16
- Security Analysis of Emerging Smart Home ApplicationsEarlence Fernandes, Jaeyeon Jung, Atul PrakashS&P 2016 · 684 citations
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo et al.NDSS 2018 · 311 citations
- FlowFence: Practical Data Protection for Emerging IoT Application FrameworksEarlence Fernandes, Justin Paupore, Amir Rahmati, Daniel Simionato et al.USENIX Security 2016 · 296 citations
- IoTGuard: Dynamic Enforcement of Security and Safety Policy in Commodity IoTZ. Berkay Celik, Gang Tan, Patrick D. McDanielNDSS 2019 · 254 citations
- Sensitive Information Tracking in Commodity IoTZ. Berkay Celik, Leonardo Babun, Amit Kumar Sikder, Hidayet Aksu et al.USENIX Security 2018 · 236 citations
Related papers
- Practical Data Access Minimization in Trigger-Action PlatformsYunang Chen, Mohannad Alhanahnah, Andrei Sabelfeld, Rahul Chatterjee et al.USENIX Security 2022
- Security Checking of Trigger-Action-Programming Smart Home IntegrationsLei Bu, Qiuping Zhang, Suwan Li, Jinglin Dai et al.ISSTA 2023 · 7 citations
- If This Then What?: Controlling Flows in IoT AppsIulia Bastys, Musard Balliu, Andrei SabelfeldCCS 2018 · 119 citations
- Decentralized Action Integrity for Trigger-Action IoT PlatformsEarlence Fernandes, Amir Rahmati, Jaeyeon Jung, Atul PrakashNDSS 2018 · 14 citations
- Data Privacy in Trigger-Action SystemsYunang Chen, Amrita Roy Chowdhury, Ruizhe Wang, Andrei Sabelfeld et al.S&P 2021 · 22 citations
