On the Efficacy of Using Android Debugging Bridge for Android Device Forensics
Chuck Easttom, Willie Sanders · 2019
Mobile device forensics is an expanding field. As mobile devices permeate society, the ability to effectively extract forensic data from such devices is critical. Malware for mobile devices is also a growing threat. The efficacy of forensic tools is of critical importance to both researchers and practitioners. Evaluating a wide range of tools enables the selection of the appropriate tool for a given investigation. One method of evaluating forensic tools is to analyze the tools ability to detect mobile malware. Many commercial and open source forensic tools do not effectively find malware on a mobile device. This gap in capabilities requires a manual approach to extracting such data. This current study documents an experimental study to determine the efficacy of specific commercial tools in identifying malware on an Android phone. Then a methodology for utilizing the Android Debugging Bridge to identify suspect files that have a high probability of being malware. That methodology is expanded into a generalized forensic analysis approach utilizing the Android Debugging Bridge.