...
首页> 外文期刊>Digital investigation >Certificate Injection-Based Encrypted Traffic Forensics in AI Speaker Ecosystem
【24h】

Certificate Injection-Based Encrypted Traffic Forensics in AI Speaker Ecosystem

机译:AI扬声器生态系统中的证书注塑加密交通取证

获取原文
获取原文并翻译 | 示例
           

摘要

AI Speakers are typical cloud-based internet of things (IoT) devices that store a variety of information regarding users on the cloud. Although analyzing encrypted traffic between these devices and the cloud, as well as the artifacts stored there, is an important research topic from the perspective of cloud-based IoT forensics, studies on directly analyzing encrypted traffic between AI Speakers and the cloud remain insufficient. In this study, we propose a forensic model that can collect and analyze encrypted traffic between an AI Speaker and the cloud based on a certificate injection. The proposed model consists of porting AI Speaker image on Android device, porting AI Speaker image using QEMU (Quick EMUlator), running exploit using the AI Speaker app vulnerability, rewriting Flash memory using H/W interface, and reworking and updating Flash memory. These five forensic methods are used to inject the certificate into AI Speakers. The proposed model shows that we can analyze encrypted traffic against various AI Speakers such as an Amazon Echo Dot, Naver Clova, SKT NUGU Candle, SKT NUGU, and KT GiGA Genie, and obtain artifacts stored on the cloud. In addition, we develop a verification tool that collects artifacts stored on KT GiGA Genie cloud. (C) 2020 The Author(s). Published by Elsevier Ltd on behalf of DFRWS. All rights reserved. .
机译:AI扬声器是基于典型的云的互联网(IOT)设备,其存储有关云用户的各种信息。虽然分析了这些设备和云之间的加密流量,以及存储在那里的伪像,但是从基于云的IOT取证的角度来看是一个重要的研究课题,即直接分析AI扬声器和云之间的加密流量的研究仍然不足。在本研究中,我们提出了一种法医模型,可以根据证书注入收集和分析AI扬声器和云之间的加密流量。所提出的模型包括在Android设备上移植AI扬声器图像,使用QEMU(快速仿真器)移植AI扬声器图像,使用AI扬声器应用程序漏洞运行Exploit,使用H / W接口重写闪存,并重新加工和更新闪存。这五种法医方法用于将证书注入AI扬声器。拟议的模型表明,我们可以分析针对亚马逊回声点,Naver Clova,Skt Nugu Candle,SKT Nugu和Kt Giga Genie等各种AI扬声器的加密流量,并获得存储在云上的伪影。此外,我们还开发一个验证工具,该工具收集存储在KT Giga Genie云上的工件。 (c)2020提交人。 elsevier有限公司代表DFRW出版。版权所有。 。

著录项

  • 来源
    《Digital investigation》 |2020年第7期|301010.s1-301010.s13|共13页
  • 作者单位

    Ajou Univ Dept Comp Engn World Cup Ro 206 Suwon 16499 South Korea;

    Ajou Univ Dept Comp Engn World Cup Ro 206 Suwon 16499 South Korea;

    Ajou Univ Dept Comp Engn World Cup Ro 206 Suwon 16499 South Korea;

    Ajou Univ Dept Comp Engn World Cup Ro 206 Suwon 16499 South Korea;

    Ajou Univ Dept Comp Engn World Cup Ro 206 Suwon 16499 South Korea;

    Ajou Univ Dept Comp Engn World Cup Ro 206 Suwon 16499 South Korea|Ajou Univ Dept Cyber Secur World Cup Ro 206 Suwon 16499 South Korea;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Al Speaker; Certificate injectiion; MitM; Cloud; Amazon alexa; KT GiGA genie; SKT NUGU;

    机译:Al扬声器;证书注射;麻省理工学院;云;亚马逊alexa;kt giga genie;skt nugu;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号