Study of identifying and managing the potential evidence for effective Android forensics. (June 2020)
- Record Type:
- Journal Article
- Title:
- Study of identifying and managing the potential evidence for effective Android forensics. (June 2020)
- Main Title:
- Study of identifying and managing the potential evidence for effective Android forensics
- Authors:
- Kim, Dohyun
Lee, Sangjin - Abstract:
- Abstract: Since the advent of various IoT devices, the need for digital forensics for mobile devices that people use most closely in their daily lives has continued to grow. Besides, as Bring Your Own Device (BYOD) becomes the trend, devices store business-related information as well as privacy. Thus, mobile devices are becoming the most critical evidence of digital forensics. For practical mobile forensics, it is necessary to identify crime-related items among the many files inside the device accurately. Also, various user information for user behavior analysis from these files should be effectively extracted and managed as potential evidence to ensure integrity. This paper proposes an efficient forensics investigation method for mobile devices with Android OS, which holds the highest share in the world among mobile devices. In this paper, we studied data pre-processing (classification and identification of data), data analysis, evidence management, and Android data Taxonomy. Highlights: We studied how to identify all apps installed on an Android device, extract each property, and the group most files by each app. We studied how to select apps that need investigation based on the type of crime and identify the files associated with them. We studied how to extract user information such as timestamp, id, geodata, etc. needed for investigation from all app logs existing on Android devices regardless of schema structure. We studied the evidence management format, which consistsAbstract: Since the advent of various IoT devices, the need for digital forensics for mobile devices that people use most closely in their daily lives has continued to grow. Besides, as Bring Your Own Device (BYOD) becomes the trend, devices store business-related information as well as privacy. Thus, mobile devices are becoming the most critical evidence of digital forensics. For practical mobile forensics, it is necessary to identify crime-related items among the many files inside the device accurately. Also, various user information for user behavior analysis from these files should be effectively extracted and managed as potential evidence to ensure integrity. This paper proposes an efficient forensics investigation method for mobile devices with Android OS, which holds the highest share in the world among mobile devices. In this paper, we studied data pre-processing (classification and identification of data), data analysis, evidence management, and Android data Taxonomy. Highlights: We studied how to identify all apps installed on an Android device, extract each property, and the group most files by each app. We studied how to select apps that need investigation based on the type of crime and identify the files associated with them. We studied how to extract user information such as timestamp, id, geodata, etc. needed for investigation from all app logs existing on Android devices regardless of schema structure. We studied the evidence management format, which consists of XML for effectively managing the potential evidence selected for analysis. We developed a new Android Data Taxonomy that can be practical and effective in user behavior analysis, and we developed an Android forensic tool by compiling all the research results. … (more)
- Is Part Of:
- Forensic science international. Volume 33(2020)
- Journal:
- Forensic science international
- Issue:
- Volume 33(2020)
- Issue Display:
- Volume 33, Issue 2020 (2020)
- Year:
- 2020
- Volume:
- 33
- Issue:
- 2020
- Issue Sort Value:
- 2020-0033-2020-0000
- Page Start:
- Page End:
- Publication Date:
- 2020-06
- Subjects:
- Mobile forensics -- Android forensics -- Data grouping -- Potential evidence identification -- Data classification -- Mobile data analysis -- Evidence management -- Data taxonomy -- Android forensics XML
- Journal URLs:
- http://www.sciencedirect.com/ ↗
- DOI:
- 10.1016/j.fsidi.2019.200897 ↗
- Languages:
- English
- ISSNs:
- 2666-2817
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 19655.xml