Skip to content
CY-702 (C) · Mobile Security and Forensics/Quick Revision Short Notes

Mobile Security and Forensics (CY-702 (C)) - Unit 4 Short Notes

UNIT 4: Advanced Mobile Security and Forensics


1.0 Mobile Penetration Testing and Vulnerability Analysis

1.1 Legal and Ethical Considerations

Impact on Organizational Decision-Making:

  • Legal Frameworks (GDPR, HIPAA, CFAA): Define boundaries, mandate breach disclosure, impose fines → influence scope, budget, and necessity of testing.

  • Ethical Frameworks (OSSTMM, PTES): Guide methodology, ensure minimal disruption, define "rules of engagement."

  • Decision Trade-offs: Risk of non-compliance vs. cost/legal risk of unauthorized testing. Written authorization is non-negotiable.

[!TIP] Exam Focus: Contrast legal (mandatory, punitive) vs. ethical (professional conduct) drivers. Always cite "authorization" as the primary legal safeguard.

1.2 Reconnaissance and Information Gathering

DNS Reconnaissance:

  • Purpose: Map attack surface by discovering subdomains, DNS records (A, MX, TXT), and infrastructure.

  • Importance of External Presence Analysis: Identifies publicly reachable assets (web servers, mail servers, APIs) before internal testing. Prevents wasted effort on non-existent or internal-only targets.

  • Tools: Sublist3r, DNSrecon, dig, nslookup.

  • Mobile-Specific: Analyze app store listings for backend domains, decompile APKs for hardcoded URLs/API endpoints.

Understanding Target Architecture:

  • Critical to identify: OS (iOS/Android), app framework (React Native, Flutter), backend tech stack, third-party libraries.

  • Informs exploit selection (e.g., Android component exposure vs. iOS jailbreak-specific bugs).

1.3 Vulnerability Assessment and Scanning

Tool Category Examples Mobile Application Focus
General Network Nessus, OpenVAS Wi-Fi, mobile carrier infrastructure
Web App OWASP ZAP, Burp Suite Mobile backend APIs, web views in apps
Mobile-Specific MobSF (Mobile Security Framework), QARK, Drozer Static (APK/IPA analysis) & dynamic analysis
Wireless Aircrack-ng, Kismet Wi-Fi network encryption, rogue AP detection

Methodology: Automated scan → manual verification → false positive filtering → risk rating (CVSS).

1.4 Exploitation Techniques

  • Web App Vulns in Mobile: Mobile apps often use webviews or call APIs. SQL Injection in a backend API can compromise all app users. HSTS is crucial to prevent SSL-stripping attacks on mobile web views.

  • Mobile App Exploitation:

    • Android: Intent exploitation, insecure storage (logcat, SharedPreferences), WebView JavaScript injection.

    • iOS: Jailbreak detection bypass, keychain access, URL scheme hijacking.

  • Wireless Exploitation: Packet Sniffing (Wireshark, tcpdump) captures unencrypted traffic, credentials, and session tokens from mobile devices on Wi-Fi.

1.5 Social Engineering and Human Factors

  • Tactics: Evil twin Wi-Fi hotspots, phishing SMS/MMS (SMiShing), malicious app store listings, USB drop attacks.

  • Employee Training: Simulated phishing campaigns, security awareness on public Wi-Fi risks, app installation policies. Creates a human firewall, reducing success rate of targeted attacks.

1.6 Cryptography and Secure Communication

RSA Algorithm for Secure Communication:

  1. Key Gen: Choose primes p, q; compute n = p*q, φ(n) = (p-1)(q-1); choose e (public), compute d (private) such that e*d ≡ 1 mod φ(n).

  2. Encryption: C = M^e mod n (using recipient's public key).

  3. Decryption: M = C^d mod n (using private key).

  4. Mobile Use: Securely exchange symmetric session keys in TLS handshake.

HTTP Strict Transport Security (HSTS):

  • Server sends Strict-Transport-Security: max-age=... header.

  • Forces browser/app to only use HTTPS for that domain, preventing protocol downgrade attacks.

  • Critical for mobile where users frequently connect to public Wi-Fi.

