首页> 外文会议>Information Security for South Africa Conference >Playing hide-and-seek: Detecting the manipulation of Android Timestamps
【24h】

Playing hide-and-seek: Detecting the manipulation of Android Timestamps

机译:玩捉迷藏游戏:检测Android时间戳的操纵

获取原文

摘要

Mobile technology continues to evolve in the 21st century, providing users with improved capabilities and advance functionality. One of the leaders of this evolution is Android, a mobile operating system that continuously elevates existing features and offers new applications. Such improvements allowed Android to gain popularity worldwide. A combination of Android's advance technology and increasing popularity allow smartphones supporting this operating system to become a rich source of trace evidence. Traces found on Android smartphones form a significant part of digital investigations, especially when the user of the smartphone is involved in criminal activities. A key component of these traces is the date and time, often formed as timestamps. These timestamps allow the examiner to relate the traces found on Android smartphones to some real event that took place. Knowing when events occurred in digital investigations is of great importance to the overall success of the investigation. This paper introduces a new solution, called the Authenticity Framework for Android Timestamps (AFAT) that establishes the authenticity of timestamps found on Android smartphones. Currently the framework determines the authenticity of timestamps found in SQLite databases by following two individual methods. The first method identifies the presence of certain changes in the Android file system, which are indications of the manipulation of the SQLite databases. The second method subsequently focuses on the individual SQLite databases and the identification of inconsistencies in these databases. The presence of specific file system changes as well as inconsistencies in the associated SQLite databases indicates that authenticity of the timestamps might be compromised. The results presented in the paper provide preliminary evidence that the suggested approach, Authenticity Framework for Android Timestamps, shows potential.
机译:移动技术在21世纪不断发展,为用户提供了改进的功能和先进的功能。这种发展的领导者之一是Android,这是一个不断提升现有功能并提供新应用程序的移动操作系统。此类改进使Android在全球范围内得到普及。 Android的先进技术与日益普及的结合,使支持此操作系统的智能手机成为丰富的痕量证据来源。在Android智能手机上发现的痕迹是数字调查的重要组成部分,尤其是当智能手机的用户参与犯罪活动时。这些跟踪的关键组成部分是日期和时间,通常形成为时间戳。这些时间戳使检查者可以将在Android智能手机上发现的跟踪信息与发生的某些实际事件相关联。知道事件何时发生在数字调查中对于调查的整体成功非常重要。本文介绍了一种称为Android时间戳的真实性框架(AFAT)的新解决方案,该解决方案可确定Android智能手机上发现的时间戳的真实性。当前,该框架通过遵循两种单独的方法来确定在SQLite数据库中找到的时间戳的真实性。第一种方法可以识别Android文件系统中某些更改的存在,这些更改表示对SQLite数据库进行操作的指示。第二种方法随后着重于各个SQLite数据库以及这些数据库中不一致的标识。特定文件系统更改的存在以及关联的SQLite数据库中的不一致指示时间戳的真实性可能受到损害。本文中提供的结果提供了初步证据,表明所建议的方法“ Android时间戳的真实性框架”具有潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号