Lune

CCS2019顶会

Charting the Attack Surface of Trigger-Action IoT Platforms

Qi Wang, Pubali Datta, Wei Yang, Si Liu, Adam Bates, Carl A. Gunter

2019年份
162被引次数
30顶会引用

摘要

Internet of Things (IoT) deployments are becoming increasingly automated and vastly more complex. Facilitated by programming abstractions such as trigger-action rules, end-users can now easily create new functionalities by interconnecting their devices and other online services. However, when multiple rules are simultaneously enabled, complex system behaviors arise that are diicult to understand or diagnose. While history tells us that such conditions are ripe for exploitation, at present the security states of trigger-action IoT deployments are largely unknown. In this work, we conduct a comprehensive analysis of the interactions between trigger-action rules in order to identify their security risks. Using IFTTT as an exemplar platform, we irst enumerate the space of inter-rule vulnerabilities that exist within trigger-action platforms. To aid users in the identiication of these dangers, we go on to present iRuler, a system that performs Satisiability Modulo Theories (SMT) solving and model checking to discover inter-rule vulnerabilities within IoT deployments. iRuler operates over an abstracted information low model that represents the attack surface of an IoT deployment, but we discover in practice that such models are diicult to obtain given the closed nature of IoT platforms. To address this, we develop methods that assist in inferring triggeraction information lows based on Natural Language Processing. We develop a novel evaluative methodology for approximating plausible real-world IoT deployments based on the installation counts of 315,393 IFTTT applets, determining that 66% of the synthetic deployments in the IFTTT ecosystem exhibit the potential for interrule vulnerabilities. Combined, these eforts provide the insight into the real-world dangers of IoT deployment misconigurations. CCS CONCEPTS • Security and privacy → Formal methods and theory of security; Vulnerability scanners; Software security engineering; • Computing methodologies → Natural language processing; • Computer systems organization → Embedded and cyber-physical systems.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper30

问问它们各自怎么用它

它引用的顶会 Paper15

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