Privacy Leakage Analysis for Colluding Smart Apps

Junzhe Wang, Lannan Luo
{"title":"Privacy Leakage Analysis for Colluding Smart Apps","authors":"Junzhe Wang, Lannan Luo","doi":"10.1109/dsn-w54100.2022.00025","DOIUrl":null,"url":null,"abstract":"The rapid proliferation of Internet-of-Things (IoT) has advanced the development of smart environments. By installing smart apps on IoT platforms, users can integrate IoT devices for convenient automation. As smart apps are exposed to a myriad of sensitive data from devices, one severe concern is about the privacy of these digitally augmented spaces. The recent work SAINT [1] has been proposed to detect sensitive data flows in individual smart apps using taint analysis. But it has high false positives and false negatives due to inappropriate consideration of taint seeds and taint sinks.One important security issue ignored by existing work is that the IoT platform supports parent-child smart apps. Their ability to communicate, however, has a negative effect on security. We call the parent-child smart apps colluding smart apps. Unfortunately, no tool exists to detect smart app collusion. We propose PDColA, which addresses the limitations of SAINT, and more importantly, can detect privacy leakages by colluding smart apps. The evaluation results show that PDColA achieves higher accuracies than SAINT in detecting privacy leakages by individual smart apps, and is effective to detect privacy leakages by colluding smart apps.","PeriodicalId":349937,"journal":{"name":"2022 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W)","volume":"16 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/dsn-w54100.2022.00025","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

The rapid proliferation of Internet-of-Things (IoT) has advanced the development of smart environments. By installing smart apps on IoT platforms, users can integrate IoT devices for convenient automation. As smart apps are exposed to a myriad of sensitive data from devices, one severe concern is about the privacy of these digitally augmented spaces. The recent work SAINT [1] has been proposed to detect sensitive data flows in individual smart apps using taint analysis. But it has high false positives and false negatives due to inappropriate consideration of taint seeds and taint sinks.One important security issue ignored by existing work is that the IoT platform supports parent-child smart apps. Their ability to communicate, however, has a negative effect on security. We call the parent-child smart apps colluding smart apps. Unfortunately, no tool exists to detect smart app collusion. We propose PDColA, which addresses the limitations of SAINT, and more importantly, can detect privacy leakages by colluding smart apps. The evaluation results show that PDColA achieves higher accuracies than SAINT in detecting privacy leakages by individual smart apps, and is effective to detect privacy leakages by colluding smart apps.
串通智能应用的隐私泄露分析
物联网(IoT)的快速发展推动了智能环境的发展。通过在物联网平台上安装智能应用程序,用户可以集成物联网设备,方便自动化。由于智能应用程序暴露在来自设备的大量敏感数据中,人们对这些数字增强空间的隐私问题感到严重担忧。最近的工作SAINT[1]已经提出使用污染分析来检测单个智能应用程序中的敏感数据流。但由于不适当考虑污染种子和污染汇,它有很高的假阳性和假阴性。现有工作忽略的一个重要安全问题是物联网平台支持亲子智能应用程序。然而,它们的通信能力对安全性有负面影响。我们把亲子智能应用称为串通智能应用。不幸的是,没有工具可以检测智能应用程序的勾结。我们提出PDColA,它解决了SAINT的局限性,更重要的是,它可以通过串通智能应用来检测隐私泄露。评价结果表明,PDColA在检测单个智能应用的隐私泄露方面比SAINT具有更高的准确率,对于检测串通智能应用的隐私泄露是有效的。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信