Private Data Acquisition Method Based on System-Level Data Migration and Volatile Memory Forensics for Android Applications

被引:9
|
作者
Feng, Peijun [1 ]
Li, Qingbao [1 ]
Zhang, Ping [1 ]
Chen, Zhifeng [1 ]
机构
[1] State Key Lab Math Engn & Adv Comp, Zhengzhou 450001, Henan, Peoples R China
来源
IEEE ACCESS | 2019年 / 7卷
基金
中国国家自然科学基金;
关键词
Android private data acquisition; system-level data migration; volatile memory forensics;
D O I
10.1109/ACCESS.2019.2894643
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays, many Android applications enable data encryption to protect the security of private data, making it difficult for investigators to access the clear data even if they have already obtained the application database. Volatile memory dynamically presents the current state of applications and OS, which contains a store of valuable information including the plain text of application data, and it is a significant analysis object in the field of digital forensics. Over the past decade, some forensics researchers have proposed a number of volatile memory acquisition methods for Android mobile devices and have made valuable contributions. However, most of the existing methods are subjecting to severe restrictions in real investigation environment and only can be applied to pre-prepared devices, resulting in these methods are impractical. In order to address this problem, this paper proposes an Android application memory data acquisition method, called PASM, which can be applied to unprepared Android devices. PASM makes use of system-level data migration function provided by Android manufacturers to migrate and load the application private data into an intermediate device. The intermediate device is pre-flashed with a custom kernel providing the function of volatile memory forensics, so that the application private data can be acquired from the volatile memory of the intermediate device. We select thirty privacy-sensitive applications as the test objects and build seven different experiment scenarios to acquire the private data stored in memory image dumped by PASM. The experiment results show that PASM is able to acquire part of private data stored in volatile memory, and more importantly, PASM has the ability to overcome most of the limitations in the real world, which is more practical than existing Android memory acquisition methods.
引用
收藏
页码:16695 / 16703
页数:9
相关论文
共 50 条
  • [1] Logical acquisition method based on data migration for Android mobile devices
    Feng, Peijun
    Li, Qingbao
    Zhang, Ping
    Chen, Zhifeng
    DIGITAL INVESTIGATION, 2018, 26 : 55 - 62
  • [2] The wireless data acquisition system based on Android system
    Zhan, Huaqun
    Chen, Huarong
    Wu, Wenjie
    PROCEEDINGS OF THE 2015 4TH INTERNATIONAL CONFERENCE ON COMPUTER, MECHATRONICS, CONTROL AND ELECTRONIC ENGINEERING (ICCMCEE 2015), 2015, 37 : 1063 - 1066
  • [3] A system-level reuse methodology for embedded data-dominated applications
    Vermuelen, F
    Catthoor, F
    Verkest, D
    De Man, H
    1998 IEEE WORKSHOP ON SIGNAL PROCESSING SYSTEMS-SIPS 98: DESIGN AND IMPLEMENTATION, 1998, : 551 - 560
  • [4] Fine-grained access control method for private data in android system
    Liu, Gang
    Zhang, Guofang
    Wang, Quan
    Ji, Shaomin
    Zhang, Lizhi
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2019, 15 (03):
  • [5] Data Acquisition System for Highway Engineering Construction Safety Based on Android Platform
    Zhang, Linliang
    Jia, Lei
    Liu, Zhiying
    PROCEEDINGS OF THE 2017 7TH INTERNATIONAL CONFERENCE ON MECHATRONICS, COMPUTER AND EDUCATION INFORMATIONIZATION (MCEI 2017), 2017, 75 : 29 - 34
  • [6] Sensor Data based System-level Anomaly Prediction for Smart Manufacturing
    Wang, Jianwu
    Liu, Chen
    Zhu, Meiling
    Guo, Pei
    Hu, Yapeng
    2018 IEEE INTERNATIONAL CONGRESS ON BIG DATA (IEEE BIGDATA CONGRESS), 2018, : 158 - 165
  • [7] Flash memory-based data acquisition system with NOBLE
    Nagasaka, Y
    Miyamoto, S
    Obata, T
    Sakamoto, Y
    Asai, M
    Tamura, N
    Kato, Y
    Saskamoto, H
    Ishihara, N
    IEEE TRANSACTIONS ON NUCLEAR SCIENCE, 2004, 51 (05) : 2069 - 2072
  • [8] A DATA-ACQUISITION SYSTEM BASED ON THE BUBBLE BUFFER MEMORY
    IVANOVLOSHKANOV, VS
    AVTOMATIKA I VYCHISLITELNAYA TEKHNIKA, 1993, (02): : 80 - 85
  • [9] Flash memory-based data acquisition system with NOBLE
    Nagasaka, Y
    Miyamoto, S
    Obata, T
    Sakamoto, Y
    Asai, M
    Tamura, N
    Kato, Y
    Saskamoto, H
    Ishihara, N
    2003 IEEE NUCLEAR SCIENCE SYMPOSIUM, CONFERENCE RECORD, VOLS 1-5, 2004, : 1332 - 1335
  • [10] System-Level Memory Management Based on Statistical Variability Compensation for Frame-Based Applications
    Sanz, Concepcion
    Ignacio Gomez, Jose
    Tenllado, Christian
    Prieto, Manuel
    Catthoor, Francky
    ACM TRANSACTIONS ON EMBEDDED COMPUTING SYSTEMS, 2013, 13