Skip to content
CY-702 (C) ยท Mobile Security and Forensics/Quick Revision Short Notes

Mobile Security and Forensics (CY-702 (C)) - Unit 5 Short Notes

UNIT 5: Mobile Security and Forensics โ€“ Short Notes


I. Foundations and Legal/Ethical Frameworks

A. Legal and Ethical Considerations

  • Regulatory Compliance: Adherence to data protection laws (GDPR, HIPAA) and mobile-specific regulations governing location data, app permissions, and carrier metadata.

  • Authorization & Scope: Penetration testing requires explicit, written authorization defining systems, methods, and timeframes. "Scope creep" is a major legal risk.

  • Ethical Vulnerability Disclosure: Process for responsibly reporting discovered flaws to vendors (coordinated disclosure) vs. public disclosure. Balances user protection with potential malicious exploitation.

B. Stakeholder Engagement

  • Roles: Legal (compliance), Development (remediation), Management (risk acceptance), End-users (awareness).

  • Communication: Tailor language: Technical details for devs, risk impact (financial/reputational) for management, simple risks for users.

C. Objectives of Security Assessments

  • Mobile App Testing: Identify data leakage, insecure communication, reverse engineering risks.

  • Network Testing: Assess Wi-Fi/cellular vulnerabilities, rogue access points.

  • Cloud Backend Testing: API security, data storage flaws in cloud services integrated with mobile apps.

  • Case Study Example: Testing rgpvonline.com would focus on its mobile web interface and any associated native apps, examining session management, input validation in mobile-specific contexts, and API endpoints.

Exam Tip: Always contextualize generic security objectives (e.g., "confidentiality") to mobile-specific assets (location history, contacts, SMS, device identifiers).


II. Reconnaissance and Information Gathering

A. External Reconnaissance

  • DNS Reconnaissance: Purpose: Map attack surface (subdomains, external services). Tools: dig, nslookup, dnsrecon.

    • Mobile Relevance: Discover backend APIs (api.company.com), admin portals, subdomains hosting mobile app configuration files or SDK endpoints.
  • OSINT for Mobile Ecosystems:

    • App Stores: Analyze app descriptions, versions, permissions, developer info.

    • Public Code Repos (GitHub): Search for exposed API keys, hardcoded credentials in mobile app projects.

    • SDK/Library Analysis: Identify third-party libraries with known vulnerabilities (e.g., outdated analytics SDKs).

B. Target System Architecture Analysis

  • Mobile OS Architecture:

    • Android: Linux Kernel โ†’ HAL โ†’ Runtime (ART) โ†’ Framework (Java APIs) โ†’ Apps. Sandboxing (UID per app) and Permissions model (install-time/runtime).

    • iOS: XNU Kernel (Mach+BSD) โ†’ Core OS โ†’ Frameworks โ†’ Apps. Strict sandboxing and mandatory code signing.

  • Application Architecture: Client-Server model. Focus on API design (REST, GraphQL, MQTT), authentication tokens (OAuth2, JWT), and data serialization (JSON, Protobuf).

  • Network Infrastructure: Cellular (GSM/3G/4G/5G), Wi-Fi (WPA2/WPA3), Bluetooth (BR/EDR, BLE), NFC.

Common Pitfall: Confusing OS layers. Remember: Kernel manages hardware; Framework provides app APIs.


III. Vulnerability Assessment and Penetration Testing Methodologies

A. Mobile Application Penetration Testing

  • OWASP Mobile Top 10 (Key Examples):

    1. M1: Improper Platform Usage: Misusing OS features (e.g., Android intents, iOS keychain).

    2. M2: Insecure Data Storage: Storing sensitive data in plaintext on external storage, logs, or SQLite.

    3. M3: Insecure Communication: Lack of TLS/SSL, weak cipher suites, no certificate pinning.

    4. M4: Insecure Authentication: Weak password policies, lack of 2FA, improper session handling.

  • Static Analysis (SAST): Reverse engineering (APK/IPA decompilation with JADX, Hopper), scanning bytecode/native libraries for vulnerabilities.

