评估跨生产版本的安卓内存分析的取证可行性:安全强化与结构保留的跨版本研究
Assessing the Forensic Viability of Android Memory Analysis Across Production Builds: A Cross-Version Study of Security Hardening and Structure Preservation
浏览论文内容
中文总结 AI 辅助
研究安卓跨版本安全强化对内存分析取证可行性的影响,利用安卓8到15的Pixel工厂镜像二进制文件测量差距,发现虽符号等信息减少,但关键结构仍完整,运行时入口点可定位,为安卓内存取证提供参考。
中文摘要 AI 辅助
安卓内存取证可恢复未接触磁盘的证据,如解密消息、会话凭证和运行应用的实时内部状态。执行此恢复的工具依赖于安卓运行时库中的调试符号来定位数据结构并解释其布局。谷歌在近期版本中剥离了大部分此类信息。本文利用从安卓8到15的Pixel工厂镜像中提取的二进制文件,测量了研究人员使用的未剥离开发版本与实际硬件上运行的生产版本之间的差距。结果显示静态符号从20495个条目降至零,动态符号下降约60%,源文件引用完全消失。安卓15二进制文件中的压缩回退部分恢复了数千个函数名但无结构布局。通过对安卓8和15的源代码审查和内存映射比较表明,堆空间、垃圾回收器基础设施和分配位图在结构上保持完整,可见变化仅限于命名和算术优化。在已root且完全剥离的Pixel 7上进行的实时验证证实,运行时入口点仍可通过动态符号表定位,并且从版本匹配的开发版本中提取的结构偏移量可解析为生产内存中的有效指针。
英文摘要
Android memory forensics recovers evidence that never touches disk: decrypted messages, session credentials, and the live internal state of a running application. The tools that perform this recovery depend on debug symbols embedded in libart.so, the Android Runtime library, to locate data structures and interpret their layout. Across recent releases Google has stripped most of that information from the binaries that ship on consumer phones as part of a broader security hardening effort, yet no prior work has measured how far the stripping has progressed on the devices examiners actually encounter, or whether the memory architecture beneath the stripped surface still resembles what the forensics literature describes. This paper measures the gap between the unstripped development builds researchers use and the production builds that ship on real hardware, using binaries extracted from Pixel factory images across Android 8 through Android 15. Static symbols fell from 20,495 entries to zero, dynamic symbols dropped by roughly 60 percent, and source file references disappeared entirely. A compressed fallback section in the Android 15 binary restores thousands of function names but carries no structure layouts. Source code review and memory map comparisons across Android 8 and 15 show that the heap spaces, garbage collector infrastructure, and allocation bitmaps remain structurally intact, with visible changes limited to naming and arithmetic optimization. Live validation on a rooted, fully stripped Pixel 7 confirms that the runtime entry point is still locatable through the dynamic symbol table, and that structural offsets pulled from a version-matched development build resolve to valid pointers inside production memory.