کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
6873427 1440636 2018 29 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Circumventing iOS security mechanisms for APT forensic investigations: A security taxonomy for cloud apps
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر نظریه محاسباتی و ریاضیات
پیش نمایش صفحه اول مقاله
Circumventing iOS security mechanisms for APT forensic investigations: A security taxonomy for cloud apps
چکیده انگلیسی
Mobile devices and apps such as cloud apps are a potential attack vector in an advanced persistent threat (APT) incident, due to their capability to store sensitive data (e.g. backup of private and personal data in digital repositories) and access sensitive resources (e.g. compromising the device to access an organisational network). These devices and apps are, thus, a rich source of digital evidence. It is vital to be able to identify artefacts of forensic interest transmitted to/from and stored on the devices. However, security mechanisms in mobile platforms and apps can complicate the forensic acquisition of data. In this paper, we present techniques to circumvent security mechanisms and facilitate collection of artefacts from cloud apps. We then demonstrate the utility of the circumvention techniques using 18 popular iOS cloud apps as case studies. Based on the findings, we present the first iOS cloud app security taxonomy that could be used in the investigation of an APT incident.
ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Future Generation Computer Systems - Volume 79, Part 1, February 2018, Pages 247-261
نویسندگان
, ,