Forensic Aspect of Remote Wiping in Android Presented by: Ming Di Leom Supervisor: Dr. Kim-Kwang Raymond Choo.

Slides:



Advertisements
Similar presentations
Android 4.0 'Ice Cream Sandwich'. As officially announced during the 2011 Google I/O, the upcoming version of Android is called Ice Cream Sandwich, a.
Advertisements

Ethan Bruning Senior Sales Engineer Mobile Capture Apps – Introduction to Mobile Capture App Design and Development.
GT-I9300 Appendix Version 2.0 Global CS ECC HHP Review 1 st June Appendix- Customer Consultant Guide Android mobile technology platform.
Chromebook Inservice. Agenda Meet the Chromebook’s Hardware Features Google Accounts Wireless Network Connectivity and Login Procedures Initial screen.
Desktop Central Managing Desktops, Servers & Devices Romanus Prabhu R Technical Account Manager LinkedIn : romanus.prabhu.
Android 4.0 ICS An Unified UI framework for Tablets and Cell Phones Ashwin. G. Balani, Founder Member, GTUG, Napur.
Nexus One Background The new Google phone, the Nexus One, may make Apple nervous due to different features that the iPhone does not contain. Google’s Nexus.
CS691 Robin Kimzey Cell Phone Security a little computer in your pocket an easy target for malcontents.
Week:#14 Windows Recovery
COMPUTER BACKUP A disaster will happen to you one day…an accidentally deleted file, a new program that caused problems or a virus that wreaked havoc, wiping.
Android Smartphones and Tablets Fall Agenda.
IOS vs. Android: Mobile Learning Yuanjie Dai, Amanda Kuhnley, Korey Page.
UFCFX5-15-3Mobile Device Development Android Development Environments and Windows.
ENCRYPTION Coffee Hour for August HISTORY OF ENCRYPTION Scytale Ciphers – paper wrapped around rod, receiver needed same size rod to get the message.
Installing and Troubleshooting Hardware Device and Drivers Chapter 6 powered by dj.
Chapter 7 Installing and Using Windows XP Professional.
Sophos Mobile Security
March 14, Microsoft Microsoft officially announced the date and time that Internet Explorer 9 (IE9) will move away from a release candidate and.
Smartphones Adrián Preciado. Smartphones Index 1.iPhone OS 1.1Pros 1.2Cons 1.3Different iPhones 1.4 App Store 2.Android 2.1Pros 2.2Cons 2.3 Some phones.
Android 2: Introduction to the Technology Kirk Scott 1.
GeoVision Inc. Mobile First Edition, July, GeoVision Inc. Goal: After this course, the apprentice should be able to understand the functionality.
1 Android- Platform Overview. 2 What is Android? Android is a software stack for mobile devices that includes an operating system, middleware and key.
© by Pearson Education, Inc. All Rights Reserved. 1 Introduction to Android From “Android: How to Program” By Paul Deitel and Harvey Deitel.
Presentation on android based application
SecureLocation Abhinav Tyagi. What is SecureLocation? SecureLocation demonstrate use of BluetoothLE based beacons for securing a region. The application.
LSHTM opendatakit.lshtm.ac.uk.
Monday, August 31, 2015 CSCI 351 – Mobile Applications Development.
MICHAEL J MONROE. What is ? Collection of online services and software offered by Apple. Compatible with Mac OSX, Windows, iPhone, and iPod Touch. Released:
MODUL 2: KEY POINTS IN DEVELOPING ANDROID APPS Studio Mobile Content Development IMTelkom 2012.
Introduction to Android
Android History.
Internet Safety and Productivity Tips Presented by ITS Kerri Sorenson and Sean Hernandez December 11, 8:30-9:00 am.
Tablet Trends The Present and Future of Tablets and Mobiles Conn McQuinn, Puget Sound ESD
Automating Installations by Using the Microsoft Windows 2000 Setup Manager Create setup scripts simply and easily. Create and modify answer files and UDFs.
 Follow the steps in order to solve the sync issue with the best fitness trackers;best fitness trackers  1. Reboot your Fitness Tracker and the device.
Thobani Shaba COSC 101.  What is an Operating System  What is iOS?  History  Features  iOS Jailbreaking  Conclusion.
AccessData User Summit 2016 April 5 th – 7 th, 2016 Lake Mary, FL iOS 9 and Android 6.
How To Restore Photos From Sumsung Galaxy S4?. Contacts Lost On Sumsung Galaxy S4 "Jesus! My baby was scrawling on my s4 touch screen and DELETED all.
How to Recover Deleted Photos from Android Cell Phone? Android is keeping on improving their products and make sure to provide the best software service.
By Collin Donaldson.   In conventional OS architectures, the user accesses the OS via an account that has certain privileges (admin, guest). They can.
Advance startup options Shift Restart. Restart options.
User Guide DCT Retail Mode for SMART CAMERA Mobile Application SAMSUNG ELECTRONICS DI IMC.
How to Recover Deleted Files from Android Phone Internal Memory and External SD Card
How to Use an Android Tablet Well Come To You few Steps For How to Use an Android Tablet?
How to Sync Android Phone to Computer (PC/Mac)? Are you a person that always has your Android phone in your hands? Nowadays, a cell phone is not just for.
/Reimage-Repair-Tool/ /u/6/b/ /channel/UCo47kkB-idAA-IMJSp0p7tQ /alexwaston14/reimage-system-repair/
How to root Android Phone and Tablet for free and safe.
Windows Vista Configuration MCTS : Maintenance and Optimization.
How Kaspersky helps in recovering lost or stolen mobile device.
Mobile Device Development
IT Security Awareness Day October 19, 2016
CS371m - Mobile Computing Runtime Permissions.
Lesson 22: Configuring System Recovery
 Gmail is a free webmail service, developed by Google.  Gmail also supports advertising.  Users can access Gmail on the desktop, laptop or through.
(Successor of android)
Rooting Android Created By : Mayank Talwar.
Android.
Operating System.
Android 4.0 Ice Cream Sandwich
Get help for any Antivirus issues by calling Norton Internet Security support number Norton antivirus software works like a security guard to protect your.
New Technology Group Meeting
McAfee Customer Support Number
Programming Workshop Quixilver 8404.
ESSENTIAL WAYS TO SPEED UP ANDROID SMARTPHONE SIMPLE STEPS TO IMPROVE PHONES PERFORMANCE.
Top 4 Data Recovery Software for Mobile in 2018 for free download
11/23/2018 3:03 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
This course is based on a Samsung Product.
This course is based on a Samsung Product.
Microsoft 365 Business Technical Fundamentals Series
How to Recover Yahoo Account Yahoo Account Recovery easily attach more than large files at one time in Yahoo mail, and easily install yahoo mail iPhone.
Presentation transcript:

