LogExtractor: Extracting digital evidence from android log messages via string and taint analysis

LogExtractor: извлечение цифровых доказательств из сообщений журнала Android с помощью строкового анализа и анализа распространения меток
Chris Chao-Chun Cheng, Shi Chen, Neil Zhenqiang Gong, Yong Guan
2021-07-01

Android log messagesApp Log Evidence DatabaseDroidBenchdigital evidence extractionstring and taint analysis
Mobile devices are increasingly involved in crimes. Therefore, digital evidence on mobile devices plays a more and more important role in crime investigations. Existing studies have designed tools to identify and/or extract digital evidence in the main memory or the file system of a mobile device. However, identifying and extracting digital evidence from the logging system of a mobile device is largely unexplored. In this work, we aim to bridge this gap.Specifically, we design, prototype, and evaluate LogExtractor, the first tool to automatically identify and extract digital evidence from log messages on an Android device. Given a log message, LogExtractor first determines whether the log message contains a given type of evidentiary data (e.g., GPS coordinates) and then further extracts the value of the evidentiary data if the log message contains it. Specifically, LogExtractor takes an offline-online approach. In the offline phase, LogExtractor builds an App Log Evidence Database (ALED) for a large number of apps via combining string and taint analysis to analyze the apps' code. Specifically, each record in the ALED contains 1) the string pattern of a log message that an app may write to the logging system, 2) the types of evidentiary data that the log message includes, and 3) the segment(s) of the string pattern that contains the value of a certain type of evidentiary data, where we represent a string pattern using a deterministic finite-state automaton. In the online phase, given a log message from a suspect's Android device, we match the log message against the string patterns in the ALED and extract evidentiary data from it if the matching succeeds. We evaluate LogExtractor on 65 benchmark apps from DroidBench and 12.1 K real-world apps. Our results show that a large number of apps write a diverse set of data to the logging system and LogExtractor can accurately extract them.
1
Evaluation on 65 DroidBench benchmark apps and 12.1K real-world apps shows that Android applications log diverse evidentiary data and that LogExtractor extracts it accurately.
2
LogExtractor is presented as the first tool designed to automatically identify and extract digital evidence from Android log messages.
3
LogExtractor represents log-message patterns with deterministic finite-state automata and matches them against suspect-device logs during online extraction.
4
The method combines offline string and taint analysis to build an App Log Evidence Database containing log patterns, evidence types, and value locations.

digital evidence contained in Android device log messages

automatic identification and extraction of evidentiary data types and values from Android log messages

Publication Details
Publication Date
2021-07-01
Journal
Publisher
ISSN
Cited by
17
Access Type
Author Information
Authors
Chris Chao-Chun Cheng
Shi Chen
Neil Zhenqiang Gong
Yong Guan
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%