Skip to content
CY-702 (C) · Mobile Security and Forensics/Quick Revision Short Notes

Mobile Security and Forensics (CY-702 (C)) - Unit 3 Short Notes

UNIT 3: Mobile Security and Forensics


I. Legal, Ethical, and Methodological Foundations

Legal and Ethical Considerations in Penetration Testing

  • Legal Considerations: Must have explicit, written authorization (Rules of Engagement) from the asset owner. Unauthorized testing is illegal (e.g., under IT Act, 2000 in India). Compliance with data protection laws (GDPR, HIPAA) is critical when handling discovered data.

  • Ethical Constraints: Scope must be strictly defined and adhered to. Testing on production systems requires extreme caution. Confidentiality of all findings and client data is paramount. Disclosure of vulnerabilities must follow responsible practices.

  • Impact on Decision-Making: Legal risks (lawsuits, regulatory fines) and ethical breaches can cause reputational damage, financial loss, and loss of client trust. Organizations must balance security needs against these risks, often opting for controlled, scoped assessments over broad, aggressive testing.

[!TIP] Exam Focus: Always link "legal/ethical" to "written authorization," "scope," and "confidentiality." Mention specific acts (IT Act) for Indian context.

Stakeholder Engagement

  • Key Stakeholders:

    • Client/Management: Define business objectives, approve scope/budget, receive final report.

    • Pentester/Team: Execute test, report findings, provide remediation guidance.

    • Legal/Compliance: Ensure activities comply with laws and regulations.

    • IT/Security Operations: Provide system access, implement fixes, manage operational impact.

  • Role in Cryptographic Initiatives: Stakeholders define data classification (what needs protection), compliance requirements, and risk appetite. Their buy-in is essential for funding, policy updates, and user training for new crypto measures.

Penetration Testing Methodologies

  • Network Penetration Testing: Focuses on network devices (routers, switches), firewalls, and network services. Goal: lateral movement and internal network compromise.

  • Application Penetration Testing: Focuses on software flaws (web, mobile, desktop apps). Follows frameworks like OWASP Testing Guide (e.g., OWASP Top 10). Goal: exploit application logic, input validation, authentication/authorization flaws.

  • Web Application Penetration Testing: A subset of app testing. Methodology: Reconnaissance → Vulnerability Scanning → Manual Testing (Burp Suite) → Exploitation → Post-Exploitation → Reporting. Emphasizes client-side (JS, HTML) and server-side (SQLi, XSS) flaws.

  • Wireless Penetration Testing: Involves packet sniffing (Aircrack-ng, Wireshark), rogue AP creation, WPA/WPA2 handshake capture/cracking, and social engineering (e.g., evil twin attacks).

[!TIP] Comparison Table: Use this for 7m "compare" questions.

| Aspect | Network Pentest | Application Pentest |

|---------------------|----------------------------------------------|---------------------------------------------|

| Primary Target | Network infrastructure, services, protocols | Software application logic & code |

| Common Tools | Nmap, Metasploit, Nessus | Burp Suite, OWASP ZAP, SQLmap |

| Key Goal | Internal network access, pivot points | Data theft, privilege escalation via app |

| Typical Flaws | Misconfigured services, weak protocols | SQLi, XSS, broken auth, insecure deserialization |

Capture the Flag (CTF) Competitions

  • Purpose: Simulate real-world, time-bound security scenarios under pressure. Test technical skills (reversing, crypto, web), problem-solving, and research ability.

  • Simulation of Real-World Scenarios: Use realistic vulnerabilities (not just textbook examples), require creative chaining of exploits, and often involve obfuscated data or incomplete information, mirroring actual incident response or red teaming.

Need, Scope, and Objectives of Computer/Mobile Forensics

  • Need: To systematically identify, preserve, analyze, and present digital evidence for legal proceedings, internal investigations, or incident response. Ensures evidence admissibility (chain of custody) and fact-based reconstruction of events.

  • Scope: Covers data acquisition (live/static), artifact analysis (files, logs, registry, metadata), timeline creation, and reporting. For mobile, includes device extraction (physical, logical, file system), app data parsing, and location history.

