{"id":"https://openalex.org/W2911962130","doi":"https://doi.org/10.1109/tifs.2019.2899758","title":"SafeChain: Securing Trigger-Action Programming From Attack Chains","display_name":"SafeChain: Securing Trigger-Action Programming From Attack Chains","publication_year":2019,"publication_date":"2019-02-15","ids":{"openalex":"https://openalex.org/W2911962130","doi":"https://doi.org/10.1109/tifs.2019.2899758","mag":"2911962130"},"language":"en","primary_location":{"id":"doi:10.1109/tifs.2019.2899758","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2019.2899758","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/1903.03760","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5066473737","display_name":"Kai-Hsiang Hsu","orcid":null},"institutions":[{"id":"https://openalex.org/I16733864","display_name":"National Taiwan University","ror":"https://ror.org/05bqach95","country_code":"TW","type":"education","lineage":["https://openalex.org/I16733864"]}],"countries":["TW"],"is_corresponding":true,"raw_author_name":"Kai-Hsiang Hsu","raw_affiliation_strings":["Department of Computer Science and Information Engineering, National Taiwan University, Taipei, Taiwan"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Information Engineering, National Taiwan University, Taipei, Taiwan","institution_ids":["https://openalex.org/I16733864"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5083410977","display_name":"Yu-Hsi Chiang","orcid":null},"institutions":[{"id":"https://openalex.org/I16733864","display_name":"National Taiwan University","ror":"https://ror.org/05bqach95","country_code":"TW","type":"education","lineage":["https://openalex.org/I16733864"]}],"countries":["TW"],"is_corresponding":false,"raw_author_name":"Yu-Hsi Chiang","raw_affiliation_strings":["Department of Computer Science and Information Engineering, National Taiwan University, Taipei, Taiwan"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Information Engineering, National Taiwan University, Taipei, Taiwan","institution_ids":["https://openalex.org/I16733864"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5031599880","display_name":"Hsu\u2010Chun Hsiao","orcid":"https://orcid.org/0000-0001-9592-6911"},"institutions":[{"id":"https://openalex.org/I16733864","display_name":"National Taiwan University","ror":"https://ror.org/05bqach95","country_code":"TW","type":"education","lineage":["https://openalex.org/I16733864"]}],"countries":["TW"],"is_corresponding":false,"raw_author_name":"Hsu-Chun Hsiao","raw_affiliation_strings":["Department of Computer Science and Information Engineering, National Taiwan University, Taipei, Taiwan"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Information Engineering, National Taiwan University, Taipei, Taiwan","institution_ids":["https://openalex.org/I16733864"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5066473737"],"corresponding_institution_ids":["https://openalex.org/I16733864"],"apc_list":null,"apc_paid":null,"fwci":4.3399,"has_fulltext":false,"cited_by_count":55,"citation_normalized_percentile":{"value":0.95414389,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":99},"biblio":{"volume":"14","issue":"10","first_page":"2607","last_page":"2622"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9972000122070312,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9972000122070312,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10772","display_name":"Distributed systems and fault tolerance","score":0.9873999953269958,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9872999787330627,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8956859111785889},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.6770508289337158},{"id":"https://openalex.org/keywords/automation","display_name":"Automation","score":0.49274757504463196},{"id":"https://openalex.org/keywords/attack-model","display_name":"Attack model","score":0.4524085819721222},{"id":"https://openalex.org/keywords/overhead","display_name":"Overhead (engineering)","score":0.4195761978626251},{"id":"https://openalex.org/keywords/false-positive-paradox","display_name":"False positive paradox","score":0.4100896120071411},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.1854918897151947},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.12540051341056824}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8956859111785889},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6770508289337158},{"id":"https://openalex.org/C115901376","wikidata":"https://www.wikidata.org/wiki/Q184199","display_name":"Automation","level":2,"score":0.49274757504463196},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.4524085819721222},{"id":"https://openalex.org/C2779960059","wikidata":"https://www.wikidata.org/wiki/Q7113681","display_name":"Overhead (engineering)","level":2,"score":0.4195761978626251},{"id":"https://openalex.org/C64869954","wikidata":"https://www.wikidata.org/wiki/Q1859747","display_name":"False positive paradox","level":2,"score":0.4100896120071411},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.1854918897151947},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.12540051341056824},{"id":"https://openalex.org/C78519656","wikidata":"https://www.wikidata.org/wiki/Q101333","display_name":"Mechanical engineering","level":1,"score":0.0},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tifs.2019.2899758","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2019.2899758","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},{"id":"pmh:oai:arXiv.org:1903.03760","is_oa":true,"landing_page_url":"http://arxiv.org/abs/1903.03760","pdf_url":"https://arxiv.org/pdf/1903.03760","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:1903.03760","is_oa":true,"landing_page_url":"http://arxiv.org/abs/1903.03760","pdf_url":"https://arxiv.org/pdf/1903.03760","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[{"score":0.5299999713897705,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[{"id":"https://openalex.org/G2270234995","display_name":null,"funder_award_id":"NTU-106R104045","funder_id":"https://openalex.org/F4320323900","funder_display_name":"National