TAPFixer: Automatic Detection and Repair of Home Automation Vulnerabilities based on Negated-property Reasoning
Yinbo Yu, Yuanqi Xu, Kepu Huang, Jiajia Liu
摘要
Trigger-Action Programming (TAP) is a popular end-user programming framework in the home automation (HA) system, which eases users to customize home automation and control devices as expected. However, its simplified syntax also introduces new safety threats to HA systems through vulnerable rule interactions. Accurately fixing these vulnerabilities by logically and physically eliminating their root causes is essential before rules are deployed. However, it has not been well studied. In this paper, we present TAPFixer, a novel framework to automatically detect and repair rule interaction vulnerabilities in HA systems. It extracts TAP rules from HA profiles, translates them into an automaton model with physical and latency features, and performs model checking with various correctness properties. It then uses a novel negated-property reasoning algorithm to automatically infer a patch via model abstraction and refinement and model checking based on negated-properties. We evaluate TAPFixer on market HA apps (1177 TAP rules and 53 properties) and find that it can achieve an 86.65% success rate in repairing rule interaction vulnerabilities. We additionally recruit 23 HA users to conduct a user study that demonstrates the usefulness of TAPFixer for vulnerability repair in practical HA scenarios.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- SoK: Automated Vulnerability Repair: Methods, Tools, and AssessmentsYiwei Hu, Zhen Li, Kedie Shu, Shenghua Guan 等USENIX Security 2025
- SoK: Towards Effective Automated Vulnerability RepairYing Li, Faysal Hossain Shezan, Bomin Wei, Gang Wang 等USENIX Security 2025
它引用的顶会 Paper18
- ContexloT: Towards Providing Contextual Integrity to Appified IoT PlatformsYunhan Jack Jia, Qi Alfred Chen, Shiqi Wang, Amir Rahmati 等NDSS 2017 · 被引用 325 次
- IoTGuard: Dynamic Enforcement of Security and Safety Policy in Commodity IoTZ. Berkay Celik, Gang Tan, Patrick D. McDanielNDSS 2019 · 被引用 254 次
- SmartAuth: User-Centered Authorization for the Internet of ThingsYuan Tian, Nan Zhang, Yue-Hsun Lin, XiaoFeng Wang 等USENIX Security 2017 · 被引用 231 次
- Rethinking Access Control and Authentication for the Home Internet of Things (IoT)Weijia He, Maximilian Golla, Roshni Padhi, Jordan Ofek 等USENIX Security 2018 · 被引用 221 次
- On the Safety of IoT Device Physical Interaction ControlWenbo Ding, Hongxin HuCCS 2018 · 被引用 169 次
相关 Paper
- Helping Users Debug Trigger-Action ProgramsLefan Zhang, Cyrus Zhou, Michael L. Littman, Blase Ur 等UbiComp 2023 · 被引用 14 次
- Detecting Smart Home Automation Application Interferences with Domain KnowledgeTao Wang, Wei Chen, Liwei Liu, Guoquan Wu 等ASE 2023 · 被引用 3 次
- Practical Data Access Minimization in Trigger-Action PlatformsYunang Chen, Mohannad Alhanahnah, Andrei Sabelfeld, Rahul Chatterjee 等USENIX Security 2022
- Retrieval-augmented Generation of Enhanced Trigger-action Programming Rules in Smart HomeYuchen Zhao, Lifu Wang, Kai DongUbiComp 2026 · 被引用 1 次
- Security Checking of Trigger-Action-Programming Smart Home IntegrationsLei Bu, Qiuping Zhang, Suwan Li, Jinglin Dai 等ISSTA 2023 · 被引用 7 次
