首页 | 本学科首页   官方微博 | 高级检索  
     检索      


Android forensics: Interpretation of timestamps
Institution:1. Institut de Recherche Criminelle de la Gendarmerie Nationale (IRCGN), Digital Forensics department (INL), 1 boulevard Théophile Sueur, 93110 Rosny-Sous-Bois, France;2. PRES Sorbonne Universités – Université Panthéon-Assas Paris II, 12 place de Panthéon, 75005 Paris Cedex 05, France;3. Kriminaltechnisches Institut (KTI) des Bundeskriminalamtes (BKA), Äppelallee 45, 65173 Wiesbaden, Germany;1. Faculty of Computing, Engineering and Science, University of South Wales, Treforest, CF37 1DL, UK;2. ECU Security Research Institute, Perth, Australia;3. Noroff University College, Norway
Abstract:Interpretation of traces found on Android devices is an important aspect of mobile forensics. This is especially true for timestamps encountered on the device under investigation. In the presence of both naive and UTC timestamps, some form of timestamp normalisation is required. In addition, the investigator needs to gain some understanding of potential clock skew that may exist, especially when evidence from the device under investigation has to be correlated to real world events or evidence from other devices. A case study is presented where the time zone on the Android device was set incorrectly, while the clock was set to correspond to the time zone where the device was actually located. Initially, the fact that both time zones enforced daylight saving time (DST) at different periods was expected to complicate the timestamps normalisation. However, it was found that the version of the Time Zone Database on the device was outdated and did not correspond to the actual time zone rules for the given period. After the case study, the results of experiments on a broader range of devices are presented. Among other things, these results demonstrate a method to detect clock skew based on the mmssms.db database. However, it was also found that the applicability of this method is highly dependent on specific implementation choices made by different vendors.
Keywords:Android  Forensics  settings  db  mmssms  db  Clock skew  Timestamp  Time zone
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号