期刊文献+

Android智能手机的取证 被引量:28

Digital Evidence Investigation on Android Smart Phone
在线阅读 下载PDF
导出
摘要 作为一种新兴的智能手机,Android手机发展势头极为迅猛,并越来越多的受到人们的关注。通过对Android智能手机的取证研究,在介绍了Android手机的基本工作原理后,详细描述了取证方式。通过Android SDK工具对手机内外置存储进行镜像备份,逻辑分析利用文件系统分析,查找每个应用程序自带的数据库文件来获得有价值信息,物理分析通过对内存镜像进行数据恢复以寻找删除的文件,两者互相结合。结果表明,能够从Android手机中有效寻找到潜在证据。 With the emergence of smart phones, Android maintains a fantastic development. This paper studies how to acquire digital evidence on Android-based cell phones. After introducing the fundamental principles of Android, the method of digital evidence investigation on Android-based cell phones are described in detail. With the tools provided by Android SDK, data mirroring of cell phones memory can be easily done. Then the logical acquisition and physical acquisition are combined to obtain valuable information, where the logical acquisition examines the information from some critical applications' local databases under the Android file system and the physical acquisition recovers the deleted sensitive information from mirroring files. The experiment showes the effectiveness of this forensics approach.
作者 姚伟 沙晶
出处 《中国司法鉴定》 2012年第1期45-49,共5页 Chinese Journal of Forensic Sciences
关键词 Android智能手机 手机取证 AndroidSDK 镜像备份 Android smart phone digital evidence investigation on cell phone Android SDK data mirroring
  • 相关文献

参考文献2

二级参考文献3

  • 1Fabio Casadei,Antonio Savoldi,Paolo Gubian.Forensics and SIM cards:an overview[J].International Journal of Digital Evidence,2006,5(1).
  • 2Svein Yngvar Willassen.Forensics and the GSM mobile telephone system[J].International Journal of Digital Evidence,2003,2(1).
  • 3Wayne Jansen,Rick Ayers.Forensic Software Tools for Cell Phone Subscriber Identity Modules[R].Conference On Digital Forensic,Association of Digital Forensics,Security and Law,2006.

共引文献25

同被引文献77

引证文献28

二级引证文献51

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部