Current and Future Trends in Mobile Device Forensics: A Survey

被引:42
作者
Barmpatsalou, Konstantia [1 ]
Cruz, Tiago [1 ]
Monteiro, Edmundo [1 ]
Simoes, Paulo [1 ]
机构
[1] Univ Coimbra, Dept Informat CISUC DEI, Ctr Informat & Syst, Polo 2 Pinhal Marrocos, P-3030290 Coimbra, Portugal
基金
欧盟地平线“2020”;
关键词
Mobile forensics; digital forensics; mobile cloud forensics; evidence acquisition; forensic ontologies; evidence parsing; digital investigations; CHALLENGES; COLLECTION; FRAMEWORK; ONTOLOGY;
D O I
10.1145/3177847
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Contemporary mobile devices are the result of an evolution process, during which computational and networking capabilities have been continuously pushed to keep pace with the constantly growing workload requirements. This has allowed devices such as smartphones, tablets, and personal digital assistants to perform increasingly complex tasks, up to the point of efficiently replacing traditional options such as desktop computers and notebooks. However, due to their portability and size, these devices are more prone to theft, to become compromised, or to be exploited for attacks and other malicious activity. The need for investigation of the aforementioned incidents resulted in the creation of the Mobile Forensics (MF) discipline. MF, a subdomain of digital forensics, is specialized in extracting and processing evidence from mobile devices in such a way that attacking entities and actions are identified and traced. Beyond its primary research interest on evidence acquisition from mobile devices, MF has recently expanded its scope to encompass the organized and advanced evidence representation and analysis of future malicious entity behavior. Nonetheless, data acquisition still remains its main focus. While the field is under continuous research activity, new concepts such as the involvement of cloud computing in the MF ecosystem and the evolution of enterprise mobile solutions-particularly mobile device management and bring your own device-bring new opportunities and issues to the discipline. The current article presents the research conducted within the MF ecosystem during the last 7 years, identifies the gaps, and highlights the differences from past research directions, and addresses challenges and open issues in the field.
引用
收藏
页数:31
相关论文
共 122 条
[61]   Android cache taxonomy and forensic process [J].
Immanuel, Felix ;
Martini, Ben ;
Choo, Kim-Kwang Raymond .
2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, :1094-1101
[62]   Windows Surface RT tablet forensics [J].
Iqbal, Asif ;
Al Obaidli, Hanan ;
Marrington, Andrew ;
Jones, Andy .
DIGITAL INVESTIGATION, 2014, 11 :S87-S93
[63]  
ISO/IEC, 2012, GUID ID COLL ACQ PRE
[64]  
ISO/IEC, 2015, GUID AN INT DIG EV
[65]  
Jamieson Alan R., 2004, TECHNICAL REPORT
[66]  
Jansen Wayne, 2007, 800101 NAT I STAND T
[67]  
Jooyoung Lee, 2011, 2011 3rd International Conference on Multimedia Information Networking and Security, P572, DOI 10.1109/MINES.2011.77
[68]  
Juanru Li, 2012, Proceedings of the 2012 32nd International Conference on Distributed Computing Systems Workshops (ICDCS Workshops), P552, DOI 10.1109/ICDCSW.2012.33
[69]   Android forensics: Interpretation of timestamps [J].
Kaart, M. ;
Laraghy, S. .
DIGITAL INVESTIGATION, 2014, 11 (03) :234-248
[70]   DIALOG: A framework for modeling, analysis and reuse of digital forensic knowledge [J].
Kahvedzic, Damir ;
Kechadi, Tahar .
DIGITAL INVESTIGATION, 2009, 6 :S23-S33