Skip to main content
Article
Network and device forensic analysis of Android social-messaging applications
Digital Investigation
  • Daniel Walnycky, University of New Haven
  • Ibrahim Baggili, University of New Haven
  • Andrew Marrington, Zayed University
  • Jason Moore, University of New Haven
  • Frank Breitinger, University of New Haven
Document Type
Article
Publication Date
1-1-2015
Abstract

In this research we forensically acquire and analyze the device-stored data and network traffic of 20 popular instant messaging applications for Android. We were able to reconstruct some or the entire message content from 16 of the 20 applications tested, which reflects poorly on the security and privacy measures employed by these applications but may be construed positively for evidence collection purposes by digital forensic practitioners. This work shows which features of these instant messaging applications leave evidentiary traces allowing for suspect data to be reconstructed or partially reconstructed, and whether network forensics or device forensics permits the reconstruction of that activity. We show that in most cases we were able to reconstruct or intercept data such as: passwords, screenshots taken by applications, pictures, videos, audio sent, messages sent, sketches, profile pictures and more.

Publisher
Elsevier Ltd
Disciplines
Keywords
  • Android (operating system),
  • Message passing,
  • World Wide Web,
  • Android forensics,
  • Application security,
  • Datapp,
  • Instant messaging,
  • Network forensics,
  • Mobile security
Scopus ID

84938984557

Creative Commons License
Creative Commons Attribution-NonCommercial-No Derivative Works 4.0 International
Indexed in Scopus
Yes
Open Access
Yes
Open Access Type
Hybrid: This publication is openly available in a subscription-based journal/series
Citation Information
Daniel Walnycky, Ibrahim Baggili, Andrew Marrington, Jason Moore, et al.. "Network and device forensic analysis of Android social-messaging applications" Digital Investigation Vol. 14 (2015) p. S77 - S84 ISSN: <p><a href="https://v2.sherpa.ac.uk/id/publication/issn/1742-2876" target="_blank">1742-2876</a></p>
Available at: http://works.bepress.com/andrew-marrington/7/