UNIT 4: Advanced Mobile Security and Forensics
1.0 Mobile Penetration Testing and Vulnerability Analysis
1.1 Legal and Ethical Considerations
Impact on Organizational Decision-Making:
-
Legal Frameworks (GDPR, HIPAA, CFAA): Define boundaries, mandate breach disclosure, impose fines → influence scope, budget, and necessity of testing.
-
Ethical Frameworks (OSSTMM, PTES): Guide methodology, ensure minimal disruption, define "rules of engagement."
-
Decision Trade-offs: Risk of non-compliance vs. cost/legal risk of unauthorized testing. Written authorization is non-negotiable.
[!TIP] Exam Focus: Contrast legal (mandatory, punitive) vs. ethical (professional conduct) drivers. Always cite "authorization" as the primary legal safeguard.
1.2 Reconnaissance and Information Gathering
DNS Reconnaissance:
-
Purpose: Map attack surface by discovering subdomains, DNS records (A, MX, TXT), and infrastructure.
-
Importance of External Presence Analysis: Identifies publicly reachable assets (web servers, mail servers, APIs) before internal testing. Prevents wasted effort on non-existent or internal-only targets.
-
Tools:
Sublist3r,DNSrecon,dig,nslookup. -
Mobile-Specific: Analyze app store listings for backend domains, decompile APKs for hardcoded URLs/API endpoints.
Understanding Target Architecture:
-
Critical to identify: OS (iOS/Android), app framework (React Native, Flutter), backend tech stack, third-party libraries.
-
Informs exploit selection (e.g., Android component exposure vs. iOS jailbreak-specific bugs).
1.3 Vulnerability Assessment and Scanning
| Tool Category | Examples | Mobile Application Focus |
|---|---|---|
| General Network | Nessus, OpenVAS | Wi-Fi, mobile carrier infrastructure |
| Web App | OWASP ZAP, Burp Suite | Mobile backend APIs, web views in apps |
| Mobile-Specific | MobSF (Mobile Security Framework), QARK, Drozer | Static (APK/IPA analysis) & dynamic analysis |
| Wireless | Aircrack-ng, Kismet | Wi-Fi network encryption, rogue AP detection |
Methodology: Automated scan → manual verification → false positive filtering → risk rating (CVSS).
1.4 Exploitation Techniques
-
Web App Vulns in Mobile: Mobile apps often use webviews or call APIs. SQL Injection in a backend API can compromise all app users. HSTS is crucial to prevent SSL-stripping attacks on mobile web views.
-
Mobile App Exploitation:
-
Android: Intent exploitation, insecure storage (logcat, SharedPreferences), WebView JavaScript injection.
-
iOS: Jailbreak detection bypass, keychain access, URL scheme hijacking.
-
-
Wireless Exploitation: Packet Sniffing (Wireshark, tcpdump) captures unencrypted traffic, credentials, and session tokens from mobile devices on Wi-Fi.
1.5 Social Engineering and Human Factors
-
Tactics: Evil twin Wi-Fi hotspots, phishing SMS/MMS (SMiShing), malicious app store listings, USB drop attacks.
-
Employee Training: Simulated phishing campaigns, security awareness on public Wi-Fi risks, app installation policies. Creates a human firewall, reducing success rate of targeted attacks.
1.6 Cryptography and Secure Communication
RSA Algorithm for Secure Communication:
-
Key Gen: Choose primes
p,q; computen = p*q,φ(n) = (p-1)(q-1); choosee(public), computed(private) such thate*d ≡ 1 mod φ(n). -
Encryption:
C = M^e mod n(using recipient's public key). -
Decryption:
M = C^d mod n(using private key). -
Mobile Use: Securely exchange symmetric session keys in TLS handshake.
HTTP Strict Transport Security (HSTS):
-
Server sends
Strict-Transport-Security: max-age=...header. -
Forces browser/app to only use HTTPS for that domain, preventing protocol downgrade attacks.
-
Critical for mobile where users frequently connect to public Wi-Fi.
Decryption Challenges: Modern crypto (AES-256, TLS 1.3) is computationally infeasible to break. Pen-testing focuses on:
-
Weak key management (hardcoded keys in app).
