The Experts below are selected from a list of 132 Experts worldwide ranked by ideXlab platform

Reiner Creutzburg - One of the best experts on this subject based on the ideXlab platform.

  • conception of a master course for it and media Forensics part ii Android Forensics
    2015 Ninth International Conference on IT Security Incident Management & IT Forensics, 2015
    Co-Authors: Knut Bellin, Reiner Creutzburg
    Abstract:

    The growth of Android in the mobile sector and the interest to investigate these devices from a forensic point of view has rapidly increased. Many companies have security problems with mobile devices in their own IT infrastructure. To respond to these incidents, it is important to have professional trained staff. Furthermore, it is necessary to further train their existing employees in the practical applications of mobile Forensics owing to the fact that a lot of companies are trusted with very sensitive data. Inspired by these facts, this paper addresses training approaches and practical exercises to investigate Android mobile devices.

  • IMF - Conception of a Master Course for IT and Media Forensics Part II: Android Forensics
    2015 Ninth International Conference on IT Security Incident Management & IT Forensics, 2015
    Co-Authors: Knut Bellin, Reiner Creutzburg
    Abstract:

    The growth of Android in the mobile sector and the interest to investigate these devices from a forensic point of view has rapidly increased. Many companies have security problems with mobile devices in their own IT infrastructure. To respond to these incidents, it is important to have professional trained staff. Furthermore, it is necessary to further train their existing employees in the practical applications of mobile Forensics owing to the fact that a lot of companies are trusted with very sensitive data. Inspired by these facts, this paper addresses training approaches and practical exercises to investigate Android mobile devices.

  • conception of a course for professional training and education in the field of computer and mobile Forensics part ii Android Forensics
    Proceedings of SPIE, 2013
    Co-Authors: Knut Kroger, Reiner Creutzburg
    Abstract:

    The growth of Android in the mobile sector and the interest to investigate these devices from a forensic point of view has rapidly increased. Many companies have security problems with mobile devices in their own IT infrastructure. To respond to these incidents, it is important to have professional trained staff. Furthermore, it is necessary to further train their existing employees in the practical applications of mobile Forensics owing to the fact that a lot of companies are trusted with very sensitive data. Inspired by these facts, this paper - a continuation of a paper of January 2012 [1] which showed the conception of a course for professional training and education in the field of computer and mobile Forensics - addresses training approaches and practical exercises to investigate Android mobile devices.

Khulood Ali Al Zaabi - One of the best experts on this subject based on the ideXlab platform.

  • Android Forensics investigating social networking cybercrimes against man in the middle attacks
    Conference on Computational Complexity, 2016
    Co-Authors: Khulood Ali Al Zaabi
    Abstract:

    Cyber-attacks are on the rise due to the increased usage of social networking application's built-in Android devices via Wi-Fi connections, which has resulted in privacy issues. Several studies have been conducted to investigate Android phones, however, none of these have proposed a comprehensive Android investigation method, which begins with a Man-in-the-Middle attack and ending in a criminal investigation. The purpose of this research is to propose an Android Forensics framework against such Wi-Fi attacks, using advanced forensic tools, such as the Cellebrite Universal Forensic Extraction Device and the Oxygen. This will assist the researcher to prove the suggested arguments in the following: 1. To implement guidelines for the forensic examiners, especially for those new in the field of Forensics, and 2. To guide Android and social networking application developers to enhance the level of security. Furthermore, this study recommends the best data extraction methods designed for Android devices.

  • CCC - Android Forensics: Investigating Social Networking Cybercrimes against Man-in-the-Middle Attacks
    2016 Cybersecurity and Cyberforensics Conference (CCC), 2016
    Co-Authors: Khulood Ali Al Zaabi
    Abstract:

    Cyber-attacks are on the rise due to the increased usage of social networking application's built-in Android devices via Wi-Fi connections, which has resulted in privacy issues. Several studies have been conducted to investigate Android phones, however, none of these have proposed a comprehensive Android investigation method, which begins with a Man-in-the-Middle attack and ending in a criminal investigation. The purpose of this research is to propose an Android Forensics framework against such Wi-Fi attacks, using advanced forensic tools, such as the Cellebrite Universal Forensic Extraction Device and the Oxygen. This will assist the researcher to prove the suggested arguments in the following: 1. To implement guidelines for the forensic examiners, especially for those new in the field of Forensics, and 2. To guide Android and social networking application developers to enhance the level of security. Furthermore, this study recommends the best data extraction methods designed for Android devices.

Knut Bellin - One of the best experts on this subject based on the ideXlab platform.

