Exploring the security and privacy risks of chatbots in messaging services

Exploring the security and privacy risks of chatbots in messaging services
复制标题

探索消息服务中聊天机器人的安全和隐私风险

DOI:
10.1145/3517745.3561433
复制
发表时间:
2022
期刊:
ACM Internet Measurement Conference (IMC
影响因子:
--
通讯作者:
Such, Jose
Such, Jose
中科院分区:
--
文献类型:
--
作者:
Edu, Jide;Mulligan, Cliona;Pierazzi, Fabio;Polakis, Jason;Suarez-Tangil, Guillermo;Such, Jose

文献摘要

相似文献

工作和娱乐的消息传递平台的前所未有的采用使其成为恶意行为者的一个有吸引力的目标。在这种情况下,第三方应用程序(所谓的聊天机器人)提供了各种有吸引力的功能,支持大型渠道的体验。不幸的是,在当前的许可和部署模型下,消息传递系统中的聊天机器人可以在受害者不知情的情况下从渠道窃取信息。在本文中,我们提出了一种结合静态和动态分析的方法,用于自动评估消息平台聊天机器人中的安全和隐私问题。我们还提供了来自流行的Discord平台的初步调查结果,突出了聊天机器人给用户带来的风险。与Slack或MS Teams等其他流行平台不同,Discord不实现用户权限检查-这是委托给第三方开发人员的任务。其中,我们发现来自领先的Discord存储库的55%的聊天机器人请求“管理员”权限,只有4.35%的聊天机器人实际上提供了隐私策略。
The unprecedented adoption of messaging platforms for work and recreation has made it an attractive target for malicious actors. In this context, third-party apps (so-called chatbots) offer a variety of attractive functionalities that support the experience in large channels. Unfortunately, under the current permission and deployment models, chatbots in messaging systems could steal information from channels without the victim's awareness. In this paper, we propose a methodology that incorporates static and dynamic analysis for automatically assessing security and privacy issues in messaging platform chatbots. We also provide preliminary findings from the popular Discord platform that highlight the risks that chatbots pose to users. Unlike other popular platforms like Slack or MS Teams, Discord does not implement user-permission checks---a task entrusted to third-party developers. Among others, we find that 55% of chatbots from a leading Discord repository request the "administrator" permission, and only 4.35% of chatbots with permissions actually provide a privacy policy.