Android Anti-forensics: Modifying CyanogenMod
This work addresses anti-forensics for mobile device security and forensics practitioners, but it is incremental as it builds on existing research with an initial empirical analysis.
The researchers tackled the problem of anti-forensics on Android devices by modifying the CyanogenMod operating system to prevent data extraction, block forensic tools, create delays, and present false data, successfully demonstrating these effects without impacting normal device use.
Mobile devices implementing Android operating systems inherently create opportunities to present environments that are conducive to anti-forensic activities. Previous mobile forensics research focused on applications and data hiding anti-forensics solutions. In this work, a set of modifications were developed and implemented on a CyanogenMod community distribution of the Android operating system. The execution of these solutions successfully prevented data extractions, blocked the installation of forensic tools, created extraction delays and presented false data to industry accepted forensic analysis tools without impacting normal use of the device. The research contribution is an initial empirical analysis of the viability of operating system modifications in an anti-forensics context along with providing the foundation for future research.