  • Objectives: 1) Preserve evidence without alteration. 2) Recover deleted/encrypted data. 3) Establish a timeline of user/device activity. 4) Attribute actions to a specific user/device. 5) Document findings for court/management.


II. Penetration Testing & Vulnerability Analysis

A. Types, Use Cases, and Methodologies

  • Wireless Penetration Testing Specifics: Beyond sniffing, includes wardriving, WPS PIN attacks, KRACK attacks on WPA2, and Bluetooth/LoWPAN testing. Mobile-specific: testing cellular protocols (SS7, 4G/5G vulnerabilities) and app-based wireless misuse (e.g., improper Wi-Fi Direct handling).

B. Reconnaissance and Information Gathering

  • DNS Reconnaissance: Purpose is to map the target's digital footprint—subdomains, IP ranges, server technologies, employee names (via DNS records), and external services.

  • Tools & Techniques:

    • dig, nslookup, host: Query DNS records.

    • Zone Transfer Attempts: dig axfr @ns1.target.com target.com (misconfigured DNS servers leak entire zone files).

    • Search Engines & OSINT: Google Dorks (site:target.com filetype:pdf), Shodan, Censys.

    • Subdomain Enumeration: Sublist3r, Amass, VirusTotal subdomain reports.

  • Why Crucial? Provides the attack surface map. Understanding external presence (public-facing apps, cloud storage buckets, employee info on LinkedIn) is the foundation for all subsequent attack vectors. Skipping this leads to blind, inefficient testing.

C. Common Vulnerabilities and Attacks

  • SQL Injection (Primary Risk): Allows an attacker to bypass authentication, read/modify/delete sensitive database contents, and potentially execute OS commands (via xp_cmdshell, UNION SELECT file writes). The core risk is unauthorized data exfiltration and data integrity loss.

  • HTTP Strict Transport Security (HSTS): A response header (Strict-Transport-Security: max-age=...) that forces browsers to use HTTPS for all future connections to that domain for a specified time.

    • Importance: Prevents SSL Stripping attacks (man-in-the-middle downgrading HTTPS to HTTP). Protects against protocol downgrade attacks and cookie hijacking.
  • Social Engineering Tactics (Wireless Focus):

    1. Evil Twin Attack: Rogue AP mimicking a legitimate one to steal credentials.

    2. Rogue DHCP Server: Assigns malicious DNS/gateway to redirect traffic.

    3. Phishing via Rogue AP Captive Portal: Fake login page to harvest credentials.

  • Active vs. Passive Security Attacks (Multimedia/Mobile):

    • Passive Attack: Eavesdropping (sniffing wireless traffic, intercepting unencrypted calls/messages). Goal: confidentiality breach. Hard to detect.

    • Active Attack: Modification, replay, or fabrication of data (injecting malicious packets, tampering with video/audio files, DoS). Goal: integrity/availability breach. Easier to detect.

D. Tools and Techniques

  • Vulnerability Scanning Tools:

    • Network: Nmap (port/service discovery), Nessus, OpenVAS (comprehensive vuln scanning).

    • Web: OWASP ZAP, Burp Suite (proxy + scanner), Nikto (web server scanner).

    • Mobile: MobSF (Mobile Security Framework), QARK (for Android), Needle (for iOS).

  • Packet Sniffing in Wireless Pentest:

    • Tool: Wireshark, Aircrack-ng suite (airodump-ng for capture).

    • Purpose: Capture handshakes (for WPA2 cracking), analyze clear-text protocols (HTTP, FTP), identify rogue devices, and detect malicious traffic patterns.

E. Human Factor and Training

  • Employee Training Programs: Reduce attack surface by making employees the first line of defense.

    • Content: Phishing identification (suspicious links/attachments), secure Wi-Fi usage (avoiding evil twins), password hygiene, social engineering tactics (pretexting, baiting).

    • Method: Regular, simulated phishing campaigns with immediate feedback. Interactive workshops, clear reporting procedures for suspicious activity.

    • Impact: Significantly lowers success rate of credential theft and initial access via social engineering.