  • conception of a master course for it and media Forensics part ii Android Forensics
    2015 Ninth International Conference on IT Security Incident Management & IT Forensics, 2015
    Co-Authors: Knut Bellin, Reiner Creutzburg
    Abstract:

    The growth of Android in the mobile sector and the interest to investigate these devices from a forensic point of view has rapidly increased. Many companies have security problems with mobile devices in their own IT infrastructure. To respond to these incidents, it is important to have professional trained staff. Furthermore, it is necessary to further train their existing employees in the practical applications of mobile Forensics owing to the fact that a lot of companies are trusted with very sensitive data. Inspired by these facts, this paper addresses training approaches and practical exercises to investigate Android mobile devices.

  • IMF - Conception of a Master Course for IT and Media Forensics Part II: Android Forensics
    2015 Ninth International Conference on IT Security Incident Management & IT Forensics, 2015
    Co-Authors: Knut Bellin, Reiner Creutzburg
    Abstract:

    The growth of Android in the mobile sector and the interest to investigate these devices from a forensic point of view has rapidly increased. Many companies have security problems with mobile devices in their own IT infrastructure. To respond to these incidents, it is important to have professional trained staff. Furthermore, it is necessary to further train their existing employees in the practical applications of mobile Forensics owing to the fact that a lot of companies are trusted with very sensitive data. Inspired by these facts, this paper addresses training approaches and practical exercises to investigate Android mobile devices.

Lin Liu - One of the best experts on this subject based on the ideXlab platform.

  • An Android Communication App Forensic Taxonomy
    Journal of forensic sciences, 2016
    Co-Authors: Abdullah Azfar, Kim-kwang Raymond Choo, Lin Liu
    Abstract:

    Due to the popularity of Android devices and applications (apps), Android Forensics is one of the most studied topics within mobile Forensics. Communication apps, such as instant messaging and Voice over IP (VoIP), are one popular app category used by mobile device users, including criminals. Therefore, a taxonomy outlining artifacts of forensic interest involving the use of Android communication apps will facilitate the timely collection and analysis of evidentiary materials from such apps. In this paper, 30 popular Android communication apps were examined, where a logical extraction of the Android phone images was collected using XRY, a widely used mobile forensic tool. Various information of forensic interest, such as contact lists and chronology of messages, was recovered. Based on the findings, a two-dimensional taxonomy of the forensic artifacts of the communication apps is proposed, with the app categories in one dimension and the classes of artifacts in the other dimension. Finally, the artifacts identified in the study of the 30 communication apps are summarized using the taxonomy. It is expected that the proposed taxonomy and the forensic findings in this paper will assist forensic investigations involving Android communication apps.

  • An Android social app Forensics adversary model
    Proceedings of the Annual Hawaii International Conference on System Sciences, 2016
    Co-Authors: Abdullah Azfar, Kim-kwang Raymond Choo, Lin Liu
    Abstract:

    Android Forensics is one of the most studied topics in the mobile Forensics literature, partly due to the popularity of Android devices and apps. However, there does not appear to have a formal model that captures the activities undertaken during a forensic investigation. In this paper, we adapt a widely used adversary model from the cryptographic literature to formally capture a forensic investigator's capabilities during the collection and analysis of evidentiary materials from mobile devices. We demonstrate the utility of the model using five popular Android social apps (Twitter, POF Dating, Snapchat, Fling and P interest). We recover various information of forensic interest, such as databases, user account information, sent-received images, profile pictures, contact lists, unviewed text messages. We are also able to determine when a notification was sent, a tweet was posted, as well as identifying the Facebook authentication token string used in the apps.

  • HICSS - An Android Social App Forensics Adversary Model
    2016 49th Hawaii International Conference on System Sciences (HICSS), 2016
    Co-Authors: Abdullah Azfar, Kim-kwang Raymond Choo, Lin Liu
    Abstract:

    Android Forensics is one of the most studied topics in the mobile Forensics literature, partly due to the popularity of Android devices and apps. However, there does not appear to have a formal model that captures the activities undertaken during a forensic investigation. In this paper, we adapt a widely used adversary model from the cryptographic literature to formally capture a forensic investigator's capabilities during the collection and analysis of evidentiary materials from mobile devices. We demonstrate the utility of the model using five popular Android social apps (Twitter, POF Dating, Snapchat, Fling and Pinterest). We recover various information of forensic interest, such as databases, user account information, sent-received images, profile pictures, contact lists, unviewed text messages. We are also able to determine when a notification was sent, a tweet was posted, as well as identifying the Facebook authentication token string used in the apps.

Kim-kwang Raymond Choo - One of the best experts on this subject based on the ideXlab platform.

