[Paper Review] Forensic Investigation of Social Media and Instant Messaging Services in Firefox OS: Facebook, Twitter, Google+, Telegram, OpenWapp and Line as Case Studies
This paper investigates digital forensic acquisition of residual data from social media and instant messaging services on Firefox OS, analyzing Facebook, Twitter, Google+, Telegram, OpenWapp, and Line. By examining filesystem artifacts, cache, and database remnants, the study identifies recoverable evidence such as login tokens, message logs, and user profiles, offering a forensic framework for future investigations on legacy mobile platforms.
Mobile devices are increasingly utilized to access social media and instant messaging services, which allow users to communicate with others easily and quickly. However, the misuse of social media and instant messaging services facilitated conducting different cybercrimes such as cyber stalking, cyber bullying, slander spreading and sexual harassment. Therefore, mobile devices are an important evidentiary piece in digital investigation. In this chapter, we report the results of our investigation and analysis of social media and instant messaging services in Firefox OS. We examined three social media services (Facebook, Twitter and Google+) as well as three instant messaging services (Telegram, OpenWapp and Line). Our analysis may pave the way for future forensic investigators to trace and examine residual remnants of forensics value in FireFox OS.
Motivation & Objective
- To identify and analyze residual digital evidence from social media and messaging services on Firefox OS.
- To evaluate the forensic value of data remnants in Firefox OS's filesystem, cache, and databases.
- To provide a practical forensic framework for investigators to extract and analyze evidence from Firefox OS devices.
- To examine the persistence of authentication tokens, message logs, and user profiles across six major platforms.
- To support future digital forensics research by documenting data artifacts on a less-studied mobile OS.
Proposed method
- Conducted live and physical acquisition of Firefox OS devices to access filesystem and storage components.
- Analyzed browser caches, local databases, and application-specific data directories for evidence.
- Used reverse engineering and static analysis to identify data structures and storage patterns of each service.
- Extracted and reconstructed user sessions, login tokens, and message histories from application databases.
- Validated evidence recovery through repeated testing on multiple Firefox OS device models.
- Applied standard digital forensic techniques to preserve data integrity and ensure forensically sound acquisition.
Experimental results
Research questions
- RQ1What types of digital evidence remain on Firefox OS after deactivation of social media and messaging applications?
- RQ2How persistent are authentication tokens and session data across Facebook, Twitter, Google+, Telegram, OpenWapp, and Line on Firefox OS?
- RQ3Which data structures and storage locations on Firefox OS contain forensically relevant artifacts for social media and messaging services?
- RQ4To what extent can message logs and user profiles be recovered from Firefox OS filesystems and caches?
- RQ5What forensic acquisition strategies are effective for extracting residual data from Firefox OS devices?
Key findings
- Forexistential evidence such as login tokens and session cookies were recoverable from Firefox OS's local storage and cache directories.
- Message logs and user profiles from Facebook, Twitter, and Google+ were found in SQLite databases within the application data folders.
- Telegram and Line stored chat history and contact information in structured local databases, enabling partial message reconstruction.
- OpenWapp and Telegram retained user authentication tokens in encrypted form, which could be extracted and analyzed post-acquisition.
- Residual data from all six services persisted even after app deinstallation, indicating forensic relevance on device imaging.
- The study confirmed that Firefox OS, despite its limited market share, retains significant digital forensic value through multiple data persistence mechanisms.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.