Delay Wreaks Havoc on Your Smart Home: Delay-based Automation Interference Attacks
Haotian Chi, Chenglong Fu, Qiang Zeng, Xiaojiang Du
摘要
With the proliferation of Internet of Things (IoT) devices and platforms, it becomes a trend that IoT devices associated with different IoT platforms coexist in a smart home, demonstrating the following characteristics. First, a smart home may use more than one platform to support its devices and automation. Second, IoT devices of a home may transmit messages over different paths. By selectively delaying IoT messages, our study finds that two issues, inconsistency and disorder, can be exacerbated by attackers significantly. We then explore how these issues can be exploited and present seven types of exploitation, collectively referred to as Delay-based Automation Interference (DAI) attacks. DAI attacks cause home automation to yield incorrect interaction results, placing the IoT devices and smart home in insecure, unsafe, or unexpected states. It is worth highlighting that DAI attacks do not depend on any IoT implementation vulnerabilities or leaked keys/tokens, and they do not trigger alarms at any layers of the IoT protocol stack. To demonstrate and evaluate the new attacks, we set up two real-world testbeds, where commercial IoT devices and apps are deployed. The week-long experiments from both testbeds show that an attacker has adequate opportunities to launch DAI attacks that cause security or safety issues.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper8
- From One Thousand Pages of Specification to Unveiling Hidden Bugs: Large Language Model Assisted Fuzzing of Matter IoT DevicesXiaoyue Ma, Lannan Luo, Qiang ZengUSENIX Security 2024 · 被引用 49 次
- Federated IoT Interaction Vulnerability AnalysisGuangjing Wang, Hanqing Guo, Anran Li, Xiaorui Liu 等ICDE 2023 · 被引用 20 次
- Make Your Home Safe: Time-aware Unsupervised User Behavior Anomaly Detection in Smart Homes via Loss-guided MaskJingyu Xiao, Zhiyao Xu, Qingsong Zou, Qing Li 等KDD 2024 · 被引用 12 次
- Graph Learning for Interactive Threat Detection in Heterogeneous Smart Home Rule DataGuangjing Wang, Nikolay Ivanov, Bocheng Chen, Qi Wang 等SIGMOD 2023 · 被引用 12 次
- Perils and Mitigation of Security Risks of Cooperation in Mobile-as-a-Gateway IoTXin'an Zhou, Jiale Guan, Luyi Xing, Zhiyun QianCCS 2022 · 被引用 9 次
相关 Paper
- Discovering and Understanding the Security Hazards in the Interactions between IoT Devices, Mobile Apps, and Clouds on Smart Home PlatformsWei Zhou, Yan Jia, Yao Yao, Lipeng Zhu 等USENIX Security 2019 · 被引用 160 次
- Detecting and Handling IoT Interaction Threats in Multi-Platform Multi-Control-Channel Smart HomesHaotian Chi, Qiang Zeng, Xiaojiang DuUSENIX Security 2023
- Discovering and Exploiting IoT Device Hidden Attributes: A New Vulnerability in Smart HomesXuening Xu, Chenglong Fu, Xiaojiang Du, Bo LuoCCS 2025
- Security Checking of Trigger-Action-Programming Smart Home IntegrationsLei Bu, Qiuping Zhang, Suwan Li, Jinglin Dai 等ISSTA 2023 · 被引用 7 次
- IoTSafe: Enforcing Safety and Security Policy with Real IoT Physical Interaction DiscoveryWenbo Ding, Hongxin Hu, Long ChengNDSS 2021
