Decrypting Digital Secrets: Browser Password Recovery from RAM Dumps in Compliance with ISO/IEC 27037
摘要
The use of digital platforms and internet activities has become an integral part of everyone’s life, and this reliance is unthinkable without browsers. Browsers often serve as repositories for storing passwords, thereby becoming vital tools for users. Considering the importance of browsers, this research explores the extraction of browser-stored passwords and other crucial artifacts from volatile memory (RAM) dumps. This is done to highlight the vulnerabilities in the encryption and memory structures of browsers. Further, it incorporates an investigative framework aligned with ISO/IEC 27037 standards for digital evidence acquisition and handling. The study focuses on methodologies for recovering sensitive information such as email IDs, passwords, Wi-Fi passwords, financial card details (including debit and credit card numbers), mobile numbers, BitLocker recovery keys, etc. A case study with practical scenarios is used to highlight the importance of the work in real-world scenarios. Furthermore, this study examines the memory structures of widely used browsers like Google Chrome, Mozilla Firefox, and Microsoft Edge, and their encryption methods. Proper acquisition, handling, and analysis techniques are the focus area of the research to ensure compliance with global forensic standards, such as ISO/IEC 27037. The paper provides a step-by-step approach and outlines best practices for conducting memory analysis, contributing valuable insights to digital forensics.