Decryption Challenges: Modern crypto (AES-256, TLS 1.3) is computationally infeasible to break. Pen-testing focuses on:

  • Weak key management (hardcoded keys in app).

  • Implementation flaws (incorrect IV, ECB mode).

  • Side-channel attacks (timing, power analysis).

1.7 Cloud Security in Mobile Environments

  • Considerations:

    • Data Segregation: Multi-tenancy risks in mobile cloud backends.

    • API Security: Mobile apps are API clients → API keys must be protected, enforce rate limiting.

    • Data in Transit/At Rest: End-to-end encryption, secure cloud storage configurations (S3 buckets).

    • Authentication: OAuth 2.0/OpenID Connect misconfigurations.

1.8 Reporting and Stakeholder Engagement

Penetration Test Report Elements:

  1. Executive Summary: Business risk overview.

  2. Scope & Methodology: Rules of engagement, tools used.

  3. Findings: Vulnerability, proof-of-concept, CVSS score, impact.

  4. Remediation: Specific, prioritized steps.

  5. Conclusion: Overall security posture.

Cryptography Audit Report Elements: Algorithm used, key length, implementation review, protocol compliance (TLS version, cipher suites).

Stakeholder Engagement:

  • Translate technical findings into business impact (e.g., "SQLi → customer PII breach → GDPR fines").

  • Collaborative remediation planning with dev/ops teams.

  • Regular updates to maintain buy-in for security initiatives.

1.9 Capture The Flag (CTF) Competitions

  • Simulation: Time-bound, scenario-based challenges (e.g., "exploit this APK to get flag").

  • Skill Development: Hands-on practice with real tools/techniques (reverse engineering, web hacking, forensics) in a legal environment.

  • Value: Identifies skill gaps, builds practical experience complementary to theoretical knowledge.


2.0 Mobile Multimedia Forensics and Security

2.1 Foundations of Multimedia Security and Forensics

  • Need for Forensics: Mobile devices generate vast multimedia (photos, video, audio). Critical for:

    • Legal evidence (cybercrime, fraud).

    • Incident response (data breach source tracing).

    • Authenticity verification (deepfakes, manipulated media).

  • Active vs. Passive Attacks:

    • Active: Modify content (tampering, steganography insertion).

    • Passive: Eavesdrop/analyze (traffic analysis, metadata extraction).

  • Interdisciplinary Vendors: Mergers of hardware (camera), software (Adobe), telecom (Verizon) to create end-to-end multimedia ecosystems.

  • Virtual Reality (VR): Mobile VR/AR apps create new forensic artifacts (motion data, 3D model logs, spatial audio recordings).

2.2 Compression, Transmission, and Quality Management

Discrete Cosine Transform (DCT):

  • Use: Core of JPEG, MPEG, MP3. Converts spatial (image) or temporal (video) data into frequency coefficients.

  • Lossy Nature: Human vision/audition is less sensitive to high-frequency components. Quantization discards these coefficients → irreversible data loss.

$$F(u,v) = \frac{1}{4}C(u)C(v)\sum_{x=0}^{7}\sum_{y=0}^{7}f(x,y)\cos\left(\frac{(2x+1)u\pi}{16}\right)\cos\left(\frac{(2y+1)v\pi}{16}\right)$$

where $$\displaystyle C(k)=1/\sqrt{2} $$ for $$\displaystyle k=0 $$, else 1.

Factors Affecting QoS in Mobile Multimedia:

Factor Impact on Mobile Delivery
Bandwidth Limited cellular data, network congestion
Latency Delay in real-time apps (video calls, gaming)
Jitter Variable packet delay → video/audio glitches
Packet Loss Corrupted frames, audio dropouts
Device Resources CPU/GPU for decoding, battery drain

Resource Management: OS scheduler prioritizes multimedia threads, allocates buffers, manages power states (e.g., Android's MediaCodec).

OS Layers for Hardware Management:

  • Hardware Abstraction Layer (HAL): Standardized interface for drivers.

  • Kernel: Manages memory, CPU scheduling, device drivers.

  • Framework: Provides APIs (e.g., Android MediaPlayer, iOS AVFoundation).

2.3 Authentication and Integrity Mechanisms

Multimedia Authentication: Verify content origin and integrity (not modified since creation).

