arrow
返回

SAFECHAIN: Securing Trigger-Action Programming From Attack Chains

delete2019-10-01
delete35
delete
OA
AI
K
Kai-Hsiang Hsu
Y
Yu-Hsi Chiang
H
Hsu‐Chun Hsiao *
DOI:10.1109/TIFS.2019.2899758delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
The proliferation of the Internet of Things (IoT) is reshaping our lifestyle. With IoT sensors and devices communicating with each other via the Internet, people can customize automation rules to meet their needs. Unless carefully defined, however, such rules can easily become points of security failure as the number of devices and complexity of rules increase. Device owners may end up unintentionally providing access or revealing private information to unauthorized entities due to complex chain reactions among devices. Prior work on trigger-action programming either focuses on conflict resolution or usability issues or fails to accurately and efficiently detect such attack chains. This paper explores the security vulnerabilities when users have the freedom to customize automation rules using trigger-action programming. We define two broad classes of attack-privilege escalation and privacy leakage-and present a practical model-checking-based system called SAFECHAIN that detects hidden attack chains exploiting the combination of rules. Built upon existing model-checking techniques, SAFECHAIN identifies attack chains by modeling the IoT ecosystem as a finitestate machine. To improve practicability, SAFECHAIN avoids the need to accurately model an environment by frequently rechecking the automation rules given the current states and employs rule-aware optimizations to further reduce overhead. Our comparative analysis shows that SAFECHAIN can efficiently and accurately identify attack chains, and our prototype implementation of SAFECHAIN can verify 100 rules in less than 1 s with no false positives.
Keyword:
Trigger-action attack chains
privilege escalation
information leakage
model checking
Internet of Things
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Transactions on Information Forensics and Security 封面图
IEEE Transactions on Information Forensics and Security
IF:
8
论文数:
5.3K
被引数:
2.3W

机构

N
National Taiwan University
学者数:
4.7W
论文数: 4.2W
被引数: 3.6W
引用论文

引用论文

Unusual C–H bond activation—aldol condensation of aromatic aldehydes with the methyl group of a carbene-like triosmium cluster
err2002-01-01
err0
PREAI
errSergey P. Tunik; Irina A. Balova; Maxim E. Borovitov; Ebbe Nordlander; Matti Haukka; Tapani A. Pakkanen
err分享
err收藏
Flexible coaxial-type fiber solid-state asymmetrical supercapacitor based on Ni 3 S 2 nanorod array and pen ink electrodes
err2016-08-01
err0
PREAI
errJian Wen; Songzhan Li; Kai Zhou; Zengcai Song; Borui Li; Zhao Chen; Tian Chen; Yaxiong Guo; Guojia Fang
err分享
err收藏
OWL 2: The next step for OWL
err2008-11-01
err0
PREAI
errBernardo Cuenca Grau; Ian Horrocks; Boris Motik; Bijan Parsia; Peter Patel-Schneider; Ulrike Sattler
err分享
err收藏
Early specialized care after a first unprovoked epileptic seizure
err2016-09-07
err0
errOAAI
errL. Fisch; A. M. Lascano; N. Vernaz Hegi; F. Girardin; V. Kapina; L. Heydrich; O. Rutschmann; F. Sarasin; M. I. Vargas; F. Picard; S. Vulliémoz; A. C. Héritier-Barras; M. Seeck
err分享
err收藏
E-transportation: the role of embedded systems in electric energy transfer from grid to vehicle
err2016-05-10
err0
errOAAI
errFederico Baronti; Mo-Yuen Chow; Chengbin Ma; Habiballah Rahimi-Eichi; Roberto Saletti
err分享
err收藏
学者 查看更多内容