modern day Smartphone's have built in apps like "WhatsApp & Viber" which allow users to exchange instant messages, share videos, audio's and images via Smartphone's instead of relying on their desktop Computers or laptop thereby increasing the portability and convenience for a layman smart phone user. An Instant Messenger (IM) can serve as a very useful yet very dangerous platform for the victim and the suspect to communicate. The increased use of Instant messengers on Android phones has turned to be the goldmine for mobile and computer forensic experts. Traces and Evidence left by applications can be held on Android phones and retrieving those potential evidences with right forensic technique is strongly required. This paper focuses on conducting forensic data analysis of 2 widely used IMs applications on Android phones: WhatsApp and Viber. 5 Android phones were analyzed covering 3 different versions of Android OS: Froyo (2.2), GingerBread (2.3.x) and Ice- Cream Sandwich (4.0.x). The tests and analysis were performed with the aim of determining what data and information can be found on the device's internal memory for instant messengers e.g. chat messaging logs and history, send & received image or video files, etc. Determining the location of data found from FileSystem Extraction of the device was also determined. The experiments and results show that heavy amount of potential evidences and valuable data can be found on Android phones by forensic investigators.
[1]
Mohammad Iftekhar Husain,et al.
iForensics: Forensic Analysis of Instant Messaging on Smart Phones
,
2009,
ICDF2C.
[2]
Nicolas Christin,et al.
Toward a general collection methodology for Android devices
,
2011,
Digit. Investig..
[3]
Kevin Curran,et al.
Mobile Phone Forensic Analysis
,
2010,
Int. J. Digit. Crime Forensics.
[4]
Marwan Al-Zarouni.
Mobile handset forensic evidence: a challenge for law enforcement
,
2006
.
[5]
Alfred Kobsa,et al.
Privacy in instant messaging: an impression management model
,
2012,
Behav. Inf. Technol..
[6]
Naveen Aggarwal,et al.
Significance of Hash Value Generation in Digital Forensic : A Case Study
,
2012
.