SkillVet: Automated Traceability Analysis of Amazon Alexa Skills

نویسندگان

چکیده

Skills, are essential components in Smart Personal Assistants (SPA). The number of skills has grown rapidly, dominated by a changing environment that no clear business model. Skills can access personal information and this may pose risk to users. However, there is little about how ecosystem works, let alone the tools facilitate its study. In article, we present largest systematic measurement Amazon Alexa skill date. We study developers’ practices ecosystem, including they collect justify need for sensitive information, designing methodology identify over-privileged with broken privacy policies. 199,295 uncover around 43% (and 50% developers) request these permissions follow bad practices, (partially) data traceability. order perform kind analysis at scale, SkillVet leverages machine learning natural language processing techniques, generates high-accuracy prediction sets. report several concerning developers bypass Alexa's permission system through account linking conversational skills, offer recommendations on improve transparency, security. Resulting from responsible disclosure did, 13% reported issues longer threat submission time.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Digital Forensic Approaches for Amazon Alexa Ecosystem

Internet of Things (IoT) devices such as the Amazon Echo a smart speaker developed by Amazon are undoubtedly great sources of potential digital evidence due to their ubiquitous use and their always-on mode of operation, constituting a human-life’s black box. The Amazon Echo in particular plays a centric role for the cloud-based intelligent virtual assistant (IVA) Alexa developed by Amazon Lab12...

متن کامل

Alexa, Ask Wikidata! Voice Interaction with Knowledge Graphs using Amazon Alexa

Voice-enabled user interfaces have become a popular means of interaction with various kinds of applications and services. In addition to more traditional interaction paradigms such as keyword search, voice interaction can be a convenient means of communication for many groups of users. Amazon Alexa has become a valuable tool for building custom voice-enabled applications. In this demo paper we ...

متن کامل

Automated traceability analysis for UML model refinements

During iterative, UML-based software development, various UML diagrams, modeling the same system at different levels of abstraction are developed. These models must remain consistent when changes are performed. In this context, we refine the notion of impact analysis and distinguish horizontal impact analysis–that focuses on changes and impacts at one level of abstraction–from vertical impact a...

متن کامل

Towards automated traceability maintenance

Traceability relations support stakeholders in understanding the dependencies between artifacts created during the development of a software system and thus enable many development-related tasks. To ensure that the anticipated benefits of these tasks can be realized, it is necessary to have an up-to-date set of traceability relations between the established artifacts. This goal requires the cre...

متن کامل

Enabling Automated Traceability Maintenance through the Upkeep of Traceability Relations

Traceability is demanded within mature development processes and offers a wide range of advantages. Nevertheless, there are deterrents to establishing traceability: it can be painstaking to achieve initially and then subject to almost instantaneous decay. To be effective, this is clearly an investment that should be retained. We therefore focus on reducing the manual effort incurred in performi...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: IEEE Transactions on Dependable and Secure Computing

سال: 2023

ISSN: ['1941-0018', '1545-5971', '2160-9209']

DOI: https://doi.org/10.1109/tdsc.2021.3129116