Skip to main content

Research Repository

Advanced Search

Forensic analysis of wireless networking evidence of Android smartphones

Andriotis, Panagiotis; Oikonomou, George; Tryfonas, Theo

Authors

Profile image of Panos Andriotis

Dr Panos Andriotis Panagiotis.Andriotis@uwe.ac.uk
Senior Lecturer in Computer Forensics and Security

George Oikonomou

Theo Tryfonas



Abstract

This paper introduces a method for acquiring forensic-grade evidence from Android smartphones using open source tools. We investigate in particular cases where the suspect has made use of the smartphone's Wi-Fi or Bluetooth interfaces. We discuss the forensic analysis of four case studies, which revealed traces that were left in the inner structure of three mobile Android devices and also indicated security vulnerabilities. Subsequently, we propose a detailed plan for forensic examiners to follow when dealing with investigations of potential crimes committed using the wireless facilities of a suspect Android smartphone. This method can be followed to perform physical acquisition of data without using commercial tools and then to examine them safely in order to discover any activity associated with wireless communications. We evaluate our method using the Association of Chief Police Officers' (ACPO) guidelines of good practice for computer-based, electronic evidence and demonstrate that it is made up of an acceptable host of procedures for mobile forensic analysis, focused specifically on device Bluetooth and Wi-Fi facilities. © 2012 IEEE.

Presentation Conference Type Conference Paper (published)
Conference Name WIFS 2012 - Proceedings of the 2012 IEEE International Workshop on Information Forensics and Security
Start Date Dec 2, 2012
End Date Dec 5, 2012
Acceptance Date Jan 17, 2012
Publication Date Dec 1, 2012
Peer Reviewed Peer Reviewed
Pages 109-114
Book Title 2012 IEEE International Workshop on Information Forensics and Security (WIFS)
DOI https://doi.org/10.1109/WIFS.2012.6412634
Keywords Android, smartphones
Public URL https://uwe-repository.worktribe.com/output/951322
Publisher URL http://dx.doi.org/10.1109/WIFS.2012.6412634
Additional Information Title of Conference or Conference Proceedings : IEEE International Workshop on Information Forensics and Security (WIFS)