首页> 外文会议>Information Security for South Africa Conference >Playing hide-and-seek: Detecting the manipulation of Android Timestamps
【24h】

Playing hide-and-seek: Detecting the manipulation of Android Timestamps

机译:播放隐藏和寻求:检测Android时间戳的操纵

获取原文

摘要

Mobile technology continues to evolve in the 21st century, providing users with improved capabilities and advance functionality. One of the leaders of this evolution is Android, a mobile operating system that continuously elevates existing features and offers new applications. Such improvements allowed Android to gain popularity worldwide. A combination of Android's advance technology and increasing popularity allow smartphones supporting this operating system to become a rich source of trace evidence. Traces found on Android smartphones form a significant part of digital investigations, especially when the user of the smartphone is involved in criminal activities. A key component of these traces is the date and time, often formed as timestamps. These timestamps allow the examiner to relate the traces found on Android smartphones to some real event that took place. Knowing when events occurred in digital investigations is of great importance to the overall success of the investigation. This paper introduces a new solution, called the Authenticity Framework for Android Timestamps (AFAT) that establishes the authenticity of timestamps found on Android smartphones. Currently the framework determines the authenticity of timestamps found in SQLite databases by following two individual methods. The first method identifies the presence of certain changes in the Android file system, which are indications of the manipulation of the SQLite databases. The second method subsequently focuses on the individual SQLite databases and the identification of inconsistencies in these databases. The presence of specific file system changes as well as inconsistencies in the associated SQLite databases indicates that authenticity of the timestamps might be compromised. The results presented in the paper provide preliminary evidence that the suggested approach, Authenticity Framework for Android Timestamps, shows potential.
机译:移动技术在21世纪继续发展,为用户提供改进的能力和提前功能。这一进化的领导者之一是Android,一个移动操作系统,连续提升现有功能并提供新的应用程序。这种改进允许Android在全球范围内获得受欢迎程度。 Android的先进技术和越来越受欢迎的组合允许支持这种操作系统的智能手机成为丰富的跟踪证据来源。在Android智能手机上找到的痕迹形成了数字调查的重要组成部分,特别是当智能手机的用户参与犯罪活动时。这些迹线的一个关键组件是日期和时间,通常形成为时间戳。这些时间戳允许审查员将Android智能手机上的痕迹与某些发生的事件相关联。知道数字调查中发生的事件时,对调查的总体成功非常重要。本文介绍了一种新的解决方案,称为Android时间戳(AFAT)的真实性框架,该解决方案建立了在Android智能手机上找到的时间戳的真实性。目前,该框架通过以下两种方法确定SQLite数据库中的时间戳的真实性。第一个方法标识了Android文件系统的某些更改的存在,这是操纵SQLite数据库的指示。第二种方法随后侧重于各个SQLite数据库并识别这些数据库中的不一致性。特定文件系统的存在更改以及关联的SQLite数据库中的不一致表示可能会损害时间戳的真实性。本文提出的结果提供了初步证据,即建议的方法,Android时间戳的真实性框架,显示出潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号