Ruwa F. Abu Hweidi, M. Jazzar, A. Eleyan, T. Bejaoui
{"title":"基于Android智能手机的社交媒体应用和Web应用信息取证研究","authors":"Ruwa F. Abu Hweidi, M. Jazzar, A. Eleyan, T. Bejaoui","doi":"10.1109/SmartNets58706.2023.10216267","DOIUrl":null,"url":null,"abstract":"The widespread usage of smartphones in many domains such as education, finance, organizations, and gaming makes hackers covet them and raises the challenge of facing cybercrime and forensic investigation of these devices. The devices run apps that can be sophisticatedly linked to other devices or platforms, or Web Apps, which duplicate the forensic investigation problem. Each social media application has its feature to deal with various types of messages and has its method of receiving and storing the messages depending on their type, i.e., text, video, contact file, image, and record. This study works on two scenarios to track the recovered data by logical acquisition method in MOBILedit and FINALmobile forensic tools. The first scenario is social media massaging between two smartphone Apps, and the second one is between Web Apps and smartphone Apps. In the two scenarios, the acquired device is the receiver’s smartphone. This study finds that logical acquisition cannot recover any Facebook or Instagram data, but in WhatsApp and Telegram, logical acquisition can extract and analyze all data except text and contact files, without knowing which linked device or Web App sent the message. There is a need for more investigation on social media Apps and Web Apps in future works.","PeriodicalId":301834,"journal":{"name":"2023 International Conference on Smart Applications, Communications and Networking (SmartNets)","volume":"24 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-07-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Forensics Investigation on Social Media Apps and Web Apps Messaging in Android Smartphone\",\"authors\":\"Ruwa F. Abu Hweidi, M. Jazzar, A. Eleyan, T. Bejaoui\",\"doi\":\"10.1109/SmartNets58706.2023.10216267\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The widespread usage of smartphones in many domains such as education, finance, organizations, and gaming makes hackers covet them and raises the challenge of facing cybercrime and forensic investigation of these devices. The devices run apps that can be sophisticatedly linked to other devices or platforms, or Web Apps, which duplicate the forensic investigation problem. Each social media application has its feature to deal with various types of messages and has its method of receiving and storing the messages depending on their type, i.e., text, video, contact file, image, and record. This study works on two scenarios to track the recovered data by logical acquisition method in MOBILedit and FINALmobile forensic tools. The first scenario is social media massaging between two smartphone Apps, and the second one is between Web Apps and smartphone Apps. In the two scenarios, the acquired device is the receiver’s smartphone. This study finds that logical acquisition cannot recover any Facebook or Instagram data, but in WhatsApp and Telegram, logical acquisition can extract and analyze all data except text and contact files, without knowing which linked device or Web App sent the message. There is a need for more investigation on social media Apps and Web Apps in future works.\",\"PeriodicalId\":301834,\"journal\":{\"name\":\"2023 International Conference on Smart Applications, Communications and Networking (SmartNets)\",\"volume\":\"24 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-07-25\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2023 International Conference on Smart Applications, Communications and Networking (SmartNets)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/SmartNets58706.2023.10216267\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 International Conference on Smart Applications, Communications and Networking (SmartNets)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SmartNets58706.2023.10216267","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
摘要
智能手机在教育、金融、组织和游戏等许多领域的广泛使用使黑客垂涎它们,并提出了面对网络犯罪和对这些设备进行法医调查的挑战。这些设备运行的应用程序可以复杂地链接到其他设备或平台,或者Web应用程序,这重复了取证调查的问题。每个社交媒体应用程序都有其处理各种类型消息的功能,并且根据其类型有其接收和存储消息的方法,即文本,视频,联系人文件,图像和记录。本研究采用MOBILedit和FINALmobile取证工具中的逻辑采集方法,在两种情况下对恢复的数据进行跟踪。第一种情况是两个智能手机应用程序之间的社交媒体信息,第二种情况是Web应用程序和智能手机应用程序之间的信息。在这两种情况下,获取的设备是接收者的智能手机。本研究发现,逻辑获取无法恢复Facebook或Instagram的任何数据,但在WhatsApp和Telegram中,逻辑获取可以提取和分析除文本和联系人文件外的所有数据,而不知道是哪个链接设备或Web App发送了消息。在未来的工作中,需要对social media Apps和Web Apps进行更多的调查。
Forensics Investigation on Social Media Apps and Web Apps Messaging in Android Smartphone
The widespread usage of smartphones in many domains such as education, finance, organizations, and gaming makes hackers covet them and raises the challenge of facing cybercrime and forensic investigation of these devices. The devices run apps that can be sophisticatedly linked to other devices or platforms, or Web Apps, which duplicate the forensic investigation problem. Each social media application has its feature to deal with various types of messages and has its method of receiving and storing the messages depending on their type, i.e., text, video, contact file, image, and record. This study works on two scenarios to track the recovered data by logical acquisition method in MOBILedit and FINALmobile forensic tools. The first scenario is social media massaging between two smartphone Apps, and the second one is between Web Apps and smartphone Apps. In the two scenarios, the acquired device is the receiver’s smartphone. This study finds that logical acquisition cannot recover any Facebook or Instagram data, but in WhatsApp and Telegram, logical acquisition can extract and analyze all data except text and contact files, without knowing which linked device or Web App sent the message. There is a need for more investigation on social media Apps and Web Apps in future works.