A lightweight framework for cold boot based forensics on mobile devices

Benjamin Taubmann, Manuel Huber, Sascha Wessel, Lukas Heim, Hans Peter Reiser, Georg Sigl

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

4 Scopus citations

Abstract

Mobile devices, like tablets and smartphones, are common place in everyday life. Thus, the degree of security these devices can provide against digital forensics is of particular interest. A common method to access arbitrary data in main memory is the cold boot attack. The cold boot attack exploits theremanence effect that causes data in DRAM modules not to lose the content immediately in case of a power cut-off. This makes it possible to restart a device and extract the data in main memory. In this paper, we present a novel framework for cold boot based data acquisition with a minimal bare metal application on a mobile device. In contrast to other cold boot approaches, our forensics tool overwrites only a minimal amount of data in main memory. This tool requires no more than five kilobytes of constant data in the kernel code section. We hence sustain all of the data relevant for the analysis of the previously running system. This makes it possible to analyze the memory with data acquisition tools. For this purpose, we extend the memory forensics tool Volatility in order to request parts of the main memory dynamically from our bare metal application. We show the feasibility of our approach by comparing it to a traditional memory dump based analysis using the Samsung Galaxy S4 mobile device.

Original languageEnglish
Title of host publicationProceedings - 10th International Conference on Availability, Reliability and Security, ARES 2015
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages120-128
Number of pages9
ISBN (Electronic)9781467365901
DOIs
StatePublished - 16 Oct 2015
Event10th International Conference on Availability, Reliability and Security, ARES 2015 - Toulouse, France
Duration: 24 Aug 201527 Aug 2015

Publication series

NameProceedings - 10th International Conference on Availability, Reliability and Security, ARES 2015

Conference

Conference10th International Conference on Availability, Reliability and Security, ARES 2015
Country/TerritoryFrance
CityToulouse
Period24/08/1527/08/15

Keywords

  • Cold Boot
  • Digital Forensics
  • Mobile Device Security
  • Smartphones
  • Virtual Machine Introspection

Fingerprint

Dive into the research topics of 'A lightweight framework for cold boot based forensics on mobile devices'. Together they form a unique fingerprint.

Cite this