{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/109385"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/109385","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Securing emerging IoT systems through systematic analysis and design","abstract":"The student, Qi Wang, accepted the attached license on 2020-11-24 at 13:26.","abstract_html":"The student, Qi Wang, accepted the attached license on 2020-11-24 at 13:26.","abstract_has_math":false,"creators":["Wang, Qi"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Gunter, Carl A","Nahrstedt, Klara","Bates, Adam","Jee, Kangkook"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2021,"date_issued":"2021-03-05T21:38:04Z","date_published":"2021-03-05T21:38:04Z","updated_at":"2026-07-22T22:24:50Z","subjects":["Internet-of-Things","Data provenance","Trigger-action platform","Security"],"languages":["en"],"rights":["Copyright 2020 Qi Wang"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/109385","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Gunter, Carl A","Nahrstedt, Klara","Bates, Adam","Jee, Kangkook"]},{"key":"dc:creator","label":"Author","values":["Wang, Qi"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2021-03-05T21:38:04Z","2020-11-25","2020-12"]},{"key":"dc:type","label":"Dc Type","values":["text","Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Internet-of-Things","Data provenance","Trigger-action platform","Security"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2020 Qi Wang"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/109385"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["The student, Qi Wang, accepted the attached license on 2020-11-24 at 13:26.","The student, Qi Wang, submitted this Dissertation for approval on 2020-11-24 at 13:35.","This Dissertation was approved for publication on 2020-11-25 at 11:09.","DSpace SAF Submission Ingestion Package generated from Vireo submission #15953 on 2021-03-04 at 15:35:03","The Internet of Things (IoT) is growing very rapidly. A variety of IoT systems have been developed and employed in many domains such as smart home, smart city and industrial control, providing great benefits to our everyday lives. However, as IoT becomes increasingly prevalent and complicated, it is also introducing new attack surfaces and security challenges. We are seeing numerous IoT attacks exploiting the vulnerabilities in IoT systems everyday. Security vulnerabilities may manifest at different layers of the IoT stack. There is no single security solution that can work for the whole ecosystem. In this dissertation, we explore the limitations of emerging IoT systems at different layers and develop techniques and systems to make them more secure. More specifically, we focus on three of the most important layers: the user rule layer, the application layer and the device layer. First, on the user rule layer, we characterize the potential vulnerabilities introduced by the interaction of user-defined automation rules. We introduce iRuler, a static analysis system that uses model checking to detect inter-rule vulnerabilities that exist within trigger-action platforms such as IFTTT in an IoT deployment. Second, on the application layer, we design and build ProvThings, a system that instruments IoT apps to generate data provenance that provides a holistic explanation of system activities, including malicious behaviors. Lastly, on the device layer, we develop ProvDetector and SplitBrain to detect malicious processes using kernel-level provenance tracking and analysis. ProvDetector is a centralized approach that collects all the audit data from the clients and performs detection on the server. SplitBrain extends ProvDetector with collaborative learning, where the clients collaboratively build the detection model and performs detection on the client device.","Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2021-03-04 without embargo terms","Made available in DSpace on 2021-03-05T21:38:04Z (GMT). No. of bitstreams: 2 WANG-DISSERTATION-2020.pdf: 4649729 bytes, checksum: caa6d6be5f0c188cf04d9e9d8503fd28 (MD5) LICENSE.txt: 4204 bytes, checksum: 3ad19def3319bb8e5b63c30da2e245ed (MD5) Previous issue date: 2020-11-25"]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Securing emerging IoT systems through systematic analysis and design"]}]}],"canonical_facts":{"dc:contributor":["Gunter, Carl A","Nahrstedt, Klara","Bates, Adam","Jee, Kangkook"],"dc:creator":["Wang, Qi"],"dc:date":["2021-03-05T21:38:04Z","2020-11-25","2020-12"],"dc:description":["The student, Qi Wang, accepted the attached license on 2020-11-24 at 13:26.","The student, Qi Wang, submitted this Dissertation for approval on 2020-11-24 at 13:35.","This Dissertation was approved for publication on 2020-11-25 at 11:09.","DSpace SAF Submission Ingestion Package generated from Vireo submission #15953 on 2021-03-04 at 15:35:03","The Internet of Things (IoT) is growing very rapidly. A variety of IoT systems have been developed and employed in many domains such as smart home, smart city and industrial control, providing great benefits to our everyday lives. However, as IoT becomes increasingly prevalent and complicated, it is also introducing new attack surfaces and security challenges. We are seeing numerous IoT attacks exploiting the vulnerabilities in IoT systems everyday. Security vulnerabilities may manifest at different layers of the IoT stack. There is no single security solution that can work for the whole ecosystem. In this dissertation, we explore the limitations of emerging IoT systems at different layers and develop techniques and systems to make them more secure. More specifically, we focus on three of the most important layers: the user rule layer, the application layer and the device layer. First, on the user rule layer, we characterize the potential vulnerabilities introduced by the interaction of user-defined automation rules. We introduce iRuler, a static analysis system that uses model checking to detect inter-rule vulnerabilities that exist within trigger-action platforms such as IFTTT in an IoT deployment. Second, on the application layer, we design and build ProvThings, a system that instruments IoT apps to generate data provenance that provides a holistic explanation of system activities, including malicious behaviors. Lastly, on the device layer, we develop ProvDetector and SplitBrain to detect malicious processes using kernel-level provenance tracking and analysis. ProvDetector is a centralized approach that collects all the audit data from the clients and performs detection on the server. SplitBrain extends ProvDetector with collaborative learning, where the clients collaboratively build the detection model and performs detection on the client device.","Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2021-03-04 without embargo terms","Made available in DSpace on 2021-03-05T21:38:04Z (GMT). No. of bitstreams: 2 WANG-DISSERTATION-2020.pdf: 4649729 bytes, checksum: caa6d6be5f0c188cf04d9e9d8503fd28 (MD5) LICENSE.txt: 4204 bytes, checksum: 3ad19def3319bb8e5b63c30da2e245ed (MD5) Previous issue date: 2020-11-25"],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/109385"],"dc:language":["en"],"dc:rights":["Copyright 2020 Qi Wang"],"dc:subject":["Internet-of-Things","Data provenance","Trigger-action platform","Security"],"dc:title":["Securing emerging IoT systems through systematic analysis and design"],"dc:type":["text","Thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:50Z"}