Hey Alexa, is this Skill Safe?: Taking a Closer Look at the Alexa Skill Ecosystem

Hey Alexa, is this Skill Safe?: Taking a Closer Look at the Alexa Skill Ecosystem
复制标题

DOI:
10.14722/ndss.2021.23111
复制
发表时间:
2021
期刊:
Proceedings 2021 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Christopher Lentzsch;Sheel Shah;Benjamin Andow;Martin Degeling;Anupam Das;W. Enck
Christopher Lentzsch;Sheel Shah;Benjamin Andow;Martin Degeling;Anupam Das;W. Enck
中科院分区:
其他
文献类型:
--
作者:
Christopher Lentzsch;Sheel Shah;Benjamin Andow;Martin Degeling;Anupam Das;W. Enck

文献摘要

相似文献

-亚马逊的语音助手Alexa,使用户能够通过自然语言对话直接与各种网络服务进行交互。它为开发人员提供了创建第三方应用程序(称为Skills)以运行在Alexa之上的选项。虽然这些应用程序简化了用户与智能设备的交互,并支持了许多额外的服务,但由于它们所处的个人环境,它们也引起了人们对安全和隐私的担忧。本文旨在对Alexa技能生态系统进行系统分析。我们对Alexa技能进行了第一次大规模分析,从七个不同的技能存储中获得了90194种独特的技能。我们的分析揭示了当前技能审查过程中存在的一些限制。我们表明,恶意用户不仅可以以任意开发人员/公司的名义发布技能,而且还可以在批准后修改后端代码,以诱使用户泄露不想要的信息。接下来,我们将形式化不同的技能-下蹲技术,并评估这些技术的功效。我们发现,虽然某些方法比其他方法更有利,但在现实世界中并没有大量滥用蹲法。最后,我们研究了不同类别技能的隐私政策的流行程度,更重要的是,使用Alexa权限模型访问敏感用户数据的技能的策略内容。我们发现,大约23.3%的此类技能没有完全披露与所请求权限相关的数据类型。最后,我们提供了一些建议,以加强整个生态系统,从而提高最终用户的透明度。
—Amazon’s voice-based assistant, Alexa, enables users to directly interact with various web services through natural language dialogues. It provides developers with the option to create third-party applications (known as Skills ) to run on top of Alexa. While such applications ease users’ interaction with smart devices and bolster a number of additional services, they also raise security and privacy concerns due to the personal setting they operate in. This paper aims to perform a systematic analysis of the Alexa skill ecosystem. We perform the first large-scale analysis of Alexa skills, obtained from seven different skill stores totaling to 90,194 unique skills. Our analysis reveals several limitations that exist in the current skill vetting process. We show that not only can a malicious user publish a skill under any arbitrary developer/company name, but she can also make backend code changes after approval to coax users into revealing unwanted information. We, next, formalize the different skill-squatting techniques and evaluate the efficacy of such techniques. We find that while certain approaches are more favorable than others, there is no substantial abuse of skill squatting in the real world. Lastly, we study the prevalence of privacy policies across different categories of skill, and more importantly the policy content of skills that use the Alexa permission model to access sensitive user data. We find that around 23.3% of such skills do not fully disclose the data types associated with the permissions requested. We conclude by providing some suggestions for strengthening the overall ecosystem, and thereby enhance transparency for end-users.