Evaluating the privacy of Android mobile applications under forensic analysis

被引:20
|
作者
Ntantogian, Christoforos [1 ]
Apostolopoulos, Dimitris [1 ]
Marinakis, Giannis [1 ]
Xenakis, Christos [1 ]
机构
[1] Univ Piraeus, Dept Digital Syst, Piraeus, Greece
关键词
Privacy of mobile applications; Mobile forensics; Android; Memory dump; Mobile applications; Volatile memory; Authentication credentials;
D O I
10.1016/j.cose.2014.01.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we investigate and evaluate through experimental analysis the possibility of recovering authentication credentials of mobile applications from the volatile memory of Android mobile devices. Throughout the carried experiments and analysis, we have, exclusively, used open-source and free forensic tools. Overall, the contribution of this paper is threefold. First, it thoroughly, examines thirteen (13) mobile applications, which represent four common application categories that elaborate sensitive users' data, whether it is possible to recover authentication credentials from the physical memory of mobile devices, following thirty (30) different scenarios. Second, it explores in the considered applications, if we can discover patterns and expressions that indicate the exact position of authentication credentials in a memory dump. Third, it reveals a set of critical observations regarding the privacy of Android mobile applications and devices. (C) 2014 Elsevier Ltd. All rights reserved.
引用
收藏
页码:66 / 76
页数:11
相关论文
共 50 条
  • [41] What's on the Horizon? An In-Depth Forensic Analysis of Android and iOS Applications
    Salamh, Fahad E.
    Mirza, Mohammad Meraj
    Hutchinson, Shinelle
    Yoon, Yung Han
    Karabiyik, Umit
    IEEE ACCESS, 2021, 9 (09): : 99421 - 99454
  • [42] Examining the Privacy Vulnerability Level of Android Applications
    Kapitsaki, Georgia M.
    Ioannou, Modestos
    WEBIST: PROCEEDINGS OF THE 15TH INTERNATIONAL CONFERENCE ON WEB INFORMATION SYSTEMS AND TECHNOLOGIES, 2019, : 34 - 45
  • [43] PRADroid: Privacy Risk Assessment for Android Applications
    Yang, Yang
    Du, Xuehui
    Yang, Zhi
    2021 IEEE 5TH INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY (ICCSP), 2021, : 90 - 95
  • [44] Comparing Privacy Labels of Applications in Android and iOS
    Khandelwal, Rishabh
    Nayak, Asmit
    Chung, Paul
    Fawaz, Kassem
    PROCEEDINGS OF THE 22ND WORKSHOP ON PRIVACY IN THE ELECTRONIC SOCIETY, WPES 2023, 2023, : 61 - 73
  • [45] Forensic analysis of Sync.com and FlipDrive cloud applications on Android platform
    Bhat, Wasim Ahmad
    Jalal, Mohammad Faid
    Khan, Sajid Sajad
    Shah, Faiqah Farooq
    Wani, Mohamad Ahtisham
    FORENSIC SCIENCE INTERNATIONAL, 2019, 302
  • [46] Automatic Detection for Privacy Violations in Android Applications
    Luo, Qian
    Yu, Yinbo
    Liu, Jiajia
    Benslimane, Abderrahim
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (08) : 6159 - 6172
  • [47] Investigating Wearable Fitness Applications: Data Privacy and Digital Forensics Analysis on Android
    Hutchinson, Shinelle
    Mirza, Mohammad Meraj
    West, Nicholas
    Karabiyik, Umit
    Rogers, Marcus K.
    Mukherjee, Tathagata
    Aggarwal, Sudhir
    Chung, Haeyong
    Pettus-Davis, Carrie
    APPLIED SCIENCES-BASEL, 2022, 12 (19):
  • [48] Forensic Analysis of Android Notifications' History
    Dragonas, Evangelos
    Lambrinoudakis, Costas
    2024 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2024, : 354 - 359
  • [49] Forensic analysis of WeChat on Android smartphones
    Wu, Songyang
    Zhang, Yong
    Wang, Xupeng
    Xiong, Xiong
    Du, Lin
    DIGITAL INVESTIGATION, 2017, 21 : 3 - 10
  • [50] Forensic analysis of hook Android malware
    Schmutz, Dominic
    Rapp, Robin
    Fehrensen, Benjamin
    FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION, 2024, 49