首页> 外文OA文献 >Forensic Analysis of the ChatSecure Instant Messaging Application on Android Smartphones
【2h】

Forensic Analysis of the ChatSecure Instant Messaging Application on Android Smartphones

机译:Chatsecure即时通讯应用程序的取证分析   android智能手机

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

We present the forensic analysis of the artifacts generated on Androidsmartphones by ChatSecure, a secure Instant Messaging application that providesstrong encryption for transmitted and locally-stored data to ensure the privacyof its users. We show that ChatSecure stores local copies of both exchanged messages andfiles into two distinct, AES-256 encrypted databases, and we devise a techniqueable to decrypt them when the secret passphrase, chosen by the user as theinitial step of the encryption process, is known. Furthermore, we show how this passphrase can be identified and extracted fromthe volatile memory of the device, where it persists for the entire executionof ChatSecure after having been entered by the user, thus allowing one to carryout decryption even if the passphrase is not revealed by the user. Finally, we discuss how to analyze and correlate the data stored in thedatabases used by ChatSecure to identify the IM accounts used by the user andhis/her buddies to communicate, as well as to reconstruct the chronology andcontents of the messages and files that have been exchanged among them. For our study we devise and use an experimental methodology, based on the useof emulated devices, that provides a very high degree of reproducibility of theresults, and we validate the results it yields against those obtained from realsmartphones.
机译:我们将介绍由ChatSecure在Android智能手机上生成的伪像的取证分析,ChatSecure是一个安全的即时消息应用程序,可为传输和本地存储的数据提供强加密,以确保其用户的隐私。我们展示了ChatSecure将交换的消息和文件的本地副本存储到两个不同的AES-256加密数据库中,并且我们设计了一种技术,当用户选择了秘密密码短语作为加密过程的初始步骤时,可以对它们进行解密。此外,我们展示了如何从设备的易失性存储器中识别并提取该密码短语,该密码短语在用户输入后在整个ChatSecure执行过程中一直存在,因此即使密码短语未被密码泄露,也允许人们进行解密。用户。最后,我们讨论如何分析和关联存储在ChatSecure使用的数据库中的数据,以识别用户和他/她的好友用于通信的IM帐户,以及重建已交换消息和文件的时间顺序和内容其中。在我们的研究中,我们设计并使用了一种基于仿真设备的实验方法,该方法可提供非常高的结果可重复性,并且可以相对于从真实智能手机获得的结果验证其产生的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号