• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

我们正在微软团队上开会:关于Windows、安卓和iOS操作系统中的法医分析。

We are meeting on Microsoft Teams: Forensic analysis in Windows, Android, and iOS operating systems.

作者信息

Bowling Herschel, Seigfried-Spellar Kathryn, Karabiyik Umit, Rogers Marcus

机构信息

Computer and Information Technology, Purdue University, West Lafayette, Indiana, USA.

出版信息

J Forensic Sci. 2023 Mar;68(2):434-460. doi: 10.1111/1556-4029.15208. Epub 2023 Feb 3.

DOI:10.1111/1556-4029.15208
PMID:36734289
Abstract

Microsoft released a new communication platform, Microsoft Teams, in 2017. Due in part to COVID-19, the popularity of communication platforms, like Microsoft Teams, increased exponentially. Given its user base and increased popularity, it seems likely that digital forensic investigators will encounter cases where Microsoft Teams is a relevant component. However, because Microsoft Teams is a relatively new application, there is limited forensic research on the application particularly focusing on mobile operating systems. To address this gap, an analysis of data stored at rest by Microsoft Teams was conducted on the Windows 10 operating system as well as on Android and Apple iOS mobile operating systems. Basic functionalities, such as messaging, sharing files, participating in video conferences, and other functionalities that Teams provides, were performed in an isolated testing environment. Cellebrite UFED Physical Analyzer and Magnet AXIOM Examine tools were used to analyze the mobile devices and the Windows device, respectively. Manual or non-automated investigation recovered, at least partially, the majority of artifacts across all three operating systems. In this study, a total of 77.6% of the populated artifacts were partially or fully recovered in the manual investigation. On the other hand, forensic tools used did not automatically recover many of the artifacts found with the manual investigation. Only 13.8% of artifacts were partially or fully recovered by the forensic tools across all three devices. These discovered artifacts and the results of the investigations are presented in order to aid digital forensic investigations.

摘要

微软在2017年发布了一个新的通信平台——微软团队。部分由于新冠疫情,像微软团队这样的通信平台的受欢迎程度呈指数级增长。鉴于其用户基础和日益增长的受欢迎程度,数字取证调查人员似乎很可能会遇到与微软团队相关的案件。然而,由于微软团队是一个相对较新的应用程序,针对该应用程序的取证研究有限,尤其是针对移动操作系统的研究。为了填补这一空白,我们在Windows 10操作系统以及安卓和苹果iOS移动操作系统上对微软团队静态存储的数据进行了分析。在一个隔离的测试环境中执行了微软团队提供的基本功能,如消息传递、文件共享、参加视频会议等功能。分别使用Cellebrite UFED Physical Analyzer和Magnet AXIOM Examine工具来分析移动设备和Windows设备。手动或非自动化调查至少部分恢复了所有三个操作系统中的大部分工件。在本研究中,在手动调查中,总共77.6%的已填充工件被部分或全部恢复。另一方面,所使用的取证工具并没有自动恢复手动调查中发现的许多工件。在所有三个设备上,只有13.8%的工件被取证工具部分或全部恢复。展示这些发现的工件和调查结果是为了协助数字取证调查。

相似文献

1
We are meeting on Microsoft Teams: Forensic analysis in Windows, Android, and iOS operating systems.我们正在微软团队上开会:关于Windows、安卓和iOS操作系统中的法医分析。
J Forensic Sci. 2023 Mar;68(2):434-460. doi: 10.1111/1556-4029.15208. Epub 2023 Feb 3.
2
Microsoft Teams desktop application forensic investigations utilizing IndexedDB storage.利用 IndexedDB 存储进行 Microsoft Teams 桌面应用程序取证调查。
J Forensic Sci. 2022 Jul;67(4):1513-1533. doi: 10.1111/1556-4029.15014. Epub 2022 Feb 18.
3
A Forensic Exploration of the Microsoft Windows 10 Timeline.对微软Windows 10时间线的法证探索
J Forensic Sci. 2019 Mar;64(2):577-586. doi: 10.1111/1556-4029.13875. Epub 2018 Jul 26.
4
An Android Communication App Forensic Taxonomy.一款安卓通信应用取证分类法。
J Forensic Sci. 2016 Sep;61(5):1337-50. doi: 10.1111/1556-4029.13164. Epub 2016 Jul 22.
5
Forensic Investigation of Cooperative Storage Cloud Service: Symform as a Case Study.合作存储云服务的法医调查:以Symform为例进行研究
J Forensic Sci. 2017 May;62(3):641-654. doi: 10.1111/1556-4029.13271. Epub 2016 Nov 25.
6
An Evidence-based Forensic Taxonomy of Windows Phone Dating Apps.基于证据的Windows Phone约会应用法医分类法。
J Forensic Sci. 2019 Jan;64(1):243-253. doi: 10.1111/1556-4029.13820. Epub 2018 May 21.
7
An Evidence-Based Forensic Taxonomy of Windows Phone Communication Apps.基于证据的Windows Phone通信应用法医分类法。
J Forensic Sci. 2018 May;63(3):868-881. doi: 10.1111/1556-4029.13624. Epub 2017 Aug 17.
8
Forensic analysis of iOS binary cookie files.对 iOS 二进制 cookie 文件的取证分析。
J Forensic Sci. 2024 May;69(3):1075-1087. doi: 10.1111/1556-4029.15499. Epub 2024 Mar 5.
9
Forensic Taxonomy of Android Social Apps.安卓社交应用的法医分类学
J Forensic Sci. 2017 Mar;62(2):435-456. doi: 10.1111/1556-4029.13267. Epub 2016 Nov 28.
10
Digital Forensic Case Studies for In-Vehicle Infotainment Systems Using Android Auto and Apple CarPlay.基于 Android Auto 和 Apple CarPlay 的车载信息娱乐系统数字取证案例研究
Sensors (Basel). 2022 Sep 22;22(19):7196. doi: 10.3390/s22197196.