Looking from the Mirror: Evaluating IoT Device Security through Mobile Companion Apps
Xueqiang Wang, Yuqiong Sun, Susanta Nanda, XiaoFeng Wang
摘要
Smart home IoT devices have increasingly become a favorite target for the cybercriminals due to their weak security designs. To identify these vulnerable devices, existing approaches rely on the analysis of either real devices or their firmware images. These approaches, unfortunately, are difficult to scale in the highly fragmented IoT market due to the unavailability of firmware images and the high cost involved in acquiring real-world devices for security analysis. In this paper, we present a platform that accelerates vulnerable device discovery and analysis, without requiring the presence of actual devices or firmware. Our approach is based on two key observations: First, IoT devices tend to reuse and customize others' components (e.g., software, hardware, protocol, and services), so vulnerabilities found in one device are often present in others. Second, reused components can be indirectly inferred from the mobile companion apps of the devices; so a cross analysis of mobile companion apps may allow us to approximate the similarity between devices. Using a suite of program analysis techniques, our platform analyzes mobile companion apps of smart home IoT devices on market and automatically discovers potentially vulnerable ones, allowing us to perform a large-scale analysis involving over 4,700 devices. Our study brings to light the sharing of vulnerable components across the smart home IoT devices (e.g., shared vulnerable protocol, backend services, device rebranding), and leads to the discovery of 324 devices from 73 different vendors that are likely to be vulnerable to a set of security issues.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper18
- Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile AppsChaoshun Zuo, Haohuang Wen, Zhiqiang Lin, Yinqian ZhangCCS 2019 · 被引用 77 次
- Diane: Identifying Fuzzing Triggers in Apps to Generate Under-constrained Inputs for IoT DevicesNilo Redini, Andrea Continella, Dipanjan Das, Giulio De Pasquale 等S&P 2021 · 被引用 72 次
- Understanding IoT Security from a Market-Scale PerspectiveXin Jin, Sunil Manandhar, Kaushal Kafle, Zhiqiang Lin 等CCS 2022 · 被引用 30 次
- IFIZZ: Deep-State and Efficient Fault-Scenario Generation to Test IoT FirmwarePeiyu Liu, Shouling Ji, Xuhong Zhang, Qinming Dai 等ASE 2021 · 被引用 16 次
- IoTFlow: Inferring IoT Device Behavior at Scale through Static Mobile Companion App AnalysisDavid Schmidt, Carlotta Tagliaro, Kevin Borgolte, Martina LindorferCCS 2023 · 被引用 13 次
它引用的顶会 Paper7
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard 等USENIX Security 2017 · 被引用 2,003 次
- Scalable Graph-based Bug Search for Firmware ImagesQian Feng, Rundong Zhou, Chengcheng Xu, Yao Cheng 等CCS 2016 · 被引用 456 次
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 被引用 428 次
- What You Corrupt Is Not What You Crash: Challenges in Fuzzing Embedded DevicesMarius Muench, Jan Stijohann, Frank Kargl, Aurélien Francillon 等NDSS 2018 · 被引用 202 次
- Harvesting Runtime Values in Android Applications That Feature Anti-Analysis TechniquesSiegfried Rasthofer, Steven Arzt, Marc Miltenberger, Eric BoddenNDSS 2016 · 被引用 157 次
相关 Paper
- Discovering and Understanding the Security Hazards in the Interactions between IoT Devices, Mobile Apps, and Clouds on Smart Home PlatformsWei Zhou, Yan Jia, Yao Yao, Lipeng Zhu 等USENIX Security 2019 · 被引用 160 次
- Are You Spying on Me? Large-Scale Analysis on IoT Data Exposure through Companion AppsYuhong Nan, Xueqiang Wang, Luyi Xing, Xiaojing Liao 等USENIX Security 2023
- FirmProj: Detecting Firmware Leakage in IoT Update Processes via Companion App AnalysisWenzhi Li, Jialong Guo, Jiongyi Chen, Fan Li 等ASE 2025
- A large-scale empirical analysis of the vulnerabilities introduced by third-party components in IoT firmwareBinbin Zhao, Shouling Ji, Jiacheng Xu, Yuan Tian 等ISSTA 2022 · 被引用 49 次
- Scalable analysis of interaction threats in IoT systemsMohannad Alhanahnah, Clay Stevens, Hamid BagheriISSTA 2020 · 被引用 63 次
