Discovering IoT Physical Channel Vulnerabilities
Muslum Ozgur Ozmen, Xuansong Li, Andrew Chu, Z. Berkay Celik, Bardh Hoxha, Xiangyu Zhang
Abstract
Smart homes contain diverse sensors and actuators controlled by IoT apps that provide custom automation. Prior works showed that an adversary could exploit physical interaction vulnerabilities among apps and put the users and environment at risk, e.g., to break into a house, an adversary turns on the heater to trigger an app that opens windows when the temperature exceeds a threshold. Currently, the safe behavior of physical interactions relies on either app code analysis or dynamic analysis of device states with manually derived policies by developers. However, existing works fail to achieve sufficient breadth and fidelity to translate the app code into their physical behavior or provide incomplete security policies, causing poor accuracy and false alarms. In this paper, we introduce a new approach, IoTSeer, which efficiently combines app code analysis and dynamic analysis with new security policies to discover physical interaction vulnerabilities. IoTSeer works by first translating sensor events and actuator commands of each app into a physical execution model (PeM) and unifying PeMs to express composite physical execution of apps (CPeM). CPeM allows us to deploy IoTSeer in different smart homes by defining its execution parameters with minimal data collection. IoTSeer supports new security policies with intended/unintended physical channel labels. It then efficiently checks them on the CPeM via falsification, which addresses the undecidability of verification due to the continuous and discrete behavior of IoT devices. We evaluate IoTSeer in an actual house with 14 actuators, six sensors, and 39 apps. IoTSeer discovers 16 unique policy violations, whereas prior works identify only 2 out of 16 with 18 falsely flagged violations. IoTSeer only requires 30 mins of data collection for each actuator to set the CPeM parameters and is adaptive to newly added, removed, and relocated devices.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext aeae3a2c-c619-472e-8179-7ed68464b910Cited by top-tier papers5
- TAPFixer: Automatic Detection and Repair of Home Automation Vulnerabilities based on Negated-property ReasoningYinbo Yu, Yuanqi Xu, Kepu Huang, Jiajia LiuUSENIX Security 2024 · 6 citations
- Cyber-Physical Deception Through Coordinated IoT HoneypotsChongqi Guan, Guohong CaoUSENIX Security 2025
- Evasion Attacks and Defenses on Smart Home Physical Event VerificationMuslum Ozgur Ozmen, Ruoyu Song, Habiba Farrukh, Z. Berkay CelikNDSS 2023
- Acoustic Keystroke Leakage on Smart TelevisionsTejas Kannan, Synthia Qia Wang, Max Sunog, Abraham Bueno de Mesquita et al.NDSS 2024
- Discovering Adversarial Driving Maneuvers against Autonomous VehiclesRuoyu Song, Muslum Ozgur Ozmen, Hyungsub Kim, Raymond Muller et al.USENIX Security 2023
Builds on9
- IoTGuard: Dynamic Enforcement of Security and Safety Policy in Commodity IoTZ. Berkay Celik, Gang Tan, Patrick D. McDanielNDSS 2019 · 254 citations
- SmartAuth: User-Centered Authorization for the Internet of ThingsYuan Tian, Nan Zhang, Yue-Hsun Lin, XiaoFeng Wang et al.USENIX Security 2017 · 231 citations
- On the Safety of IoT Device Physical Interaction ControlWenbo Ding, Hongxin HuCCS 2018 · 169 citations
- Charting the Attack Surface of Trigger-Action IoT PlatformsQi Wang, Pubali Datta, Wei Yang, Si Liu et al.CCS 2019 · 162 citations
- HAWatcher: Semantics-Aware Anomaly Detection for Appified Smart HomesChenglong Fu, Qiang Zeng, Xiaojiang DuUSENIX Security 2021 · 109 citations
Related papers
- IoTSafe: Enforcing Safety and Security Policy with Real IoT Physical Interaction DiscoveryWenbo Ding, Hongxin Hu, Long ChengNDSS 2021
- Scalable analysis of interaction threats in IoT systemsMohannad Alhanahnah, Clay Stevens, Hamid BagheriISSTA 2020 · 63 citations
- Detecting and Handling IoT Interaction Threats in Multi-Platform Multi-Control-Channel Smart HomesHaotian Chi, Qiang Zeng, Xiaojiang DuUSENIX Security 2023
- Looking from the Mirror: Evaluating IoT Device Security through Mobile Companion AppsXueqiang Wang, Yuqiong Sun, Susanta Nanda, XiaoFeng WangUSENIX Security 2019 · 65 citations
- Discovering and Understanding the Security Hazards in the Interactions between IoT Devices, Mobile Apps, and Clouds on Smart Home PlatformsWei Zhou, Yan Jia, Yao Yao, Lipeng Zhu et al.USENIX Security 2019 · 160 citations