III. Cryptography and Secure Communication

A. Cryptographic Algorithms and Applications (RSA)

  • Application for Secure Communication (Key Exchange & Encryption):

    1. Key Generation (by Receiver): Choose large primes $p, q$. Compute $$\displaystyle n = p \times q $$, $$\displaystyle \phi(n) = (p-1)(q-1) $$. Choose public exponent $e$ (usually 65537) where $$\displaystyle 1 < e < \phi(n) $$ and $$\displaystyle \gcd(e, \phi(n)) = 1 $$. Compute private exponent $d$ such that $$\displaystyle d \equiv e^{-1} \pmod{\phi(n)} $$. Public Key: $(e, n)$. Private Key: $(d, n)$.

    2. Encryption (by Sender): Ciphertext $$\displaystyle C = M^e \bmod n $$, where $M$ is the plaintext message (as a number < n).

    3. Decryption (by Receiver): Plaintext $$\displaystyle M = C^d \bmod n $$.

  • Demonstration: Used in SSL/TLS handshakes (key exchange), digital signatures (sign with private key, verify with public), and encrypting symmetric session keys.

B. Cryptography Implementation and Audit

  • Key Elements of Audit Documentation Report:

    1. Executive Summary: High-level risk overview for management.

    2. Scope & Methodology: Systems, algorithms, and protocols audited; tools and standards used (e.g., NIST SP 800-57).

    3. Detailed Findings: For each issue: Vulnerability Description, Affected Component, Evidence (screenshots/code), Risk Rating (CVSS score), Impact Analysis.

    4. Remediation Recommendations: Specific, actionable steps (e.g., "Upgrade to TLS 1.3," "Increase RSA key size to 3072 bits").

    5. Conclusion & Overall Risk Posture.

  • Stakeholder Engagement for Implementation:

    • Management: Approves budget for new hardware/software (HSMs, newer cipher suites).

    • Developops/Engineers: Implement changes (code updates, config changes).

    • Legal/Compliance: Ensures new crypto meets regulatory standards (e.g., FIPS 140-2).

    • End-Users: Trained on new procedures (e.g., certificate warnings, key management). Failure to engage any group leads to failed implementation or workarounds that weaken security.


IV. Digital Forensics and Multimedia Analysis

A. Evidence Handling and Extraction

  • Process (Acquisition-Focused):

    1. Identification: Recognize potential evidence source (device, file, network log).

    2. Preservation: Isolate device (airplane mode for mobile), create forensic image (bit-by-bit copy) using write-blockers. Hash (SHA-256) original and image to verify integrity.

    3. Acquisition: Use tools like FTK Imager, EnCase, Cellebrite UFED (mobile) to extract data from the image.

    4. Analysis: Examine file systems, logs, unallocated space, metadata using tools like Autopsy, Wireshark, ExifTool.

    5. Presentation: Document chain of custody, tools/versions, hash values, and findings in a report.

  • Tools: Mobile: Cellebrite, Magnet AXIOM, Oxygen Forensic. General: Autopsy (Sleuth Kit), Wireshark, Volatility (memory analysis).

B. Authentication and Integrity

  • Multimedia Authentication Mechanisms:

    • Digital Watermarking: Embedding imperceptible data (owner ID, hash) for ownership proof and tamper detection.

    • Digital Signatures: Using PKI to sign the file's hash. Provides source authentication and integrity (any change invalidates signature).

    • Fragile Watermarks: Designed to break upon modification, indicating tampering.

  • Audio Recording Authentication in Legal Context:

    1. Chain of Custody: Document every person who handled the recording.

    2. Metadata Analysis: Check creation/modification timestamps, device ID (EXIF for audio), software used.

    3. Spectrogram & Waveform Analysis: Look for edits, splicing, noise inconsistencies.

    4. Source Device Identification: Analyze acoustic signatures (background noise, frequency response) of the recording device.

    5. Hash Verification: Ensure the presented file matches the originally seized hash.

C. Specific Media and Device Forensics

  • Printer and Scanner Forensics:

    • Risks: Document forgery, anonymous threat letters, counterfeit materials.

