In the rapidly advancing technological landscape, smartwatches have materialized as multifunctional devices integral to our daily routines. Smartwatches store a substantial amount of personal information, potentially serving as repositories of digital evidence. Thus, digital forensic researchers have devoted considerable effort to exploring smartwatch forensic techniques. However, it has been observed that prior studies have primarily treated smartwatches as mere storage mediums for digital evidence, neglecting their potential role in criminal activities. This paper presents the information leakage perpetrated through smartwatches. We represent crime scenarios in an environment where smartphones are not available, considering that the perception that smartphones can be used as tools for criminal behavior prevails in many organizations, while the potential of similar-use smartwatches is often overlooked. We detail mechanisms for information leakage via file transfer and camera control using smartwatches. Additionally, we present methods to investigate each crime incident through smartwatch forensics. Finally, we describe the limitations of post-incident responses and propose proactive measures to prepare for potential crimes involving smartwatches. Keywords: Information Leakage, Smartwatch Forensics, Android Forensics, Mobile Device Management, Security Policy
翻译:在快速发展的技术背景下,智能手表已成为融入日常生活的多功能设备。智能手表存储大量个人信息,可能成为数字证据的仓库。因此,数字取证研究人员投入了大量精力探索智能手表取证技术。然而,此前研究主要将智能手表视为数字证据的存储介质,忽视了其在犯罪活动中可能扮演的角色。本文揭示了通过智能手表实施的信息泄露行为。鉴于许多机构普遍认为智能手机可作为犯罪工具,而对类似用途的智能手表的潜在威胁往往被忽视,我们构建了无智能手机环境下的犯罪场景。我们详细阐述了通过文件传输和摄像头控制利用智能手表进行信息泄露的机制。此外,我们提出了通过智能手表取证调查每起犯罪事件的方法。最后,我们描述了事后响应的局限性,并提出了应对潜在智能手表犯罪的主动措施。关键词:信息泄露;智能手表取证;安卓取证;移动设备管理;安全策略