An Android Communication App Forensic Taxonomy

J Forensic Sci. 2016 Sep;61(5):1337-50. doi: 10.1111/1556-4029.13164. Epub 2016 Jul 22.

Abstract

Due to the popularity of Android devices and applications (apps), Android forensics is one of the most studied topics within mobile forensics. Communication apps, such as instant messaging and Voice over IP (VoIP), are one popular app category used by mobile device users, including criminals. Therefore, a taxonomy outlining artifacts of forensic interest involving the use of Android communication apps will facilitate the timely collection and analysis of evidentiary materials from such apps. In this paper, 30 popular Android communication apps were examined, where a logical extraction of the Android phone images was collected using XRY, a widely used mobile forensic tool. Various information of forensic interest, such as contact lists and chronology of messages, was recovered. Based on the findings, a two-dimensional taxonomy of the forensic artifacts of the communication apps is proposed, with the app categories in one dimension and the classes of artifacts in the other dimension. Finally, the artifacts identified in the study of the 30 communication apps are summarized using the taxonomy. It is expected that the proposed taxonomy and the forensic findings in this paper will assist forensic investigations involving Android communication apps.

Keywords: Android forensics; Viber app; WeChat app; communication app taxonomy; digital forensics; forensic science; line app; mobile app.

MeSH terms

  • Cell Phone*
  • Communication*
  • Crime
  • Forensic Sciences
  • Internet*
  • Mobile Applications*