  • Performance of Android Forensics Data Recovery Tools
    arXiv: Cryptography and Security, 2017
    Co-Authors: Bernard Chukwuemeka Ogazi-onyemaechi, Ali Dehghantanha, Kim-kwang Raymond Choo
    Abstract:

    Recovering deleted or hidden data is among most important duties of Forensics investigators. Extensive utilisation of smartphones as subject, objects or tools of crime made them an important part of residual Forensics. This chapter investigates the effectiveness of mobile forensic data recovery tools in recovering evidences from a Samsung Galaxy S2 i9100 Android phone. We seek to determine the amount of data that could be recovered using Phone image carver, Access data FTK, Foremost, Diskdigger, and Recover My File forensic tools. The findings reflected the difference between recovery capacities of studied tools showing their suitability in their specialised contexts only.

  • performance of Android Forensics data recovery tools
    Contemporary Digital Forensic Investigations of Cloud and Mobile Applications, 2017
    Co-Authors: Bernard Chukwuemeka Ogazionyemaechi, Kim-kwang Raymond Choo, Ali Dehghantanha
    Abstract:

    Recovering deleted or hidden data is among the most important duties of Forensics investigators. Extensive utilization of smartphones as subject, objects, or tools of crime made them an important part of residual Forensics. This chapter investigates the effectiveness of mobile forensic data recovery tools in recovering evidences from a Samsung Galaxy S2 i9100 Android phone. We seek to determine the amount of data that could be recovered using Phone image carver, Access data FTK, Foremost, Diskdigger, and Recover My File forensic tools. The findings reflected the difference between recovery capacities of studied tools showing their suitability in their specialized contexts only.

  • Contemporary Digital Forensic Investigations of Cloud and Mobile Applications - Performance of Android Forensics data recovery tools
    Contemporary Digital Forensic Investigations of Cloud and Mobile Applications, 2017
    Co-Authors: Bernard Chukwuemeka Ogazi-onyemaechi, Ali Dehghantanha, Kim-kwang Raymond Choo
    Abstract:

    Recovering deleted or hidden data is among the most important duties of Forensics investigators. Extensive utilization of smartphones as subject, objects, or tools of crime made them an important part of residual Forensics. This chapter investigates the effectiveness of mobile forensic data recovery tools in recovering evidences from a Samsung Galaxy S2 i9100 Android phone. We seek to determine the amount of data that could be recovered using Phone image carver, Access data FTK, Foremost, Diskdigger, and Recover My File forensic tools. The findings reflected the difference between recovery capacities of studied tools showing their suitability in their specialized contexts only.

  • An Android Communication App Forensic Taxonomy
    Journal of forensic sciences, 2016
    Co-Authors: Abdullah Azfar, Kim-kwang Raymond Choo, Lin Liu
    Abstract:

    Due to the popularity of Android devices and applications (apps), Android Forensics is one of the most studied topics within mobile Forensics. Communication apps, such as instant messaging and Voice over IP (VoIP), are one popular app category used by mobile device users, including criminals. Therefore, a taxonomy outlining artifacts of forensic interest involving the use of Android communication apps will facilitate the timely collection and analysis of evidentiary materials from such apps. In this paper, 30 popular Android communication apps were examined, where a logical extraction of the Android phone images was collected using XRY, a widely used mobile forensic tool. Various information of forensic interest, such as contact lists and chronology of messages, was recovered. Based on the findings, a two-dimensional taxonomy of the forensic artifacts of the communication apps is proposed, with the app categories in one dimension and the classes of artifacts in the other dimension. Finally, the artifacts identified in the study of the 30 communication apps are summarized using the taxonomy. It is expected that the proposed taxonomy and the forensic findings in this paper will assist forensic investigations involving Android communication apps.

  • An Android social app Forensics adversary model
    Proceedings of the Annual Hawaii International Conference on System Sciences, 2016
    Co-Authors: Abdullah Azfar, Kim-kwang Raymond Choo, Lin Liu
    Abstract:

    Android Forensics is one of the most studied topics in the mobile Forensics literature, partly due to the popularity of Android devices and apps. However, there does not appear to have a formal model that captures the activities undertaken during a forensic investigation. In this paper, we adapt a widely used adversary model from the cryptographic literature to formally capture a forensic investigator's capabilities during the collection and analysis of evidentiary materials from mobile devices. We demonstrate the utility of the model using five popular Android social apps (Twitter, POF Dating, Snapchat, Fling and P interest). We recover various information of forensic interest, such as databases, user account information, sent-received images, profile pictures, contact lists, unviewed text messages. We are also able to determine when a notification was sent, a tweet was posted, as well as identifying the Facebook authentication token string used in the apps.