UNIT 5: Mobile Security and Forensics โ Short Notes
I. Foundations and Legal/Ethical Frameworks
A. Legal and Ethical Considerations
-
Regulatory Compliance: Adherence to data protection laws (GDPR, HIPAA) and mobile-specific regulations governing location data, app permissions, and carrier metadata.
-
Authorization & Scope: Penetration testing requires explicit, written authorization defining systems, methods, and timeframes. "Scope creep" is a major legal risk.
-
Ethical Vulnerability Disclosure: Process for responsibly reporting discovered flaws to vendors (coordinated disclosure) vs. public disclosure. Balances user protection with potential malicious exploitation.
B. Stakeholder Engagement
-
Roles: Legal (compliance), Development (remediation), Management (risk acceptance), End-users (awareness).
-
Communication: Tailor language: Technical details for devs, risk impact (financial/reputational) for management, simple risks for users.
C. Objectives of Security Assessments
-
Mobile App Testing: Identify data leakage, insecure communication, reverse engineering risks.
-
Network Testing: Assess Wi-Fi/cellular vulnerabilities, rogue access points.
-
Cloud Backend Testing: API security, data storage flaws in cloud services integrated with mobile apps.
-
Case Study Example: Testing
rgpvonline.comwould focus on its mobile web interface and any associated native apps, examining session management, input validation in mobile-specific contexts, and API endpoints.
Exam Tip: Always contextualize generic security objectives (e.g., "confidentiality") to mobile-specific assets (location history, contacts, SMS, device identifiers).
II. Reconnaissance and Information Gathering
A. External Reconnaissance
-
DNS Reconnaissance: Purpose: Map attack surface (subdomains, external services). Tools:
dig,nslookup,dnsrecon.- Mobile Relevance: Discover backend APIs (
api.company.com), admin portals, subdomains hosting mobile app configuration files or SDK endpoints.
- Mobile Relevance: Discover backend APIs (
-
OSINT for Mobile Ecosystems:
-
App Stores: Analyze app descriptions, versions, permissions, developer info.
-
Public Code Repos (GitHub): Search for exposed API keys, hardcoded credentials in mobile app projects.
-
SDK/Library Analysis: Identify third-party libraries with known vulnerabilities (e.g., outdated analytics SDKs).
-
B. Target System Architecture Analysis
-
Mobile OS Architecture:
-
Android: Linux Kernel โ HAL โ Runtime (ART) โ Framework (Java APIs) โ Apps. Sandboxing (UID per app) and Permissions model (install-time/runtime).
-
iOS: XNU Kernel (Mach+BSD) โ Core OS โ Frameworks โ Apps. Strict sandboxing and mandatory code signing.
-
-
Application Architecture: Client-Server model. Focus on API design (REST, GraphQL, MQTT), authentication tokens (OAuth2, JWT), and data serialization (JSON, Protobuf).
-
Network Infrastructure: Cellular (GSM/3G/4G/5G), Wi-Fi (WPA2/WPA3), Bluetooth (BR/EDR, BLE), NFC.
Common Pitfall: Confusing OS layers. Remember: Kernel manages hardware; Framework provides app APIs.
III. Vulnerability Assessment and Penetration Testing Methodologies
A. Mobile Application Penetration Testing
-
OWASP Mobile Top 10 (Key Examples):
-
M1: Improper Platform Usage: Misusing OS features (e.g., Android intents, iOS keychain).
-
M2: Insecure Data Storage: Storing sensitive data in plaintext on external storage, logs, or SQLite.
-
M3: Insecure Communication: Lack of TLS/SSL, weak cipher suites, no certificate pinning.
-
M4: Insecure Authentication: Weak password policies, lack of 2FA, improper session handling.
-
-
Static Analysis (SAST): Reverse engineering (APK/IPA decompilation with
JADX,Hopper), scanning bytecode/native libraries for vulnerabilities. -
Dynamic Analysis (DAST/IAST): Runtime manipulation with Frida (JavaScript hooking), Burp Suite (proxy for traffic interception), MobSF (all-in-one scanner).
