A Novel Android Memory Forensics for Discovering Remnant Data

A Novel Android Memory Forensics for Discovering Remnant Data
复制标题

用于发现残留数据的新型 Android 内存取证

DOI:
10.18517/ijaseit.10.3.9363
复制
发表时间:
2020
影响因子:
--
通讯作者:
F. Kurniawan
F. Kurniawan
中科院分区:
--
文献类型:
--
作者:
Gandeva Bayu Satrya;F. Kurniawan

文献摘要

参考文献

被引文献

相似文献

根据最近更新的2019年漏洞统计数据,安卓驱动的智能手机、平板电脑和其他安卓设备都很容易受到攻击,无论是来自内部还是外部威胁。大多数用户将电子邮件、照片、云存储访问和联系人列表等敏感数据存储在Android智能手机上。这些信息对于移动设备的数字调查过程越来越重要,例如,内部存储器或随机存取存储器(RAM)取证,或Android智能手机上的外部存储器或只读存储器(ROM)取证。内部记忆检索被一些研究者认为是有缺陷和困难的,因为它以一种侵入性的方式改变了数字证据。另一方面,外部存储器检索也称为逻辑获取,它意味着逻辑存储项(例如,文件、数据库、目录等)位于逻辑存储上的映像。本研究提供了一种新颖的方法,只关注内部记忆法医在法医健全的方式。本研究还提出了两种算法,即收集原始信息(CRI)用于解析原始数据,调查原始信息(IRI)用于提取数字证据,使其更具可读性。本研究分析了14个事件,每个事件都被SHA-1捕获作为数字证据。通过使用GDrive作为案例研究,作者得出结论,所提出的方法可以作为法庭上法医分析师、网络法律从业者和专家证人的指导。
As recently updated on the vulnerability statistics shown in 2019, Android-driven smartphones, tablet PCs, and other Android devices are vulnerable, whether from internal or external threats. Most users store sensitive data like emails, photos, cloud storage access, and contact lists on Android smartphones. This information holds a growing-importance for the digital investigation process of mobile devices, e.g., internal memory or random-access memory (RAM) forensics, or external memory or read-only memory (ROM) forensics on Android smartphones. Internal memory retrieval is considered flawed and difficult by some researchers as it alters the digital evidence in an intrusive way. On the other hand, external memory retrieval also called logical acquisition that implies the image of logical storage items (e.g., files, database, directories, etc.) that locate on logical storage. This research provides a novel methodology that focuses only on internal memory forensic in a forensically sound manner. This research also contributes two algorithms, e.g., collect raw information (CRI) for parsing the raw data, and investigate raw information (IRI) for extracting the digital evidence to be more readable. This research conducted with fourteenth events to be analyzed, and each event was captured by SHA-1 as digital evidence. By using GDrive as the case study, the authors concluded that the proposed methodology could be used as guidance by forensics analyst(s), cyberlaw practitioner(s), and expert witness(es) in the court.
DroidScraper:Android 内存对象恢复和重建工具
DOI: --
发表时间: 2019
期刊: RAID 2019
影响因子: --
作者:
Ali-Gombe, A.;Sudhakaran, S.;Case, A.;Richard, G.
通讯作者: Richard, G.