首页> 外文会议>IFIP WG 6.1 International Conference on Testing Software and Systems >Interrogating Virtual Agents: In Quest of Security Vulnerabilities
【24h】

Interrogating Virtual Agents: In Quest of Security Vulnerabilities

机译:询问虚拟代理:在寻求安全漏洞中

获取原文

摘要

Chatbots, i.e., systems that communicate in natural language, have been of increasing importance over the last few years. These virtual agents provide specific services or products to clients on a 24/7 basis. Chatbots provide a simple and intuitive interface, i.e., natural language processing, which makes them increasingly attractive for various applications. In fact, chatbots are used as substitutes for repetitive tasks or user inquiries that can be automated. However, these advantages always are accompanied with concerns, e.g., whether security and privacy can be assured. These concerns become more and more important, because in contrast to simple requests, more sophisticated chatbots are able to utilize personalized services to users. In such cases, sensitive user data are processed and exchanged. Hence, such systems become natural targets for cyber-attacks with unforeseen consequences. For this reason, assuring information security of chatbots is an important challenge in practice. In this paper, we contribute to this challenge and introduce an automated security testing approach for chatbots. The presented framework is able to generate and run tests in order to detect intrinsic software weaknesses leading to the XSS vulnerability. We assume a vulnerability to be triggered when obtaining critical information from or crashing the virtual agent, regardless of its purpose. We discuss the underlying basic foundations and demonstrate the testing approach using several real-world chatbots.
机译:Chatbots,即以自然语言通信的系统,在过去几年中越来越重要。这些虚拟代理商在24/7的基础上为客户提供特定的服务或产品。 Chatbots提供简单而直观的接口,即自然语言处理,使它们对各种应用程序越来越吸引人。实际上,Chatbots被用作可以自动化的重复任务或用户查询的替代品。然而,这些优点总是伴随着担忧,例如,无论是否可以确保安全和隐私。这些问题变得越来越重要,因为与简单的请求相反,更复杂的聊天禁止能够对用户使用个性化服务。在这种情况下,处理和交换敏感的用户数据。因此,这种系统成为具有无法预见的后果的网络攻击的自然目标。出于这个原因,确保Chatbots的信息安全是实践中的重要挑战。在本文中,我们为此挑战造成了贡献,并为Chatbots引入自动安全测试方法。呈现的框架能够生成和运行测试,以检测导致XSS漏洞的内在软件缺点。无论其目的如何,我们假设在从虚拟代理中获取或崩溃虚拟代理时要触发的漏洞。我们讨论基本基础基础,并使用几个现实世界聊天展示测试方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号