<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Enabling End-Users to Specify Security Rules with the EFESTO-5W Platform</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Vincenzo Deufemia</string-name>
          <email>deufemia@unisa.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Bernardo Breve</string-name>
          <email>bbreve@unisa.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Francesco Greco</string-name>
          <email>francesco.greco@uniba.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Giuseppe Desolda</string-name>
          <email>giuseppe.desolda@uniba.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Maristella Matera</string-name>
          <email>maristella.matera@polimi.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>End-User Development, Internet of Things</institution>
          ,
          <addr-line>Cyber Security</addr-line>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Politecnico di Milano</institution>
          ,
          <addr-line>Milano MI 20133</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>University of Bari Aldo Moro</institution>
          ,
          <addr-line>Bari BA 70121</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>University of Salerno</institution>
          ,
          <addr-line>Fisciano SA 84084</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2021</year>
      </pub-date>
      <abstract>
        <p>threats. Given the spread of the Internet of Things (IoT) technology, end-users have begun raising the need for configuring their smart environments. Task Automation Systems (TASs) recently emerged as tools to simplify the definition of trigger-action rules for personalizing the behavior of such devices. However, such tools do not take into account a typical aspect of IoT technologies, i.e., the security and privacy threats to which the smart devices are exposed to. This position paper describes how TASs can be extended to support end-users in the specification of trigger-action rules addressing security and privacy EMPATHY: Empowering People in Dealing with Internet of Things Ecosystems. Workshop co-located with INTERACT</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>EFESTO-5W</p>
    </sec>
    <sec id="sec-2">
      <title>1. Introduction</title>
      <p>
        In the last years, the Internet of Things (IoT) fostered the development of the so-called smart
objects, which are digital devices embedding sensors and/or actuators, connected to the Internet,
and that communicate among them creating ecosystems of heterogeneous and distributed
services [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. Given the spread of such technology, end-users began raising the need for
configuring their smart environments. Task Automation Systems (TASs) recently emerged as tools to
support non-technical users in defining the personalized behavior of smart objects. Such tools
provide visual simplified mechanisms that help users in performing trigger-action programming
by defining Event-Condition-Action (ECA) rules that specify smart objects’ behavior. With
TASs, the users can therefore take advantage of their smart objects by creating synchronizations
that accommodate their every day and contextual needs.
      </p>
      <p>
        Despite their unquestionable benefits TASs still neglect an important aspect in the IoT
landscape, i.e., security and privacy issues. Indeed, smart objects represent an attractive target
for attackers, who might violate smart environments for manipulating data and stealing personal
nEvelop-O
information [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. This problem is amplified when end-users, who are not provided with suficient
skills in security and privacy, put in communication their devices by using TASs. In addition,
they underestimate the importance of these aspects in defending their smart environments,
thus they neglect countermeasures that might protect the security of their smart devices [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
      </p>
      <p>This position paper describes an ongoing work that aims to support end-users in defending
their smart environment. To this aim, we designed and evaluated a visual paradigm for TASs
that facilitates the end-users in understanding and controlling security and privacy threats.
This paper reports some technical details on how TASs can implement the proposed solution.</p>
    </sec>
    <sec id="sec-3">
      <title>2. Extending TAS capabilities for managing security and privacy aspects</title>
      <p>
        In order to include security and privacy management capabilities in TASs, we focused on
EFESTO-5W, a TAS that provides visual mechanisms to create ECA rules characterized by
multiple events/actions and temporal and spatial constraints on events and actions [
        <xref ref-type="bibr" rid="ref4 ref5">4, 5</xref>
        ]. We
extended the EFESTO-5W visual paradigm and its functionalities so that end-users could manage
security and privacy threats of a smart environment. The seed of this research is a smart object
called Intrusion Defender (ID), which monitors the network trafic of a private area network
(PAN) to detect attacks against smart devices. The proposed visual paradigm facilitates
endusers to leverage the monitor capabilities of the ID through the definition of ECA rules like
“IF the ID detects a virus in the IP camera THEN turn of the IP camera ”. It is worth remarking
that the visual mechanisms and the functionalities described in this paper, despite have been
designed and tested for EFESTO-5W, can be applied to any TAS.
      </p>
    </sec>
    <sec id="sec-4">
      <title>3. Intrusion Defender architecture</title>
      <p>
        The ID is built on top of Snort1 [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], a Network Intrusion Detection System that monitors all
packets traveling from/to the PAN to detect attacks and suspect activities. Any anomalous
pattern in the network trafic is identified and associated by the ID with a known security or
privacy threatening event.