  • Dynamic Analysis (DAST/IAST): Runtime manipulation with Frida (JavaScript hooking), Burp Suite (proxy for traffic interception), MobSF (all-in-one scanner).

B. Network and Wireless Penetration Testing

  • Wireless-Specific Testing:

    • Packet Sniffing: Wireshark, Aircrack-ng suite. Capture handshakes for WPA2/WPA3 cracking.

    • Rogue AP/Evil Twin: Create fake access point mimicking legitimate network to intercept credentials or launch MITM.

    • Deauthentication Attacks: Force clients off a network to capture reconnection handshakes.

  • Cellular Network Vulnerabilities: Exploiting SS7/Diameter protocol flaws for location tracking, call/SMS interception (requires specialized equipment/access).

  • Social Engineering (Wireless): Phishing via captive portal, "Free Wi-Fi" baiting, Bluetooth pairing attacks (BlueBorne).

C. Web Application Security for Mobile Backends

  • SQL Injection: Primary risk: Unauthorized access to/ manipulation of backend database. Impact: data theft, deletion, privilege escalation. Mobile context: API endpoints accepting user input without sanitization.

  • HTTP Strict Transport Security (HSTS):

    • Purpose: Forces browsers/apps to use HTTPS only, preventing SSL Stripping attacks.

    • Implementation: Server sends Strict-Transport-Security header. Crucial for mobile apps to ensure all API calls are encrypted.

    • Bypass: First connection must be HTTPS; initial MITM can strip HSTS if first visit is HTTP.

  • Other OWASP Top 10 in API Context: XSS (in webviews), CSRF (state-changing API calls), broken access control (IDOR in mobile API parameters).

D. Vulnerability Scanning Tools and Automation

  • Categories:

    • Network: Nmap (port/service discovery).

    • Web: Nikto, OWASP ZAP, Burp Suite Scanner.

    • Mobile-Specific: MobSF, QARK (Android), iMAS (iOS).

  • Limitations: High false positive rate, inability to find business logic flaws, requires manual verification. Automated scanners are starting points, not final verdicts.

Exam Tip: For "vulnerability scanning tools," list 2-3 per category and state one key limitation for mobile environments (e.g., "MobSF may miss runtime vulnerabilities requiring Frida").


IV. Exploitation and Attack Vectors

A. Mobile OS and Application Exploits

  • Privilege Escalation: Exploiting kernel or system service vulnerabilities to gain root/jailbreak.

  • Sandbox Escape: Abusing inter-process communication (IPC) mechanisms (e.g., Android Binder transactions) to break app isolation.

  • Native Code Exploits: Buffer overflows, ROP chains in C/C++ libraries used by apps (common in games, media codecs).

B. Wireless Network Attacks

  • Packet Injection: Crafting and injecting malicious packets into a network (e.g., deauth packets).

  • WPA2/WPA3 Cracking: Offline dictionary/brute-force attacks on captured 4-way handshake. WPA3's SAE is more resistant.

  • Rogue AP/Captive Portal: Luring users to connect to a fake network that harvests credentials or serves malware.

C. Social Engineering in Mobile Contexts

  • SMiShing: SMS phishing with malicious links or numbers.

  • Malicious Apps: Apps on third-party stores with hidden trojans or excessive permissions.

  • QR Code Attacks: Redirecting to phishing sites or triggering actions on the device.

  • Lifecycle: Reconnaissance (target selection) โ†’ Hook (lure) โ†’ Exploit (payload delivery) โ†’ Execution (action on objective).


V. Cryptography in Mobile Security

A. Cryptographic Principles and Algorithms

  • Symmetric: Same key for encrypt/decrypt (AES, 3DES). Fast, used for bulk data.

  • Asymmetric: Public/private key pair (RSA, ECC). Slow, used for key exchange/signing.

  • Hashing: One-way function (SHA-256, bcrypt). Integrity checking, password storage.

  • Digital Signatures: Hash + asymmetric encryption (RSA-PSS, ECDSA). Authentication & non-repudiation.

