New tool can recover smartphone data to help solve crimes

Image
Press Trust of India Washington
Last Updated : Aug 13 2016 | 2:22 PM IST
Scientists, including one of Indian-origin, have developed a new technique that could help law enforcement officials gather data from smartphones while investigating crimes.
The increasing use of mobile technology in today's society has made information stored in the memory of smartphones just as important as evidence recovered from traditional crime scenes.
The new technique, called RetroScope, moves the focus from a smartphone's hard drive, which holds information after the phone is shut down, to the device's RAM, which is volatile memory.
"We argue this is the frontier in cybercrime investigation in the sense that the volatile memory has the freshest information from the execution of all the apps," said Dongyan Xu, professor at Purdue University, who led the research along with colleague Xiangyu Zhang.
"Investigators are able to obtain more timely forensic information toward solving a crime or an attack," Xu said.
Although the contents of volatile memory are gone as soon as the phone is shut down, it can unveil surprising amounts of forensic data if the device is up and running.
It was discovered that apps left a lot of data in the volatile memory long after that data was displayed, Xu said.
To uncover that data, researchers including doctoral students Rohit Bhatia theorised that rather than focusing on searching for that data, the phone's graphical rendering code could be re-targeted to specific memory areas to obtain and bring up several previous screens shown by an app.
RetroScope makes use of the common rendering framework used by Android to issue a redraw command and obtain as many previous screens as available in the volatile memory for any Android app.
The screens recovered, beginning with the last screen the app displayed, are presented in the order they were seen previously.
"Anything that was shown on the screen at the time of use is indicated by the recovered screens, offering investigators a litany of information," Xu said.
In testing, RetroScope recovered anywhere from three to 11 previous screens in 15 different apps, an average of five pages per app.
The apps ranged from popular social media platforms Facebook and Instagram to more privacy-conscious apps and others.
"We feel without exaggeration that this technology really represents a new paradigm in smart phone forensics," Xu said.
"It is very different from all the existing methodologies for analysing both hard drives and volatile memories," he said.

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Aug 13 2016 | 2:22 PM IST

Next Story