      </p>
      <p>According to our proposal, it runs on a Raspberry Pi board that must be installed inside the
PAN the users want to protect. The ID monitors the PAN trafic and eventually sends messages
to the EFESTO-5W remote server when an attack is detected (see Figure 1).</p>
      <p>
        Through the TAS, like EFESTO-5W in our case, users are given the possibility to trigger
a rule according to 6 diferent security and privacy threatening events, each one associated
with a specific attack the ID can detect. These events are the results of the previous study that
addressed two main challenges. First, since the ID natively detects several attacks (35 in the
current implementation), this high number can overload the users with too much information.
Second, the detected attacks refer to technical cybersecurity concepts (e.g., DDoS, man in the
middle, etc.), which are too complex for lay users. To address the first challenge, we performed
a card sorting study with 11 IT and cybersecurity experts to group the 35 attacks detected
by Snort according to their similarity [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. This activity led to the definition of 6 groups of
attacks. To solve the second challenge, and in particular to expose the ID events in a simple
way within TASs, we purposely designed 6 event messages, one for each group of attacks, in
order to simplify the meaning of the attacks to non-technical users. The resulting ID events are:
1. Someone is attacking one of your smart devices. This has the goal to make the device collapse;
2. A virus has infected one of your smart devices. This virus can compromise your device and
your privacy (e.g., steal your files and passwords) ;
3. A non-authorized user has accessed one of your devices (or is trying to). If not stopped, this
user may damage your device and steal your private data;
4. Someone is trying to steal your private data on one of your smart devices. This can threaten
your privacy (e.g., pictures/video stolen);
5. Someone is looking for vulnerabilities in your network. This event might reveal an incoming
attack;
6. Suspicious activity is going on against your network. Someone could be trying to attack and
access your network.
      </p>
      <p>End-users can thus define an ECA rule using these ID events according to the threat they
want to manage, and one or more actions in response to it. Figure 2 shows an example of an
ECA rule configured with EFESTO-5W. This rule is triggered when the ID detects a virus in the
Hallway camera, and reacts by turning of the attacked camera.</p>
      <p>
        Every time a user defines an ECA rule in EFESTO-5W, a JSON file describing the rule is
created according to the Node-RED syntax, since Node-RED is used in EFESTO-5W as rule
engine [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. Each rule of EFESTO-5W is, thus, represented as a Node-RED ”flow” (i.e., a set of
nodes which describe the rule). An EFESTO-5W rule, containing as event the ID smart object,
translates to a Node-RED flow, in which the ID event is represented by an MQTT node listening
on a specific port (in our configuration it is port 18883).
      </p>
      <p>If the ID device detects an attack, it sends the attack details to the MQTT broker; the latter, in
turn, notifies the MQTT node of the Node-RED flow (which represents the rule in EFESTO-5W).
Then, the node checks if this attack is the one defined by the user in the rule. For example, to
check if the triggered event of the ID is “Someone is attacking one of your smart devices...”, in the
node there is the following code:</p>
      <p>In this code, the msg.payload includes the details of the attack received through the MQTT
broker. To verify whether the attack is the one defined in the rule event, the classname attribute
of the payload is compared with all the labels representing the ID event. Indeed, as we already
explained above, the ID device can detect 35 attacks but they were grouped in 6 events, each
one including similar attacks whose name is reported in a label. If the attack detected by the
ID device is the same of one of the labels related to the event specified in the rule, the rule is
triggered. This architecture is general enough to be implemented in every TAS. Of course, while
in EFESTO-5W the ID device is represented by a Node-RED node, in other TASs it must be
coded according to the specific solutions adopted to develop the tool, but the MQTT guarantees
a strong decoupling between the ID device and the specific TAS.</p>
    </sec>
    <sec id="sec-5">
      <title>4. Conclusions</title>
      <p>In this position paper, we presented a solution to help users defend their smart environment
thanks to the use of a specific smart device, the Intrusion Defender, whose monitor capabilities
can be leveraged by using a TAS. In addition, we also reported some technical details about the
integration of TASs and the ID device.</p>
      <p>
        As future works, we are going to refine the 6 events provided by the ID device, according to
the results of the study presented in [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. In addition, we are empowering the entire solution
ofering, on demands, more powerful and low-level mechanisms to deeply control the ID device,
for example, giving to IT and security experts the possibility to create ECA rules including one
or more attacks selected from all the 35 attacks the ID device can detect.
