...
首页> 外文期刊>Information management & computer security >Forensic analysis of Google Allo messenger on Android platform
【24h】

Forensic analysis of Google Allo messenger on Android platform

机译:Android平台上的Google Allo Messenger的取证分析

获取原文
获取原文并翻译 | 示例
           

摘要

Purpose - The purpose of this paper is to conduct a forensic analysis of Google Allo messenger on an Android-based mobile phone. The focus was on the analysis of the data stored by this application in the internal memory of the mobile device, with minimal use of third-party applications. The findings were compared with the already existing works on this topic. Android is the most popular operating system for mobile devices, and these devices often contain a massive amount of personal information about the user such as photos and contact details. Analysis of these applications is required in case of a forensic investigation and makes the process easier for forensic analysts. Design/methodology/approach - Logical acquisition of the data stored by these applications was performed. A locked Android device was used for this purpose. Some scripts are presented to help in data acquisition using Android Debug Bridge (ADB). Manual forensic analysis of the device image was performed to see whether the activities carried out on these applications are stored in the internal memory of the device. A comparative analysis of an existing mobile forensic tool was also performed to show the effectiveness of the methodology adopted. Findings - Forensic artifacts were recovered from Allo application. Multimedia content such as images were also retrieved from the internal memory. Research limitations/implications - As this study was conducted for forensic analysis, it assumed that the mobile device used already has USB debugging enabled on it, although this might not be the applicable in some of the cases. This work provides an optimal approach to acquiring artifacts with minimal use of third-party applications. Practical implications - Most of the mobile devices contain messaging application such as Allo installed. A large amount of personal information can be obtained from the forensic analysis of these applications, which can be useful in any criminal investigation. Originality/value - This is the first study which focuses on the Google Allo application. The proposed methodology was able to extract almost as much as the data obtained using earlier approaches, but with minimal third-party application usage.
机译:目的-本文的目的是对基于Android的手机上的Google Allo Messenger进行取证分析。重点是分析此应用程序在移动设备的内部存储器中存储的数据,而最少使用第三方应用程序。将调查结果与有关该主题的现有作品进行了比较。 Android是最流行的移动设备操作系统,这些设备通常包含大量有关用户的个人信息,例如照片和联系方式。在进行法医调查的情况下,需要对这些应用程序进行分析,这会使法医分析人员的工作更加轻松。设计/方法/方法-逻辑获取这些应用程序存储的数据。为此使用了锁定的Android设备。提供了一些脚本,以帮助使用Android调试桥(ADB)进行数据获取。对设备图像进行了手动取证分析,以查看在这些应用程序上执行的活动是否存储在设备的内部存储器中。还对现有的移动取证工具进行了比较分析,以显示所采用方法的有效性。结果-从Allo应用程序中恢复了法医文物。诸如图像之类的多媒体内容也从内部存储器中检索到。研究的局限性/意义-由于这项研究是为进行取证分析而进行的,因此假定所使用的移动设备已经启用了USB调试功能,尽管在某些情况下可能不适用。这项工作提供了一种在最少使用第三方应用程序的情况下获取工件的最佳方法。实际意义-大多数移动设备都包含诸如Allo之类的消息传递应用程序。从这些应用程序的法医分析中可以获取大量个人信息,这对任何刑事调查都非常有用。原创性/价值-这是第一项针对Google Allo应用程序的研究。所提出的方法能够提取几乎与使用早期方法获得的数据一样多的数据,但是使用第三方应用程序的可能性却很小。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号