论文标题
基于Web的Chatbots的安全性和隐私风险的经验评估
An Empirical Assessment of Security and Privacy Risks of Web based-Chatbots
论文作者
论文摘要
基于Web的聊天机器人为网站所有者提供了增加销售,对客户的立即响应以及对客户行为的洞察力的好处。尽管基于Web的聊天机器人越来越受欢迎,但他们并没有受到安全研究人员的审查。所有者的好处是以用户隐私和安全为代价的。漏洞(例如跟踪cookie和第三方域)可以隐藏在聊天机器人的iframe脚本中。本文对前100万Alexa网站中的五个基于网络的聊天机器人进行了大规模分析。通过我们的爬行工具,我们在这100万个网站中确定了聊天机器人的存在。我们发现,在前100万Alexa网站(1.59%)中,有13,515个使用了五个分析的聊天机器人之一。我们的分析表明,前300k Alexa排名网站由嵌入最少数量的第三方域的对讲机器人主导。 Livechat聊天机器人主导了其余的网站,并嵌入了第三方域的最高样本。我们还发现850(6.29%)的聊天机器人使用不安全协议以纯文本传输用户的聊天。此外,有些聊天机器人在很大程度上依靠cookie来跟踪和广告。聊天机器人IFRAMES中确定的cookie中有三分之二(68.92%)用于广告和跟踪用户。我们的结果表明,尽管大多数网站给出了隐私,安全性和匿名性的承诺,但数百万用户可能会在不知不觉中受到聊天机器人服务提供商的安全保证的不良保证
Web-based chatbots provide website owners with the benefits of increased sales, immediate response to their customers, and insight into customer behaviour. While Web-based chatbots are getting popular, they have not received much scrutiny from security researchers. The benefits to owners come at the cost of users' privacy and security. Vulnerabilities, such as tracking cookies and third-party domains, can be hidden in the chatbot's iFrame script. This paper presents a large-scale analysis of five Web-based chatbots among the top 1-million Alexa websites. Through our crawler tool, we identify the presence of chatbots in these 1-million websites. We discover that 13,515 out of the top 1-million Alexa websites (1.59%) use one of the five analysed chatbots. Our analysis reveals that the top 300k Alexa ranking websites are dominated by Intercom chatbots that embed the least number of third-party domains. LiveChat chatbots dominate the remaining websites and embed the highest samples of third-party domains. We also find that 850 (6.29%) of the chatbots use insecure protocols to transfer users' chats in plain text. Furthermore, some chatbots heavily rely on cookies for tracking and advertisement purposes. More than two-thirds (68.92%) of the identified cookies in chatbot iFrames are used for ads and tracking users. Our results show that, despite the promises for privacy, security, and anonymity given by the majority of the websites, millions of users may unknowingly be subject to poor security guarantees by chatbot service providers