[Paper Review] A Survey of Analysis Methods for Security and Safety verification in IoT Systems
This survey proposes a comprehensive analysis of program analysis techniques for verifying security and safety in IoT applications, focusing on interactions among heterogeneous IoT platforms. It classifies existing tools and methods, identifies key challenges in verification, and highlights research gaps in standardization and cross-platform compatibility, offering a foundation for future secure and safe IoT system development.
Internet of Things (IoT) has been rapidly growing in the past few years in all life disciplines. IoT provides automation and smart control to its users in different domains such as home automation, healthcare systems, automotive, and many more. Given the tremendous number of connected IoT devices, this growth leads to enormous automatic interactions among sizeable IoT apps in their environment, making IoT apps more intelligent and more enjoyable to their users. But some unforeseen interactions of IoT apps and any potential malicious behaviour can seriously cause insecure and unsafe consequences to its users, primarily non-experts, who lack the required knowledge regarding the potential impact of their IoT automation processes. In this paper, we study the problem of security and safety verification of IoT systems. We survey techniques that utilize program analysis to verify IoT applications' security and safety properties. The study proposes a set of categorization and classification attributes to enhance our understanding of the research landscape in this domain. Moreover, we discuss the main challenges considered in the surveyed work and potential solutions that could be adopted to ensure the security and safety of IoT systems.
Motivation & Objective
- To address the growing challenge of security and safety verification in complex, heterogeneous IoT systems with increasing app interactions.
- To identify and categorize program analysis techniques used in recent research for verifying IoT application security and safety properties.
- To examine how existing tools detect, prevent, or mitigate security and safety violations in IoT applications.
- To analyze the representation and handling of safety and security requirements in different IoT platforms and tools.
- To uncover research gaps in standardization, tool generalizability, and cross-platform verification capabilities in IoT security and safety analysis.
Proposed method
- Conduct a systematic survey of recent research papers focusing on program analysis techniques for IoT security and safety verification.
- Classify surveyed works based on analysis techniques (e.g., static, dynamic, symbolic execution), verification goals (security, safety, or both), and support for multi-app interactions.
- Categorize tools based on their target IoT platforms (e.g., SmartThings, OpenHAB, IFTTT), representation of requirements, and verification capabilities.
- Analyze the extent to which tools consider the surrounding IoT runtime environment and platform heterogeneity during verification.
- Compare surveyed tools with prior surveys to identify newly released tools and techniques not previously covered.
- Synthesize findings to identify recurring challenges, limitations, and opportunities for future research in IoT verification.
Experimental results
Research questions
- RQ1What program analysis techniques are most commonly used for verifying security and safety in IoT applications?
- RQ2How do existing tools represent and verify safety and security requirements in IoT systems?
- RQ3To what extent do current tools support verification in multi-app, heterogeneous IoT environments?
- RQ4What are the key limitations and research gaps in existing IoT security and safety verification approaches?
- RQ5How do recent tools compare to earlier surveys in terms of tool coverage, platform support, and verification capabilities?
Key findings
- This survey is the first to comprehensively analyze program analysis techniques specifically for both security and safety verification in IoT applications, with a focus on multi-app interactions.
- Many existing tools lack support for heterogeneous IoT platforms, limiting their generalizability and real-world applicability in complex environments.
- A significant number of surveyed tools focus only on security, with limited attention to safety properties, especially in critical domains like healthcare and industrial IoT.
- There is a notable gap in standardized representations of safety and security requirements, making cross-tool and cross-platform verification difficult.
- Recent tools not covered in prior surveys—especially those leveraging advanced static or symbolic analysis—show promise but remain limited in scalability and deployment readiness.
- The survey identifies a lack of unified frameworks for verifying both security and safety simultaneously, highlighting a key area for future research and tool development.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.