[論文レビュー] Forensics Acquisition and Analysis of instant messaging and VoIP applications
本論文は、iOSおよびAndroidプラットフォーム上の4つの主要なインスタントメッセージングおよびVoIPアプリケーション—WhatsApp、Skype、Viber、Tango—の包括的なフォレンジック取得および分析フレームワークを提示する。本研究では、これらのプラットフォーム間でデジタルアーカイブを特定・分類・比較し、標的アーカイブの分類法を提示するとともに、証拠回収の可能性を評価しており、主な発見ではプラットフォーム固有のデータ保持およびフォレンジックへのアクセス可能性の差が浮き彫りになった。
The advent of the Internet has significantly transformed the daily activities of millions of people, with one of them being the way people communicate where Instant Messaging (IM) and Voice over IP (VoIP) communications have become prevalent. Although IM applications are ubiquitous communication tools nowadays, it was observed that the relevant research on the topic of evidence collection from IM services was limited. The reason is an IM can serve as a very useful yet very dangerous platform for the victim and the suspect to communicate. Indeed, the increased use of Instant Messengers on smart phones has turned to be the goldmine for mobile and computer forensic experts. Traces and Evidence left by applications can be held on smart phones and retrieving those potential evidences with right forensic technique is strongly required. Recently, most research on IM forensics focus on applications such as WhatsApp, Viber and Skype. However, in the literature, there are very few forensic analysis and comparison related to IM applications such as WhatsApp, Viber and Skype and Tango on both iOS and Android platforms, even though the total users of this application already exceeded 1 billion. Therefore, in this paper we present forensic acquisition and analysis of these four IMs and VoIPs for both iOS and Android platforms. We try to answer on how evidence can be collected when IM communications are used. We also define taxonomy of target artefacts in order to guide and structure the subsequent forensic analysis. Finally, a review of the information that can become available via the IM vendor was conducted. The achieved results of this research provided elaborative answers on the types of artifacts that can be identified by these IM and VoIP applications. We compare moreover the forensics analysis of these popular applications: WhatApp, Skype, Viber and Tango.
研究の動機と目的
- WhatsApp、Viber、Skype、Tangoのような人気のあるIMおよびVoIPアプリケーションにおけるフォレンジック研究の空白を埋めるため。これらは広く使用されているが、そのフォレンジック的側面については十分に調査されていない。
- これらのアプリケーションが生成するデジタルアーカイブの体系的な分類法を構築し、構造的なフォレンジック分析を可能にするため。
- iOSおよびAndroidプラットフォーム間でのフォレンジック取得手法および証拠の可用性の差を比較するため。
- デバイスレベルの取得に加え、ベンダーが提供するデータソースを用いた証拠抽出の可能性を評価するため。
- IM/ VoIP通信の収集および分析に関するデジタルフォレンジック捜査官への実用的ガイダンスを提供するため。
提案手法
- WhatsApp、Skype、Viber、TangoがインストールされたiOSおよびAndroidデバイスに対して、デバイスレベルのフォレンジック取得を実施した。
- メッセージログ、連絡先リスト、メディアファイル、メタデータなどのデジタルアーカイブを、プラットフォーム間で特定・分類した。
- 体系的なフォレンジック分析を支援するため、標準化された標的アーカイブの分類法を構築した。
- 4つのアプリケーションがiOSおよびAndroidの両方で生成する証拠タイプおよびアクセス可能性を比較分析した。
- 直接的なデバイス抽出およびベンダーへのデータ要請を通じて、証拠の可用性と信頼性を評価した。
- リバースエンジニアリングおよびファイルシステム分析を用いて、揮発性および恒久的データを特定・抽出した。
実験結果
リサーチクエスチョン
- RQ1WhatsApp、Skype、Viber、Tangoは、iOSおよびAndroidプラットフォームでどのような種類のデジタルアーカイブを生成するか?
- RQ2これらのIM/ VoIPアプリケーションについて、iOSとAndroidの両方でフォレンジック取得手法および証拠の可用性にどのような差が生じるか?
- RQ3回収可能な証拠の観点から、4つのアプリケーションのフォレンジック的価値を比較するとどうなるか?
- RQ4標準化されたアーカイブ分類法は、IM/ VoIPフォレンジックスの効率性および一貫性をどのように向上させるか?
- RQ5デバイスレベルの取得に加え、ベンダーが提供するデータソースから証拠を入手できる範囲はどの程度か?
主な発見
- WhatsAppのiOS版は、Android版に比べて回収可能なメッセージデータがより多い。特にSQLiteデータベースおよびキャッシュファイルに顕著である。
- SkypeのAndroid版は、メッセージログをより構造のない形式で保存しているため、iOS版と比較して証拠の信頼性が低い。
- ViberのiOS版は、暗号化されたがアクセス可能なデータベースファイルにメッセージを保存しており、強いデータ永続性を示している。
- Tangoは両方のプラットフォームで、証拠保持が限定的であり、多くのデータが揮発性または変換済みの形式で保存されている。
- 提案された分類法は、メッセージログ、メディア、メタデータ、設定ファイルの4つのカテゴリにアーカイブを効果的に分類でき、体系的な分析を可能にした。
- ベンダーが提供するデータは補足的ではあるが、特にエンドツーエンド暗号化サービスでは常に入手可能ではないことが判明した。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。