Skip to main content
QUICK REVIEW

[论文解读] A Survey on Sensor-based Threats to Internet-of-Things (IoT) Devices and Applications

Amit Kumar Sikder, Giuseppe Petracca|arXiv (Cornell University)|Feb 6, 2018
Mobile Crowdsensing and Crowdsourcing参考文献 10被引用 115
一句话总结

本次综述分析面向物联网设备的基于传感器的威胁、攻击分类、物联网操作系统中的现有传感器管理,以及安全对策,并强调尚待研究的方向。

ABSTRACT

The concept of Internet of Things (IoT) has become more popular in the modern era of technology than ever before. From small household devices to large industrial machines, the vision of IoT has made it possible to connect the devices with the physical world around them. This increasing popularity has also made the IoT devices and applications in the center of attention among attackers. Already, several types of malicious activities exist that attempt to compromise the security and privacy of the IoT devices. One interesting emerging threat vector is the attacks that abuse the use of sensors on IoT devices. IoT devices are vulnerable to sensor-based threats due to the lack of proper security measurements available to control use of sensors by apps. By exploiting the sensors (e.g., accelerometer, gyroscope, microphone, light sensor, etc.) on an IoT device, attackers can extract information from the device, transfer malware to a device, or trigger a malicious activity to compromise the device. In this survey, we explore various threats targeting IoT devices and discuss how their sensors can be abused for malicious purposes. Specifically, we present a detailed survey about existing sensor-based threats to IoT devices and countermeasures that are developed specifically to secure the sensors of IoT devices. Furthermore, we discuss security and privacy issues of IoT devices in the context of sensor-based threats and conclude with future research directions.

研究动机与目标

  • 表征IoT设备与应用中的基于传感器的威胁。
  • 评估当前物联网操作系统的传感器管理系统如何处理传感器访问及其不足。
  • 提供基于传感器威胁的分类,并总结现有安全对策。
  • 识别未解决的问题并提出面向IoT中传感器安全的未来研究方向。

提出的方法

  • 基于传感器威胁文献的文献综述与已确认的攻击情景。
  • 建立基于传感器威胁的分类(信息泄露、传输恶意传感器模式、伪数据注入、DoS)。
  • 分析跨物联网操作系统的传感器管理系统并识别基于同意的访问薄弱点。
  • 在传感器威胁背景下讨论安全解决方案及其局限性。

实验结果

研究问题

  • RQ1哪些基于传感器的威胁针对物联网设备,它们如何运作?
  • RQ2当前的物联网操作系统如何管理传感器访问,它们的安全短板是什么?
  • RQ3现有的基于传感器威胁的安全对策有哪些,它们的不足之处在哪?
  • RQ4确保物联网传感器安全的未解决问题与未来方向是什么?

主要发现

  • 基于传感器的威胁分为信息泄露、传输恶意传感器模式或指令、伪传感数据注入,以及拒绝服务。
  • 按键输入推断、任务推断、位置推断和窃听说明了在运动、音频、视频和磁传感器上的信息泄露。
  • 物联网操作系统中的传感器访问依赖基于权限的模型,可能被恶意应用程序绕过,从而滥用传感器。
  • 攻击利用可访问的传感器(如加速度计、陀螺仪、麦克风、摄像头、光传感器),无需大量工具。
  • 存在安全解决方案,但在检测或阻止物联网生态系统中的传感器滥用方面存在局限性。

更好的研究,从现在开始

从论文设计到论文写作,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。