Scrutinizing Implementations of Smart Home Integrations

被引:8
|
作者
Mahadewa, Kulani [3 ]
Wang, Kailong [3 ]
Bai, Guangdong [5 ]
Shi, Ling [4 ]
Liu, Yan [6 ]
Dong, Jin Song [1 ,2 ]
Liang, Zhenkai [3 ]
机构
[1] Natl Univ Singapore, Sch Comp, Singapore, Singapore
[2] Griffith Univ, Nathan, Qld 4111, Australia
[3] Natl Univ Singapore, Dept Comp Sci, Singapore, Singapore
[4] Natl Univ Singapore, Singapore, Singapore
[5] Univ Queensland, Brisbane, Qld, Australia
[6] Ant Financial, Hangzhou 310000, Peoples R China
基金
新加坡国家研究基金会;
关键词
Network security; Smart homes; Zigbee; Protocols; Authentication; !text type='Java']Java[!/text; Wireless fidelity; Internet of Things; IoT security; smart home; specification extraction; program analysis; SECURITY;
D O I
10.1109/TSE.2019.2960690
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
A key feature of the booming smart home is the integration of a wide assortment of technologies, including various standards, proprietary communication protocols and heterogeneous platforms. Due to customization, unsatisfied assumptions and incompatibility in the integration, critical security vulnerabilities are likely to be introduced by the integration. Hence, this work addresses the security problems in smart home systems from an integration perspective, as a complement to numerous studies that focus on the analysis of individual techniques. We propose HomeScan, an approach that examines the security of the implementations of smart home systems. It extracts the abstract specification of application-layer protocols and internal behaviors of entities, so that it is able to conduct an end-to-end security analysis against various attack models. Applying HomeScan on three extensively-used smart home systems, we have found twelve non-trivial security issues, which may lead to unauthorized remote control and credential leakage.
引用
收藏
页码:2667 / 2683
页数:17
相关论文
共 50 条
  • [21] LMAS-SHS: A Lightweight Mutual Authentication Scheme for Smart Home Surveillance
    Jan, Saeed Ullah
    Abbasi, Irshad Ahmed
    Alqarni, Mohammed A.
    IEEE ACCESS, 2022, 10 : 52791 - 52803
  • [22] Improving smart home security; integrating behaviour prediction into smart home
    Jose, Arun Cyril
    Malekian, Reza
    Letswamotse, Babedi B.
    INTERNATIONAL JOURNAL OF SENSOR NETWORKS, 2018, 28 (04) : 253 - 269
  • [23] Improving Smart Home Security: Integrating Logical Sensing Into Smart Home
    Jose, Arun Cyril
    Malekian, Reza
    IEEE SENSORS JOURNAL, 2017, 17 (13) : 4269 - 4286
  • [24] User Perceptions and Experiences with Smart Home Updates
    Haney, Julie M.
    Furman, Susanne M.
    2023 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, SP, 2023, : 2867 - 2884
  • [25] A trust model for popular smart home devices
    Ferraris, Davide
    Bastos, Daniel
    Fernandez-Gago, Carmen
    El-Moussa, Fadi
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2021, 20 (04) : 571 - 587
  • [26] Smart Home Tracking: A Smart Home Architecture for Smart Energy Consumption in a Residence with Multiple Users
    Andrade, Sergio H. M. S.
    Contente, Gustavo O.
    Rodrigues, Lucas B.
    Lima, Luiguy X.
    Vijaykumar, N. L.
    Frances, Carlos Renato L.
    WIRELESS PERSONAL COMMUNICATIONS, 2022, 123 (04) : 3241 - 3262
  • [27] A trust model for popular smart home devices
    Davide Ferraris
    Daniel Bastos
    Carmen Fernandez-Gago
    Fadi El-Moussa
    International Journal of Information Security, 2021, 20 : 571 - 587
  • [28] Investigating Smart Home Security: Is Blockchain the Answer?
    Arif, Samrah
    Khan, M. Arif
    Rehman, Sabih Ur
    Kabir, Muhammad Ashad
    Imran, Muhammad
    IEEE ACCESS, 2020, 8 (08): : 117802 - 117816
  • [29] Review of Ethereum: Smart Home Case Study
    Aung, Yu Nandar
    Tantidham, Thitinan
    2017 2ND INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY (INCIT), 2017, : 219 - 222
  • [30] Securing the smart home: A real case study
    Sicari, Sabrina
    Rizzardi, Alessandra
    Miorandi, Daniele
    Coen-Porisini, Alberto
    INTERNET TECHNOLOGY LETTERS, 2018, 1 (03):