Tipped Off by Your Memory Allocator: Device-Wide User Activity Sequencing from Android Memory Images
Rohit Bhatia, Brendan Saltaformaggio, Seung Jei Yang, Aisha I. Ali-Gombe, Xiangyu Zhang, Dongyan Xu, Golden G. Richard III
摘要
An essential forensic capability is to infer the sequence of actions performed by a suspect in the commission of a crime. Unfortunately, for cyber investigations, user activity timeline reconstruction remains an open research challenge, currently requiring manual identification of datable artifacts/logs and heuristic-based temporal inference. In this paper, we propose a memory forensics capability to address this challenge. We present Timeliner, a forensics technique capable of automatically inferring the timeline of user actions on an Android device across all apps, from a single memory image acquired from the device. Timeliner is inspired by the observation that Android app Activity launches leave behind key self-identifying data structures. More importantly, this collection of data structures can be temporally ordered, owing to the predictable manner in which they were allocated and distributed in memory. Based on these observations, Timeliner is designed to (1) identify and recover these residual data structures, (2) infer the user-induced transitions between their corresponding Activities, and (3) reconstruct the devicewide, cross-app Activity timeline. Timeliner is designed to leverage the memory image of Android's centralized ActivityManager service. Hence, it is able to sequence Activity launches across all apps -even those which have terminated. Our evaluation shows that Timeliner can reveal substantial evidence (up to an hour) across a variety of apps on different Android platforms.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Forecasting Malware Capabilities From Cyber Attack Memory ImagesOmar Alrawi, Moses Ike, Matthew Pruett, Ranjita Pai Kasturi 等USENIX Security 2021 · 被引用 32 次
- DangZero: Efficient Use-After-Free Detection via Direct Page Table AccessFloris Gorter, Koen Koning, Herbert Bos, Cristiano GiuffridaCCS 2022 · 被引用 15 次
- Total Recall: Persistence of Passwords in AndroidJaeho Lee, Ang Chen, Dan S. WallachNDSS 2019 · 被引用 11 次
- AI Psychiatry: Forensic Investigation of Deep Learning Networks in Memory ImagesDavid Oygenblik, Carter Yagemann, Joseph Zhang, Arianna Mastali 等USENIX Security 2024 · 被引用 6 次
它引用的顶会 Paper1
相关 Paper
- LogicMEM: Automatic Profile Generation for Binary-Only Memory Forensics via Logic InferenceZhenxiao Qi, Yu Qu, Heng YinNDSS 2022
- An OS-agnostic Approach to Memory ForensicsAndrea Oliveri, Matteo Dell'Amico, Davide BalzarottiNDSS 2023
- EviHunter: Identifying Digital Evidence in the Permanent Storage of Android Devices via Static AnalysisChris Chao-Chun Cheng, Chen Shi, Neil Zhenqiang Gong, Yong GuanCCS 2018 · 被引用 13 次
- C^2SR: Cybercrime Scene Reconstruction for Post-mortem Forensic AnalysisYonghwi Kwon, Weihang Wang, Jinho Jung, Kyu Hyung Lee 等NDSS 2021
- Detecting resource utilization bugs induced by variant lifecycles in AndroidYifei Lu, Minxue Pan, Yu Pei, Xuandong LiISSTA 2022 · 被引用 1 次
