Certificate Injection-Based Encrypted Traffic Forensics in AI Speaker Ecosystem

被引:18
|
作者
Shin, Yeonghun [1 ]
Kim, Hyungchan [1 ]
Kim, Sungbum [1 ]
Yoo, Dongkyun [1 ]
Jo, Wooyeon [1 ]
Shon, Taeshik [1 ,2 ]
机构
[1] Ajou Univ, Dept Comp Engn, World Cup Ro 206, Suwon 16499, South Korea
[2] Ajou Univ, Dept Cyber Secur, World Cup Ro 206, Suwon 16499, South Korea
基金
新加坡国家研究基金会;
关键词
Al Speaker; Certificate injectiion; MitM; Cloud; Amazon alexa; KT GiGA genie; SKT NUGU;
D O I
10.1016/j.fsidi.2020.301010
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
AI Speakers are typical cloud-based internet of things (IoT) devices that store a variety of information regarding users on the cloud. Although analyzing encrypted traffic between these devices and the cloud, as well as the artifacts stored there, is an important research topic from the perspective of cloud-based IoT forensics, studies on directly analyzing encrypted traffic between AI Speakers and the cloud remain insufficient. In this study, we propose a forensic model that can collect and analyze encrypted traffic between an AI Speaker and the cloud based on a certificate injection. The proposed model consists of porting AI Speaker image on Android device, porting AI Speaker image using QEMU (Quick EMUlator), running exploit using the AI Speaker app vulnerability, rewriting Flash memory using H/W interface, and reworking and updating Flash memory. These five forensic methods are used to inject the certificate into AI Speakers. The proposed model shows that we can analyze encrypted traffic against various AI Speakers such as an Amazon Echo Dot, Naver Clova, SKT NUGU Candle, SKT NUGU, and KT GiGA Genie, and obtain artifacts stored on the cloud. In addition, we develop a verification tool that collects artifacts stored on KT GiGA Genie cloud. (C) 2020 The Author(s). Published by Elsevier Ltd on behalf of DFRWS. All rights reserved. .
引用
收藏
页数:13
相关论文
共 1 条
  • [1] AI-Based Malicious Encrypted Traffic Detection in 5G Data Collection and Secure Sharing
    Han, Gang
    Zhang, Haohe
    Zhang, Zhongliang
    Ma, Yan
    Yang, Tiantian
    ELECTRONICS, 2025, 14 (01):