Remote Desktop Software as a forensic resource

被引:3
|
作者
Manson, Jonathan [1 ]
机构
[1] School of Computing, Edinburgh Napier University, Edinburgh, United Kingdom
关键词
COVID-19 - [!text type='Python']Python[!/text] - Computer software;
D O I
10.1080/23742917.2022.2049560
中图分类号
学科分类号
摘要
Remote Desktop Software (RDS) enables the controlling of a computer system without the need for physical access. Operations are sent to the remote machine and executed as if performed by a local user. With an unprecedented shift to remote working due to the COVID-19 Pandemic, more people are working on home devices without enterprise IT support and therefore reliant upon this software to collaborate and keep their systems available and secure. RDS complicates a Forensic Investigation as any person with remote access privileges or knowledge of bypassing them could be responsible for an action. Despite its importance and prevalence, forensic research into RDS is minimal. As a market-leading solution for Windows, TeamViewer is an impactful starting point to demonstrate that such software is forensically-valuable to explore. This paper shows that with suitable evidence, an Investigator can identify which machines have performed remote control or been controlled, transferred files and have been remotely rebooted, among other events. We also highlight a potential privacy concern due to inadequate uninstallation processes. To illustrate the value of our findings we publish a Python module for Autopsy that automatically locates, processes and visualises key TeamViewer artefacts for an Investigator. © 2022 The Author(s). Published by Informa UK Limited, trading as Taylor & Francis Group.
引用
收藏
页码:1 / 26
相关论文
共 50 条
  • [31] Desktop and mobile software development for surgical practice
    Oyama, L
    Tannas, HS
    Moulton, S
    JOURNAL OF PEDIATRIC SURGERY, 2002, 37 (03) : 477 - 481
  • [32] Streaming Legacy Desktop Software from the Cloud
    Zhang, Youhui
    Su, Gelin
    Zheng, Weimin
    PROCEEDINGS OF THE FOURTH INTERNATIONAL CONFERENCE ON ADVANCED ENGINEERING COMPUTING AND APPLICATIONS IN SCIENCES (ADVCOMP 2010), 2010, : 130 - 136
  • [33] Desktop simulation software aids machine design
    Erickson, WM
    I&CS-INSTRUMENTATION & CONTROL SYSTEMS, 1998, 71 (04): : 49 - +
  • [34] PC software brings EDA design to the desktop
    Varhol, P
    COMPUTER DESIGN, 1997, : 33 - 34
  • [35] Characterizing resource availability in enterprise desktop grids
    Kondo, Derrick
    Fedak, Gilles
    Cappello, Franck
    Chien, Andrew A.
    Casanova, Henri
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2007, 23 (07): : 888 - 903
  • [36] Remote access protocols for Desktop-as-a-Service solutions
    Magana, Eduardo
    Sesma, Iris
    Morato, Daniel
    Izal, Mikel
    PLOS ONE, 2019, 14 (01):
  • [37] A strategy for middleman attack prevention in remote desktop protocol
    He J.-S.
    Xu C.
    Zhang Y.-X.
    Zhou S.-Y.
    Journal of Shanghai Jiaotong University (Science), 2015, 20 (01) : 82 - 85
  • [38] Forensic and Software (UN) Obfuscation
    Desnos, Anthony
    Vanderbeken, Eloi
    PROCEEDINGS OF THE 9TH EUROPEAN CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2010, : 416 - 430
  • [39] Software calibration in forensic analyses
    Ozkan, K
    FORENSIC SCIENCE INTERNATIONAL, 2003, 136 : 7 - 8
  • [40] RESOURCE REQUIREMENTS IN FORENSIC PSYCHIATRY
    FRASER, K
    JOURNAL OF FORENSIC PSYCHIATRY, 1994, 5 (03): : 478 - 482