Program Analysis of Commodity IoT Applications for Security and Privacy: Challenges and Opportunities

被引:71
|
作者
Celik, Z. Berkay [1 ,3 ]
Fernandes, Earlence [2 ,4 ]
Pauley, Eric [1 ,5 ]
Tan, Gang [1 ,5 ]
Mcdaniel, Patrick [1 ,5 ]
机构
[1] Penn State Univ, University Pk, PA 16802 USA
[2] Univ Washington, Seattle, WA 98195 USA
[3] Purdue Univ, Dept Comp Sci, W Lafayette, IN 47907 USA
[4] Univ Wisconsin Madison, Dept Comp Sci, Madison, WI 53706 USA
[5] Penn State Univ Penn State, Dept Comp Sci & Engn, State Coll, PA 16802 USA
基金
美国国家科学基金会;
关键词
IoT security and privacy; IoT programming platforms; program analysis; INTERNET; THINGS;
D O I
10.1145/3333501
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Recent advances in Internet of Things (IoT) have enabled myriad domains such as smart homes, personal monitoring devices, and enhanced manufacturing. IoT is now pervasive-new applications are being used in nearly every conceivable environment, which leads to the adoption of device-based interaction and automation. However, IoT has also raised issues about the security and privacy of these digitally augmented spaces. Program analysis is crucial in identifying those issues, yet the application and scope of program analysis in IoT remains largely unexplored by the technical community. In this article, we study privacy and security issues in IoT that require program-analysis techniques with an emphasis on identified attacks against these systems and defenses implemented so far. Based on a study of five IoT programming platforms, we identify the key insights that result from research efforts in both the program analysis and security communities and relate the efficacy of program-analysis techniques to security and privacy issues. We conclude by studying recent IoT analysis systems and exploring their implementations. Through these explorations, we highlight key challenges and opportunities in calibrating for the environments in which IoT systems will be used.
引用
收藏
页数:30
相关论文
共 50 条
  • [41] Security and Privacy in Smart City Applications: Challenges and Solutions
    Zhang, Kuan
    Ni, Jianbing
    Yang, Kan
    Liang, Xiaohui
    Ren, Ju
    Shen, Xuemin
    IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (01) : 122 - 129
  • [42] Security Threats and Challenges to IoT and its Applications: A Review
    Anwar, Raja Waseem
    Zainal, Anazida
    Abdullah, Tariq
    Iqbal, Saleem
    2020 FIFTH INTERNATIONAL CONFERENCE ON FOG AND MOBILE EDGE COMPUTING (FMEC), 2020, : 301 - 305
  • [43] Internet of Things (IoT) applications security trends and challenges
    Laghari, Asif Ali
    Li, Hang
    Khan, Abdullah Ayub
    Shoulin, Yin
    Karim, Shahid
    Khani, Muhammad Adnan Kaim
    Discover Internet of Things, 2024, 4 (01):
  • [44] A SURVEY ON IoT APPLICATIONS, SECURITY CHALLENGES AND COUNTER MEASURES
    Pawar, Ankush B.
    Ghumbre, Shashikant
    2016 INTERNATIONAL CONFERENCE ON COMPUTING, ANALYTICS AND SECURITY TRENDS (CAST), 2016, : 294 - 299
  • [45] Serverless Security Analysis for IoT Applications
    Ortega Candel, Jose Manuel
    Mora Gimeno, Francisco Jose
    Mora Mora, Higinio
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON UBIQUITOUS COMPUTING & AMBIENT INTELLIGENCE (UCAMI 2022), 2023, 594 : 393 - 400
  • [46] Security Analysis for SmartThings IoT Applications
    Schmeidl, Florian
    Nazzal, Bara'
    Alalfi, Manar H.
    2019 IEEE/ACM 6TH INTERNATIONAL CONFERENCE ON MOBILE SOFTWARE ENGINEERING AND SYSTEMS (MOBILESOFT 2019), 2019, : 25 - 29
  • [47] Iot - Challenges and opportunities
    Skinner, Tim
    Journal of the Institute of Telecommunications Professionals, 2015, 9 (03): : 14 - 15
  • [48] IOT - CHALLENGES AND OPPORTUNITIES
    不详
    JOURNAL OF THE INSTITUTE OF TELECOMMUNICATIONS PROFESSIONALS, 2015, 9 : 14 - 15
  • [49] Issues, Challenges, and Research Opportunities in Intelligent Transport System for Security and Privacy
    Ali, Qazi Ejaz
    Ahmad, Naveed
    Malik, Abdul Haseeb
    Ali, Gauhar
    Rehman, Waheed Ur
    APPLIED SCIENCES-BASEL, 2018, 8 (10):
  • [50] Security and Privacy in Smart Grids: Challenges, Current Solutions and Future Opportunities
    Butun, Ismail
    Lekidis, Alexios
    dos Santos, Daniel Ricardo
    ICISSP: PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2020, : 733 - 741