skip to main content
US FlagAn official website of the United States government
dot gov icon
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
https lock icon
Secure .gov websites use HTTPS
A lock ( lock ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


Title: We Need a “Building Inspector for IoT” When Smart Homes Are Sold
Roughly 6 million homes are sold each year in the United States alone.1 Before a home is sold, a building inspector often examines the integrity of the building and renders an opinion on its soundness— examining things like structural integrity, electrical safety, mold and mildew, and radon or other toxins. These inspectors have specialized tools, knowledge, and experience to make a more informed judgment than nonprofessionals are capable of making.  more » « less
Award ID(s):
1955231 1955805 1955228
PAR ID:
10527248
Author(s) / Creator(s):
; ; ; ; ; ;
Publisher / Repository:
IEEE
Date Published:
Journal Name:
IEEE Security & Privacy
ISSN:
1540-7993
Page Range / eLocation ID:
2 to 11
Format(s):
Medium: X
Sponsoring Org:
National Science Foundation
More Like this
  1. Internet of Things (IoT) devices left behind when a home is sold create security and privacy concerns for both prior and new residents. We envision a specialized “building inspector for IoT” to help securely facilitate transfer of the home. 
    more » « less
  2. In this work we present an equilibrium formulation for price impacts. This is motivated by the Bühlmann equilibrium in which assets are sold into a system of market participants, for example, a fire sale in systemic risk, and can be viewed as a generalization of the Esscher premium. Existence and uniqueness of clearing prices for the liquidation of a portfolio are studied. We also investigate other desired portfolio properties including monotonicity and concavity. Price per portfolio unit sold is also calculated. In special cases, we study price impacts generated by market participants who follow the exponential utility and power utility. 
    more » « less
  3. Tor M. Aamodt; Natalie D. Enright Jerger; Michael M. Swift (Ed.)
    System calls are a critical building block in many serious security attacks, such as control-flow hijacking and privilege escalation attacks. Security-sensitive system calls (e.g., execve, mprotect), especially play a major role in completing attacks. Yet, few defense efforts focus to ensure their legitimate usage, allowing attackers to maliciously leverage system calls in attacks. In this paper, we propose a novel System Call Integrity, which enforces the correct use of system calls throughout runtime. We propose three new contexts enforcing (1) which system call is called and how it is invoked (Call Type), (2) how a system call is reached (Control Flow), and (3) that arguments are not corrupted (Argument Integrity). Our defense mechanism thwarts attacks by breaking the critical building block in their attack chains. We implement Bastion, as a compiler and runtime monitor system, to demonstrate the efficacy of the three system call contexts. Our security case study shows that Bastion can effectively stop all the attacks including real-world exploits and recent advanced attack strategies. Deploying Bastion on three popular system call-intensive programs, NGINX, SQLite, and vsFTPd, we show Bastion is secure and practical, demonstrating overhead of 0.60%, 2.01%, and 1.65%, respectively 
    more » « less
  4. The emergence of the novel SARS-CoV-2 (Covid-19) virus in 2019 has led to continuous monitoring of the outbreak attempting to generate accurate reports of people's health information to understand the pandemic's impact. It is likely that more variants will emerge since not all countries and populations have been vaccinated. Thus, with SARS-CoV-2's constant mutation, researchers need to collect individuals' health data to study these variants and vaccine efficacy, especially those who show symptoms. However, researchers have difficulties building comprehensive datasets because people are unwilling to release their health information or have no way to report their health statuses (i.e., at-home testing). This problem stems from a lack of complete control over who assesses their health data. Hence, they cannot guarantee the security, privacy, and integrity of the disclosed health information. As the problem of building secure databases persists, researchers find it challenging to accurately report any evolving variants within a short period. In this work, we propose a blockchain architecture that can guarantee patients' health data integrity, privacy, and security, encouraging individuals to disclose their health information freely. This solution gives patients complete control over who assesses their health information. The framework proposed access management to patients' health data for researchers and contact tracers. This solution classifies patient health information to different sensitivity levels and manages access based on this sensitivity. In case of unauthorized access, the proposed solution detects and prevents such access, thereby ensuring the patient's health information's security, integrity, and privacy. 
    more » « less
  5. Marine heatwaves are starting to occur several times a decade, yet we do not understand the effect this has on corals across biological scales. This study combines tissue-, organism-, and community-level analyses to investigate the effects of a marine heatwave on reef-building corals. Adjacent conspecific pairs of coral colonies of Montipora capitata and Porites compressa that showed contrasting phenotypic responses (i.e., bleached vs. not bleached) were first identified during a marine heatwave that occurred in 2015 in Kāne’ohe Bay, Hawai‘ i. These conspecific pairs of bleaching-resistant and bleaching-susceptible colonies were sampled for histology and photographed before, during, and after a subsequent marine heatwave that occurred in 2019. Histology samples were quantified for: (i) abundance of mesenterial filaments, (ii) tissue structural integrity, (iii) clarity of epidermis, and (iv) cellular integrity (lack of necrosis/granulation) on a 1–5 scale and averaged for an overall tissue integrity score. Tissue integrity scores revealed a significant decline in overall tissue health during the 2019 heatwave relative to the months prior to the heatwave for individuals of both species, regardless of past bleaching history in 2015 or bleaching severity during the 2019 heatwave. Coral tissue integrity scores were then compared to concurrent colony bleaching severity, which revealed that tissue integrity was significantly correlated with colony bleaching severity and suggests that the stability of the symbiosis is related to host tissue health. Colony partial mortality was also quantified as the cumulative proportion of each colony that appeared dead 2.5 years following the 2019 bleaching event, and tissue integrity during the heatwave was found to be strongly predictive of the extent of partial mortality following the heatwave for M. capitata but not P. compressa, the latter of which suffered little to no mortality. Surprisingly, bleaching severity and partial mortality were not significantly correlated for either species, suggesting that tissue integrity was a better predictor of mortality than bleaching severity in M. capitata. Despite negative effects of heat stress at the tissue- and colony-level, no significant changes in coral cover were detected, indicating resilience at the community level. However, declines in tissue integrity in response to heat stress that are not accompanied by a visible bleaching response may still have long-term consequences for fitness, and this is an important area of future investigation as heat stress is commonly associated with long-term decreases in coral fecundity and growth. Our results suggest that histology is a valuable tool for revealing the harmful effects of marine heatwaves on corals before they are visually evident as bleaching, and may thus improve the predictability of ecosystem changes following climate change-driven heat stress by providing a more comprehensive assessment of coral health. 
    more » « less