Don't Bite Off More than You Can Chew: Investigating Excessive Permission Requests in Trigger-Action Integrations
Liuhuo Wan, Kailong Wang, Kulani Mahadewa, Haoyu Wang, Guangdong Bai
摘要
Web-based trigger-action platforms (TAP) allow users to integrate Internet of Things (IoT) systems and online services into triggeraction integrations (TAIs), facilitating rich automation tasks known as applets. Despite their benefits, these integrations (typically involving the TAP, trigger, and action service providers) pose significant security and privacy challenges, such as mis-triggering and data leakage. This work investigates cross-entity permission management within TAIs to address the underlying causes of these security and privacy issues, emphasizing permission-functionality consistency to ensure fairness in permission requests. We introduce PFCon, a system that leverages GPT-based language models for analyzing required and requested permissions, revealing excessive permission requests in a large-scale study of IFTTT TAP. Our findings highlight the need for service providers to enforce permission-functionality consistency, raising awareness of the importance of security and privacy in TAI. CCS CONCEPTS • Security and privacy → Web application security; • Networks → Network privacy and anonymity.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper17
- Chain-of-Thought Prompting Elicits Reasoning in Large Language ModelsJason Wei, Xuezhi Wang, Dale Schuurmans, Maarten Bosma 等NeurIPS 2022 · 被引用 22,562 次
- ContexloT: Towards Providing Contextual Integrity to Appified IoT PlatformsYunhan Jack Jia, Qi Alfred Chen, Shiqi Wang, Amir Rahmati 等NDSS 2017 · 被引用 325 次
- Sensitive Information Tracking in Commodity IoTZ. Berkay Celik, Leonardo Babun, Amit Kumar Sikder, Hidayet Aksu 等USENIX Security 2018 · 被引用 236 次
- Fear and Logging in the Internet of ThingsQi Wang, Wajih Ul Hassan, Adam Bates, Carl A. GunterNDSS 2018 · 被引用 205 次
- Charting the Attack Surface of Trigger-Action IoT PlatformsQi Wang, Pubali Datta, Wei Yang, Si Liu 等CCS 2019 · 被引用 162 次
相关 Paper
- Identifying privacy weaknesses from multi-party trigger-action integration platformsKulani Mahadewa, Yanjun Zhang, Guangdong Bai, Lei Bu 等ISSTA 2021 · 被引用 25 次
- Practical Data Access Minimization in Trigger-Action PlatformsYunang Chen, Mohannad Alhanahnah, Andrei Sabelfeld, Rahul Chatterjee 等USENIX Security 2022
- Decentralized Action Integrity for Trigger-Action IoT PlatformsEarlence Fernandes, Amir Rahmati, Jaeyeon Jung, Atul PrakashNDSS 2018 · 被引用 14 次
- Data Privacy in Trigger-Action SystemsYunang Chen, Amrita Roy Chowdhury, Ruizhe Wang, Andrei Sabelfeld 等S&P 2021 · 被引用 22 次
- TKPERM: Cross-platform Permission Knowledge Transfer to Detect Overprivileged Third-party ApplicationsFaysal Hossain Shezan, Kaiming Cheng, Zhen Zhang, Yinzhi Cao 等NDSS 2020
