Remote Desktop Software as a forensic resource

被引:3
|
作者
Manson, Jonathan [1 ]
机构
[1] School of Computing, Edinburgh Napier University, Edinburgh, United Kingdom
关键词
COVID-19 - [!text type='Python']Python[!/text] - Computer software;
D O I
10.1080/23742917.2022.2049560
中图分类号
学科分类号
摘要
Remote Desktop Software (RDS) enables the controlling of a computer system without the need for physical access. Operations are sent to the remote machine and executed as if performed by a local user. With an unprecedented shift to remote working due to the COVID-19 Pandemic, more people are working on home devices without enterprise IT support and therefore reliant upon this software to collaborate and keep their systems available and secure. RDS complicates a Forensic Investigation as any person with remote access privileges or knowledge of bypassing them could be responsible for an action. Despite its importance and prevalence, forensic research into RDS is minimal. As a market-leading solution for Windows, TeamViewer is an impactful starting point to demonstrate that such software is forensically-valuable to explore. This paper shows that with suitable evidence, an Investigator can identify which machines have performed remote control or been controlled, transferred files and have been remotely rebooted, among other events. We also highlight a potential privacy concern due to inadequate uninstallation processes. To illustrate the value of our findings we publish a Python module for Autopsy that automatically locates, processes and visualises key TeamViewer artefacts for an Investigator. © 2022 The Author(s). Published by Informa UK Limited, trading as Taylor & Francis Group.
引用
收藏
页码:1 / 26
相关论文
共 50 条
  • [1] Research on Software Resource Sharing Management in Collaborative Design Environment Based on Remote Virtual Desktop
    Xu, Wensheng
    Li, Nan
    Tang, Hong
    Cha, Jianzhong
    MOVING INTEGRATED PRODUCT DEVELOPMENT TO SERVICE CLOUDS IN THE GLOBAL ECONOMY, 2014, 1 : 278 - 286
  • [2] Resource allocation for remote desktop sessions in utility Grids
    Talwar, Vanish
    Agarwalla, Bikash
    Basu, Sujoy
    Kumar, Raj
    Nahrstedt, Klara
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2006, 18 (06): : 667 - 684
  • [3] Desktop forensic recovery
    Obstgarten, Mike
    Advanced Imaging, 1999, 14 (07):
  • [4] Forensic Analysis of File Exfiltrations Using AnyDesk, TeamViewer and Chrome Remote Desktop
    Paneda, Xabiel G.
    Melendi, David
    Corcoba, Victor
    Paneda, Alejandro G.
    Garcia, Roberto
    Garcia, Dan
    ELECTRONICS, 2024, 13 (08)
  • [5] Desktop publishing software
    Mercando, AD
    PACE-PACING AND CLINICAL ELECTROPHYSIOLOGY, 1996, 19 (03): : 357 - 359
  • [6] SELF-DEVELOPED SOFTWARE APPLICATIONS FOR REMOTE MONITORING. THE DESKTOP AND WEB APPLICATIONS
    Bogdan-Alexandru, Deaky
    Mircea-Viorel, Dragoi
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON MANUFACTURING SCIENCE AND EDUCATION (MSE 2011), VOL I, 2011, : 105 - 108
  • [7] WEB ORIENTED SYSTEM OF ACCESS TO THE REMOTE DESKTOP AND GRAN SOFTWARE FOR TEACHING MATHEMATICS IN SCHOOL
    Zhaldak, Myroslav, I
    Franchuk, Vasyl M.
    INFORMATION TECHNOLOGIES AND LEARNING TOOLS, 2020, 76 (02) : 14 - 29
  • [8] Free desktop publishing software
    Business Forms Labels & Systems, 2000, 38 (04):
  • [9] Desktop sequence analysis software
    Perkel, JM
    SCIENTIST, 2001, 15 (23): : 29 - 31
  • [10] Replacing proprietary software on the desktop
    Hardaway, Don
    COMPUTER, 2007, 40 (03) : 96 - 97