Zooming into the pandemic! A forensic analysis of the Zoom Application.

Zooming into the pandemic! A forensic analysis of the Zoom Application.
复制标题

放大到流行病!缩放应用程序的取证分析。

DOI:
10.1016/j.fsidi.2021.301107
复制
发表时间:
2021-03
影响因子:
2
通讯作者:
Baggili, Ibrahim
Baggili, Ibrahim
中科院分区:
医学3区
文献类型:
--
作者:
Mahr, Andrew;Cichon, Meghan;Mateo, Sophia;Grajeda, Cinthya;Baggili, Ibrahim

文献摘要

被引文献

相似文献

COVID-19全球大流行使视频会议应用前所未有地受到关注。在这个关键时刻,Zoom等应用程序的用户群激增,突破了每日3亿大关。使用的增加导致恶意行为者利用应用程序,并在许多情况下执行Zoom Bombings。因此,对极速进行法医检查是不可避免的。我们的工作详细介绍了Zoom视频会议应用程序的主磁盘,网络和内存取证分析。结果表明,通过网络捕获、数字设备取证成像和内存取证,可以以纯文本和/或加密/编码的形式找到用户的关键信息,如聊天消息、姓名、电子邮件地址、密码等。此外,我们详细介绍了有趣的反取证技术所采用的缩放应用程序时,联系人从缩放应用程序的联系人列表中删除。
The global pandemic of COVID-19 has turned the spotlight on video conferencing applications like never before. In this critical time, applications such as Zoom have experienced a surge in its user base jump over the 300 million daily mark. The increase in use has led malicious actors to exploit the application, and in many cases perform Zoom Bombings. Therefore forensically examining Zoom is inevitable. Our work details the primary disk, network, and memory forensic analysis of the Zoom video conferencing application. Results demonstrate it is possible to find users' critical information in plain text and/or encrypted/encoded, such as chat messages, names, email addresses, passwords, and much more through network captures, forensic imaging of digital devices, and memory forensics. Furthermore we elaborate on interesting anti-forensics techniques employed by the Zoom application when contacts are deleted from the Zoom application's contact list.