  • Mechanisms:

    • Digital Signatures: Hash content → sign with private key (RSA/ECDSA). Verifiable with public key.

    • Watermarking: Embed imperceptible data.

      • Visible: Overlay logo/text. Use: Copyright notice, professional portfolio (deters theft, asserts ownership).

      • Invisible: Embed in frequency domain (DCT coefficients). Use: Stock photography (track sales, prove ownership without deterring buyers), client previews (low-res with invisible watermark to trace leaks).

[!TIP] Exam Scenario: Professional Portfolio → Visible watermark (branding, deterrence). Stock Photography → Invisible (buyer sees clean image, you can prove source). Client Previews → Visible low-res (prevents use) OR invisible (if you trust client but want traceability).

2.4 Digital Evidence Extraction and Protocols

Process (A-C-A-I Model):

  1. Acquisition: Secure, forensically sound copy. Tools: Cellebrite UFED, Magnet AXIOM, FTK Imager. Use physical/data extraction (ADB backup, iTunes backup, JTAG).

  2. Preservation: Hash verification (SHA-256), write-blockers, chain of custody.

  3. Analysis: Carve files, parse databases (/data/data/), recover deleted data.

  4. Interpretation: Timeline reconstruction, artifact correlation.

Protocols in Investigations:

  • Network: TCP/IP, HTTP/HTTPS, MMS, SIP (VoIP).

  • Device: USB, ADB (Android), AFC (iOS).

  • Cloud: API calls to Google Drive, iCloud, WhatsApp servers (with legal request).

2.5 Metadata Analysis

Significance:

  • Authentication: EXIF data (camera model, timestamp) can prove origin or reveal manipulation (inconsistent timestamps).

  • Timeline Analysis: Create event chronology from file creation/modification times, GPS logs.

  • Source Identification: Device serial number in EXIF, software fingerprints, compression artifacts.

Mobile-Specific Metadata:

  • Images: EXIF (GPS, camera settings), XMP (editing history).

  • Audio: ID3 tags, recording app metadata.

  • Video: QuickTime metadata, container format headers.

  • Challenges: Apps may strip metadata (WhatsApp, Instagram) → need to analyze file system or app databases.

2.6 Audio/Video Forensics and Content Analysis

Audio Recording Validation (Legal Context):

  1. Authenticity Check: Spectrogram analysis for edits (frequency discontinuities), background noise consistency.

  2. Source Identification: Voice stress analysis, acoustic environment matching.

  3. Tamper Detection: Digital signal processing to find gaps, splicing (using cross-correlation).

  4. Legal Standards: Must meet Daubert or Frye standards for scientific reliability.

Multimedia Content Forensics Techniques:

  • Photo: Error Level Analysis (ELA) for compression artifacts, clone detection, lighting consistency.

  • Video: Frame interpolation analysis, motion vector consistency.

  • Deepfake Detection: Neural network artifacts, blinking patterns, head pose inconsistencies.

2.7 Case Studies and Applied Forensics

Printer/Scanner Forensics:

  • Role: Identify source printer/scanner from document artifacts.

    • Printer: Mechanical tolerances create unique banding/noise patterns (Printer Steganography). Tracking codes (e.g., HP, Canon) embed serial numbers in yellow dots.

    • Scanner: CCD sensor noise pattern (Photo Response Non-Uniformity - PRNU) acts as a "fingerprint."

  • Mobile Printing Scenarios: Investigate if a leaked document was printed from a mobile device via cloud print service (Google Cloud Print logs).

  • Case Illustration: United States v. Boucher (2009): Used PRNU to link a scanned image to a specific scanner, placing suspect at crime scene.

Legal/Procedural Considerations:

  • Chain of Custody: Document every handler, time, location.

  • Search Warrants: Specific to device/data; cannot broadly seize all cloud data.

  • Authentication in Court: Expert testimony on methodology (ISO/IEC 27037 guidelines).

  • Jurisdiction: Cloud data may reside in different legal jurisdictions.


\boxed{\text{Key Exam Themes: Legal/Ethics, DNS Recon, HSTS, SQLi, RSA, Reporting, DCT, Watermarking Scenarios, Metadata, Audio Validation}}

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in