1.1: Organize document or presentation clearly in a manner that promotes understanding and meets the requirements of the assignment.
RUNNING HEAD: MOBILE FORENSICS 1
MOBILE FORENSICS 14
Mobile Forensic Investigation Comment by Shumba: This project needs a lot of work. Please see embedded feedback. I also do not see the lab component.
Table of Contents Introduction and Purpose of the Report 3 Incident Summary 3 The Investigation plan 4 The plan itself: 6 Data extraction 6 Data Types 6 Data Retrieval 6 Forensic Imager Report 7 Analysis 8 Conclusion 9 Comparative Analysis Report 10
Mobile Forensics
Introduction and Purpose of the Report
Mobile forensics is a subsidiary of the famed discipline of digital forensics that focuses its investigation activities on the recovery of digital evidence on mobile phones. Just like the mainstream investigation process of digital forensics, mobile forensics processes also involve steps such as identifying the location of the evidence within mobile phones and then engage the means of obtaining the evidence through from the mobile usually described as forensically sound methods. The next step is the examination of the piece of evidence before finally making a final summary report that details findings in a language that can be understood by the majority of the people interested in the story. Mobile forensic processes exist in many types, mainly influenced by parameters such as type of the phone being investigated and the operating system of the phone. Other parameters include encryption levels and the existence of necessary passcodes to scale up. When talking about the mobile, we address ourselves on the issues such as manufacturer, make as well as model. The purpose of this report is to provide digital evidence concerning the missing girl to Mr. Sheriff Johnson and other interested parties for further action.
Incident Summary
In summary, one Mr. Sheriff Jamison is dealing with a case that involves a missing girl. A mobile phone belonging to the girl is available and is believed to contain some information that can help peace up issues concerning the case. The only forensic investigation that a mobile phone can be subjected to is the mobile forensic investigation. A type of forensic investigation that focuses its investigation activities on the recovery of digital evidence from mobile phones. The kind of phone, in this case, is an iPhone. The investigation process is required to furnish Mr. Sheriff with the final forensic report that contains an investigation plan, issue findings on the mobile phone image analyzed, all pieces of evidence, and other findings from the forensic report together with a comparative analysis.
The Investigation plan
Before putting down the plan, it is essential to understand some of the processes that entail forensic investigation and are particular consumed write from the beginning to the end. The investigation process comprises important phases such as identification of the evidence location, preservation of the identified evidence, examining it, analyzing it, and presenting it to the rightful authority. The very final step that summarizes the process is decision making which arrives much later and is usually influenced by the outcome of the report (Abdilalem Ali, 2017). The mentioned phases of the investigation plan cover the whole range of investigation plans, starting from where the acquisition takes place. The process of investigation, as indicated in this plan, comprises important steps, such as described below. Comment by Shumba: Really? You have very limited number of pages for the plan. I suggest you only include what is required by the specification.
Preparation- the step upon which tools and other necessities are put in place. These necessities may include things like search warrants, techniques to be used as well as prepared as well as the monitoring authorization, and support management are also done (DeFranco, 2014).
Extraction- the investigator in this step looks for the evidence, recognizes the found ones, collects them, and documents them as found from the crime scene.
Identification- the step is equally important as it enables the investigator to identify possible data sources so as to make it possible to verify the integrity of the data while also ensuring important things such as chain of custody are well maintained (Caloyannides & Caloyannides, 2014). Identification is particularly important as it is through it that incidences can be recognized from indicators and hence determining what types they are.
Preservation- in forensic investigation, this step involves isolation of the evidence collected and safely preserving as dictated by principles of forensic evidence preservation. This should be able to be done whether the evidence is in a physical or digital state.
Collection- involves the recording of the duplicate digital evidence as well as the physical scene using well-recognized procedures.
Analysis- the analysis step entails determining the significance, reconstruction of data fragments as well as drawing the likeliest conclusions guided by the outcome or evidence that the intervention has come up with.
Results Reporting- as soon as the evidence is found, it is analyzed then a summary accompanied by an explanation bordering conclusions is drawn so that the interested parties can be able to know whatever might have taken place.
