{"title":"FAP","authors":"D. Spiekermann","doi":"10.1145/3424954.3424961","DOIUrl":null,"url":null,"abstract":"The forensic investigation of data stored on mobile devices is a common option to analyze and solve cyber-crime cases. The analysis of the installed applications extracts and collects information to clarify unknown conditions and might provide additional details. Unfortunately, some applications store messages encrypted. So, the information is only readable in the app, which sometimes require online access to start and display these messages. The demanded online access is a predicament; whereas the start of the app or the download of these messages provides new information to solve the case, the danger of remote wiping during the online connection is high. Available environments to facilitate an online access and simultaneously block other connections are available, but they fail during a forensic investigation. In this paper a novel approach for a forensic access point (FAP) is proposed. The design of FAP focuses on the implementation of an isolated environment, which allows the connection of the device and specific online services considering current requirements. The architecture is evaluated by a proof-of-concept (PoC), which proves the usability in a forensically sound manner.","PeriodicalId":143137,"journal":{"name":"Proceedings of the European Interdisciplinary Cybersecurity Conference","volume":"73 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-11-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the European Interdisciplinary Cybersecurity Conference","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3424954.3424961","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
The forensic investigation of data stored on mobile devices is a common option to analyze and solve cyber-crime cases. The analysis of the installed applications extracts and collects information to clarify unknown conditions and might provide additional details. Unfortunately, some applications store messages encrypted. So, the information is only readable in the app, which sometimes require online access to start and display these messages. The demanded online access is a predicament; whereas the start of the app or the download of these messages provides new information to solve the case, the danger of remote wiping during the online connection is high. Available environments to facilitate an online access and simultaneously block other connections are available, but they fail during a forensic investigation. In this paper a novel approach for a forensic access point (FAP) is proposed. The design of FAP focuses on the implementation of an isolated environment, which allows the connection of the device and specific online services considering current requirements. The architecture is evaluated by a proof-of-concept (PoC), which proves the usability in a forensically sound manner.