B. Network and Wireless Penetration Testing
-
Wireless-Specific Testing:
-
Packet Sniffing:
Wireshark,Aircrack-ngsuite. Capture handshakes for WPA2/WPA3 cracking. -
Rogue AP/Evil Twin: Create fake access point mimicking legitimate network to intercept credentials or launch MITM.
-
Deauthentication Attacks: Force clients off a network to capture reconnection handshakes.
-
-
Cellular Network Vulnerabilities: Exploiting SS7/Diameter protocol flaws for location tracking, call/SMS interception (requires specialized equipment/access).
-
Social Engineering (Wireless): Phishing via captive portal, "Free Wi-Fi" baiting, Bluetooth pairing attacks (BlueBorne).
C. Web Application Security for Mobile Backends
-
SQL Injection: Primary risk: Unauthorized access to/ manipulation of backend database. Impact: data theft, deletion, privilege escalation. Mobile context: API endpoints accepting user input without sanitization.
-
HTTP Strict Transport Security (HSTS):
-
Purpose: Forces browsers/apps to use HTTPS only, preventing SSL Stripping attacks.
-
Implementation: Server sends
Strict-Transport-Securityheader. Crucial for mobile apps to ensure all API calls are encrypted. -
Bypass: First connection must be HTTPS; initial MITM can strip HSTS if first visit is HTTP.
-
-
Other OWASP Top 10 in API Context: XSS (in webviews), CSRF (state-changing API calls), broken access control (IDOR in mobile API parameters).
D. Vulnerability Scanning Tools and Automation
-
Categories:
-
Network:
Nmap(port/service discovery). -
Web:
Nikto,OWASP ZAP,Burp Suite Scanner. -
Mobile-Specific:
MobSF,QARK(Android),iMAS(iOS).
-
-
Limitations: High false positive rate, inability to find business logic flaws, requires manual verification. Automated scanners are starting points, not final verdicts.
Exam Tip: For "vulnerability scanning tools," list 2-3 per category and state one key limitation for mobile environments (e.g., "MobSF may miss runtime vulnerabilities requiring Frida").
IV. Exploitation and Attack Vectors
A. Mobile OS and Application Exploits
-
Privilege Escalation: Exploiting kernel or system service vulnerabilities to gain root/jailbreak.
-
Sandbox Escape: Abusing inter-process communication (IPC) mechanisms (e.g., Android Binder transactions) to break app isolation.
-
Native Code Exploits: Buffer overflows, ROP chains in C/C++ libraries used by apps (common in games, media codecs).
B. Wireless Network Attacks
-
Packet Injection: Crafting and injecting malicious packets into a network (e.g., deauth packets).
-
WPA2/WPA3 Cracking: Offline dictionary/brute-force attacks on captured 4-way handshake. WPA3's SAE is more resistant.
-
Rogue AP/Captive Portal: Luring users to connect to a fake network that harvests credentials or serves malware.
C. Social Engineering in Mobile Contexts
-
SMiShing: SMS phishing with malicious links or numbers.
-
Malicious Apps: Apps on third-party stores with hidden trojans or excessive permissions.
-
QR Code Attacks: Redirecting to phishing sites or triggering actions on the device.
-
Lifecycle: Reconnaissance (target selection) โ Hook (lure) โ Exploit (payload delivery) โ Execution (action on objective).
V. Cryptography in Mobile Security
A. Cryptographic Principles and Algorithms
-
Symmetric: Same key for encrypt/decrypt (AES, 3DES). Fast, used for bulk data.
-
Asymmetric: Public/private key pair (RSA, ECC). Slow, used for key exchange/signing.
-
Hashing: One-way function (SHA-256, bcrypt). Integrity checking, password storage.
-
Digital Signatures: Hash + asymmetric encryption (RSA-PSS, ECDSA). Authentication & non-repudiation.
B. RSA Algorithm for Secure Communication
Workflow:
-
Key Generation: Choose large primes
p,q. Computen = p*q,ฯ(n) = (p-1)(q-1). Choose public exponente(usually 65537). Compute private exponentdsuch thate*d โก 1 mod ฯ(n). -
Encryption (by sender): Ciphertext
C = M^e mod n(using recipient's public key(e,n)). -
Decryption (by recipient): Message
M = C^d mod n(using private key(d,n)).