    • Forensic Techniques:

      • Printer Tracking Dots: Many color laser printers embed microscopic yellow dots encoding serial number, date, time. Visible under magnification/blue light.

      • Scanner Artifacts: Analyze sensor noise patterns, dust/scratches on glass plate, interpolation artifacts.

      • Device Calibration Data: Unique patterns left on printed/scanned pages.

    • Case Study: In a threat letter investigation, forensic analysis of printer dots on the letter linked it to a specific printer in a suspect's office, corroborating other evidence.

D. Watermarking Strategies

  • Visible vs. Invisible Watermark Decision Factors:

    | Scenario | Recommended Type | Key Reasoning Factors | |---------------------------------------|----------------------|-------------------------------------------------------------------------------------------| | Professional Portfolio Website | Visible | Branding/Deterrence. Clearly marks ownership, discourages direct theft. Can be placed unobtrusively (corner, semi-transparent). | | Stock Photography Platform | Invisible | Sales & User Experience. Must not degrade image quality for paying customers. Invisible watermark (robust) proves ownership if stolen. | | Client Preview Image Distribution| Visible (Low-Res)| Prevent Misuse & Promote Brand. Low-resolution with visible watermark ensures preview is not usable commercially, while promoting the photographer's brand. |

E. Multimedia Compression and Standards

  • Discrete Cosine Transform (DCT) in Compression:

    • Process: Converts spatial pixel data (image block, e.g., 8x8) into frequency domain. Low-frequency components (smooth areas) are kept; high-frequency (edges, noise) are quantized aggressively.

    • Why Lossy? The Quantization step discards less important frequency data irreversibly. This is the primary source of compression artifacts (blocking, blurring) and data loss. Standards: JPEG (image), MPEG (video), MP3/AAC (audio) all use DCT variants.

F. Applications and Industry Trends

  • Virtual Reality (VR) as Multimedia Application: Immersive, interactive 3D environment. Requires high bandwidth, low latency for real-time rendering of stereoscopic video/audio. Security concerns: user motion tracking data privacy, virtual asset theft, malicious content injection.

  • Interdisciplinary Industry Mergers: Convergence of telecom (5G), media/entertainment (streaming), IT (cloud), and semiconductor (AI chips). Example: Apple (hardware, OS, content store, streaming service), Netflix (content + CDN + recommendation AI).

G. Foundational Concepts

  • Need for Computer/Mobile Forensics: To provide scientifically sound, legally admissible evidence from digital devices. Essential for cybercrime investigation (hacking, fraud), civil litigation (e-discovery), internal policy violation probes, and incident response.

  • Protocols in Security & Forensics Context:

    • Security: TLS/SSL (confidentiality/integrity in transit), IPsec (network layer security), SSH (secure remote admin).

    • Forensics: NTP (timestamp synchronization for timeline accuracy), Syslog (centralized logging), HTTP/HTTPS (web artifact analysis), SMB/FTP (file transfer analysis). Understanding protocol headers is key for packet analysis (Wireshark).


V. System, Network, and Cloud Security

A. Network Security Fundamentals

  • DNS Reconnaissance (Revisited): A network security reconnaissance activity. Exploiting DNS can lead to zone transfers, subdomain takeover (pointing to unclaimed cloud resources), and information leakage (internal IPs in TXT records).

  • Protocols Role: Secure protocols (TLS, SSH, IPsec) provide confidentiality, integrity, authentication. Insecure/legacy protocols (FTP, Telnet, SNMPv1) are common attack vectors. Forensically, protocol analysis reveals attack patterns (e.g., repeated failed SSH logins).

B. Operating System and Resource Management

  • OS Layers for Hardware Management (Example: Modern OS like Linux/Windows):

    1. Hardware: CPU, Memory, I/O Devices.

    2. Kernel: Core OS, direct hardware interaction, process/memory management.

    3. System Libraries/APIs: Provide standardized interfaces (e.g., POSIX, Win32 API) to applications.

    4. Shell/User Interface: CLI (bash, PowerShell) or GUI.

    • Efficiency: Abstraction layers allow hardware independence for apps and centralized, secure resource control by the kernel.
  • Quality of Service (QoS) in Multimedia Delivery:

    • Resource Management Types:

      • Bandwidth Management: Traffic shaping, priority queues (VoIP > file download).

