ReLF: Scalable Remote Live Forensics for Android

Ruipeng Zhang,Mengjun Xie,Jiang Bian
DOI: https://doi.org/10.1109/trustcom53373.2021.00117
2021-01-01
Abstract:The world has witnessed the proliferation of mobile technologies as well as smartphone-related cybercrimes in recent years. However, due to high mobility of smartphones and tablets and transient nature of those attacks, previous forensic approaches become inadequate to retrieve forensic data and respond to cybersecurity incidents in time, especially when the investigation involves a large number of mobile devices. In this paper, we propose ReLF 11Source code available at https://github.com/nexus-lab?q=relf, a remote live forensics system for Android smartphones and tablets. ReLF enables forensic investigators to effectively triage operating Android devices and acquire a wide range of forensic artifacts at scale. Compared to existing Android forensic tools that are publicly available, ReLF provides a much more comprehensive set of collectible artifacts and better OS compatibility. Our evaluation results demonstrate that the ReLF client only introduces minor energy overhead to Android devices and that the ReLF server can well handle a large number of Android devices with increasing workload. We also showcase how ReLF can be used in real-world forensic investigation through case studies.
What problem does this paper attempt to address?