Abstract

Researchers have developed forensic analysis techniques for so many types of digital media that there is a procedure for almost every digital media that a law enforcement officer may encounter at a crime scene. However, a new type of device has started to gain momentum in the consumer market: web thin clients. These web thin clients are characterized by native support for basic web browsing, yet other functionality relies on a combination of web applications and web storage. In fact, these devices are so different from other types of computing and storage devices that virtually all of the techniques forensic examiners and researchers typically use do not apply. The most popular web thin client, Chrome OS, has additional forensic challenges: (1) all data associated with users is encrypted, (2) Chrome OS correctly uses TPM and Secure Boot, and (3) user data is stored on the device and in the cloud. In this work, we present a novel approach to extract residual evidence stored on Chrome OS devices that successfully bypasses these challenges. Specifically, we are able to determine which extensions and apps are installed on an encrypted Chrome OS device, without breaking or otherwise extracting the encryption keys. Our framework, called dbling, generates signatures or fingerprints of extension and app code that persist after encryption, and we are able to use these fingerprints to identify the installed extensions and apps. We create fingerprints of 160,025 extensions for Chrome OS, we measure the uniqueness of these fingerprints, and we perform a case study by installing 14 extensions on a Chrome OS device and attempt to find their fingerprints.

Original languageEnglish (US)
Pages (from-to)S55-S65
JournalDigital Investigation
Volume18
DOIs
StatePublished - Aug 7 2016

Fingerprint

Application programs
Digital storage
Dermatoglyphics
digital media
Equipment and Supplies
Cryptography
Crime
examiner
Law enforcement
law enforcement
functionality
Momentum
offense
Research Personnel
market
Police
evidence

Keywords

  • Chrome OS
  • Digital forensics
  • Forensics on encrypted data
  • Web thin clients

ASJC Scopus subject areas

  • Computer Science Applications
  • Medical Laboratory Technology
  • Law

Cite this

dbling : Identifying extensions installed on encrypted web thin clients. / Mabey, Mike; Doupe, Adam; Zhao, Ziming; Ahn, Gail-Joon.

In: Digital Investigation, Vol. 18, 07.08.2016, p. S55-S65.

Research output: Contribution to journalArticle

@article{41d90e7d78dc48da81ea8cd2166d83e6,
title = "dbling: Identifying extensions installed on encrypted web thin clients",
abstract = "Researchers have developed forensic analysis techniques for so many types of digital media that there is a procedure for almost every digital media that a law enforcement officer may encounter at a crime scene. However, a new type of device has started to gain momentum in the consumer market: web thin clients. These web thin clients are characterized by native support for basic web browsing, yet other functionality relies on a combination of web applications and web storage. In fact, these devices are so different from other types of computing and storage devices that virtually all of the techniques forensic examiners and researchers typically use do not apply. The most popular web thin client, Chrome OS, has additional forensic challenges: (1) all data associated with users is encrypted, (2) Chrome OS correctly uses TPM and Secure Boot, and (3) user data is stored on the device and in the cloud. In this work, we present a novel approach to extract residual evidence stored on Chrome OS devices that successfully bypasses these challenges. Specifically, we are able to determine which extensions and apps are installed on an encrypted Chrome OS device, without breaking or otherwise extracting the encryption keys. Our framework, called dbling, generates signatures or fingerprints of extension and app code that persist after encryption, and we are able to use these fingerprints to identify the installed extensions and apps. We create fingerprints of 160,025 extensions for Chrome OS, we measure the uniqueness of these fingerprints, and we perform a case study by installing 14 extensions on a Chrome OS device and attempt to find their fingerprints.",
keywords = "Chrome OS, Digital forensics, Forensics on encrypted data, Web thin clients",
author = "Mike Mabey and Adam Doupe and Ziming Zhao and Gail-Joon Ahn",
year = "2016",
month = "8",
day = "7",
doi = "10.1016/j.diin.2016.04.007",
language = "English (US)",
volume = "18",
pages = "S55--S65",
journal = "Digital Investigation",
issn = "1742-2876",
publisher = "Elsevier Limited",

}

TY - JOUR

T1 - dbling

T2 - Identifying extensions installed on encrypted web thin clients

AU - Mabey, Mike

AU - Doupe, Adam

AU - Zhao, Ziming

AU - Ahn, Gail-Joon

PY - 2016/8/7

Y1 - 2016/8/7

N2 - Researchers have developed forensic analysis techniques for so many types of digital media that there is a procedure for almost every digital media that a law enforcement officer may encounter at a crime scene. However, a new type of device has started to gain momentum in the consumer market: web thin clients. These web thin clients are characterized by native support for basic web browsing, yet other functionality relies on a combination of web applications and web storage. In fact, these devices are so different from other types of computing and storage devices that virtually all of the techniques forensic examiners and researchers typically use do not apply. The most popular web thin client, Chrome OS, has additional forensic challenges: (1) all data associated with users is encrypted, (2) Chrome OS correctly uses TPM and Secure Boot, and (3) user data is stored on the device and in the cloud. In this work, we present a novel approach to extract residual evidence stored on Chrome OS devices that successfully bypasses these challenges. Specifically, we are able to determine which extensions and apps are installed on an encrypted Chrome OS device, without breaking or otherwise extracting the encryption keys. Our framework, called dbling, generates signatures or fingerprints of extension and app code that persist after encryption, and we are able to use these fingerprints to identify the installed extensions and apps. We create fingerprints of 160,025 extensions for Chrome OS, we measure the uniqueness of these fingerprints, and we perform a case study by installing 14 extensions on a Chrome OS device and attempt to find their fingerprints.

AB - Researchers have developed forensic analysis techniques for so many types of digital media that there is a procedure for almost every digital media that a law enforcement officer may encounter at a crime scene. However, a new type of device has started to gain momentum in the consumer market: web thin clients. These web thin clients are characterized by native support for basic web browsing, yet other functionality relies on a combination of web applications and web storage. In fact, these devices are so different from other types of computing and storage devices that virtually all of the techniques forensic examiners and researchers typically use do not apply. The most popular web thin client, Chrome OS, has additional forensic challenges: (1) all data associated with users is encrypted, (2) Chrome OS correctly uses TPM and Secure Boot, and (3) user data is stored on the device and in the cloud. In this work, we present a novel approach to extract residual evidence stored on Chrome OS devices that successfully bypasses these challenges. Specifically, we are able to determine which extensions and apps are installed on an encrypted Chrome OS device, without breaking or otherwise extracting the encryption keys. Our framework, called dbling, generates signatures or fingerprints of extension and app code that persist after encryption, and we are able to use these fingerprints to identify the installed extensions and apps. We create fingerprints of 160,025 extensions for Chrome OS, we measure the uniqueness of these fingerprints, and we perform a case study by installing 14 extensions on a Chrome OS device and attempt to find their fingerprints.

KW - Chrome OS

KW - Digital forensics

KW - Forensics on encrypted data

KW - Web thin clients

UR - http://www.scopus.com/inward/record.url?scp=84982796337&partnerID=8YFLogxK

UR - http://www.scopus.com/inward/citedby.url?scp=84982796337&partnerID=8YFLogxK

U2 - 10.1016/j.diin.2016.04.007

DO - 10.1016/j.diin.2016.04.007

M3 - Article

VL - 18

SP - S55-S65

JO - Digital Investigation

JF - Digital Investigation

SN - 1742-2876

ER -