Taiwan University"},{"id":"https://openalex.org/G4207321544","display_name":null,"funder_award_id":"MOST 106-2633-E-002-001","funder_id":"https://openalex.org/F4320322795","funder_display_name":"Ministry of Science and Technology, Taiwan"},{"id":"https://openalex.org/G6501956291","display_name":null,"funder_award_id":"107-2636-E-002-005-","funder_id":"https://openalex.org/F4320322795","funder_display_name":"Ministry of Science and Technology, Taiwan"}],"funders":[{"id":"https://openalex.org/F4320307102","display_name":"Intel Corporation","ror":"https://ror.org/01ek73717"},{"id":"https://openalex.org/F4320322795","display_name":"Ministry of Science and Technology, Taiwan","ror":"https://ror.org/02kv4zf79"},{"id":"https://openalex.org/F4320323900","display_name":"National Taiwan University","ror":"https://ror.org/05bqach95"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":35,"referenced_works":["https://openalex.org/W1787074469","https://openalex.org/W1866799138","https://openalex.org/W1966590372","https://openalex.org/W1994703499","https://openalex.org/W2016159237","https://openalex.org/W2043475427","https://openalex.org/W2056451850","https://openalex.org/W2086239403","https://openalex.org/W2095840868","https://openalex.org/W2158395308","https://openalex.org/W2158396456","https://openalex.org/W2165653922","https://openalex.org/W2293605433","https://openalex.org/W2399248522","https://openalex.org/W2410888651","https://openalex.org/W2461749621","https://openalex.org/W2519460064","https://openalex.org/W2533712304","https://openalex.org/W2535751405","https://openalex.org/W2605367183","https://openalex.org/W2606062705","https://openalex.org/W2613352518","https://openalex.org/W2686848947","https://openalex.org/W2770057444","https://openalex.org/W2788819230","https://openalex.org/W2791710451","https://openalex.org/W2792078641","https://openalex.org/W2889557246","https://openalex.org/W2902205770","https://openalex.org/W2951084996","https://openalex.org/W3104449659","https://openalex.org/W4231640108","https://openalex.org/W4236991443","https://openalex.org/W6683354071","https://openalex.org/W6754230774"],"related_works":["https://openalex.org/W1557094818","https://openalex.org/W2183246718","https://openalex.org/W2099261052","https://openalex.org/W3209204065","https://openalex.org/W2105707930","https://openalex.org/W1755711892","https://openalex.org/W2160907113","https://openalex.org/W2070813941","https://openalex.org/W3046510185","https://openalex.org/W4387171935"],"abstract_inverted_index":{"The":[0],"proliferation":[1],"of":[2,5,43,49,53,124,146,213],"the":[3,22,47,104,110,144,159,171,181,185],"Internet":[4],"Things":[6],"(IoT)":[7],"is":[8],"reshaping":[9],"our":[10,210],"lifestyle.":[11],"With":[12],"IoT":[13,160],"sensors":[14],"and":[15,51,95,127,188,204,209],"devices":[16,50],"communicating":[17],"with":[18,224],"each":[19],"other":[20],"via":[21],"Internet,":[23],"people":[24],"can":[25,39,202,215],"customize":[26,113],"automation":[27,114,182],"rules":[28,38,54,115,183,218],"to":[29,68,72,93,112,173,192],"meet":[30],"their":[31],"needs.":[32],"Unless":[33],"carefully":[34],"defined,":[35],"however,":[36],"such":[37,98],"easily":[40],"become":[41],"points":[42],"security":[44,105],"failure":[45],"as":[46,162],"number":[48],"complexity":[52],"increase.":[55],"Device":[56],"owners":[57],"may":[58],"end":[59],"up":[60],"unintentionally":[61],"providing":[62],"access":[63],"or":[64,88,91],"revealing":[65],"private":[66],"information":[67],"unauthorized":[69],"entities":[70],"due":[71],"complex":[73],"chain":[74],"reactions":[75],"among":[76],"devices.":[77],"Prior":[78],"work":[79],"on":[80,85],"trigger-action":[81,117],"programming":[82],"either":[83],"focuses":[84],"conflict":[86],"resolution":[87],"usability":[89],"issues":[90],"fails":[92],"accurately":[94,174,205],"efficiently":[96,203],"detect":[97],"attack":[99,141,155,207],"chains.":[100],"This":[101],"paper":[102],"explores":[103],"vulnerabilities":[106],"when":[107],"users":[108],"have":[109],"freedom":[111],"using":[116],"programming.":[118],"We":[119],"define":[120],"two":[121],"broad":[122],"classes":[123],"attack-privilege":[125],"escalation":[126],"privacy":[128],"leakage":[129],"-and":[130],"present":[131],"a":[132,163],"practical":[133],"model-checking-based":[134],"system":[135],"called":[136],"SafeChain":[137,153,169,201,214],"that":[138,200],"detects":[139],"hidden":[140],"chains":[142,156],"exploiting":[143],"combination":[145],"rules.":[147],"Built":[148],"upon":[149],"existing":[150],"model-checking":[151],"techniques,":[152],"identifies":[154],"by":[157,178],"modeling":[158],"ecosystem":[161],"finite-state":[164],"machine.":[165],"To":[166],"improve":[167],"practicability,":[168],"avoids":[170],"need":[172],"model":[175],"an":[176],"environment":[177],"frequently":[179],"rechecking":[180],"given":[184],"current":[186],"states":[187],"employs":[189],"rule-aware":[190],"optimizations":[191],"further":[193],"reduce":[194],"overhead.":[195],"Our":[196],"comparative":[197],"analysis":[198],"shows":[199],"identify":[206],"chains,":[208],"prototype":[211],"implementation":[212],"verify":[216],"100":[217],"in":[219],"less":[220],"than":[221],"1":[222],"s":[223],"no":[225],"false":[226],"positives.":[227]},"counts_by_year":[{"year":2025,"cited_by_count":6},{"year":2024,"cited_by_count":13},{"year":2023,"cited_by_count":6},{"year":2022,"cited_by_count":12},{"year":2021,"cited_by_count":7},{"year":2020,"cited_by_count":7},{"year":2019,"cited_by_count":4}],"updated_date":"2026-03-20T23:20:44.827607","created_date":"2019-02-21T00:00:00"}
