Abstract
At the time of this writing, Android devices are widely used, and many studies considering methods of forensic acquisition of data from Android devices have been conducted. Similarly, a diverse collection of smartphone forensic tools has also been introduced. However, studies conducted thus far do not normally guarantee data integrity required for digital forensic investigations. Therefore, this work uses a previously proposed method of Android device acquisition utilizing 'Recovery Mode'. This work evaluates Android Recovery Mode variables that potentially compromise data integrity at the time of data acquisition. Based on the conducted analysis, an Android data acquisition tool that ensures the integrity of acquired data is developed, which is demonstrated in a case study to test tool's ability to preserve data integrity.
Original language | English |
---|---|
Pages | S3-S11 |
DOIs | |
Publication status | Published - 2013 Aug 1 |
Event | 2013 Digital Forensic Research Conference, DFRWS 2013 USA - Monterey, United States Duration: 2013 Aug 4 → 2013 Aug 7 |
Conference
Conference | 2013 Digital Forensic Research Conference, DFRWS 2013 USA |
---|---|
Country/Territory | United States |
City | Monterey |
Period | 13/8/4 → 13/8/7 |
Keywords
- Android forensics
- Android Recovery Mode
- Data acquisition
- Data integrity
- Digital forensic investigation
- JTAG
ASJC Scopus subject areas
- Information Systems