Returning the evidence- once the investigation is completed, the investigation team must return everything they used in the investigation, which was not part of their belonging to the owners. These can be either in physical or in digital form.
The Challenges Comment by Shumba: There are a lot of missing aspects here. BYOD, 3rd party application etc. Please read the Step 2 of the project specification and include the missing parts.
Mobile forensics just like computer forensics examination, has a couple of a challenges unique to it. Some of the known challenges associated with mobile forensics include: the many operating systems that mobile have. For the last seven years, mobile phone manufacturers have been exposed to four types of operating systems namely Android, iOS, Symbian and Blackberry. Operating Systems vary in terms of security protocols, privacy layers and many more. The challenge is that an investigator can chose to familiarize with the market’s leading mobile OS only to learn that another OS is use. The ever changing platform environment is believed to be a critical challenge to investigators as far as mobile forensics is concerned. This investigation involved the iOS. Although this OS has been around for some time now, it has gone through various update improvements altering some features that were initially easy to learn.
The plan itself: Comment by Shumba: I do not see coverage of the two below: mobile phone applications that may hold useful information to this case how the evidence will be handled in anticipation of court admissibility
Data extraction: this refers to the retrieval of data from unorganized state such as unstructured databases. In this, data extraction involves obtaining any data from the iPhone’s main memory that if subjected to further actions can provide relevant information and probably form part of the digital evidence. Once the investigators get hold of the phone, they can either choose to combine all the data or separate the ones initially deleted from the ones still on the phone. The data can be images, contacts, GPS history logs, messages, and recordings. Comment by Shumba: Where can the date be extracted from. Sim card, cell towers??? etc. In other words this is asking for where the evidence can be obtained from.
Data Types: iPhones ordinarily involve numerous data types. These may include text messages, audio recordings, image deletion, web searches, event timelines, web pages visited, and many more. iPhone apps, just like other mobile apps basically store data in two forms; local storage of app which is temporary means that will be washed out when user will be logged out of app. Comment by Shumba: We are dealing with the FB app, what type of data can be retrieved from here?
If app is native so it can store your data in form of database SQLite is highly used for this purpose which stores data as a database into your phone’s internal storage. For E.g. You may see it clearly in WhatsApp it keeps backing up of your chat messages into your phone’s internal storage and as well as on iCloud if you allow.
Data Retrieval: Data retrieval can be described as obtaining data from an organized data storage such as the database while data extraction of data, on the other hand, is retrieving data from unstructured source. One way the investigators can access data from the phone is through direct access which is retrieval. However, deleted data can only be retrieved by the engaging forensic intervention. iPhones have three layers of data deleted data retrieval (Binaryintel, 2013). They include the file system, logical and physical organizations. The following are some of the file organizations on an iPhone. Comment by Shumba: This needs to be expanded. How does J-TAG come into play here?
Forensic Imager Report Comment by Shumba: Is this the comparison of the tools section?
The forensic imager basically refers to a window that premised on a program that has the ability to acquire, convert, and perform verification on a forensic image manufactured by Access Data Company. It is particularly significant when it comes to monitoring and investigation process tracking. The forensic toolbox is a device that is also developed by the very Access Data Company which has grown to become the organization's leading product that has expanded the effectiveness of password recovery (Data, 2016). Such solutions have been utilized by experts in mobile forensic examinations to get to retrieve deleted protect records as well as files that are protected that needs to be opened. The police can utilize such a tool for recovering passwords of phones belonging to the deceased or lost people.
This report demonstrates the degree of integrity of the case through the utilization of the hash algorithms referred to as Message Digest5 (MD5-HASH) as well as the Secure Hash Algorithm (SHA 1 HASH) all of which possesses the ability tell that the case is indistinguishable from the media it originated from (Patil, n.d). The hash's length is unique in relation to alternate file images since files possess contents that different from those of images. Forensic Toolkit of whatever kind has to be hashed. In this file, hashing 'SHA 1' and 'MD5'show up consequently. It is imperative to guarantee that the computerized proof stays unaltered from the hour of procurement to the time of presentation.
