首页> 外文会议>IEEE Annual Consumer Communications and Networking Conference >Using network traffic to verify mobile device forensic artifacts
【24h】

Using network traffic to verify mobile device forensic artifacts

机译:使用网络流量来验证移动设备的取证伪像

获取原文

摘要

This paper presents a method of device type verification via network behavior examination. This work is compared to methods and applications like nMap or xProbe, because it is capable of discerning mobile operating systems (OS) by using both active and passive network traffic. Our approach, which is based on repeatable experiments, suggests that the three major mobile OS vendors (i.e., Android, iOS, and Microsoft) down throttle the network response of some network traffic sent to them (e.g., ICMP pings) or requested by them (e.g., streaming TCP/IP) in different ways, likely to conserve battery power. Consequently, it affects the network behavior of the devices and how they handle certain events. We took the following steps as a proof-of-concept: (1) ICMP packets are actively sent to (i.e., ping) or (2) passively received by (i.e., streaming video) Android, iOS, and Microsoft mobile devices, (3) the resulting network traffic is analyzed, and (4) machine learning methods are trained to discern among the three OS types. We demonstrate that this method works well using either actively or passively generated network traffic. This method is more flexible than methods that rely solely on MAC addresses or other historical analysis methods for the identification of mobile OS type.
机译:本文提出了一种通过网络行为检查进行设备类型验证的方法。这项工作与nMap或xProbe之类的方法和应用程序进行了比较,因为它能够通过使用主动和被动网络流量来识别移动操作系统(OS)。我们基于可重复实验的方法表明,三个主要的移动OS供应商(即Android,iOS和Microsoft)降低了发送给他们或由他们请求的某些网络流量的网络响应速度(例如,流式传输TCP / IP)可能会节省电池电量。因此,它会影响设备的网络行为以及它们如何处理某些事件。我们采取以下步骤作为概念验证:(1)ICMP数据包被主动发送到(即ping)或(2)被Android,iOS和Microsoft移动设备被动地接收(即,流式传输视频),( 3)分析所得的网络流量,并训练(4)机器学习方法以区分这三种OS类型。我们证明了此方法使用主动或被动生成的网络流量都可以很好地工作。与仅依靠MAC地址或其他历史分析方法来识别移动OS类型的方法相比,此方法更加灵活。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号