Evaluating the privacy of Android mobile applications under forensic analysis

被引:20
|
作者
Ntantogian, Christoforos [1 ]
Apostolopoulos, Dimitris [1 ]
Marinakis, Giannis [1 ]
Xenakis, Christos [1 ]
机构
[1] Univ Piraeus, Dept Digital Syst, Piraeus, Greece
关键词
Privacy of mobile applications; Mobile forensics; Android; Memory dump; Mobile applications; Volatile memory; Authentication credentials;
D O I
10.1016/j.cose.2014.01.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we investigate and evaluate through experimental analysis the possibility of recovering authentication credentials of mobile applications from the volatile memory of Android mobile devices. Throughout the carried experiments and analysis, we have, exclusively, used open-source and free forensic tools. Overall, the contribution of this paper is threefold. First, it thoroughly, examines thirteen (13) mobile applications, which represent four common application categories that elaborate sensitive users' data, whether it is possible to recover authentication credentials from the physical memory of mobile devices, following thirty (30) different scenarios. Second, it explores in the considered applications, if we can discover patterns and expressions that indicate the exact position of authentication credentials in a memory dump. Third, it reveals a set of critical observations regarding the privacy of Android mobile applications and devices. (C) 2014 Elsevier Ltd. All rights reserved.
引用
收藏
页码:66 / 76
页数:11
相关论文
共 50 条
  • [1] A Forensic Investigation of Android Mobile Applications
    Kitsaki, Theodoula-Ioanna
    Angelogianni, Anna
    Ntantogian, Christoforos
    Xenakis, Christos
    22ND PAN-HELLENIC CONFERENCE ON INFORMATICS (PCI 2018), 2018, : 58 - 63
  • [2] Breaking into the vault: Privacy, security and forensic analysis of Android vault applications
    Zhang, Xiaolu
    Baggili, Ibrahim
    Breitinger, Frank
    COMPUTERS & SECURITY, 2017, 70 : 516 - 531
  • [3] Privacy Profiling Impact of Android Mobile Applications
    Barca, Cristian
    Barca, Dan Claudiu
    Mara, Constantin
    Raducu, Marian
    Gavriloaia, Bogdan
    Vizireanu, Radu
    Craciunescu, Razvan
    Halunga, Simona
    PROCEEDINGS OF THE 2015 7TH INTERNATIONAL CONFERENCE ON ELECTRONICS, COMPUTERS AND ARTIFICIAL INTELLIGENCE (ECAI), 2015,
  • [4] Forensic Analysis of Android Mobile Devices
    Rao, V. Venkateswara
    Chakravarthy, A. S. N.
    2016 INTERNATIONAL CONFERENCE ON RECENT ADVANCES AND INNOVATIONS IN ENGINEERING (ICRAIE), 2016,
  • [5] Forensic Analysis of Fitness Applications on Android
    Sinha, Rahul
    Sihag, Vikas
    Choudhary, Gaurav
    Vardhan, Manu
    Singh, Pradeep
    MOBILE INTERNET SECURITY, MOBISEC 2021, 2022, 1544 : 222 - 235
  • [6] Forensic Analysis of Encrypted Instant Messaging Applications on Android
    Rathi, Khushboo
    Karabiyik, Umit
    Aderibigbe, Temilola
    Chi, Hongmei
    2018 6TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSIC AND SECURITY (ISDFS), 2018, : 165 - 170
  • [7] Forensic Analysis of Secure Ephemeral Messaging Applications on Android Platforms
    Bin Azhar, M. A. Hannan
    Barton, Thomas Edward Allen
    GLOBAL SECURITY, SAFETY AND SUSTAINABILITY: THE SECURITY CHALLENGES OF THE CONNECTED WORLD, ICGS3 2017, 2016, 630 : 27 - 41
  • [8] Towards a Forensic Analysis of Mobile Devices Using Android
    Gomez-Torres, Estevan
    Moscoso-Zea, Oswaldo
    Herrera Herrera, Nelson
    Lujan-Mora, Sergio
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY & SYSTEMS (ICITS 2018), 2018, 721 : 30 - 39
  • [9] Forensic Analysis of Dating Applications on Android and iOS Devices
    Hutchinson, Shinelle
    Shantaram, Neesha
    Karabiyik, Umit
    2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 837 - 848
  • [10] The Android Forensics Automator (AnForA): A tool for the Automated Forensic Analysis of Android Applications
    Anglano, Cosimo
    Canonico, Massimo
    Guazzone, Marco
    COMPUTERS & SECURITY, 2020, 88 (88)