-
Implementation flaws (incorrect IV, ECB mode).
-
Side-channel attacks (timing, power analysis).
1.7 Cloud Security in Mobile Environments
-
Considerations:
-
Data Segregation: Multi-tenancy risks in mobile cloud backends.
-
API Security: Mobile apps are API clients → API keys must be protected, enforce rate limiting.
-
Data in Transit/At Rest: End-to-end encryption, secure cloud storage configurations (S3 buckets).
-
Authentication: OAuth 2.0/OpenID Connect misconfigurations.
-
1.8 Reporting and Stakeholder Engagement
Penetration Test Report Elements:
-
Executive Summary: Business risk overview.
-
Scope & Methodology: Rules of engagement, tools used.
-
Findings: Vulnerability, proof-of-concept, CVSS score, impact.
-
Remediation: Specific, prioritized steps.
-
Conclusion: Overall security posture.
Cryptography Audit Report Elements: Algorithm used, key length, implementation review, protocol compliance (TLS version, cipher suites).
Stakeholder Engagement:
-
Translate technical findings into business impact (e.g., "SQLi → customer PII breach → GDPR fines").
-
Collaborative remediation planning with dev/ops teams.
-
Regular updates to maintain buy-in for security initiatives.
1.9 Capture The Flag (CTF) Competitions
-
Simulation: Time-bound, scenario-based challenges (e.g., "exploit this APK to get flag").
-
Skill Development: Hands-on practice with real tools/techniques (reverse engineering, web hacking, forensics) in a legal environment.
-
Value: Identifies skill gaps, builds practical experience complementary to theoretical knowledge.
2.0 Mobile Multimedia Forensics and Security
2.1 Foundations of Multimedia Security and Forensics
-
Need for Forensics: Mobile devices generate vast multimedia (photos, video, audio). Critical for:
-
Legal evidence (cybercrime, fraud).
-
Incident response (data breach source tracing).
-
Authenticity verification (deepfakes, manipulated media).
-
-
Active vs. Passive Attacks:
-
Active: Modify content (tampering, steganography insertion).
-
Passive: Eavesdrop/analyze (traffic analysis, metadata extraction).
-
-
Interdisciplinary Vendors: Mergers of hardware (camera), software (Adobe), telecom (Verizon) to create end-to-end multimedia ecosystems.
-
Virtual Reality (VR): Mobile VR/AR apps create new forensic artifacts (motion data, 3D model logs, spatial audio recordings).
2.2 Compression, Transmission, and Quality Management
Discrete Cosine Transform (DCT):
-
Use: Core of JPEG, MPEG, MP3. Converts spatial (image) or temporal (video) data into frequency coefficients.
-
Lossy Nature: Human vision/audition is less sensitive to high-frequency components. Quantization discards these coefficients → irreversible data loss.
$$F(u,v) = \frac{1}{4}C(u)C(v)\sum_{x=0}^{7}\sum_{y=0}^{7}f(x,y)\cos\left(\frac{(2x+1)u\pi}{16}\right)\cos\left(\frac{(2y+1)v\pi}{16}\right)$$
where $$\displaystyle C(k)=1/\sqrt{2} $$ for $$\displaystyle k=0 $$, else 1.
Factors Affecting QoS in Mobile Multimedia:
| Factor | Impact on Mobile Delivery |
|---|---|
| Bandwidth | Limited cellular data, network congestion |
| Latency | Delay in real-time apps (video calls, gaming) |
| Jitter | Variable packet delay → video/audio glitches |
| Packet Loss | Corrupted frames, audio dropouts |
| Device Resources | CPU/GPU for decoding, battery drain |
Resource Management: OS scheduler prioritizes multimedia threads, allocates buffers, manages power states (e.g., Android's MediaCodec).
OS Layers for Hardware Management:
-
Hardware Abstraction Layer (HAL): Standardized interface for drivers.
-
Kernel: Manages memory, CPU scheduling, device drivers.
-
Framework: Provides APIs (e.g., Android
MediaPlayer, iOSAVFoundation).
2.3 Authentication and Integrity Mechanisms
Multimedia Authentication: Verify content origin and integrity (not modified since creation).
