The function that a Digital Forensics Investigator (DFI) is rife with non-stop learning possibilities, mainly as technology expands and proliferates into each nook of communications, entertainment and business. As a DFI, we address a day by day onslaught of latest gadgets. Many of these gadgets, like the cell telephone or pill, use not unusual running structures that we want to be familiar with. Certainly, the Android OS is important within the tablet and cell phone industry. Given the predominance of the Android OS within the mobile device market, DFIs will run into Android gadgets inside the course of many investigations. While there are numerous models that recommend processes to obtaining records from Android gadgets, this text introduces four viable strategies that the DFI have to recall whilst proof amassing from Android devices.
A Bit of History of the Android OS
Android’s first industrial release changed into in September, 2008 with model 1.Zero. Android is the open supply and ‘unfastened to apply’ operating system for cell gadgets advanced by Google. Importantly, early on, Google and different hardware corporations formed the “Open Handset Alliance” (OHA) in 2007 to foster and support the growth of the Android within the marketplace. The OHA now consists of 84 hardware companies which include giants like Samsung, HTC, and Motorola (to call a few). This alliance was established to compete with corporations who had their own market offerings, along with aggressive devices offered by using Apple, Microsoft (Windows Phone 10 – that’s now reportedly dead to the market), and Blackberry (which has ceased making hardware). Regardless if an OS is defunct or now not, the DFI have to recognise about the numerous variations of multiple running system structures, mainly if their forensics recognition is in a selected realm, together with cellular devices.
Linux and Android
The cutting-edge generation of the Android OS is based on Linux. Keep in mind that “based on Linux” does now not imply the same old Linux apps will always run on an Android and, conversely, the Android apps which you would possibly revel in (or are acquainted with) will not always run in your Linux computer. But Linux is not Android. To clarify the point, please be aware that Google selected the Linux kernel, the essential part of the Linux working machine, to manage the hardware chipset processing in order that Google’s developers would not should be involved with the specifics of ways processing takes place on a given set of hardware. This allows their developers to focus on the broader operating machine layer and the user interface functions of the Android OS.
A Large Market Share
The Android OS has a giant marketplace share of the mobile device market, in general because of its open-supply nature. An excess of 328 million Android gadgets were shipped as of the third quarter in 2016. And, in step with netwmarketshare.Com, the Android operating system had the bulk of installations in 2017 — nearly sixty seven% — as of this writing.
As a DFI, we can assume to stumble upon Android-primarily based hardware within the course of an average research. Due to the open supply nature of the Android OS along with the numerous hardware platforms from Samsung, Motorola, HTC, and so on., the style of mixtures between hardware type and OS implementation presents a further mission. Consider that Android is currently at model 7.1.1, yet every telephone manufacturer and cell device provider will generally modify the OS for the precise hardware and provider services, giving an extra layer of complexity for the DFI, since the approach to statistics acquisition might also range.