Remote Desktop Software as a forensic resource

被引:3
|
作者
Manson, Jonathan [1 ]
机构
[1] School of Computing, Edinburgh Napier University, Edinburgh, United Kingdom
关键词
COVID-19 - [!text type='Python']Python[!/text] - Computer software;
D O I
10.1080/23742917.2022.2049560
中图分类号
学科分类号
摘要
Remote Desktop Software (RDS) enables the controlling of a computer system without the need for physical access. Operations are sent to the remote machine and executed as if performed by a local user. With an unprecedented shift to remote working due to the COVID-19 Pandemic, more people are working on home devices without enterprise IT support and therefore reliant upon this software to collaborate and keep their systems available and secure. RDS complicates a Forensic Investigation as any person with remote access privileges or knowledge of bypassing them could be responsible for an action. Despite its importance and prevalence, forensic research into RDS is minimal. As a market-leading solution for Windows, TeamViewer is an impactful starting point to demonstrate that such software is forensically-valuable to explore. This paper shows that with suitable evidence, an Investigator can identify which machines have performed remote control or been controlled, transferred files and have been remotely rebooted, among other events. We also highlight a potential privacy concern due to inadequate uninstallation processes. To illustrate the value of our findings we publish a Python module for Autopsy that automatically locates, processes and visualises key TeamViewer artefacts for an Investigator. © 2022 The Author(s). Published by Informa UK Limited, trading as Taylor & Francis Group.
引用
收藏
页码:1 / 26
相关论文
共 50 条
  • [41] The Design and Implementation of Remote Desktop Access Audit System
    Cui, Wenchao
    Li, Hao
    Li, Wei
    An, Sicheng
    2012 7TH INTERNATIONAL CONFERENCE ON COMPUTING AND CONVERGENCE TECHNOLOGY (ICCCT2012), 2012, : 1239 - 1243
  • [42] Remote Web Desktop实现电脑遥控手机
    方亚会
    电脑迷, 2011, (10) : 18 - 19
  • [43] A Strategy for Middleman Attack Prevention in Remote Desktop Protocol
    何泾沙
    徐琛
    张伊璇
    周世义
    JournalofShanghaiJiaotongUniversity(Science), 2015, 20 (01) : 82 - 85
  • [44] A Platform Agnostic Remote Desktop System for Screen Reading
    Billah, Syed Masum
    Ashok, Vikas
    Porter, Donald E.
    Ramakrishnan, I. V.
    ASSETS'16: PROCEEDINGS OF THE 18TH INTERNATIONAL ACM SIGACCESS CONFERENCE ON COMPUTERS AND ACCESSIBILITY, 2016, : 283 - 284
  • [45] The Windows Registry as a forensic resource
    Carvey, H
    DIGITAL INVESTIGATION, 2005, 2 (03) : 201 - 205
  • [46] Maximizing environmental validity: Remote recording of desktop videoconferencing
    Rintel, Sean
    Human-Computer Interaction, Pt 1, Proceedings: INTERACTION DESIGN AND USABILITY, 2007, 4550 : 911 - 920
  • [47] I Know What You Are Doing With Remote Desktop
    Jiang, Minghao
    Gou, Gaopeng
    Shi, Junzheng
    Xiong, Gang
    2019 IEEE 38TH INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE (IPCCC), 2019,
  • [48] Resource Allocation and Forensic Ethics
    Appel, Jacob M.
    JOURNAL OF THE AMERICAN ACADEMY OF PSYCHIATRY AND THE LAW, 2023, 51 (01): : 56 - 60
  • [49] GIS-Enabled Desktop Software Development Pardigms
    Aburizaiza, Ahmad O.
    Ames, Daniel P.
    INTERNATIONAL CONFERENCE ON ADVANCED GEOGRAPHIC INFORMATION SYSTEMS AND WEB SERVICES: GEOWS 2009, PROCEEDINGS, 2009, : 75 - 79