Lune

WWW2024顶会

Don't Bite Off More than You Can Chew: Investigating Excessive Permission Requests in Trigger-Action Integrations

Liuhuo Wan, Kailong Wang, Kulani Mahadewa, Haoyu Wang, Guangdong Bai

2024年份
4被引次数
1顶会引用

摘要

Web-based trigger-action platforms (TAP) allow users to integrate Internet of Things (IoT) systems and online services into triggeraction integrations (TAIs), facilitating rich automation tasks known as applets. Despite their benefits, these integrations (typically involving the TAP, trigger, and action service providers) pose significant security and privacy challenges, such as mis-triggering and data leakage. This work investigates cross-entity permission management within TAIs to address the underlying causes of these security and privacy issues, emphasizing permission-functionality consistency to ensure fairness in permission requests. We introduce PFCon, a system that leverages GPT-based language models for analyzing required and requested permissions, revealing excessive permission requests in a large-scale study of IFTTT TAP. Our findings highlight the need for service providers to enforce permission-functionality consistency, raising awareness of the importance of security and privacy in TAI. CCS CONCEPTS • Security and privacy → Web application security; • Networks → Network privacy and anonymity.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext 110f98d5-e839-419c-a31e-5fa67f6135ad

引用它的顶会 Paper1

问问它们各自怎么用它

它引用的顶会 Paper17

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