USENIX Security2016Top-tier venue
Screen after Previous Screens: Spatial-Temporal Recreation of Android App Displays from Memory Images
Brendan Saltaformaggio, Rohit Bhatia, Xiangyu Zhang, Dongyan Xu, Golden G. Richard III
Abstract
Smartphones are increasingly involved in cyber and real world crime investigations. In this paper, we demonstrate a powerful smartphone memory forensics technique, called RetroScope, which recovers multiple previous screens of an Android app -in the order they were displayed -from the phone's memory image. Different from traditional memory forensics, RetroScope enables spatial-temporal forensics, revealing the progression of the phone user's interactions with the app (e.g., a banking transaction, online chat, or document editing session). RetroScope achieves near perfect accuracy in both the recreation and ordering of reconstructed screens. Further, RetroScope is app-agnostic, requiring no knowledge about an app's internal data definitions or rendering logic. RetroScope is inspired by the observations that (1) app-internal data on previous screens exists much longer in memory than the GUI data structures that "package" them and (2) each app is able to perform context-free redrawing of its screens upon command from the Android framework. Based on these, RetroScope employs a novel interleaved re-execution engine to selectively reanimate an app's screen redrawing functionality from within a memory image. Our evaluation shows that RetroScope is able to recover full temporally-ordered sets of screens (each with 3 to 11 screens) for a variety of popular apps on a number of different Android devices.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1d3756e8-6eb4-432f-b499-bc06212fc47cCited by top-tier papers13
- DeepMem: Learning Graph Neural Network Models for Fast and Robust Memory Forensic AnalysisWei Song, Heng Yin, Chang Liu, Dawn SongCCS 2018 · 57 citations
- Ginseng: Keeping Secrets in Registers When You Distrust the Operating SystemMin Hong Yun, Lin ZhongNDSS 2019 · 48 citations
- Forecasting Malware Capabilities From Cyber Attack Memory ImagesOmar Alrawi, Moses Ike, Matthew Pruett, Ranjita Pai Kasturi et al.USENIX Security 2021 · 32 citations
- DangZero: Efficient Use-After-Free Detection via Direct Page Table AccessFloris Gorter, Koen Koning, Herbert Bos, Cristiano GiuffridaCCS 2022 · 15 citations
- Tipped Off by Your Memory Allocator: Device-Wide User Activity Sequencing from Android Memory ImagesRohit Bhatia, Brendan Saltaformaggio, Seung Jei Yang, Aisha I. Ali-Gombe et al.NDSS 2018 · 14 citations
Related papers
- An OS-agnostic Approach to Memory ForensicsAndrea Oliveri, Matteo Dell'Amico, Davide BalzarottiNDSS 2023
- Cross-device record and replay for Android appsCong Li, Yanyan Jiang, Chang XuFSE 2022 · 13 citations
- LogicMEM: Automatic Profile Generation for Binary-Only Memory Forensics via Logic InferenceZhenxiao Qi, Yu Qu, Heng YinNDSS 2022
- EviHunter: Identifying Digital Evidence in the Permanent Storage of Android Devices via Static AnalysisChris Chao-Chun Cheng, Chen Shi, Neil Zhenqiang Gong, Yong GuanCCS 2018 · 13 citations
- Recovering and Rehosting Mobile Local LLM Conversations and Contexts via Memory ForensicsHaichuan Xu, David Oygenblik, Runze Zhang, Mingxuan Yao et al.S&P 2026 · 1 citation
