Logo des Repositoriums
  • English
  • Deutsch
Anmelden
Keine TU-ID? Klicken Sie hier für mehr Informationen.
  1. Startseite
  2. Publikationen
  3. Publikationen der Technischen Universität Darmstadt
  4. Erstveröffentlichungen
  5. Alexa Lied to Me: Skill-based Man-in-the-Middle Attacks on Virtual Assistants
 
  • Details
2019

Alexa Lied to Me: Skill-based Man-in-the-Middle Attacks on Virtual Assistants

TUDa URI
tuda/4515
URN
urn:nbn:de:tuda-tuprints-86890
DOI
10.26083/tuprints-00008689
Autor:innen
Mitev, Richard
Miettinen, Markus
Sadeghi, Ahmad-Reza
Kurzbeschreibung (Abstract)

Voice-based virtual personal assistants such as Amazon’s Alexa or Google Assistant have become highly popular and are used for diverse daily tasks ranging from querying on-line information, shopping, smart home control and a variety of enterprise application scenarios. Capabilities of virtual assistants can be enhanced with so-called Skills , i.e., programmatic extensions that allow thirdparty providers to integrate their services with the respective voice assistant.

In this paper, we show that specially crafted malicious Skills can use the seemingly limited Skill interaction model to cause harm. We present novel man-in-the-middle attacks against benign Skills and Virtual Assistant functionalities. Our attack uses loopholes in the Skill interface to redirect a victim’s voice input to a malicious Skill, thereby hijacking the conversation between Alexa and the victim. To the best of our knowledge this is the first man-in-the-middle attack targeting the Skill ecosystem. We present the design of our attack and demonstrate its feasibility based on a proof-of-concept implementation attacking the Alexa Skills of a smart lock as well as a home security system.

Sprache
Englisch
Fachbereich/-gebiet
20 Fachbereich Informatik > Sicherheit in der Informationstechnik
DDC
000 Allgemeines, Informatik, Informationswissenschaft > 004 Informatik
600 Technik, Medizin, angewandte Wissenschaften > 600 Technik
Institution
Universitäts- und Landesbibliothek Darmstadt
Ort
Darmstadt
Veranstaltungstitel
ASIACCS 2019
Veranstaltungsort
Auckland, New Zealand
Startdatum der Veranstaltung
09.07.2019
Enddatum der Veranstaltung
12.07.2019
Titel der Zeitschrift / Schriftenreihe
Proceedings of the 2019 on Asia Conference on Computer and Communications Security
PPN
452901111

  • TUprints Leitlinien
  • Cookie-Einstellungen
  • Impressum
  • Datenschutzbestimmungen
  • Webseitenanalyse
Diese Webseite wird von der Universitäts- und Landesbibliothek Darmstadt (ULB) betrieben.