SkillVet: Automated Traceability Analysis of Amazon Alexa Skills

SkillVet: Automated Traceability Analysis of Amazon Alexa Skills
复制标题

DOI:
10.1109/tdsc.2021.3129116
复制
发表时间:
2021-03
影响因子:
7.3
通讯作者:
Jide S. Edu;Xavier Ferrer-Aran;J. Such;Guillermo Suarez-Tangil
Jide S. Edu;Xavier Ferrer-Aran;J. Such;Guillermo Suarez-Tangil
中科院分区:
计算机科学2区
文献类型:
--
作者:
Jide S. Edu;Xavier Ferrer-Aran;J. Such;Guillermo Suarez-Tangil

文献摘要

相似文献

技能是智能个人助理(SPA)的重要组成部分。技能的数量迅速增长,主要是由于环境不断变化,没有明确的商业模式。技能可以访问个人信息,这可能会给用户带来风险。然而,关于这个生态系统如何运作的信息很少,更不用说可以促进其研究的工具了。在本文中,我们介绍了迄今为止亚马逊Alexa技能生态系统的最大系统测量。我们研究开发人员在这个生态系统中的做法,包括他们如何收集和证明对敏感信息的需求,通过设计一种方法来识别违反隐私政策的过度特权技能。我们收集了199,295个Alexa技能,发现大约43%的技能(和50%的开发人员)请求这些权限遵循不良的隐私惯例,包括(部分)破坏数据权限可追溯性。为了大规模地进行这种分析,我们提出了SkillVet,它利用机器学习和自然语言处理技术,并生成高精度的预测集。我们报告了几个有关的做法,包括开发人员如何通过帐户链接和会话技能绕过Alexa的许可系统,并就如何提高透明度,隐私和安全性提供建议。由于我们所做的负责任的披露,13%的报告问题在提交时不再构成威胁。
Skills, are essential components in Smart Personal Assistants (SPA). The number of skills has grown rapidly, dominated by a changing environment that has no clear business model. Skills can access personal information and this may pose a risk to users. However, there is little information about how this ecosystem works, let alone the tools that can facilitate its study. In this article, we present the largest systematic measurement of the Amazon Alexa skill ecosystem to date. We study developers’ practices in this ecosystem, including how they collect and justify the need for sensitive information, by designing a methodology to identify over-privileged skills with broken privacy policies. We collect 199,295 Alexa skills and uncover that around 43% of the skills (and 50% of the developers) that request these permissions follow bad privacy practices, including (partially) broken data permissions traceability. In order to perform this kind of analysis at scale, we present SkillVet that leverages machine learning and natural language processing techniques, and generates high-accuracy prediction sets. We report several concerning practices, including how developers can bypass Alexa's permission system through account linking and conversational skills, and offer recommendations on how to improve transparency, privacy and security. Resulting from the responsible disclosure we did, 13% of the reported issues no longer pose a threat at submission time.