...
首页> 外文期刊>Digital investigation >VIDE - Vault App Identification and Extraction System for iOS Devices
【24h】

VIDE - Vault App Identification and Extraction System for iOS Devices

机译:视频 - Vault应用IOS设备的App识别和提取系统

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Content hiding (or vault) apps are a class of applications that allow users to hide photos, videos, documents and other content securely. A subclass of these applications called decoy apps further supports secret hiding by having a mode which mimics standard apps such as calculators but can turn into a vault app through entering a specific input. In this work we focus on iOS devices and first describe how to identify content hiding applications from the App Store. We consider not only the US Store but also give results for App Stores in Russia, India and China. We show an effective and very fast identification of content hiding apps through a two-phase process: initial categorization using keywords followed by more precise binary classification. We next turn to understanding the behavior and features of these vault apps and how to extract the hidden information from artifacts of the app's stored data. Based on this work, we have designed and built a fully automated vault app identification and extraction system that first identifies and then extracts the hidden data from the apps on an iOS smartphone. Using our vault identification and data extraction system (VIDE), law enforcement investigators can more easily identify and extract data from such apps as needed. Although vault apps are removed regularly from the App Store, VIDE can still identify removed apps as our system continues to maintain information on such apps in our vault database. (C) 2020 The Author(s). Published by Elsevier Ltd on behalf of DFRWS. All rights reserved.
机译:内容隐藏(或Vault)应用程序是一类应用程序,允许用户安全地隐藏照片,视频,文档和其他内容。这些应用程序的子类称为诱饵应用程序进一步支持秘密隐藏,通过使用一种模仿标准的应用程序(如计算器)而且可以通过输入特定输入来进入Vault应用程序。在这项工作中,我们专注于iOS设备,首先介绍如何从App Store识别内容隐藏应用程序。我们不仅考虑美国商店,还考虑在俄罗斯,印度和中国的应用商店提供结果。我们通过两阶段处理显示内容隐藏应用程序的有效且非常快速地识别:使用关键字进行初始分类,然后更精确分类。接下来,我们将理解这些保管库应用程序的行为和功能以及如何从应用程序存储数据的伪像中提取隐藏信息。根据这项工作,我们设计并构建了一个完全自动化的Vault应用程序标识和提取系统,首先识别,然后从iOS智能手机上的应用中提取隐藏数据。使用我们的Vault识别和数据提取系统(视频),法律执行调查人员可以根据需要更容易地从这些应用中识别和提取数据。虽然Vault应用程序从App Store定期删除,但Vide仍可识别删除的应用程序,因为我们的系统继续维护在保管库数据库中的此类应用程序中的信息。 (c)2020提交人。 elsevier有限公司代表DFRW出版。版权所有。

著录项

  • 来源
    《Digital investigation》 |2020年第7期|301007.s1-301007.s10|共10页
  • 作者单位

    Augusta Univ Sch Comp & Cyber Sci Augusta GA 30912 USA;

    Florida State Univ Dept Comp Sci Tallahassee FL 32304 USA;

    Florida State Univ Dept Comp Sci Tallahassee FL 32304 USA;

    Florida State Univ Dept Comp Sci Tallahassee FL 32304 USA;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号