mobile device forensics in academia - nist · mobile device forensics in academia how we find out...

82
Mobile Device Forensics in Academia How we find out what we need to find out.

Upload: tranthuan

Post on 10-Apr-2018

254 views

Category:

Documents


7 download

TRANSCRIPT

Page 1: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Mobile Device Forensics in Academia

How we find out what we need to find out.

Page 2: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Mobile Device Forensics in Academia

Page 3: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Academia

ac·a·de·mi·a /ˌakəˈdēmēə/

Noun. Origin 1945–50; Neo-Latin

the environment concerned with the pursuit of Research, Education, and Scholarship.

Page 4: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

"Study the past if you would define the future...."

- Confucius

Page 5: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a
Page 6: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a
Page 7: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

In 2002…

Page 8: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a
Page 9: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Michael Burnette

Page 10: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a
Page 11: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Palm DD (PDD) – Joe Grand Joe Grand

RAM.txtROM.txt

Page 12: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

2 years later…

2004

Page 13: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Rick Ayers & Wayne Jansen

August 2004

Page 14: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Tools and Operating Systems – THEN…

Page 15: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a
Page 16: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Barrie Mellars

Page 17: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

AT Commands

Page 18: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Eoghan Casey

Page 19: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a
Page 20: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Mobile Forensics in Academia

• SIMs• Shielding• SMS• GPS• Hashing• Images/Videos• Legal

•Operating Systems• Android• BlackBerry• iOS• Maemo• Symbian• WebOS• Windows

•Other…

Page 21: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

SIM

Page 23: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

SMS

Page 24: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

GPS

Page 25: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Hashing

Page 26: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Images/Videos

Page 27: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Legal

Page 28: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Legal

Page 29: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Operating Systems

Page 30: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Android

Page 31: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

BlackBerry

Page 32: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

BlackBerry

Page 33: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

iOS

Jonathan Zdziarski

Sean Morrisey

Ryan Kubasiak

Page 34: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Maemo

Page 35: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Symbian

Page 36: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

WebOS

Page 37: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Windows

Page 38: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Comparing OS’s

Page 39: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Comparing OS’s

Page 40: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

and a few others worth mentioning…

Not found in the Journals…

Page 41: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Levels of Forensics

Page 42: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Levels of Forensics

Page 43: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Process for Examination

Page 44: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

JTAG

Page 45: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Academic Journals and Conferences

Page 46: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Australian Digital Forensics Conference – Edith Cowan University

http://ro.ecu.edu.au/adf/

Page 47: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Digital Forensic Reasearch Work Shop

http://www.dfrws.org/2014/cfp.shtml

Page 48: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Digital Investigation

http://www.journals.elsevier.com/digital-investigation/

Page 49: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Hawaii International Conferenceon Systems Sciences

http://www.hicss.hawaii.edu/

Page 50: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

International Conference on Digital Forensics an Cyber Crime

http://d-forensics.org/2014/show/home

Page 51: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

International Journal of Digital Crime and Forensics

http://www.igi-global.com/journal/international-journal-digital-crime-forensics/1112

Page 52: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

International Journal of Digital Evidence

Archive.org – IJDE.org

Page 53: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

International Journal of Electronic Security and Digital Forensics

http://www.inderscience.com/jhome.php?jcode=ijesdf

Page 54: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

International Federation for Information Processing

http://www.ifip.org/

Page 55: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Journal of Digital Forensic Practice

http://www.tandfonline.com/toc/udfp20/current#.U588efldWac

Page 56: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

The Journal of Digital Forensics, Security and Law

http://www.adfsl.org/journal.htm

Page 57: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Small Scale Digital Device Forensics Journal

http://www.ssddfj.org

Page 58: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a
Page 59: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a
Page 60: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

A Call to ArmsAn Invitation for Research

Page 61: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Anti-Forensics

Page 62: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

App Forensics

Page 63: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Chinese Knockoffs

Page 64: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

The Cloud

Page 65: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Flasher Devices

Page 66: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Tool Validation

Page 67: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Triage

Page 68: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

User Knowledge

Page 69: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

The Vendor Tools

Ad Hoc Reactive Methodology

a. User Has an Issue

b. Emails Problem to Vendor

c. Fixes Issue in Next Revision

Validation and Verification

How do we know what we don’t know!

Page 70: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Drinking the Kool-Aid

Research:

• Prove or disprove a hypothesis

• Learn new facts

• Advance the common body of knowledge

We have a need to know!

Page 71: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

One more thing…

for Steve…

Page 72: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Historical Review

Page 73: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Mobile Forensics ToolsFrom A-Z

Page 74: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a
Page 75: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a
Page 76: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a
Page 77: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a
Page 78: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a
Page 79: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Research is sometimes difficult…

Page 80: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

But, research is necessary!

Page 81: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a
Page 82: Mobile Device Forensics in Academia - NIST · Mobile Device Forensics in Academia How we find out what we need to find out. ... Windows. Comparing OS’s. Comparing OS’s. and a

Thank you!

www.mislan.com