Skip navigation
Use este identificador para citar ou linkar para este item: http://repositorio.unb.br/handle/10482/10860
Arquivos associados a este item:
Arquivo Descrição TamanhoFormato 
ARTIGO_AcquisitionAnalysisDigital.pdf869,04 kBAdobe PDFVisualizar/Abrir
Título: Acquisition and Analysis of Digital Evidencein Android Smartphones
Autor(es): Simão, André Morum de Lima
Sícoli, Fábio Caús
Melo, Laerte Peotta de
Deus, Flávio Elias Gomes de
Sousa Júnior, Rafael Timóteo de
Assunto: Sistemas de comunicação sem fio
Telefonia celular - dispositivos
Computação forense
Data de publicação: 2011
Referência: SIMÃO, André Morum de Lima et al. Acquisition and Analysis of Digital Evidencein Android Smartphones. The International Journal of Forensic Computer Science, v. 6, n. 1, p. 28-43, 2011. Disponível em:<http://www.ijofcs.org/abstract-v06n1-pp02.html>. Acesso em: 19 jun. 2012. Doi: 10.5769/J201101002
Resumo: From an expert's standpoint, an Android phone is a large data repositorythat can be stored either locally or remotely. Besides, its platform allows analysts toacquire device data and evidence, collecting information about its owner and facts underinvestigation. This way, by means of exploring and cross referencing that rich data source,one can get information related to unlawful acts and its perpetrator. There are widespreadand well documented approaches to forensic examining mobile devices and computers.Nevertheless, they are neither specific nor detailed enough to be conducted on Androidcell phones. These approaches are not totally adequate to examine modern smartphones,since these devices have internal memories whose removal or mirroring procedures areconsidered invasive and complex, due to difficulties in having direct hardware access. Theexam and analysis are not supported by forensic tools when having to deal with specific filesystems, such as YAFFS2 (Yet Another Flash File System). Furthermore, specific featuresof each smartphone platform have to be considered prior to acquiring and analyzing itsdata. In order to deal with those challenges, this paper proposes a method to perform dataacquisition and analysis of Android smartphones, regardless of version and manufacturer.The proposed approach takes into account existing techniques of computer and cellphone forensic examination, adapting them to specific Android characteristics, its datastorage structure, popular applications and the conditions under which the device wassent to the forensic examiner. The method was defined in a broad manner, not namingspecific tools or techniques. Then, it was deployed into the examination of six Androidsmartphones, which addressed different scenarios that an analyst might face, and wasvalidated to perform an entire evidence acquisition and analysis.
Licença: Disponível sob Licença Creative Commons 3.0, que permite copiar, distribuir e transmitir o trabalho, desde que seja citado o autor e licenciante. Não permite o uso para fins comerciais nem a adaptação desta.
DOI: https://dx.doi.org/10.5769/J201101002
Aparece nas coleções:Artigos publicados em periódicos e afins

Mostrar registro completo do item Visualizar estatísticas



Este item está licenciada sob uma Licença Creative Commons Creative Commons