      </p>
    </sec>
    <sec id="sec-6">
      <title>Acknowledgments</title>
      <p>This work has been supported by the Italian Ministry of Education, University and Research
(MIUR) under grant PRIN 2017 “EMPATHY: Empowering People in deAling with internet of
THings ecosYstems” (Progetti di Rilevante Interesse Nazionale – Bando 2017, Grant 2017MX9T7H).</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>L.</given-names>
            <surname>Atzori</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Iera</surname>
          </string-name>
          ,
          <string-name>
            <surname>G. Morabito,</surname>
          </string-name>
          <article-title>The internet of things: A survey</article-title>
          ,
          <source>Computer networks 54</source>
          (
          <year>2010</year>
          )
          <fpage>2787</fpage>
          -
          <lpage>2805</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>M.</given-names>
            <surname>Galluscio</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Neshenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Bou-Harb</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Huang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Ghani</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Crichigno</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Kaddoum</surname>
          </string-name>
          ,
          <article-title>A ifrst empirical look on internet-scale exploitations of iot devices</article-title>
          ,
          <source>in: Proceedings of IEEE 28th annual international symposium on personal, indoor, and mobile radio communications (PIMRC)</source>
          , IEEE,
          <year>2017</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>7</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>A.</given-names>
            <surname>Alqhatani</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H. R.</given-names>
            <surname>Lipford</surname>
          </string-name>
          , “
          <article-title>there is nothing that i need to keep secret”: Sharing practices and concerns of wearable fitness data</article-title>
          ,
          <source>in: Proceedings of Fifteenth Symposium on Usable Privacy and Security (SOUPS'19)</source>
          ,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>G.</given-names>
            <surname>Desolda</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Ardito</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Matera</surname>
          </string-name>
          ,
          <article-title>End-user development for the internet of things: Efesto and the 5w composition paradigm</article-title>
          , in: International Rapid Mashup Challenge, Springer,
          <year>2016</year>
          , pp.
          <fpage>74</fpage>
          -
          <lpage>93</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>G.</given-names>
            <surname>Desolda</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Ardito</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Matera</surname>
          </string-name>
          ,
          <article-title>Empowering end users to customize their smart environments: model, composition paradigms, and domain-specific tools, ACM Transactions on Computer-Human Interaction (TOCHI) 24 (</article-title>
          <year>2017</year>
          )
          <fpage>1</fpage>
          -
          <lpage>52</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>M.</given-names>
            <surname>Roesch</surname>
          </string-name>
          ,
          <article-title>Snort - lightweight intrusion detection for networks</article-title>
          ,
          <source>in: Proceedings of the 13th USENIX Conference on System Administration, LISA '99</source>
          ,
          <string-name>
            <given-names>USENIX</given-names>
            <surname>Association</surname>
          </string-name>
          , USA,
          <year>1999</year>
          , p.
          <fpage>229</fpage>
          -
          <lpage>238</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>B.</given-names>
            <surname>Breve</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Desolda</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Deufemia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Greco</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Matera</surname>
          </string-name>
          ,
          <article-title>An end-user development approach to secure smart environments</article-title>
          , in: D.
          <string-name>
            <surname>Fogli</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          <string-name>
            <surname>Tetteroo</surname>
            ,
            <given-names>B. R.</given-names>
          </string-name>
          <string-name>
            <surname>Barricelli</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Borsci</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          <string-name>
            <surname>Markopoulos</surname>
            ,
            <given-names>G. A.</given-names>
          </string-name>
          <string-name>
            <surname>Papadopoulos</surname>
          </string-name>
          (Eds.),
          <string-name>
            <surname>End-User</surname>
            <given-names>Development</given-names>
          </string-name>
          , Springer International Publishing, Cham,
          <year>2021</year>
          , pp.
          <fpage>36</fpage>
          -
          <lpage>52</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>G.</given-names>
            <surname>Desolda</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Greco</surname>
          </string-name>
          ,
          <article-title>Integrating the node-red server in an iot platform for ECA rules management</article-title>
          , in: G. Desolda,
          <string-name>
            <given-names>V.</given-names>
            <surname>Deufemia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Gena</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Matera</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Paternò</surname>
          </string-name>
          ,
          <string-name>
            <surname>B.</surname>
          </string-name>
          Treccani (Eds.),
          <source>Proceedings of the 1st International Workshop on Empowering People in Dealing with Internet of Things Ecosystems co-located with International Conference on Advanced Visual Interfaces (AVI</source>
          <year>2020</year>
          ), Online / Island of Ischia, Italy,
          <year>September 29</year>
          ,
          <year>2020</year>
          , volume
          <volume>2702</volume>
          <source>of CEUR Workshop Proceedings, CEUR-WS.org</source>
          ,
          <year>2020</year>
          , pp.
          <fpage>45</fpage>
          -
          <lpage>48</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>