Sensitive Information Tracking in Commodity IoT
نویسندگان
چکیده
Broadly defined as the Internet of Things (IoT), the growth of commodity devices that integrate physical processes with digital connectivity has had profound effects on society– smart homes, personal monitoring devices, enhanced manufacturing and other IoT apps have changed the way we live, play, and work. Yet extant IoT platforms provide few means of evaluating the use (and potential avenues for misuse) of sensitive information. Thus, consumers and organizations have little information to assess the security and privacy risks these devices present. In this paper, we present SAINT, a static taint analysis tool for IoT applications. SAINT operates in three phases; (a) translation of platform-specific IoT source code into an intermediate representation (IR), (b) identifying sensitive sources and sinks, and (c) performing static analysis to identify sensitive data flows. We evaluate SAINT on 230 SmartThings market apps and find 138 (60%) include sensitive data flows. In addition, we demonstrate SAINT on IOTBENCH, a novel open-source test suite containing 19 apps with 27 unique data leaks. Through this effort, we introduce a rigorously grounded framework for evaluating the use of sensitive information in IoT apps—and therein provide developers, markets, and consumers a means of identifying potential threats to security and privacy.
منابع مشابه
ContexloT: Towards Providing Contextual Integrity to Appified IoT Platforms
The Internet-of-Things (IoT) has quickly evolved to a new appified era where third-party developers can write apps for IoT platforms using programming frameworks. Like other appified platforms, e.g., the smartphone platform, the permission system plays an important role in platform security. However, design flaws in current IoT platform permission models have been reported recently, exposing us...
متن کاملInvestigation of the Status of IoT-Based Health Information Systems in a Three-Dimensional Conceptual Framework
Introduction: The ability to transfer data over the Internet of Things (IoT) to make right and timely decisions through accurate data collection has provided incredible interactive power and has resulted in an intelligent world with automated decision-making capability. The objective of this study was to investigate the status of IoT-based health information systems in a three-dimensional conce...
متن کاملInvestigation of the Status of IoT-Based Health Information Systems in a Three-Dimensional Conceptual Framework
Introduction: The ability to transfer data over the Internet of Things (IoT) to make right and timely decisions through accurate data collection has provided incredible interactive power and has resulted in an intelligent world with automated decision-making capability. The objective of this study was to investigate the status of IoT-based health information systems in a three-dimensional conce...
متن کاملTraffic congestion control using Smartphone sensors based on IoT Technology
Traffic congestion in road networks is one of the main issues to be addressed, also vehicle traffic congestion and monitoring has become one of the critical issues in road transport. With the help of Intelligent Transportation System (ITS), current information of traffic can be used by control room to improve the traffic efficiency. The suggested system utilize technologies for real-time collect...
متن کاملDiscovering the Underlying Components Affecting the Usability of IoT in Iranian Libraries: A Theory Based on Context
Objective: The aim is to discover the underlying context components of IOT usability in Iranian libraries: A qualitative approach consistent with grounded theory. Method: This qualitative study was conducted based on grounded theory. Data were collected through semi-structured interviews with 13 faculty members of knowledge and information science based on purposeful and chain methods. Responsi...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- CoRR
دوره abs/1802.08307 شماره
صفحات -
تاریخ انتشار 2018