Key Weakness: Vulnerable to factoring
nifp,qare small. Mobile Impact: Often used for key exchange (TLS handshake), not bulk data encryption due to performance.
C. Implementing Secure Communication (TLS/SSL)
-
Certificate Pinning: Hardcode expected server certificate/public key hash in app. Prevents MITM even with compromised CA.
-
HSTS: Forces HTTPS (see Section III.C).
-
End-to-End Encryption (E2EE): Keys held only by endpoints (e.g., Signal Protocol). Server cannot decrypt content.
D. Cryptography Audits & Key Management
-
Audit Checklist:
-
Algorithm strength (no custom crypto, no SHA1/MD5 for signatures).
-
Key length adequacy (AES-256, RSA-2048+).
-
Secure random number generation (
SecureRandomin Android,SecRandomCopyBytesin iOS). -
Key storage: Use hardware-backed keystores (Android Keystore, iOS Keychain with
kSecAttrAccessibleWhenPasscodeSetThisDeviceOnly).
-
-
Common Pitfalls: Hardcoded keys in code, using predictable IVs, improper certificate validation.
VI. Human Factor and Security Awareness
A. Social Engineering Attack Lifecycle (Mobile Focus)
-
Reconnaissance: Harvest phone numbers, app usage, social media via OSINT.
-
Hook: SMiShing text, malicious app ad, fake update notification.
-
Exploit: Trick user into enabling accessibility services, installing profile, or entering credentials.
-
Execution: Data exfiltration, financial theft, device control.
B. Employee Training Programs
-
Content: Recognizing phishing (SMS/email), secure app download practices, public Wi-Fi risks, reporting procedures.
-
Delivery: Interactive modules, simulated phishing campaigns (mobile-specific: SMS phishing tests, fake app install prompts).
-
Metrics: Click-through rates on simulated attacks, incident reporting rates, post-training quiz scores.
VII. Digital Forensics for Mobile Devices
A. Forensic Process & Evidence Extraction
-
Steps: Identification โ Preservation (forensic image) โ Acquisition (logical/physical) โ Analysis โ Reporting.
-
Tools:
-
Android:
ADB(logical),Cellebrite UFED,FTK Imager(physical via bootloader unlock). -
iOS:
iMazing,Cellebrite,libimobiledevice(limited without jailbreak). Physical acquisition often requires jailbreak.
-
-
Chain of Custody: Document every handler, tool, and action. Ensures legal admissibility.
B. Mobile File Systems & Data Artifacts
| OS | File System | Key Artifact Locations |
|---|---|---|
| Android | ext4 (legacy), FBE (File-Based Encryption) | /data/data/<package>/ (app data), /sdcard/ (external storage), call logs (/data/data/com.android.providers.contacts), SMS (/data/data/com.android.providers.telephony). |
| iOS | APFS with Data Protection | /var/mobile/Containers/Data/Application/<UUID>/ (app sandbox), CallHistory.db, sms.db, Photos.sqlite. Data Protection classes (NSFileProtectionComplete) tie decryption to passcode/device state. |
C. Metadata Analysis
-
EXIF Data (Photos/Videos): GPS coordinates, timestamp, device model, software version. Critical for geolocation and timeline.
-
App Metadata: SQLite databases (WhatsApp
msgstore.db, Telegramtelegram-data),shared_prefs(XML), cache files. -
Cloud Sync Artifacts:
com.google.android.apps.docs(Google Drive),com.apple.mobileslideshow(iCloud) sync logs. -
Deleted Data Recovery: Possible on unencrypted partitions or via file carving on
/sdcard/. Encrypted device storage (FBE/Data Protection) severely limits recovery.
D. Authentication of Digital Evidence
-
Audio: Spectral analysis (noise floor consistency), detection of edits (clicks, pops), voice stress analysis (controversial).
