论文标题
使用亚马逊Alexa API作为数字证据的来源
Using Amazon Alexa APIs as a Source of Digital Evidence
论文作者
论文摘要
随着Amazon Alexa的发行和第一个亚马逊回声设备,该公司彻底改变了智能家居。它允许用户纯粹使用语音命令与用户与智能家居生态系统进行通信并控制其智能家居生态系统。但是,这也意味着亚马逊流程并存储有关用户的大量个人数据,因为这些设备始终存在并始终在人们的私人住宅中聆听。这使得该数据成为执行数字取证的研究人员的宝贵证据来源。 Alexa语音服务使用一系列API进行客户端与Amazon Cloud之间的通信。这些API返回与所使用设备功能有关的广泛数据。 这项研究的第一个目标是准确澄清通过这些API存储和访问用户的哪种信息。为此,使用了文献综述和探索性分析的组合来建立所有相关API的列表。然后,从其反应中得出可能的伪影和结论,并提出了。最后,采取了用户的观点,并审查了改善其隐私的选择。具体而言,用户和Alexa之间的互动历史可通过多个API获得,并且有几个选项可以删除它。已经确定这些选项具有不同的行为,并且大多数没有删除与用户互动相关的所有数据。
With the release of Amazon Alexa and the first Amazon Echo device, the company revolutionised the smart home. It allowed their users to communicate with, and control, their smart home ecosystem purely using voice commands. However, this also means that Amazon processes and stores a large amount of personal data about their users, as these devices are always present and always listening in peoples' private homes. That makes this data a valuable source of evidence for investigators performing digital forensics. The Alexa Voice Service uses a series of APIs for communication between clients and the Amazon cloud. These APIs return a wide range of data related to the functionality of the device used. The first goal of this research was to clarify exactly what kind of information about the user is stored and accessible through these APIs. To do this, a combination of literature review and exploratory analysis was used to establish a list of all relevant APIs. Then, possible artefacts and conclusions to be drawn from their responses were identified and presented. Lastly, the perspective of the users was taken, and options for improving their privacy were reviewed. Specifically, the history of interaction between the user and Alexa is available through multiple APIs, and there are several options to delete it. It was determined that these options have different behaviours and that most of them do not remove all data related to user interaction.