      • Latency Management: Buffering, jitter buffers, using UDP with FEC for real-time.

      • CPU/Memory Management: Scheduling algorithms favoring real-time threads, efficient codec resource use.

    • Factors Affecting QoS:

      1. Network: Bandwidth, latency, jitter, packet loss.

      2. Server/Client: Processing power, memory, codec efficiency.

      3. Application: Stream bitrate, resolution, adaptive bitrate algorithms (HLS, DASH).

C. Cloud Security Considerations

  • In Penetration Testing Context:

    • Shared Responsibility Model: Pentester must understand what the cloud provider secures (hypervisor, physical) vs. what the client secures (OS, app, data, config).

    • Unique Attack Surfaces: Misconfigured S3 buckets, exposed serverless functions, compromised cloud credentials, insecure APIs.

    • Tools: Cloud-specific scanners (Prowler for AWS, ScoutSuite), cloud-native exploitation (abusing IAM roles, metadata service).

  • In Forensics Context:

    • Challenges: Multi-tenancy (data isolation), volatility (ephemeral instances), geographic dispersion (jurisdiction), limited access to physical/logs (depends on CSP cooperation).

    • Process: Rely heavily on CSP-provided logs (CloudTrail, Azure Activity Log), memory snapshots of VMs, and object storage versioning. Legal agreements (SLAs, contracts) are critical for evidence acquisition.


VI. Applied Case Studies and Scenarios

Penetration Test Objectives for rgpvonline.com (Hypothetical Case)

  1. Identify OWASP Top 10 Vulnerabilities: Specifically test for SQL Injection, XSS, Broken Access Control in student portal, result portal, and admin panels.

  2. Information Disclosure: Check for sensitive data in source code (API keys, internal IPs), directory listing, backup files (.bak, .git).

  3. Authentication & Session Flaws: Test for credential stuffing, session fixation, weak password policies, logout functionality.

  4. Server & Configuration Security: Scan for outdated server software (Apache, PHP), default credentials, misconfigured CORS, security headers (missing HSTS).

  5. Business Logic Flaws: Test enrollment/result manipulation (e.g., changing student ID parameters), price/fee alteration if e-commerce exists.

  6. Objective: Provide a risk-based report enabling RGPV to secure student PII, academic records, and financial data, and ensure service availability.

Integration of Security Testing and Forensics

  • Organizational Context: Red Team (offensive pentest) simulates attacks to find flaws. Blue Team (defense) uses forensic readiness (logging, monitoring) to detect, respond, and investigate. Purple Team collaboration ensures findings from pentests inform forensic detection rules (e.g., create SIEM rule for a newly discovered exploit pattern).

  • Cycle: Pentest finds vulnerability → Patch deployed → Forensic team validates patch by checking for related IOCs (Indicators of Compromise) in historical logs → Update detection capabilities.

Real-World Scenario Analysis (Watermarking)

  • Professional Portfolio: Visible watermark (semi-transparent logo/name). Reason: Branding and deterrence. Clients should easily see who created the work. Aesthetics are secondary to protection.

  • Stock Photography Platform: Invisible, robust watermark. Reason: Commercial usability. Visible watermark would make the image unsellable. Invisible watermark survives compression/cropping, proving ownership if stolen.

  • Client Preview Images: Visible watermark on low-resolution version. Reason: Prevents misuse while showcasing quality. Low-res is useless for print/merchandise. Visible watermark clearly marks "preview only," encouraging client to purchase high-res, clean version.

[!TIP] Final Exam Strategy: For 7m questions, structure answers as: 1) Clear Definition/Explanation, 2) 3-4 Key Points with Examples, 3) Importance/Impact, 4) (If applicable) Tools/Methodologies. Always relate back to mobile/forensics context where possible. For "decide" questions (watermarking), use a decision matrix as shown.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in