-
Mechanisms:
-
Digital Signatures: Hash content → sign with private key (RSA/ECDSA). Verifiable with public key.
-
Watermarking: Embed imperceptible data.
-
Visible: Overlay logo/text. Use: Copyright notice, professional portfolio (deters theft, asserts ownership).
-
Invisible: Embed in frequency domain (DCT coefficients). Use: Stock photography (track sales, prove ownership without deterring buyers), client previews (low-res with invisible watermark to trace leaks).
-
-
[!TIP] Exam Scenario: Professional Portfolio → Visible watermark (branding, deterrence). Stock Photography → Invisible (buyer sees clean image, you can prove source). Client Previews → Visible low-res (prevents use) OR invisible (if you trust client but want traceability).
2.4 Digital Evidence Extraction and Protocols
Process (A-C-A-I Model):
-
Acquisition: Secure, forensically sound copy. Tools: Cellebrite UFED, Magnet AXIOM, FTK Imager. Use physical/data extraction (ADB backup, iTunes backup, JTAG).
-
Preservation: Hash verification (SHA-256), write-blockers, chain of custody.
-
Analysis: Carve files, parse databases (
/data/data/), recover deleted data. -
Interpretation: Timeline reconstruction, artifact correlation.
Protocols in Investigations:
-
Network: TCP/IP, HTTP/HTTPS, MMS, SIP (VoIP).
-
Device: USB, ADB (Android), AFC (iOS).
-
Cloud: API calls to Google Drive, iCloud, WhatsApp servers (with legal request).
2.5 Metadata Analysis
Significance:
-
Authentication: EXIF data (camera model, timestamp) can prove origin or reveal manipulation (inconsistent timestamps).
-
Timeline Analysis: Create event chronology from file creation/modification times, GPS logs.
-
Source Identification: Device serial number in EXIF, software fingerprints, compression artifacts.
Mobile-Specific Metadata:
-
Images: EXIF (GPS, camera settings), XMP (editing history).
-
Audio: ID3 tags, recording app metadata.
-
Video: QuickTime metadata, container format headers.
-
Challenges: Apps may strip metadata (WhatsApp, Instagram) → need to analyze file system or app databases.
2.6 Audio/Video Forensics and Content Analysis
Audio Recording Validation (Legal Context):
-
Authenticity Check: Spectrogram analysis for edits (frequency discontinuities), background noise consistency.
-
Source Identification: Voice stress analysis, acoustic environment matching.
-
Tamper Detection: Digital signal processing to find gaps, splicing (using cross-correlation).
-
Legal Standards: Must meet Daubert or Frye standards for scientific reliability.
Multimedia Content Forensics Techniques:
-
Photo: Error Level Analysis (ELA) for compression artifacts, clone detection, lighting consistency.
-
Video: Frame interpolation analysis, motion vector consistency.
-
Deepfake Detection: Neural network artifacts, blinking patterns, head pose inconsistencies.
2.7 Case Studies and Applied Forensics
Printer/Scanner Forensics:
-
Role: Identify source printer/scanner from document artifacts.
-
Printer: Mechanical tolerances create unique banding/noise patterns (Printer Steganography). Tracking codes (e.g., HP, Canon) embed serial numbers in yellow dots.
-
Scanner: CCD sensor noise pattern (Photo Response Non-Uniformity - PRNU) acts as a "fingerprint."
-
-
Mobile Printing Scenarios: Investigate if a leaked document was printed from a mobile device via cloud print service (Google Cloud Print logs).
-
Case Illustration: United States v. Boucher (2009): Used PRNU to link a scanned image to a specific scanner, placing suspect at crime scene.
Legal/Procedural Considerations:
-
Chain of Custody: Document every handler, time, location.
-
Search Warrants: Specific to device/data; cannot broadly seize all cloud data.
-
Authentication in Court: Expert testimony on methodology (ISO/IEC 27037 guidelines).
-
Jurisdiction: Cloud data may reside in different legal jurisdictions.
\boxed{\text{Key Exam Themes: Legal/Ethics, DNS Recon, HSTS, SQLi, RSA, Reporting, DCT, Watermarking Scenarios, Metadata, Audio Validation}}