Risk Assessment and Detection of API Abuse in the IoT Cloud

Bin YUAN,Kaimin ZHENG,Jun WAN,Deqing ZOU,Hai JIN
DOI: https://doi.org/10.1360/ssi-2022-0466
2023-01-01
Scientia Sinica Informationis
Abstract:Recently,the vigorous development of Internet of Things technology has rapidly developed smart home applications.Smart home platforms increasingly provide open interfaces for users to implement customized smart home applications(e.g.,device automation control).The possible defects of these open interfaces have also become an important issue affecting the security of smart home systems.In this paper,we study the open interfaces of the SmartThings platform.We identified a series of new vulnerable interfaces and conducted proof-of-concept attacks to demonstrate the security impact of such interfaces.To mitigate this problem,we propose SmartNotify,a tool for identifying malicious smart home applications abusing vulnerable interfaces.Experiment results show the efficiency and effectiveness of SmartNotify.
What problem does this paper attempt to address?