A forensic investigation inside the attached file was checked utilizing the windows vista. The device examines a hard drive searching for various data from the picture. The report gives the subtleties of the case as the entrance information program. From the report, there is the situation data; for example, the case number and the structure used to procure the case. The case number is distinguished as the '10-24-2016 CYB610' and the proof number (Data, 2015). For one of a kind portrayal, an image is shown for exact data to keep away from any disarray or logical inconsistencies of the case. The imager additionally has the subtleties of the time, the date that the picture was obtained in the examinations. Comment by Shumba: How do you ensure integrity of the evidence? How do you isolate the device such that there is no interference from other devices?
Analysis
This is a very significant phase of forensic investigation. In all the stages of examination and analysis, a forensic auditor can manage duplicates of the primary verification of the data recovered from the contraption instead of the principal inspector. They accustomed to recognizing, defending, and reporting any verification of the proof found on the device from the media capacity. The essential method of reasoning of this is by taking a shot at a data mining process using the PC forensics to set up the data for examination and analysis, find any acts of wrongdoing; assisting the investigation officials must be the initial step towards précising the route of lighting up infringement and furthermore do PC legal forensic for criminal endeavors.
Conclusion
Taking everything into account, apparently, the potential access has a lot of individual information, and the police obligation is not to mishandle the information or negligence the security benefits to accuse people since the heads can take a gander at the law necessities access to mechanized information. A few points of interest of the assessment of each device may fluctuate; the gathering of anticipating and recording assessment methods will help the expert in ensuring the affirmation to be expelled from each telephone is particularly detailed and the result one repeatable in court. The information in this is relied upon to be a guide for crime scene investigation in the improvement of methodology that would fit the necessities.
Comparative Analysis Report Comment by Shumba: What is the criteria for the comparison of the tools?
Introduction
In every field, respective experts require the necessary tools to undertake various tasks. Similarly, mobile forensics as an emerging field has certain software tools that enable forensic experts to carry out investigations. In digital forensics, investigators use various software tools to extract data or digital evidence that may be of interest to the investigation process. These tools are either open source or commercial. The previous examination and analysis were carried out using the Mobile Phone Examiner (MPE+). The MPE+ is a stand-alone forensic tool mainly used for mobile investigation exercises. The tool can be found on a preconfigured touch screen smartphone or tablet for mobile forensics triage on on-screen states. The tool functions by integrating it in conjunction with other tools specifically the Forensics Toolkit (FTK) hence allowing for evidence correlation from numerous mobile devices. In this section, we will carry out a comparative analysis involving the other three forensic tools against the MPE+ targeting differences and similarities between each of them as well as the MPE+. The three include Encase Forensics Software, FTK Mobile Examiner and Oxygen Forensic Suite. We begin this analysis by looking at the operation of MPE+.
Mobile Phone Examiner (MPE+) and Forensic Toolkit Imager
Both the Mobile Phone Examiner and Forensic Toolkit are products developed by AccessData Solutions. In recent days, the two products have since been integrated to form one solution referred to as FTK Mobile Phone Examiner (FTKMBE). It is the most utilized forensic tool for mobile devices not only in the US but also in Europe and other major markets, a distinction it shares with EnCase Forensic suite of Guidance.
Despite the integration, Mobile Phone Examiner can be utilized as an independent application or as a completely incorporated piece of Forensic Toolkit (FTK) interface. In the Sheriff Jamison case, the MPE+ was used independent of other digital forensic tools and was able to deliver the desired result. Utilizing MPE bears the analyst the choice of a prompt and simple field securing through a link, Infrared, or connecting via Bluetooth without modifying information on the device, which is fundamental in setting up evidence that can be admitted in court.
