Using digital forensics for android smartphone devices to aid criminal investigations
Loading...
Date
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
University of the Western Cape
Abstract
Over the past decade, there has been an exponential increase in the adoption of smartphones by billions of users worldwide. As usage has increased, these devices have also been exploited for illicit purposes, making smartphone data an invaluable source of information in criminal investigations. While prior research has emphasised the presentation of mobile evidence at trial, the investigatory phase, where evidence is triaged, contextualised, and prioritised, remains underexplored. This dissertation addresses the central research question: How can a snapshot of smartphone data be constructed to assist a criminal investigation? It focuses on constructing concise, context-rich “snapshots” of Android smartphone data to assist investigators in answering critical investigative questions during case triage. A review of the literature highlights the supportive role of smartphone evidence in guiding investigations and the need for investigator-focused tools. Using a Design Science Research approach, the study develops and evaluates a Python automation layer that extends the open-source Android Logs, Events, and Protobuf Parser (ALEAPP). The artefact programmatically executes ALEAPP, applies investigator-defined temporal filters, normalises heterogeneous timestamps, and generates examiner-ready outputs in the form of interactive Plotly HTML timelines and structured CSV reports. Evaluation employed three publicly available Android training images (Android 10, 12, 14), combining quantitative metrics with qualitative usability observations. Results demonstrate that the automation layer substantially reduced the number of events requiring manual review while preserving relevant artefacts. Interactive visualisations and embedded device context improved examiner focus, navigability, and overall triage efficiency. This study contributes both a validated automation artefact and an evaluation framework, demonstrating how temporally constrained, contextual snapshots can accelerate and enhance the investigative phase of Android mobile forensics. Future work will expand device coverage and refine time zone handling.