首页> 外文会议>IEEE Security and Privacy Workshops >HybriDiagnostics: Evaluating Security Issues in Hybrid SmartHome Companion Apps
【24h】

HybriDiagnostics: Evaluating Security Issues in Hybrid SmartHome Companion Apps

机译:Hybridiagnostics:评估混合体Smarthome Companion Apps中的安全问题

获取原文

摘要

This work presents HybriDiagnostics, a vulnerability-assessment framework that identifies nine preexisting security issues in IoT companion apps built using hybrid app development frameworks. At the heart of HybriDiagnostics is an analysis engine that identifies misconfigured policies (including Content Security Policy, and whitelist), usage of inline scripts, unsafe eval() usage, unsafe HTML and JQuery APIs and attributes, unencrypted storage, usage of vulnerable Cordova SDKs and more. The results of the analyses are documented in a security assessment report.A set of 102 Apache Cordova, Ionic, Monaca, OnsenUI, Phonegap, and Framework7 smarthome apps are analyzed to identify the security issues. For each security issue, either a proofof-concept attack or a hypothetical attack scenario is presented to demonstrate how the issue can be exploited to launch a serious cyberattack against the companion IoT device or the smartphone itself and compromise user privacy.
机译:这项工作提出了杂交诊断,一个漏洞评估框架,它识别使用混合应用程序开发框架建造的IOT Companion应用程序中的九个预先存在的安全问题。 在HybridiaGnostics的核心是一个分析引擎,它识别错误配置的策略(包括内容安全策略和白名单),内联脚本的用法,不安全eval()用法,不安全的HTML和jQuery API和属性,未加密的存储,易受攻击的Cordova SDK的使用 和更多。 分析结果记录在安全评估报告中。分析了102个Apache Cordova,IONIC,MONACA,ONSENUI,PhoneGAP和Framework7 Smarthome应用程序以确定安全问题。 对于每个安全问题,提出了校对概念攻击或假设的攻击方案,以展示如何利用问题,以便对伴侣IOT设备或智能手机本身启动严重的网络攻击,并妥协用户隐私。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号