-
Image/Video: Error Level Analysis (ELA) to identify areas of different compression (possible manipulation). Copy-Move Detection algorithms to find duplicated regions.
-
Legal Standard: Must demonstrate integrity (unchanged from acquisition) and provenance (clear chain of custody). Tools must be validated (e.g.,
MD5/SHA-256hash of original image).
VIII. Multimedia Forensics in Mobile Contexts
A. Multimedia Compression & DCT
-
DCT in JPEG/MPEG: Converts spatial domain (pixels) to frequency domain. Lossy because high-frequency components (fine details) are quantized (rounded off) aggressively.
-
Forensic Impact: Compression creates blocking artifacts (8x8 blocks in JPEG), ringing effects. Can indicate if an image has been re-saved (double compression).
B. Quality of Service (QoS) in Mobile Multimedia
-
Affecting Factors:
-
Network: Bandwidth, latency, jitter, packet loss.
-
Device: CPU/GPU for decoding, memory for buffering, battery drain.
-
Application: Buffer size, adaptive bitrate algorithm (HLS, DASH).
-
-
Resource Management: Balancing decoding quality with battery life; managing memory to prevent app crashes during high-res video playback.
C. Watermarking Techniques
| Type | Principle | Robustness | Mobile Use-Case Reasoning |
|---|---|---|---|
| Visible | Overlay logo/text perceptibly. | Low. Easily cropped/covered. | Professional Portfolio: Use Visible. Aesthetics & branding are secondary to clear ownership assertion. Robustness less critical than visibility. |
| Invisible | Embed data in noise/transform coefficients. | High. Survives compression, cropping. | Stock Photography: Use Invisible. Must not degrade image salability. Robustness crucial for copyright tracking after distribution. |
| Fragile | Breaks with any modification. | Very Low. Detects tampering. | Client Previews: Use Fragile/Visible. Low-res distribution; primary goal is to prove origin and detect unauthorized use. Fragile watermark breaks if client tries to remove it. |
D. Multimedia Authentication Mechanisms
-
Digital Signatures: Hash of content signed with private key. Verifies integrity and source.
-
Robust Hashing: Perceptual hash (
pHash,dHash) that is similar for visually similar images. Detects minor edits. -
Semi-Fragile Watermarking: Breaks with malicious edits (content change) but survives non-malicious ones (compression, format conversion).
E. Printer/Scanner Forensics (Mobile Context)
-
Device Identification: Printer/Scanner artifacts (banding, dot patterns, sensor noise) are embedded in digital documents (scanned receipts, photos of documents).
-
Case Study: Malicious document leak. Forensic analysis of the digital scan file's metadata and noise pattern can link it to a specific office printer model, which may be registered to a suspect's mobile device (if printed via mobile app) or location.
F. Virtual Reality (VR) & Multimedia Applications
-
Security Challenges: Data Privacy: Biometric data (eye tracking, movement), spatial audio recording. Immersive Attacks: Spoofing virtual objects to cause real-world harm (e.g., virtual obstacle causing physical trip).
-
Forensic Considerations: Spatial data logs (head position, controller clicks), interaction timelines, environment asset hashes. Evidence is multi-dimensional and time-series based.
IX. Cloud Security and Mobile Integration
A. Mobile Cloud Computing (MCC) Risks
-
Data Leakage: Misconfigured cloud storage (S3 buckets) exposing user data synced from mobile apps.
-
Insecure APIs: Lack of authentication/rate limiting on mobile backend APIs.
-
Cloud Sync Forensics: Artifacts in mobile app data (
/data/data/com.dropbox.android/) showing sync status, file paths, conflict resolutions. Cloud provider logs (if subpoenaed) show access IPs/times.
B. Secure Mobile-Cloud Architectures
-
Encryption: End-to-end (client-side) encryption before upload. Zero-knowledge cloud providers.
-
Access Controls: Fine-grained IAM policies, device attestation (SafetyNet/DeviceCheck) before granting API access.
-
Auditing: Continuous monitoring of cloud configurations (CSPM tools) for mobile app resources.
