Enabling the forensic study of application-level encrypted data in Android via a Frida-based decryption framework

Cosimo Anglano, Massimo Canonico, Andrea Cepollina, Davide Freggiaro, Alderico Gallo, Marco Guazzone

Risultato della ricerca: Capitolo in libro/report/atti di convegnoContributo a conferenzapeer review

Abstract

The forensic study of mobile apps that use application-level encryption requires the decryption of the data they generate. Such a decryption requires the knowledge of the encryption algorithm and key. Determining them requires, however, a quite complex analysis that is time-consuming, error prone, and often beyond the reach of many forensic examiners. In this paper, we tackle this problem by devising a framework able to automate the decryption of these data when third-party encryption libraries or platforms are used. Our framework is based on the use of dynamic instrumentation of app's binary code by means of hooking, which enables it to export the plaintext of data after they have been decrypted by the app, as well as the corresponding encryption key and parameters. This framework has been conceived to be used only with test devices used for forensic study purposes, and not with devices that need to be forensically analyzed. We describe the architecture of the framework as well as the implementation of its components and of the hooks supporting three prominent and popular encryption libraries, namely SQLCipher, Realm and Jetpack Security. Also, we validate our framework by comparing its decryption results against those published in the literature for Wickr Me, Signal, Threema, and Element.

Lingua originaleInglese
Titolo della pubblicazione ospiteARES 2023 - 18th International Conference on Availability, Reliability and Security, Proceedings
EditoreAssociation for Computing Machinery
ISBN (elettronico)9798400707728
DOI
Stato di pubblicazionePubblicato - 29 ago 2023
Evento18th International Conference on Availability, Reliability and Security, ARES 2023 - Benevento, Italy
Durata: 29 ago 20231 set 2023

Serie di pubblicazioni

NomeACM International Conference Proceeding Series

???event.eventtypes.event.conference???

???event.eventtypes.event.conference???18th International Conference on Availability, Reliability and Security, ARES 2023
Paese/TerritorioItaly
CittàBenevento
Periodo29/08/231/09/23

Fingerprint

Entra nei temi di ricerca di 'Enabling the forensic study of application-level encrypted data in Android via a Frida-based decryption framework'. Insieme formano una fingerprint unica.

Cita questo