Digital Evidence Identification on Google Drive in Android Device Using NIST Mobile Forensic Method

Main Authors: Yudhana, Anton, Umar, Rusydi, Ahmadi, Ahwan
Format: Article info application/pdf eJournal
Bahasa: eng
Terbitan: Universitas Negeri Semarang , 2019
Online Access: https://journal.unnes.ac.id/nju/index.php/sji/article/view/17767
https://journal.unnes.ac.id/nju/index.php/sji/article/view/17767/pdf
https://journal.unnes.ac.id/nju/index.php/sji/article/downloadSuppFile/17767/3407
Daftar Isi:
  • The use of cloud storage media is very popular nowadays, especially with the Google Drive cloud storage media on smartphones. The increasing number of users of google drive storage media does not rule out the possibility of being used as a medium for storing illegal data, such as places to store negative content and so on. On a smartphone with an Android operating system that has a Google Drive application installed, digital evidence can be extracted by acquiring and analyzing the system files. This study implemented a mobile forensic method based on guidelines issued by the National Institute of Standards of Technology (NIST). The results of this study are presented in the form of data recovery in the deleted Google Drive storage media, which results in the form of headers of the data type in the form of deleting account names, deleted file types, and timestamp of deleted files. Digital evidence obtained with 59 Axiom Magnet software found in the Entry227 file, with 46 files, if the percentage is a success rate of 77%.