首页> 外文期刊>Digital investigation >DROP (DRone Open source Parser) your drone: Forensic analysis of the DJI Phantom III
【24h】

DROP (DRone Open source Parser) your drone: Forensic analysis of the DJI Phantom III

机译:DROP(DRone开源分析器)您的无人机:DJI Phantom III的法医分析

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

The DJI Phantom III drone has already been used for malicious activities (to drop bombs, remote surveillance and plane watching) in 2016 and 2017. At the time of writing, DJI was the drone manufacturer with the largest market share. Our work presents the primary thorough forensic analysis of the DJI Phantom III drone, and the primary account for proprietary file structures stored by the examined drone. It also presents the forensically sound open source tool DRone Open source Parser (DROP) that parses proprietary DAT files extracted from the drone's nonvolatile internal storage. These DAT files are encrypted and encoded. The work also shares preliminary findings on TXT files, which are also proprietary, encrypted, encoded, files found on the mobile device controlling the drone. These files provided a slew of data such as GPS locations, battery, flight time, etc. By extracting data from the controlling mobile device, and the drone, we were able to correlate data and link the user to a specific device based on extracted metadata. Furthermore, results showed that the best mechanism to forensically acquire data from the tested drone is to manually extract the SD card by disassembling the drone. Our findings illustrated that the drone should not be turned on as turning it on changes data on the drone by creating a new DAT file, but may also delete stored data if the drone's internal storage is full. (C) 2017 The Author(s). Published by Elsevier Ltd. on behalf of DFRWS.
机译:DJI Phantom III无人机已于2016年和2017年用于恶意活动(投下炸弹,远程监视和飞机监视)。在撰写本文时,DJI是拥有最大市场份额的无人机制造商。我们的工作介绍了DJI Phantom III无人机的主要全面取证分析,以及被检查无人机存储的专有文件结构的主要说明。它还提供了具有法医声音的开源工具DRone Open Source Parser(DROP),该工具解析从无人机的非易失性内部存储中提取的专有DAT文件。这些DAT文件已加密和编码。这项工作还分享了关于TXT文件的初步发现,这些文件也是在控制无人机的移动设备上找到的专有,加密,编码的文件。这些文件提供了大量数据,例如GPS位置,电池,飞行时间等。通过从控制移动设备和无人机中提取数据,我们能够将数据关联起来,并基于提取的元数据将用户链接到特定设备。此外,结果表明,从被测无人机取证数据的最佳机制是通过拆卸无人机来手动提取SD卡。我们的发现表明,不应在打开无人机时打开无人机,因为它会通过创建新的DAT文件来更改无人机上的数据,但如果无人机的内部存储空间已满,也可能会删除存储的数据。 (C)2017作者。由Elsevier Ltd.代表DFRWS发布。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号