The EnCase Neutrino
Guidance Software has grown to become one of the leaders in the mobile forensic software industry. This has been solely driven by the strong market showing of its product, the Encase Forensic Software. The tool is designed to offer similar technology and establishment for forensic examinations of mobile phones just as the MPE+. The main difference between the EnCase Neutrino and MPE+ is that the former cannot generate evidence from multiple device sources like the MPE+. However, the noted difference could not have disqualified the EnCase solution from being used in the investigation of the process of Sheriff Jamison’s case. The only issue that may not be clear is that the phone from which evidence is supposed to be extracted from is one, but targeted potential evidence areas may be more than one.
Oxygen Forensic Suite
Oxygen Forensic Suite is occasionally treated as an optional tool for various organizations in Europe, assisting in fulfilling law enforcement operations, customs, and taxes, authorities in governments sitting in Great Britain, Australia, Germany, Finland, and Sweden, among others. Some of the functions of Oxygen Forensic Suite include finding passwords to encrypted backups and images among others like us as listed below:
· Bypassing screen locks on various devices containing Android OS.
· Acquisition of data from IT devices as well as smartwatches
The Oxygen Forensic Suite, as indicated earlier, as an alternative forensic tool suited Mr. Sheriff Jamison’s case. In retrospect, there is no extra quality that this tool could have brought in the case that the EPE+ tool used failed on. The device prides itself on its notoriety of having the option to extricate one of a kind data from a smartphone, for example, smartphone fundamental data and SIM-card information, phone book, guest gatherings, speed dials, missed/active/approaching calls, standard SMS/MMS/E-mail envelopes, custom SMS/MMS/E-mail organizers, schedule occasions timetable, errands, and content notes. Anyway, the highlights are not genuinely one of a kind as every one of the three instruments can separate this data. Anyway, Oxygen's capacity to take advantage of the LifeBlog and geotagging in Symbian OS in Nokia telephones gives it a preferred position over its opposition. Not at all, like MPE or Device Seizure, is a specialist application utilized to perform criminological investigation consolidating the upsides of both consistent and physical acquisitions of data.
Conclusion
In conclusion, all four forensic tools could have delivered a desirable outcome as far as Mr. Sheriff Jamison’s case is concerned. Going forward, the Mobile Phone Examiner (MPE+) will remain as the preferred forensic tool. The previous examination and analysis were carried out using the Mobile Phone Examiner (MPE+), and the results remain mostly satisfactory. The MPE+ is a stand-alone forensic tool used primarily for mobile investigation exercises. The device can be found on a preconfigured touch screen smartphone or tablet for mobile forensics triage on on-screen states. The tool functions by integrating it in conjunction with other tools specifically the Forensics Toolkit (FTK) hence allowing for evidence correlation from numerous mobile devices. In this section, we will carry out a comparative analysis involving the other three forensic tools against the MPE+ targeting differences and similarities between each of them as well as the MPE+. The three include Encase Forensics Software, FTK Mobile Examiner and Oxygen Forensic Suite.
References
Abdilalem Ali, S.A (2017). A metamodel for the mobile forensics investigation domain. Retrieved from https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5433730 on August 28, 2017
Anglano, C., Canonico, M., & Guazzone, M. (2017). Forensic analysis of telegram messenger on android smartphones. Digital Investigation, 23, 31-49.
Binaryintel (2013). Apple Forensics-iPhone, iPod, and iPad Forensics. Retrieved from binary item: http://www.binaryintel.com/apple-forensics-iphone-ipod-ipad-forensics/ on August 28, 2017
Caloyannides, M. & Caloyannides, M. (2014). Privacy protection and computer forensics (1st ed.). Boston: Artech House.
Data, A. (2015). “Forensic Toolkit (FTK).
DeFranco, J. F. ( 2014). What every engineer should know about cybersecurity and digital forensics. Boca Raton: CRC Press.
Patil, A.M. (n.d) Data mining techniques for Digital Forensic Analysis. International Journal on Recent and Innovation Trends in Computing and Communication ISSN: 2321-8169, 6
Walnycky, D., Baggili, I., Marrington, A., Moore, J., & Breitinger, F. (2015). Network and device forensic analysis of android social-messaging applications. Digital Investigation, 14, S77-S84.