MALWARE PROOF ON MOBILE PHONE EXHIBITS BASED ON GSM/GPRS TRACES
Proceeding: The Second International Conference on Cyber Security, Cyber Peacefare and Digital Forensic (CyberSec)Publication Date: 2013-03-04
Authors : Philip Schutz Michael Breuer Hans Hofken Marko Schuba;
Page : 89-96
Keywords : Malware Proof; Mobile P hone; GSM; GPRS; Exhibit; Forensics;
Abstract
This paper presents a system for proving the existence of malware on mobile phones that are exhibits in a criminal investigation. The system masquerades as legitimate GSM/GPRS network and thus is able to intercept and process all traffic sent from and received by the mobile. Eavesdropping the complete traffic is important, as mobile malware applications use IP as well as SMSs for communication. Some malware apps even check the type of IP connectivity and require both, GPRS and GSM to be present to work correctly. The proposed system intercepts the traffic in a simulated GSM/GPRS environment and additionally provides a connection to the real or a simulated Internet. After the traffic has been recorded it is post-processed using various filter options and presented in the form of an HTML report for further analysis.
Other Latest Articles
- COMPUTER FORENSICS INVESTIGATION AN APPROACH TO EVIDENCE IN CYPERSPACE
- APPLICATION OF SECRET SHARING TECHNIQUES ON CONFIDENTIAL FORENSIC INVESTIGATION
- AN ENTERPRISE-GRADE SECURE DATA STORAGE AND SHARING SYSTEM
- A PROPOSAL AND IMPLEMENTATION OF THE SHOULDER-SURFING ATTACK RESISTANT AUTHENTICATION METHOD USING TWO SHIFT FUNCTIONS
- DIGITAL VIDEO WATERMARKING ON CLOUD COMPUTING ENVIRONMENTS
Last modified: 2013-06-18 22:05:50