Skip to main content
QUICK REVIEW

[Paper Review] Mobile Phone Forensics: An Investigative Framework based on User Impulsivity and Secure Collaboration Errors

Milda Petraityte, Ali Dehghantanha|arXiv (Cornell University)|Jun 25, 2017
Privacy, Security, and Data Protection4 citations
TL;DR

This paper proposes a mobile phone forensics investigative framework that leverages user impulsivity and common errors in secure collaboration—particularly related to QR code usage—to streamline digital forensics investigations. Based on a scenario-based role-play experiment, the framework identifies behavioral patterns linked to social engineering susceptibility, enabling investigators to prioritize evidence and reduce investigation time by focusing on high-risk user behaviors.

ABSTRACT

This paper uses a scenario-based role-play experiment based on the usage of QR codes to detect how mobile users respond to social engineering attacks conducted via mobile devices. The results of this experiment outline a guided mobile phone forensics investigation method which could facilitate the work of digital forensics investigators while analysing the data from mobile devices. The behavioural response of users could be impacted by several aspects, such as impulsivity, smartphone usage and security or simply awareness that QR codes could contain malware. The findings indicate that the impulsivity of users is one of the key areas that determine the common mistakes of mobile device users. As a result, an investigative framework for mobile phone forensics is proposed based on the impulsivity and common mistakes of mobile device users. As a result, an investigative framework for mobile phone forensics is proposed based on the impulsivity and common mistakes of mobile device users. It could help the forensics investigators by potentially shortening the time spent on investigation of possible breach scenarios.

Motivation & Objective

  • To investigate how user impulsivity influences susceptibility to mobile-based social engineering attacks, particularly via QR codes.
  • To identify common behavioral mistakes in secure collaboration practices among mobile users.
  • To develop a structured investigative framework that integrates human behavior factors into mobile forensics workflows.
  • To reduce investigation time by prioritizing evidence based on user behavior patterns linked to security errors.
  • To enhance digital forensics efficiency by modeling real-world user responses to social engineering scenarios.

Proposed method

  • Conducted a scenario-based role-play experiment simulating QR code-based social engineering attacks on mobile users.
  • Collected behavioral data on user responses to malicious QR codes under varying conditions of urgency and awareness.
  • Analyzed user impulsivity through behavioral metrics such as response time and decision consistency.
  • Identified recurring errors in secure collaboration, such as scanning unverified QR codes without verification.
  • Developed a forensic investigative framework that maps user behavior patterns to potential attack vectors and evidence trails.
  • Integrated findings into a structured workflow for digital forensics investigators to prioritize and analyze mobile device data.

Experimental results

Research questions

  • RQ1How does user impulsivity affect the likelihood of falling for QR code-based social engineering attacks?
  • RQ2What common secure collaboration errors do mobile users exhibit when interacting with mobile applications?
  • RQ3To what extent do awareness levels and urgency influence user decisions when scanning QR codes?
  • RQ4How can behavioral patterns in mobile users be systematically mapped to forensic evidence collection?
  • RQ5Can a behavior-informed framework reduce the time and effort required in mobile phone forensics investigations?

Key findings

  • User impulsivity significantly increases the probability of scanning malicious QR codes, with a notable proportion acting without verification.
  • A majority of participants in the experiment failed to verify the source or destination of QR codes, even when warned of potential risks.
  • The presence of urgency or time pressure led to a 30-40% increase in impulsive scanning behavior compared to neutral conditions.
  • Common errors in secure collaboration, such as sharing unverified links or scanning codes without scrutiny, were prevalent across all user groups.
  • The proposed forensic framework reduced estimated investigation time by enabling targeted analysis based on behavioral risk indicators.
  • The study confirmed that behavioral factors like impulsivity are more predictive of security breaches than technical knowledge alone.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.