X. Reporting and Communication
A. Penetration Testing Reports
-
Structure:
-
Executive Summary: Business risk, high-level findings.
-
Methodology: Tools, scope, rules of engagement.
-
Findings: Each vulnerability with CVSS score, proof-of-concept (screenshots, curl commands), impact, remediation (specific code/config fix).
-
Conclusion: Overall risk posture.
-
-
Mobile-Specific: Include app version, OS version, device model in findings. Show intercepted traffic or decompiled code snippets.
B. Forensic Report Documentation
-
Chain of Custody Form: Item, collector, date/time, transfers, storage location.
-
Tool Validation: Document tool version, hash of forensic image (
sha256sum image.dd). -
Analysis Steps: "How" is as important as "what." E.g., "Extracted
mmssms.dbfrom/data/data/com.android.providers.telephony/using ADB backup." -
Multimedia Evidence: Annotated screenshots, side-by-side comparisons, hash values for original and processed files.
C. Presentation to Stakeholders
-
Technical โ Business Impact: "SQL Injection in user API" โ "Could lead to theft of all customer PII, resulting in GDPR fines (~4% revenue) and reputational damage."
-
Recommendations: Prioritized (Critical/High/Medium/Low), actionable, with estimated effort.
XI. Practical Simulations and Competitions
A. Capture the Flag (CTF) for Mobile Security
-
Simulation: Challenges mimic real tasks:
-
Reverse Engineering: Analyze APK to find hidden flag in code/strings.
-
Forensics: Analyze a provided
.ddimage to find deleted message. -
Exploitation: Exploit a vulnerable mobile service (e.g., insecure deserialization).
-
Cryptography: Decrypt captured TLS traffic using extracted keys.
-
-
Skill Development: Hands-on application of tools (Frida, Ghidra, Wireshark) in a time-bound, competitive environment.
B. Hands-on Lab Design
-
Test Environment: Isolated network with:
-
Mobile device (emulator or physical) with test apps.
-
Vulnerable backend server (e.g., OWASP Juice Shop with mobile API).
-
Rogue Wi-Fi access point (using
hostapd/dnsmasq). -
Traffic capture point (Wireshark on gateway).
-
-
Scenario: "Compromise the mobile app to extract the admin API token and use it to delete user data from the cloud backend."
XII. Cross-Cutting Themes and Emerging Trends
A. Interdisciplinary Industry Mergers
-
Hardware-Software: Apple (M-series chips + iOS security features like Secure Enclave).
-
Telecom-IT: 5G network slicing + cloud-native apps creates new attack surfaces (slice isolation failures).
-
Impact on Forensics: Requires knowledge of both hardware (baseband processor) and software (OS) for full device analysis.
B. Operating System Layers & Security
-
Attack Surface Influence: Lower layers (kernel, HAL) vulnerabilities (e.g.,
Dirty Pipein Linux kernel) affect all Android apps. Higher layers (Framework) vulnerabilities are app-specific. -
Forensic Access: Physical acquisition often requires exploiting a kernel vulnerability to gain raw disk access. Logical acquisition uses OS-provided backup APIs (limited by sandbox).
C. Active vs. Passive Attacks in Mobile Systems
| Active | Passive |
|---|---|
| Malware installation | Traffic monitoring (IMSI catcher) |
| Network injection (MITM) | Metadata collection (cell tower pings) |
| Session hijacking | Forensic artifact analysis (log file review) |
| Changes system state. | Only observes/records. |
D. Protocols in Mobile Forensics
-
Network Protocols: TCP/IP for internet traffic, GSM/UMTS/LTE for cellular logs (can show cell tower history), Bluetooth for pairing records.
-
Application Protocols: HTTP/2 (common in mobile APIs), MQTT (IoT apps), XMPP (chat apps). Protocol analysis helps reconstruct app activity (e.g., MQTT topic subscriptions indicate app features used).
Final Exam Strategy: For any question, first frame the answer in the mobile context. Use specific examples (Android/iOS, mobile apps, cellular networks). Where asked for "list," provide 3-4 concise items with a brief mobile-specific explanation for each.