کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
456277 695687 2012 10 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Acquisition and analysis of volatile memory from android devices
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
Acquisition and analysis of volatile memory from android devices
چکیده انگلیسی

The Android operating system for mobile phones, which is still relatively new, is rapidly gaining market share, with dozens of smartphones and tablets either released or set to be released. In this paper, we present the first methodology and toolset for acquisition and deep analysis of volatile physical memory from Android devices. The paper discusses some of the challenges in performing Android memory acquisition, discusses our new kernel module for dumping memory, named dmd, and specifically addresses the difficulties in developing device-independent acquisition tools. Our acquisition tool supports dumping memory to either the SD on the phone or via the network. We also present analysis of kernel structures using newly developed Volatility functionality. The results of this work illustrate the potential that deep memory analysis offers to digital forensics investigators.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Digital Investigation - Volume 8, Issues 3–4, February 2012, Pages 175–184
نویسندگان
, , , ,