Dissecting the Droid: Forensic Analysis of Android and its malicious Applications

Michael Spreitzenbarth · OPUS FAU (Kooperativer Bibliotheksverbund Berlin-Brandenburg (KOBV), on behalf of the Universitätsbibliothek Erlangen-Nürnberg) · 2013

In recent years, the sales volume of smartphones has tremendously increased and the trend changed from old-fashioned mobile phones with limited functionality to powerful smartphones with plenty of features. The Google smartphone platform Android has become the most popular operating system and has overtaken Symbian- and iOS-based smartphones. Smartphones are ubiquitous which is why they increasingly play an important role for evidence in forensic examinations. In this context, the recovery of digital traces is an important factor when examining and clarifying facts of a criminal action. Although there are already some tools and process descriptions existent, a huge demand for methods and tools which are needed for forensic extraction and analysis of data that have been stored on a smartphone can be noticed. This demand is fueled by the rapid growth and increasing diversification of the mobile phone market, too. Due to the high penetration rate as well as the increasing popularity, smartphones are not only used by criminal actions but they become an attractive target for criminals, too. For a better understanding of the related threats to end users it is important to analyze and identify malicious software. The exponentially growing number of Android Malware within the last months demands an automation of the analysis process to cope with the fast growing data volume. Within this thesis the specifications and particularities of Android smartphones are described. Moreover, an extended framework is presented. This framework is able to extract and analyze data, being interesting for criminal investigation, from an SQLite-database as well as system files of Android smartphones ADEL. In addition, it is shown how movement profiles of smartphones users can be generated. With these movement profiles the smartphone’s location can be proven for a certain time span in the past. This step could be particularly important for resolving criminal cases in which a determined time-location-relationship is essential. An example for such a questions is: “Was the suspect close to the robbed villa during the time of burglary?” When resolving crimes, an investigator often comes to the point at which he has to question: “Was the activity on the smartphone made by the owner or has the smartphone been manipulated?”As to provide support to answer this question, the second part of the Thesis focuses on the analysis of mobile malicious code and the analysis system Mobile-Sandbox is presented. This system has been developed to automatically analyze Android applications, in large quantities, too. It combines static and dynamic analysis methods to test the largest possible part of implemented functions of an application. Furthermore, it uses particular techniques to monitor calls from “non-JAVA” API’s. These techniques and the combination of static and dynamic analysis turn the Mobile-Sandbox into a unique and powerful system at present. With the tools and methodical procedure models presented within this Thesis, an investigator as well as security officers in companies receive important assistance for their daily work.

Read the paper · More papers on PaperTik