Skip to main content
QUICK REVIEW

[Paper Review] A Survey on Sensor-based Threats to Internet-of-Things (IoT) Devices and Applications

Amit Kumar Sikder, Giuseppe Petracca|arXiv (Cornell University)|Feb 6, 2018
Mobile Crowdsensing and Crowdsourcing10 references115 citations
TL;DR

This survey analyzes sensor-based threats targeting IoT devices, taxonomy of attacks, existing sensor management in IoT OSes, and security countermeasures, and highlights open research directions.

ABSTRACT

The concept of Internet of Things (IoT) has become more popular in the modern era of technology than ever before. From small household devices to large industrial machines, the vision of IoT has made it possible to connect the devices with the physical world around them. This increasing popularity has also made the IoT devices and applications in the center of attention among attackers. Already, several types of malicious activities exist that attempt to compromise the security and privacy of the IoT devices. One interesting emerging threat vector is the attacks that abuse the use of sensors on IoT devices. IoT devices are vulnerable to sensor-based threats due to the lack of proper security measurements available to control use of sensors by apps. By exploiting the sensors (e.g., accelerometer, gyroscope, microphone, light sensor, etc.) on an IoT device, attackers can extract information from the device, transfer malware to a device, or trigger a malicious activity to compromise the device. In this survey, we explore various threats targeting IoT devices and discuss how their sensors can be abused for malicious purposes. Specifically, we present a detailed survey about existing sensor-based threats to IoT devices and countermeasures that are developed specifically to secure the sensors of IoT devices. Furthermore, we discuss security and privacy issues of IoT devices in the context of sensor-based threats and conclude with future research directions.

Motivation & Objective

  • Characterize sensor-based threats in IoT devices and applications.
  • Evaluate how current IoT OS sensor management systems handle sensor access and their shortcomings.
  • Provide a taxonomy of sensor-based threats and summarize existing security countermeasures.
  • Identify open issues and propose future research directions for securing sensors in IoT.

Proposed method

  • Literature survey of sensor-based threat literature and confirmed attack scenarios.
  • Development of a taxonomy of sensor-based threats (information leakage, transmitting malicious sensor patterns, false data injection, DoS).
  • Analysis of sensor management systems across IoT OSes and identification of consent-based access weaknesses.
  • Discussion of security solutions and their limitations in the context of sensor threats.

Experimental results

Research questions

  • RQ1What sensor-based threats target IoT devices and how do they operate?
  • RQ2How do current IoT OSes manage sensor access and what are their security shortcomings?
  • RQ3What security countermeasures exist for sensor-based threats and where do they fall short?
  • RQ4What are the open issues and future directions for securing IoT sensors?

Key findings

  • Sensor-based threats are categorized into information leakage, transmitting malicious sensor patterns or commands, false sensor data injection, and denial-of-service.
  • Keystroke inference, task inference, location inference, and eavesdropping illustrate information leakage across motion, audio, video, and magnetic sensors.
  • Sensor access in IoT OSes relies on permission-based models, which can be bypassed by malicious apps, enabling sensor abuse.
  • Attacks leverage accessible sensors (e.g., accelerometer, gyroscope, microphone, camera, light sensor) without requiring extensive tools.
  • Security solutions exist but have limitations in detecting or preventing sensor abuse within the IoT ecosystem.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.