Skip to main content
QUICK REVIEW

[论文解读] Forensics Acquisition and Analysis of instant messaging and VoIP applications

Christos Sgaras, Tahar Kechadi|arXiv (Cornell University)|Dec 1, 2016
Advanced Malware Detection Techniques参考文献 10被引用 4
一句话总结

本文提出了一套全面的数字取证采集与分析框架,针对iOS和Android平台上的四种主流即时通讯和VoIP应用——WhatsApp、Skype、Viber和Tango。该研究识别、分类并比较了这些平台上的数字证据,提出了目标证据的分类体系,并评估了证据恢复潜力,关键发现突出了各平台在数据保留和取证可访问性方面的差异。

ABSTRACT

The advent of the Internet has significantly transformed the daily activities of millions of people, with one of them being the way people communicate where Instant Messaging (IM) and Voice over IP (VoIP) communications have become prevalent. Although IM applications are ubiquitous communication tools nowadays, it was observed that the relevant research on the topic of evidence collection from IM services was limited. The reason is an IM can serve as a very useful yet very dangerous platform for the victim and the suspect to communicate. Indeed, the increased use of Instant Messengers on smart phones has turned to be the goldmine for mobile and computer forensic experts. Traces and Evidence left by applications can be held on smart phones and retrieving those potential evidences with right forensic technique is strongly required. Recently, most research on IM forensics focus on applications such as WhatsApp, Viber and Skype. However, in the literature, there are very few forensic analysis and comparison related to IM applications such as WhatsApp, Viber and Skype and Tango on both iOS and Android platforms, even though the total users of this application already exceeded 1 billion. Therefore, in this paper we present forensic acquisition and analysis of these four IMs and VoIPs for both iOS and Android platforms. We try to answer on how evidence can be collected when IM communications are used. We also define taxonomy of target artefacts in order to guide and structure the subsequent forensic analysis. Finally, a review of the information that can become available via the IM vendor was conducted. The achieved results of this research provided elaborative answers on the types of artifacts that can be identified by these IM and VoIP applications. We compare moreover the forensics analysis of these popular applications: WhatApp, Skype, Viber and Tango.

研究动机与目标

  • 填补现有数字取证研究中对WhatsApp、Viber、Skype和Tango等广泛应用的IM和VoIP应用研究不足的空白。
  • 为这些应用生成的数字证据建立系统化的分类体系,以支持结构化的取证分析。
  • 比较iOS和Android平台上这些IM/VoIP应用的取证采集技术与证据可得性差异。
  • 评估通过设备级采集和厂商提供的数据源从这些应用中提取证据的潜力。
  • 为数字取证调查人员提供关于收集和分析IM/VoIP通信的实用指导。

提出的方法

  • 在运行WhatsApp、Skype、Viber和Tango的iOS和Android设备上执行设备级取证采集。
  • 识别并分类跨平台的数字证据,如消息日志、联系人列表、媒体文件和元数据。
  • 开发标准化的目标证据分类体系,以指导系统化的取证分析。
  • 对四种应用在两种操作系统上的证据类型和可访问性进行对比分析。
  • 通过直接设备提取和厂商数据请求,评估证据的可用性和可靠性。
  • 利用逆向工程和文件系统分析,定位并提取易失性和持久性数据。

实验结果

研究问题

  • RQ1WhatsApp、Skype、Viber和Tango在iOS和Android平台上分别生成哪些类型的数字证据?
  • RQ2对于这些IM/VoIP应用,iOS与Android平台在取证采集技术与证据可得性方面有何差异?
  • RQ3从可恢复证据的角度来看,这四种应用的取证价值如何比较?
  • RQ4标准化的证据分类体系在多大程度上能提升IM/VoIP取证的效率与一致性?
  • RQ5除了设备级采集外,从厂商提供的数据源中获取证据的潜力有多大?

主要发现

  • WhatsApp在iOS上保留的可恢复消息数据多于Android平台,尤其体现在SQLite数据库和缓存文件中。
  • Skype在Android上以非结构化格式存储消息日志,导致证据可靠性低于iOS平台。
  • Viber在iOS上表现出更强的数据持久性,消息存储于加密但可访问的数据库文件中。
  • Tango在两个平台上均表现出有限的证据保留能力,多数数据以易失性或混淆格式存储。
  • 所提出的分类体系有效将证据分为消息日志、媒体、元数据和配置文件四类,支持系统化分析。
  • 厂商提供的数据被证实为补充性资源,但并非始终可用,尤其对于端到端加密服务。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。