Skip to main content
QUICK REVIEW

[论文解读] Forensic Investigation of Social Media and Instant Messaging Services in Firefox OS: Facebook, Twitter, Google+, Telegram, OpenWapp and Line as Case Studies

Mohd Najwadi Yusoff, Ali Dehghantanha|arXiv (Cornell University)|Jun 25, 2017
Advanced Malware Detection Techniques被引用 7
一句话总结

本文研究了在Firefox OS上对社交媒体和即时通讯服务的残留数字取证数据获取,分析了Facebook、Twitter、Google+、Telegram、OpenWapp和Line。通过检查文件系统痕迹、缓存和数据库残留,研究识别出可恢复的证据,如登录令牌、消息记录和用户资料,为未来在传统移动平台上的取证调查提供了取证框架。

ABSTRACT

Mobile devices are increasingly utilized to access social media and instant messaging services, which allow users to communicate with others easily and quickly. However, the misuse of social media and instant messaging services facilitated conducting different cybercrimes such as cyber stalking, cyber bullying, slander spreading and sexual harassment. Therefore, mobile devices are an important evidentiary piece in digital investigation. In this chapter, we report the results of our investigation and analysis of social media and instant messaging services in Firefox OS. We examined three social media services (Facebook, Twitter and Google+) as well as three instant messaging services (Telegram, OpenWapp and Line). Our analysis may pave the way for future forensic investigators to trace and examine residual remnants of forensics value in FireFox OS.

研究动机与目标

  • 识别并分析Firefox OS上社交媒体和即时通讯服务的残留数字证据。
  • 评估Firefox OS文件系统、缓存和数据库中数据残留的取证价值。
  • 为调查人员提供一个实用的取证框架,以从Firefox OS设备中提取和分析证据。
  • 研究在六个主要平台(Facebook、Twitter、Google+、Telegram、OpenWapp和Line)上,认证令牌、消息记录和用户资料的持久性。
  • 通过记录在较少研究的移动操作系统上的数据痕迹,为未来数字取证研究提供支持。

提出的方法

  • 对Firefox OS设备进行实时和物理取证,以访问文件系统和存储组件。
  • 分析浏览器缓存、本地数据库和应用程序特定的数据目录以寻找证据。
  • 使用逆向工程和静态分析,识别各服务的数据结构和存储模式。
  • 从应用程序数据库中提取并重建用户会话、登录令牌和消息历史记录。
  • 通过在多个Firefox OS设备型号上重复测试,验证证据恢复的有效性。
  • 应用标准的数字取证技术,以保护数据完整性并确保取证操作的可靠性。

实验结果

研究问题

  • RQ1在社交媒体和即时通讯应用停用后,Firefox OS上残留的数字证据类型有哪些?
  • RQ2在Firefox OS上,Facebook、Twitter、Google+、Telegram、OpenWapp和Line的认证令牌和会话数据有多持久?
  • RQ3Firefox OS上的哪些数据结构和存储位置包含与社交媒体和即时通讯服务相关的取证痕迹?
  • RQ4在多大程度上可从Firefox OS的文件系统和缓存中恢复消息记录和用户资料?
  • RQ5哪些取证采集策略在从Firefox OS设备中提取残留数据方面是有效的?

主要发现

  • 从Firefox OS的本地存储和缓存目录中可恢复如登录令牌和会话Cookie等残留证据。
  • Facebook、Twitter和Google+的消息记录和用户资料存在于应用程序数据文件夹内的SQLite数据库中。
  • Telegram和Line将聊天历史记录和联系人信息存储在结构化本地数据库中,支持部分消息的重建。
  • OpenWapp和Telegram将用户认证令牌以加密形式存储,可在取证采集后提取并分析。
  • 在应用程序卸载后,所有六个服务的残留数据仍持续存在,表明设备镜像具有显著的取证价值。
  • 本研究证实,尽管Firefox OS市场占有率有限,但其通过多种数据持久化机制,仍具有重要的数字取证价值。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。