AmpleDroid Recovering Large Object Files from Android Application Memory
Autor: | Andrew Case, Aisha Ali-Gombe, Golden G. Richard, Sneha Sudhakaran, Augustine Orgah |
---|---|
Rok vydání: | 2020 |
Předmět: |
050101 languages & linguistics
Information retrieval Computer science 05 social sciences Digital forensics Cognitive neuroscience of visual object recognition Process (computing) 02 engineering and technology Data structure Object (computer science) Memory management 0202 electrical engineering electronic engineering information engineering 020201 artificial intelligence & image processing 0501 psychology and cognitive sciences Android (operating system) Resource management (computing) |
Zdroj: | WIFS |
Popis: | Analysis of app-specific behavior has become an increasingly important capability in the fields of digital forensics and incident response. The ability to determine the precise actions performed by a user, such as URLs visited, files downloaded, messages sent and received, images and video viewed, and personal files accessed can be the difference between a successful analysis and one that fails to meet its goals. Unfortunately, proper analysis of volatile app-specific evidence, especially the recovery of large objects such as multimedia and large text files stored in memory has not been explored. This is mainly because the allocation function in the various Android memory management algorithms handles large objects differently and in separate memory regions than small objects. Thus, in this paper our effort is focused on developing an app-agnostic memory analysis tool capable of recovering and reconstructing large objects from process memory captures. We present AmpleDroid, a tool that identifies and extracts large objects loaded in an application memory space. Our methodology involves the inspection of the process image to identify vital Android runtime data structures utilized during large object allocation. AmpleDroid is evaluated on a number of apps and the results shows the recovery of almost 91% of the allocated large objects from process memory |
Databáze: | OpenAIRE |
Externí odkaz: |