Using Amazon Alexa APIs as a Source of Digital Evidence

No ratings

Presented at CyberScience2020 2020 by

With the release of Amazon Alexa and the first Amazon Echo device, the company revolutionised thesmart home. It allowed their users to communicate with, and control, their smart home ecosystem purely using voicecommands. However, this also means that Amazon processes and store a large amount of personal data about theirusers, as these devices are always present and always listening in peoples’ private homes. That makes this data avaluable source of evidence for investigators performing digital forensics. The Alexa Voice Service uses a series ofAPIs for communication between clients and the Amazon cloud. These APIs return a wide range of datarelated to the functionality of the device used. The first goal of this research was to clarify exactly what kind of information about the user is stored and accessible through these APIs. To do this, a combination of literature reviewand exploratory analysis was used to establish a list of all relevant APIs. Then, possible artefacts and conclusions tobe drawn from their responses were identified and presented. Lastly, the perspective of the users was taken, andoptions for improving their privacy were reviewed. Specifically, the history of interaction between the user and Alexais available through multiple APIs, and there are several options to delete it. It was determined that these optionshave different behaviours and that most of them do not remove all data related to user interaction.