Screen after Previous Screens: Spatial-Temporal Recreation of Android App Displays from Memory Images
Brendan Saltaformaggio, Rohit Bhatia, Xiangyu Zhang, Dongyan Xu, Golden G. Richard III
摘要
Smartphones are increasingly involved in cyber and real world crime investigations. In this paper, we demonstrate a powerful smartphone memory forensics technique, called RetroScope, which recovers multiple previous screens of an Android app -in the order they were displayed -from the phone's memory image. Different from traditional memory forensics, RetroScope enables spatial-temporal forensics, revealing the progression of the phone user's interactions with the app (e.g., a banking transaction, online chat, or document editing session). RetroScope achieves near perfect accuracy in both the recreation and ordering of reconstructed screens. Further, RetroScope is app-agnostic, requiring no knowledge about an app's internal data definitions or rendering logic. RetroScope is inspired by the observations that (1) app-internal data on previous screens exists much longer in memory than the GUI data structures that "package" them and (2) each app is able to perform context-free redrawing of its screens upon command from the Android framework. Based on these, RetroScope employs a novel interleaved re-execution engine to selectively reanimate an app's screen redrawing functionality from within a memory image. Our evaluation shows that RetroScope is able to recover full temporally-ordered sets of screens (each with 3 to 11 screens) for a variety of popular apps on a number of different Android devices.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper13
- DeepMem: Learning Graph Neural Network Models for Fast and Robust Memory Forensic AnalysisWei Song, Heng Yin, Chang Liu, Dawn SongCCS 2018 · 被引用 57 次
- Ginseng: Keeping Secrets in Registers When You Distrust the Operating SystemMin Hong Yun, Lin ZhongNDSS 2019 · 被引用 48 次
- Forecasting Malware Capabilities From Cyber Attack Memory ImagesOmar Alrawi, Moses Ike, Matthew Pruett, Ranjita Pai Kasturi 等USENIX Security 2021 · 被引用 32 次
- DangZero: Efficient Use-After-Free Detection via Direct Page Table AccessFloris Gorter, Koen Koning, Herbert Bos, Cristiano GiuffridaCCS 2022 · 被引用 15 次
- Tipped Off by Your Memory Allocator: Device-Wide User Activity Sequencing from Android Memory ImagesRohit Bhatia, Brendan Saltaformaggio, Seung Jei Yang, Aisha I. Ali-Gombe 等NDSS 2018 · 被引用 14 次
相关 Paper
- An OS-agnostic Approach to Memory ForensicsAndrea Oliveri, Matteo Dell'Amico, Davide BalzarottiNDSS 2023
- Cross-device record and replay for Android appsCong Li, Yanyan Jiang, Chang XuFSE 2022 · 被引用 13 次
- LogicMEM: Automatic Profile Generation for Binary-Only Memory Forensics via Logic InferenceZhenxiao Qi, Yu Qu, Heng YinNDSS 2022
- EviHunter: Identifying Digital Evidence in the Permanent Storage of Android Devices via Static AnalysisChris Chao-Chun Cheng, Chen Shi, Neil Zhenqiang Gong, Yong GuanCCS 2018 · 被引用 13 次
- Recovering and Rehosting Mobile Local LLM Conversations and Contexts via Memory ForensicsHaichuan Xu, David Oygenblik, Runze Zhang, Mingxuan Yao 等S&P 2026 · 被引用 1 次
