showSidebars ==
showTitleBreadcrumbs == 1
node.field_disable_title_breadcrumbs.value ==

Pre-Conference Talk by KANG Hong Jin | IoTBox: Sandbox Mining to Prevent Interaction Threats in IoT Systems

Please click here if you are unable to view this page.

 
IoTBox: Sandbox Mining to Prevent Interaction Threats in IoT Systems

Speaker (s):

KANG Hong Jin
PhD Student
School of Computing and Information Systems
Singapore Management University

Date:

Time:

Venue:

 

29 March 2021, Monday

10:30am - 11:00am

This is a virtual seminar. Please register by 26 March, the webex link will be sent out by end of the day to those who have registered.

We look forward to seeing you at this research seminar.

About the Talk

Internet of Things (IoT) apps provide great convenience but exposes us to new safety threats. Unlike traditional software systems, threats may emerge from the joint behavior of multiple apps. While prior studies use handcrafted safety and security policies to detect these threats, these policies may not anticipate all usages of the devices and apps in a smart home, causing false alarms. In this study, we propose to use the technique of mining sandboxes for securing an IoT environment. After a set of behaviors are analyzed from a bundle of apps and devices, a sandbox is deployed, which enforces that previously unseen behaviors are disallowed. Hence, the execution of malicious behavior, introduced from software updates or obscured through methods to hinder program analysis, is blocked.

While sandbox mining techniques have been proposed for Android apps, we show and discuss why they are insufficient for detecting malicious behavior in a more complex IoT system. We prototype IoTBox to address these limitations. IoTBox explores behavior through a formal model of a smart home. In our empirical evaluation to detect malicious code changes, we find that IoTBox achieves substantially higher precision and recall compared to existing techniques for mining sandboxes.

About the Speaker

Hong Jin is a PhD student in School of Computing and Information Systems, Singapore Management University. He is supervised by Prof. David Lo. He works in the area of mining rules and specifications for Software Engineering.