B. RSA Algorithm for Secure Communication

Workflow:

  1. Key Generation: Choose large primes p, q. Compute n = p*q, ฯ†(n) = (p-1)(q-1). Choose public exponent e (usually 65537). Compute private exponent d such that e*d โ‰ก 1 mod ฯ†(n).

  2. Encryption (by sender): Ciphertext C = M^e mod n (using recipient's public key (e,n)).

  3. Decryption (by recipient): Message M = C^d mod n (using private key (d,n)).

Key Weakness: Vulnerable to factoring n if p,q are small. Mobile Impact: Often used for key exchange (TLS handshake), not bulk data encryption due to performance.

C. Implementing Secure Communication (TLS/SSL)

  • Certificate Pinning: Hardcode expected server certificate/public key hash in app. Prevents MITM even with compromised CA.

  • HSTS: Forces HTTPS (see Section III.C).

  • End-to-End Encryption (E2EE): Keys held only by endpoints (e.g., Signal Protocol). Server cannot decrypt content.

D. Cryptography Audits & Key Management

  • Audit Checklist:

    • Algorithm strength (no custom crypto, no SHA1/MD5 for signatures).

    • Key length adequacy (AES-256, RSA-2048+).

    • Secure random number generation (SecureRandom in Android, SecRandomCopyBytes in iOS).

    • Key storage: Use hardware-backed keystores (Android Keystore, iOS Keychain with kSecAttrAccessibleWhenPasscodeSetThisDeviceOnly).

  • Common Pitfalls: Hardcoded keys in code, using predictable IVs, improper certificate validation.


VI. Human Factor and Security Awareness

A. Social Engineering Attack Lifecycle (Mobile Focus)

  1. Reconnaissance: Harvest phone numbers, app usage, social media via OSINT.

  2. Hook: SMiShing text, malicious app ad, fake update notification.

  3. Exploit: Trick user into enabling accessibility services, installing profile, or entering credentials.

  4. Execution: Data exfiltration, financial theft, device control.

B. Employee Training Programs

  • Content: Recognizing phishing (SMS/email), secure app download practices, public Wi-Fi risks, reporting procedures.

  • Delivery: Interactive modules, simulated phishing campaigns (mobile-specific: SMS phishing tests, fake app install prompts).

  • Metrics: Click-through rates on simulated attacks, incident reporting rates, post-training quiz scores.


VII. Digital Forensics for Mobile Devices

A. Forensic Process & Evidence Extraction

  • Steps: Identification โ†’ Preservation (forensic image) โ†’ Acquisition (logical/physical) โ†’ Analysis โ†’ Reporting.

  • Tools:

    • Android: ADB (logical), Cellebrite UFED, FTK Imager (physical via bootloader unlock).

    • iOS: iMazing, Cellebrite, libimobiledevice (limited without jailbreak). Physical acquisition often requires jailbreak.

  • Chain of Custody: Document every handler, tool, and action. Ensures legal admissibility.

B. Mobile File Systems & Data Artifacts

OS File System Key Artifact Locations
Android ext4 (legacy), FBE (File-Based Encryption) /data/data/<package>/ (app data), /sdcard/ (external storage), call logs (/data/data/com.android.providers.contacts), SMS (/data/data/com.android.providers.telephony).
iOS APFS with Data Protection /var/mobile/Containers/Data/Application/<UUID>/ (app sandbox), CallHistory.db, sms.db, Photos.sqlite. Data Protection classes (NSFileProtectionComplete) tie decryption to passcode/device state.

C. Metadata Analysis

  • EXIF Data (Photos/Videos): GPS coordinates, timestamp, device model, software version. Critical for geolocation and timeline.

  • App Metadata: SQLite databases (WhatsApp msgstore.db, Telegram telegram-data), shared_prefs (XML), cache files.

  • Cloud Sync Artifacts: com.google.android.apps.docs (Google Drive), com.apple.mobileslideshow (iCloud) sync logs.

  • Deleted Data Recovery: Possible on unencrypted partitions or via file carving on /sdcard/. Encrypted device storage (FBE/Data Protection) severely limits recovery.