Forensic Aspect of Remote Wiping in Android Presented by: Ming Di Leom Supervisor: Dr. Kim-Kwang Raymond Choo

Structure Background Thumbnail recovery Effectiveness of remote wiping apps Discussion Future research 2

Background In August 2013, Google announced Android Device Manager (ADM). Remotely Locate Ring Erase (factory reset) your Android device Available to Android v2.3 (Gingerbread) and above (~99%). No setup or installation required. Automatically installed through Google Play Service. Just need Google Account.

Remote wipe feature is not new in Android. Previously offered to Google Apps customer, or via third party app (e.g. anti-virus).

Research motivation ADM marks remote wiping as official (built-in) feature in Android. This means most Android phone is already equipped with remote wiping capability. Previous studies have shown factory reset is ineffective.

Thumbnail recovery 8

Preliminary study Repeat the experiment done by previous study (Schwamm 2014). Using older Android device (Nexus S vs. Samsung S3). Attempt to recover camera photos. Using similar forensic software to recover photos. Recovery rate is much lower (~50% vs 100%) Why? Let’s try to manually recover Schwamm, R 2014, 'Effectiveness of the factory reset on a mobile device', Master's thesis, Naval Postgraduate School, Monterey, California, USA.

RecoveredOriginal Fragmentation

However, not all kind of files are fragmented. e.g. thumbnail Smaller version of original picture. Less likely to be fragmented.

Thumbnail recovery Structure of thumbnail cache Existing (free) file recovery tool can be tweaked to target thumbnail only. Reduce false positive

Result* Thumbnail typeThumbnails recoveredPercentage 200 x 200 resolution thumbnail in thumbcache10/10 100% VGA resolution thumbnail in thumbcache 3/10 (9/10 if include fragmented thumbnail) 30% Embedded thumbnail in JPEG file10/10 100% (* After factory reset)

Effectiveness of remote wiping/factory reset In 3 rd -party app 15

Effectiveness of remote wiping/factory reset Schwamm, (2014) tested default factory reset function. 7 apps were tested against the default. Compare the recovery rate. 2 apps offer “secure” wiping, which should make the files unrecoverable. Test on 3 mobile devices: Moto G (< 3 months of usage, using new file system) Nexus S (> 3 years of usage, older file system) Nexus 4 (~2 years of usage, most common file system, test still ongoing)

Results: 1 app default wipe method remove almost nothing Out of 2 apps which offer secure wiping, only 1 is more effective. Even with secure wiping, data recovery is still possible Almost all apps are similar to default’s. Very low recovery rate on Moto G (secure wiping or not)

Discussion Data remnant issue can be solved through full-disk encryption Introduced in Android 4.0 (Ice Cream Sandwich) Default in Android 5.0 (Lollipop) However, 4 months after Android Lollipop release, encryption is back to optional due to performance issue of current hardware. Recommendation: Enable full-disk encryption if possible Secure wiping, although not very effective, but better than nothing.

Future research Thumbnail recovery More photo gallery apps More devices (i.e. camera resolution) Effectiveness study Secure wiping method used. Which/how factor (usage, file system) affects recovery rate. 19

Q & A 20