A Method of Android Application Forensics Based on Heap Memory Analysis
Junfu Zhang, E. Chengyuan, Aiqun Hu · Proceedings of the 2nd International Conference on Computer Science and Application Engineering · 2018
This1 thesis presents a new method of Android application forensics, based on the heap memory analysis. In this method, the heap memory data of an Android app, running on the virtual machine, is directly extracted, parsed and reconstructed. The path of target data can be located depending on the exported testing data. Next, it designs the steps of data extraction and directly applies them in real forensics work. This thesis discusses the way of searching targeting data in detail. It successfully acquires various records from memory data, including user's password hash, based on experiments on applications like Tencent QQ. As a specialized realization of memory forensics, it is more effective and helpful for current forensics work.