D. Authentication of Digital Evidence

  • Audio: Spectral analysis (noise floor consistency), detection of edits (clicks, pops), voice stress analysis (controversial).

  • Image/Video: Error Level Analysis (ELA) to identify areas of different compression (possible manipulation). Copy-Move Detection algorithms to find duplicated regions.

  • Legal Standard: Must demonstrate integrity (unchanged from acquisition) and provenance (clear chain of custody). Tools must be validated (e.g., MD5/SHA-256 hash of original image).


VIII. Multimedia Forensics in Mobile Contexts

A. Multimedia Compression & DCT

  • DCT in JPEG/MPEG: Converts spatial domain (pixels) to frequency domain. Lossy because high-frequency components (fine details) are quantized (rounded off) aggressively.

  • Forensic Impact: Compression creates blocking artifacts (8x8 blocks in JPEG), ringing effects. Can indicate if an image has been re-saved (double compression).

B. Quality of Service (QoS) in Mobile Multimedia

  • Affecting Factors:

    • Network: Bandwidth, latency, jitter, packet loss.

    • Device: CPU/GPU for decoding, memory for buffering, battery drain.

    • Application: Buffer size, adaptive bitrate algorithm (HLS, DASH).

  • Resource Management: Balancing decoding quality with battery life; managing memory to prevent app crashes during high-res video playback.

C. Watermarking Techniques

Type Principle Robustness Mobile Use-Case Reasoning
Visible Overlay logo/text perceptibly. Low. Easily cropped/covered. Professional Portfolio: Use Visible. Aesthetics & branding are secondary to clear ownership assertion. Robustness less critical than visibility.
Invisible Embed data in noise/transform coefficients. High. Survives compression, cropping. Stock Photography: Use Invisible. Must not degrade image salability. Robustness crucial for copyright tracking after distribution.
Fragile Breaks with any modification. Very Low. Detects tampering. Client Previews: Use Fragile/Visible. Low-res distribution; primary goal is to prove origin and detect unauthorized use. Fragile watermark breaks if client tries to remove it.

D. Multimedia Authentication Mechanisms

  • Digital Signatures: Hash of content signed with private key. Verifies integrity and source.

  • Robust Hashing: Perceptual hash (pHash, dHash) that is similar for visually similar images. Detects minor edits.

  • Semi-Fragile Watermarking: Breaks with malicious edits (content change) but survives non-malicious ones (compression, format conversion).

E. Printer/Scanner Forensics (Mobile Context)

  • Device Identification: Printer/Scanner artifacts (banding, dot patterns, sensor noise) are embedded in digital documents (scanned receipts, photos of documents).

  • Case Study: Malicious document leak. Forensic analysis of the digital scan file's metadata and noise pattern can link it to a specific office printer model, which may be registered to a suspect's mobile device (if printed via mobile app) or location.

F. Virtual Reality (VR) & Multimedia Applications

  • Security Challenges: Data Privacy: Biometric data (eye tracking, movement), spatial audio recording. Immersive Attacks: Spoofing virtual objects to cause real-world harm (e.g., virtual obstacle causing physical trip).

  • Forensic Considerations: Spatial data logs (head position, controller clicks), interaction timelines, environment asset hashes. Evidence is multi-dimensional and time-series based.


IX. Cloud Security and Mobile Integration

A. Mobile Cloud Computing (MCC) Risks

  • Data Leakage: Misconfigured cloud storage (S3 buckets) exposing user data synced from mobile apps.

  • Insecure APIs: Lack of authentication/rate limiting on mobile backend APIs.

  • Cloud Sync Forensics: Artifacts in mobile app data (/data/data/com.dropbox.android/) showing sync status, file paths, conflict resolutions. Cloud provider logs (if subpoenaed) show access IPs/times.

B. Secure Mobile-Cloud Architectures

  • Encryption: End-to-end (client-side) encryption before upload. Zero-knowledge cloud providers.

  • Access Controls: Fine-grained IAM policies, device attestation (SafetyNet/DeviceCheck) before granting API access.

  • Auditing: Continuous monitoring of cloud configurations (CSPM tools) for mobile app resources.


