http://repositorio.unb.br/handle/10482/10860
File | Description | Size | Format | |
---|---|---|---|---|
ARTIGO_AcquisitionAnalysisDigital.pdf | 869,04 kB | Adobe PDF | View/Open |
Title: | Acquisition and Analysis of Digital Evidencein Android Smartphones |
Authors: | Simão, André Morum de Lima Sícoli, Fábio Caús Melo, Laerte Peotta de Deus, Flávio Elias Gomes de Sousa Júnior, Rafael Timóteo de |
Assunto:: | Sistemas de comunicação sem fio Telefonia celular - dispositivos Computação forense |
Issue Date: | 2011 |
Citation: | SIMÃO, André Morum de Lima et al. Acquisition and Analysis of Digital Evidencein Android Smartphones. The International Journal of Forensic Computer Science, v. 6, n. 1, p. 28-43, 2011. Disponível em:<http://www.ijofcs.org/abstract-v06n1-pp02.html>. Acesso em: 19 jun. 2012. Doi: 10.5769/J201101002 |
Abstract: | From an expert's standpoint, an Android phone is a large data repositorythat can be stored either locally or remotely. Besides, its platform allows analysts toacquire device data and evidence, collecting information about its owner and facts underinvestigation. This way, by means of exploring and cross referencing that rich data source,one can get information related to unlawful acts and its perpetrator. There are widespreadand well documented approaches to forensic examining mobile devices and computers.Nevertheless, they are neither specific nor detailed enough to be conducted on Androidcell phones. These approaches are not totally adequate to examine modern smartphones,since these devices have internal memories whose removal or mirroring procedures areconsidered invasive and complex, due to difficulties in having direct hardware access. Theexam and analysis are not supported by forensic tools when having to deal with specific filesystems, such as YAFFS2 (Yet Another Flash File System). Furthermore, specific featuresof each smartphone platform have to be considered prior to acquiring and analyzing itsdata. In order to deal with those challenges, this paper proposes a method to perform dataacquisition and analysis of Android smartphones, regardless of version and manufacturer.The proposed approach takes into account existing techniques of computer and cellphone forensic examination, adapting them to specific Android characteristics, its datastorage structure, popular applications and the conditions under which the device wassent to the forensic examiner. The method was defined in a broad manner, not namingspecific tools or techniques. Then, it was deployed into the examination of six Androidsmartphones, which addressed different scenarios that an analyst might face, and wasvalidated to perform an entire evidence acquisition and analysis. |
Licença:: | Disponível sob Licença Creative Commons 3.0, que permite copiar, distribuir e transmitir o trabalho, desde que seja citado o autor e licenciante. Não permite o uso para fins comerciais nem a adaptação desta. |
DOI: | https://dx.doi.org/10.5769/J201101002 |
Appears in Collections: | Artigos publicados em periódicos e afins |
This item is licensed under a Creative Commons License