Private Data Acquisition Method Based on System-Level Data Migration and Volatile Memory Forensics for Android Applications

被引:9
|
作者
Feng, Peijun [1 ]
Li, Qingbao [1 ]
Zhang, Ping [1 ]
Chen, Zhifeng [1 ]
机构
[1] State Key Lab Math Engn & Adv Comp, Zhengzhou 450001, Henan, Peoples R China
来源
IEEE ACCESS | 2019年 / 7卷
基金
中国国家自然科学基金;
关键词
Android private data acquisition; system-level data migration; volatile memory forensics;
D O I
10.1109/ACCESS.2019.2894643
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays, many Android applications enable data encryption to protect the security of private data, making it difficult for investigators to access the clear data even if they have already obtained the application database. Volatile memory dynamically presents the current state of applications and OS, which contains a store of valuable information including the plain text of application data, and it is a significant analysis object in the field of digital forensics. Over the past decade, some forensics researchers have proposed a number of volatile memory acquisition methods for Android mobile devices and have made valuable contributions. However, most of the existing methods are subjecting to severe restrictions in real investigation environment and only can be applied to pre-prepared devices, resulting in these methods are impractical. In order to address this problem, this paper proposes an Android application memory data acquisition method, called PASM, which can be applied to unprepared Android devices. PASM makes use of system-level data migration function provided by Android manufacturers to migrate and load the application private data into an intermediate device. The intermediate device is pre-flashed with a custom kernel providing the function of volatile memory forensics, so that the application private data can be acquired from the volatile memory of the intermediate device. We select thirty privacy-sensitive applications as the test objects and build seven different experiment scenarios to acquire the private data stored in memory image dumped by PASM. The experiment results show that PASM is able to acquire part of private data stored in volatile memory, and more importantly, PASM has the ability to overcome most of the limitations in the real world, which is more practical than existing Android memory acquisition methods.
引用
收藏
页码:16695 / 16703
页数:9
相关论文
共 50 条
  • [21] AN ANDROID-BASED DISTRIBUTED TEST DATA ACQUISITION INTELLIGENT SYSTEM FOR MOBILE NETWORK OPTIMIZATION
    Bian, Jiali
    Liu, Lin
    Kuang, Jian
    2012 IEEE 2nd International Conference on Cloud Computing and Intelligent Systems (CCIS) Vols 1-3, 2012, : 38 - 42
  • [22] Communication Technologies for Smart Grid Applications and proposed method of Embedded Data Acquisition Based on Linux System
    Araari, T.
    Charaabi, L.
    Jelassi, K.
    2015 7TH INTERNATIONAL CONFERENCE ON MODELLING, IDENTIFICATION AND CONTROL (ICMIC), 2014, : 21 - 27
  • [23] System-level performance optimization of the data queueing memory management in high-speed network processors
    Ykman-Couvreur, C
    Lambrecht, J
    Verkest, D
    Catthoor, F
    Nikologiannis, A
    Konstantoulakis, G
    39TH DESIGN AUTOMATION CONFERENCE, PROCEEDINGS 2002, 2002, : 518 - 523
  • [24] 1xEV-DO system-level simulator based on measured link-level data
    Baek, SY
    Jung, BC
    Moon, SH
    Chung, JH
    Jung, CY
    Sung, DK
    Cho, HU
    Cheong, JM
    VTC2004-FALL: 2004 IEEE 60TH VEHICULAR TECHNOLOGY CONFERENCE, VOLS 1-7: WIRELESS TECHNOLOGIES FOR GLOBAL SECURITY, 2004, : 4486 - 4490
  • [25] A Data Acquisition System Based on Outlier Detection Method for Weighing Lysimeters
    Huang, Wenqian
    Zhang, Chi
    Xue, Xuzhang
    Chen, Liping
    COMPUTER AND COMPUTING TECHNOLOGIES IN AGRICULTURE V, PT I, 2012, 368 : 471 - 478
  • [26] A data-driven knowledge acquisition method based on system uncertainty
    Zhao, J
    Wang, GY
    ICCI 2005: Fourth IEEE International Conference on Cognitive Informatics - Proceedings, 2005, : 267 - 275
  • [27] Low cost, LoRa based river water level data acquisition system
    Kabi, Jason N.
    Maina, Ciira Wa
    Mharakurwa, Edwell T.
    Mathenge, Stephen W.
    HARDWAREX, 2023, 14
  • [28] Family-Based Big Medical-Level Data Acquisition System
    Xu, Jie
    Wang, Li
    Shen, Yunfeng
    Yuan, Kaifen
    Nie, Yue
    Tian, Yingxuan
    Jian, Xiangdong
    Ma, Xing
    Guo, Jinhong
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2019, 15 (04) : 2321 - 2329
  • [29] Failure-Atomic Synchronization of Memory Mapped Data in Non-volatile Memory Based System
    Haga, Koki
    Yamazaki, Kenichi
    2018 12TH SOUTH EAST ASIAN TECHNICAL UNIVERSITY CONSORTIUM (SYMPOSIUM SEATUC 2018): ENGINEERING EDUCATION AND RESEARCH FOR SUSTAINABLE DEVELOPMENT, 2018,
  • [30] Relationship between patient experience and hospital readmission: system-level survey with deterministic data linkage method
    Eliza Lai-Yi Wong
    Chin-Man Poon
    Annie Wai-Ling Cheung
    Frank Youhua Chen
    Eng-Kiong Yeoh
    BMC Medical Research Methodology, 22