X. Reporting and Communication

A. Penetration Testing Reports

  • Structure:

    1. Executive Summary: Business risk, high-level findings.

    2. Methodology: Tools, scope, rules of engagement.

    3. Findings: Each vulnerability with CVSS score, proof-of-concept (screenshots, curl commands), impact, remediation (specific code/config fix).

    4. Conclusion: Overall risk posture.

  • Mobile-Specific: Include app version, OS version, device model in findings. Show intercepted traffic or decompiled code snippets.

B. Forensic Report Documentation

  • Chain of Custody Form: Item, collector, date/time, transfers, storage location.

  • Tool Validation: Document tool version, hash of forensic image (sha256sum image.dd).

  • Analysis Steps: "How" is as important as "what." E.g., "Extracted mmssms.db from /data/data/com.android.providers.telephony/ using ADB backup."

  • Multimedia Evidence: Annotated screenshots, side-by-side comparisons, hash values for original and processed files.

C. Presentation to Stakeholders

  • Technical โ†’ Business Impact: "SQL Injection in user API" โ†’ "Could lead to theft of all customer PII, resulting in GDPR fines (~4% revenue) and reputational damage."

  • Recommendations: Prioritized (Critical/High/Medium/Low), actionable, with estimated effort.


XI. Practical Simulations and Competitions

A. Capture the Flag (CTF) for Mobile Security

  • Simulation: Challenges mimic real tasks:

    • Reverse Engineering: Analyze APK to find hidden flag in code/strings.

    • Forensics: Analyze a provided .dd image to find deleted message.

    • Exploitation: Exploit a vulnerable mobile service (e.g., insecure deserialization).

    • Cryptography: Decrypt captured TLS traffic using extracted keys.

  • Skill Development: Hands-on application of tools (Frida, Ghidra, Wireshark) in a time-bound, competitive environment.

B. Hands-on Lab Design

  • Test Environment: Isolated network with:

    • Mobile device (emulator or physical) with test apps.

    • Vulnerable backend server (e.g., OWASP Juice Shop with mobile API).

    • Rogue Wi-Fi access point (using hostapd/dnsmasq).

    • Traffic capture point (Wireshark on gateway).

  • Scenario: "Compromise the mobile app to extract the admin API token and use it to delete user data from the cloud backend."


XII. Cross-Cutting Themes and Emerging Trends

A. Interdisciplinary Industry Mergers

  • Hardware-Software: Apple (M-series chips + iOS security features like Secure Enclave).

  • Telecom-IT: 5G network slicing + cloud-native apps creates new attack surfaces (slice isolation failures).

  • Impact on Forensics: Requires knowledge of both hardware (baseband processor) and software (OS) for full device analysis.

B. Operating System Layers & Security

  • Attack Surface Influence: Lower layers (kernel, HAL) vulnerabilities (e.g., Dirty Pipe in Linux kernel) affect all Android apps. Higher layers (Framework) vulnerabilities are app-specific.

  • Forensic Access: Physical acquisition often requires exploiting a kernel vulnerability to gain raw disk access. Logical acquisition uses OS-provided backup APIs (limited by sandbox).

C. Active vs. Passive Attacks in Mobile Systems

Active Passive
Malware installation Traffic monitoring (IMSI catcher)
Network injection (MITM) Metadata collection (cell tower pings)
Session hijacking Forensic artifact analysis (log file review)
Changes system state. Only observes/records.

D. Protocols in Mobile Forensics

  • Network Protocols: TCP/IP for internet traffic, GSM/UMTS/LTE for cellular logs (can show cell tower history), Bluetooth for pairing records.

  • Application Protocols: HTTP/2 (common in mobile APIs), MQTT (IoT apps), XMPP (chat apps). Protocol analysis helps reconstruct app activity (e.g., MQTT topic subscriptions indicate app features used).

Final Exam Strategy: For any question, first frame the answer in the mobile context. Use specific examples (Android/iOS, mobile apps, cellular networks). Where asked for "list," provide 3-4 concise items with a brief mobile-specific explanation for each.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in