Securing Cross-App Interactions in IoT Platforms

التفاصيل البيبلوغرافية
العنوان: Securing Cross-App Interactions in IoT Platforms
المؤلفون: Balliu, Musard, Merro, Massimo, Pasqua, Michele
المصدر: 2019 IEEE 32nd Computer Security Foundations Symposium (CSF) Proceedings - IEEE Computer Security Foundations Symposium. :319-334
الوصف: IoT platforms enable users to connect various smart devices and online services via reactive apps running on the cloud. These apps, often developed by third-parties, perform simple computations on data triggered by external information sources and actuate the results of computation on external information sinks. Recent research shows that unintended or malicious interactions between the different (even benign) apps of a user can cause severe security and safety risks. These works leverage program analysis techniques to build tools for unveiling unexpected interference across apps for specific use cases. Despite these initial efforts, we are still lacking a semantic framework for understanding interactions between IoT apps. The question of what security policy cross-app interference embodies remains largely unexplored. This paper proposes a semantic framework capturing the essence of cross-app interactions in IoT platforms. The framework generalizes and connects syntactic enforcement mechanisms to bisimulation-based notions of security, thus providing a baseline for formulating soundness criteria of these enforcement mechanisms. Specifically, we present a calculus that models the behavioral semantics of a system of apps executing concurrently, and use it to define desirable semantic policies in the security and safety context of IoT apps. To demonstrate the usefulness of our framework, we define static mechanisms for enforcing crossapp security and safety, and prove them sound with respect to our semantic conditions. Finally, we leverage real-world apps to validate the practical benefits of our policy framework.
وصف الملف: electronic
URL الوصول: https://urn.kb.se/resolve?urn=urn:nbn:se:kth:diva-251321
https://doi.org/10.1109/CSF.2019.00029
https://web.stevens.edu/csf2019/cfp.html
https://kth.diva-portal.org/smash/get/diva2:1315086/FULLTEXT01.pdf
قاعدة البيانات: SwePub
الوصف
تدمد:19401434
DOI:10.1109/CSF.2019.00029