Annual Computer Security Applications Conference (ACSAC) 2021

Full Program »

Westworld: Fuzzing-Assisted Remote Dynamic Symbolic Execution of Smart Apps on IoT Cloud Platforms

Existing symbolic execution typically assumes the analyzer can control the I/O environment and/or access the library code, which, however, is not the case when programs run on a remote proprietary execution environment managed by another party. For example, SmartThings, one of the most popular IoT device integration platforms, is such a cloud-based execution environment managed by Samsung. For programmers who write automation applications to be deployed on IoT cloud platforms, it raises significant challenges when they want to systematically test code and find bugs. We propose remote dynamic symbolic execution (remote DSE), which symbolically executes programs running in a remote proprietary execution environment where the analyzer has little control, attaining both precision (in terms of analysis results) and completeness (in terms of path coverage). As a case study, we enable remote DSE for analyzing automation apps running on SmartThings. We have developed a prototype and the evaluation shows it is effective in testing automation apps and finding bugs.

Lannan Luo
University of South Carolina

Qiang Zeng
University of South Carolina

Bokai Yang
University of South Carolina

Fei Zuo
University of South Carolina

Junzhe Wang
University of South Carolina

Paper (ACM DL)

Slides

Video

 



Powered by OpenConf®
Copyright©2002-2021 Zakon Group LLC