...
首页> 外文期刊>Digital investigation >Live acquisition of main memory data from Android smartphones and smartwatches
【24h】

Live acquisition of main memory data from Android smartphones and smartwatches

机译:从Android智能手机和智能手表实时获取主内存数据

获取原文
获取原文并翻译 | 示例
           

摘要

Recent research in Android device forensics has largely focused on evidence recovery from NAND flash memory. However, pervasive deployment of NAND flash encryption technologies and the increase in malware infections which reside only in main memory have motivated an urgent need for the forensic study of main memory. Existing Android main memory forensics techniques are hardly being adopted in practical forensic investigations because they often require solving several usability constraints, such as requiring root privilege escalation, custom kernel replacement, or screen lock bypass. Moreover, there are still no commercially available tools for acquiring the main memory data of smart devices. To address these problems, we have developed an automated tool, called AMD, which is capable of acquiring the entire content of main memory from a range of Android smartphones and smartwatches. In developing AMD, we analyzed the firmware update protocols of these devices by reverse engineering the Android bootloader. Based on this study, we have devised a method that allows access to main memory data through the firmware update protocols. Our experimental results show that AMD overcomes the usability constraints of previous main memory acquisition approaches and that the acquired main memory data of a smartphone or smartwatch can be accurately used in forensic investigations. (c) 2017 Elsevier Ltd. All rights reserved.
机译:Android设备取证的最新研究主要集中在从NAND闪存中恢复证据。但是,NAND闪存加密技术的广泛部署以及仅驻留在主存储器中的恶意软件感染的增加,激发了对主存储器进行法医研究的迫切需求。现有的Android主内存取证技术几乎没有在实际的取证研究中采用,因为它们通常需要解决几个可用性约束,例如要求root特权升级,自定义内核替换或屏幕锁定旁路。而且,仍然没有可商购的工具来获取智能设备的主存储器数据。为了解决这些问题,我们开发了一种称为AMD的自动化工具,该工具能够从一系列Android智能手机和智能手表中获取主存储器的全部内容。在开发AMD时,我们通过对Android Bootloader进行反向工程来分析这些设备的固件更新协议。基于这项研究,我们设计了一种方法,该方法允许通过固件更新协议访问主存储器数据。我们的实验结果表明,AMD克服了以前的主内存获取方法的可用性限制,并且所获取的智能手机或智能手表的主内存数据可以准确地用于法医调查。 (c)2017 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号