A TOOL FOR VOLATILE MEMORY ACQUISITION FROM ANDROID DEVICES

被引:6
|
作者
Yang, Haiyu [1 ]
Zhuge, Jianwei [2 ]
Liu, Huiming [3 ]
Liu, Wei [3 ]
机构
[1] Tsinghua Univ, Thermal Engn, Beijing, Peoples R China
[2] Tsinghua Univ, Inst Network Sci & Cyberspace, Comp Sci, Beijing, Peoples R China
[3] Tsinghua Univ, Comp Sci, Beijing, Peoples R China
来源
基金
中国国家自然科学基金;
关键词
Mobile device forensics; memory forensics; Android; rootkit detection; FORENSICS;
D O I
10.1007/978-3-319-46279-0_19
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Memory forensic tools provide a thorough way to detect malware and investigate cyber crimes. However, existing memory forensic tools must be compiled against the exact version of the kernel source code and the exact kernel configuration. This poses a problem for Android devices because there are more than 1,000 manufacturers and each manufacturer maintains its own kernel. Moreover, new security enhancements introduced in Android Lollipop prevent most memory acquisition tools from executing. This chapter describes AMExtractor, a tool for acquiring volatile physical memory from a wide range of Android devices with high integrity. AMExtractor uses /dev/kmem to execute code in kernel mode, which is supported by most Android devices. Device-specific information is extracted at runtime without any assumptions about the target kernel source code and configuration. AMExtractor has been successfully tested on several devices shipped with different versions of the Android operating system, including the latest Android Lollipop. Memory images dumped by AMExtractor can be exported to other forensic frameworks for deep analysis. A rootkit was successfully detected using the Volatility Framework on memory images retrieved by AMExtractor.
引用
收藏
页码:365 / 378
页数:14
相关论文
共 50 条
  • [31] ANTS ROAD: A New Tool for SQLite Data Recovery on Android Devices
    Aouad, Lamine M.
    Kechadi, Tahar M.
    Di Russo, Roberto
    DIGITAL FORENSICS AND CYBER CRIME, ICDF2C 2012, 2013, 114 : 253 - 263
  • [32] Bluetooth Low Energy used for Memory Acquisition from Smart Health Care Devices
    Wu, Tina
    Martin, Andrew
    2018 17TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (IEEE TRUSTCOM) / 12TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (IEEE BIGDATASE), 2018, : 1256 - 1261
  • [33] A Website Fingerprinting Attack based on the Virtual Memory of the Process on Android Devices
    Okazaki, Tatsuya
    Kato, Hiroya
    Haruta, Shuichiro
    Sasase, Iwao
    2021 26TH IEEE ASIA-PACIFIC CONFERENCE ON COMMUNICATIONS {APCC), 2021, : 7 - 12
  • [34] An Anti-forensics Method against Memory Acquiring for Android Devices
    Zheng, Jiamin
    Tan, Yu-An
    Zhang, Xiaosong
    Liang, Chen
    Zhang, Changyou
    Zheng, Jun
    2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND ENGINEERING (CSE) AND IEEE/IFIP INTERNATIONAL CONFERENCE ON EMBEDDED AND UBIQUITOUS COMPUTING (EUC), VOL 1, 2017, : 214 - 218
  • [35] Implementation of Si nanocrystals in non-volatile memory devices
    Yater, Jane A.
    PHYSICA STATUS SOLIDI A-APPLICATIONS AND MATERIALS SCIENCE, 2013, 210 (08): : 1505 - 1511
  • [36] Memristive tonotopic mapping with volatile resistive switching memory devices
    Milozzi, Alessandro
    Ricci, Saverio
    Ielmini, Daniele
    NATURE COMMUNICATIONS, 2024, 15 (01)
  • [37] Technology CAD of non-volatile SONOS memory devices
    Chakraborty, P.
    Mahato, S. S.
    Maiti, T. K.
    Saha, S.
    Maiti, C. K.
    PROCEEDINGS OF THE 2007 INTERNATIONAL WORKSHOP ON THE PHYSICS OF SEMICONDUCTOR DEVICES: IWPSD-2007, 2007, : 164 - +
  • [38] Memristive tonotopic mapping with volatile resistive switching memory devices
    Alessandro Milozzi
    Saverio Ricci
    Daniele Ielmini
    Nature Communications, 15
  • [39] Nanoimprint for future non-volatile memory and logic devices
    Meier, M.
    Nauenheim, C.
    Gilles, S.
    Mayer, D.
    Kuegeler, C.
    Waser, R.
    MICROELECTRONIC ENGINEERING, 2008, 85 (5-6) : 870 - 872
  • [40] Non-volatile Memory Devices Based on Chalcogenide Materials
    Wang, Fei
    Wu, Xiaolong
    PROCEEDINGS OF THE 2009 SIXTH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: NEW GENERATIONS, VOLS 1-3, 2009, : 5 - +