Best practices for identifying and extracting relevant data from mobile devices
Introduction
Mobile devices, such as smartphones and tablets, are often involved in forensic
investigations, as they can store valuable information about the user's activities,
communications, locations, and preferences. However, extracting relevant data from
mobile devices can be challenging, as they have different operating systems, security
features, and data formats. In this article, you will learn some of the best practices for
identifying and extracting relevant data from mobile devices, based on the principles of
digital forensics.
1 Prepare the device
Before you attempt to access the data on a mobile device, it is essential to prepare it
properly to avoid altering or damaging the evidence. You should isolate the device from
any network connections, such as Wi-Fi, Bluetooth, or cellular, to prevent remote wiping
or data synchronization. Additionally, document the physical condition of the device and
take photos of the screen and ports. It is also important to identify the make, model, and
serial number of the device and check if it has any encryption, password, or biometric
protection. Utilize appropriate tools and techniques to bypass or remove the lock
screen, such as brute force, logical acquisition, or physical extraction. Finally, charge
the device sufficiently to avoid power loss during the data extraction process.
Choose the extraction method
Depending on the type and amount of data you want to extract from a mobile device,
you can choose from different extraction methods, each with its own advantages and
limitations. Manual extraction, for instance, is simple and fast, but it can be incomplete
and time-consuming. Logical extraction involves connecting the device to a computer
and using software tools to access and copy the data stored in the device's file system,
yet it can be restricted by the device's security settings or encryption. Physical
extraction is the most complete and reliable method, but it requires specialized
equipment and skills, and may damage the device. Therefore, when selecting an
extraction method, consider your data needs, the device’s security settings, and the
complexity of the process.
Analyze the data
Once you have extracted the data from a mobile device, you need to analyze it to find
the relevant information for your investigation. To ensure the integrity and authenticity of
the data, you should use hashes, timestamps, or digital signatures. You can then
organize and filter the data by using categories, keywords, or criteria to identify what is
relevant. Additionally, interpret and correlate the data by using tools, techniques, or
frameworks to extract meaningful patterns, trends, or anomalies. Finally, report and
present the data in formats like charts, tables, or narratives to communicate your
findings to your audience. Follow the ethical and legal guidelines
Extracting data from mobile devices requires not only technical knowledge, but also an
understanding of the ethical and legal guidelines that apply to the context and
jurisdiction. It is important to obtain proper authorization and consent from the device
owner or custodian, or from a court order or warrant, before accessing or extracting the
data. Additionally, you should respect the privacy and confidentiality of the data and
individuals involved by only accessing and extracting necessary information.
Furthermore, you must document and justify your actions by keeping a detailed record
of the steps taken, tools used, and reasons for accessing and extracting data. Finally,
you must comply with applicable laws and regulations by following standards and
procedures that govern the admissibility of evidence in legal proceedings.
Digital forensics can be a valuable skill for investigators to solve cases, find answers, or
prove facts. However, it can be a challenging skill due to the diversity and complexity of
mobile devices. By following best practices outlined in this article, you can improve your
chances of successfully identifying and extracting relevant data from mobile devices
while respecting ethical and legal principles.
Evidence extraction and forensic examination of each mobile device may differ.
However, following a consistent examination process will assist the forensic examiner to
ensure that the evidence extracted from each phone is well documented and that the
results are repeatable and defendable. There is no well-established standard process
for mobile forensics. However, the following figure provides an overview of process
considerations for extraction of evidence from mobile devices. All methods used when
extracting data from mobile devices should be tested, validated, and well documented.
The evidence intake phase
The evidence intake phase is the starting phase and entails request forms and
paperwork to document ownership information and the type of incident the mobile
device was involved in, and outlines the type of data or information the requester is
seeking. Developing specific objectives for each examination is the critical part of this
phase. It serves to clarify the examiner's goals.
The identification phase
The forensic examiner should identify the following details for every examination of a
mobile device:
The legal authority
The goals of the examination
The make, model, and identifying information for the device
Removable and external data storage
Other sources of potential evidence
We will discuss each of them in the following sections.
The legal authority
It is important for the forensic examiner to determine and document what legal authority
exists for the acquisition and examination of the device as well as any limitations placed
on the media prior to the examination of the device.
The goals of the examination
The examiner will identify how in-depth the examination needs to be based upon the
data requested. The goal of the examination makes a significant difference in selecting
the tools and techniques to examine the phone and increases the efficiency of the
examination process.
The make, model, and identifying information for the device
As part of the examination, identifying the make and model of the phone assists in
determining what tools would work with the phone.
Removable and external data storage
Many mobile phones provide an option to extend the memory with removable storage
devices, such as the Trans Flash Micro SD memory expansion card. In cases when
such a card is found in a mobile phone that is submitted for examination, the card
should be removed and processed using traditional digital forensic techniques. It is wise
to also acquire the card while in the mobile device to ensure data stored on both the
handset memory and card are linked for easier analysis. This will be discussed in detail
in upcoming chapters.
Other sources of potential evidence
Mobile phones act as good sources of fingerprint and other biological evidence. Such
evidence should be collected prior to the examination of the mobile phone to avoid
contamination issues unless the collection method will damage the device. Examiners
should wear gloves when handling the evidence.
The preparation phase
Once the mobile phone model is identified, the preparation phase involves research
regarding the particular mobile phone to be examined and the appropriate methods and
tools to be used for acquisition and examination.
The isolation phase
Mobile phones are by design intended to communicate via cellular phone networks,
Bluetooth, Infrared, and wireless (Wi-Fi) network capabilities. When the phone is
connected to a network, new data is added to the phone through incoming calls,
messages, and application data, which modifies the evidence on the phone. Complete
destruction of data is also possible through remote access or remote wiping commands.
For this reason, isolation of the device from communication sources is important prior to
the acquisition and examination of the device. Isolation of the phone can be
accomplished through the use of faraday bags, which block the radio signals to or from
the phone. Past research has found inconsistencies in total communication protection
with faraday bags. Therefore, network isolation is advisable. This can be done by
placing the phone in radio frequency shielding cloth and then placing the phone into
airplane or flight mode.
The processing phase
Once the phone has been isolated from the communication networks, the actual
processing of the mobile phone begins. The phone should be acquired using a tested
method that is repeatable and is as forensically sound as possible. Physical acquisition
is the preferred method as it extracts the raw memory data and the device is commonly
powered off during the acquisition process. On most devices, the least amount of
changes occur to the device during physical acquisition. If physical acquisition is not
possible or fails, an attempt should be made to acquire the file system of the mobile
device. A logical acquisition should always be obtained as it may contain only the
parsed data and provide pointers to examine the raw memory image.
The verification phase
After processing the phone, the examiner needs to verify the accuracy of the data
extracted from the phone to ensure that data is not modified. The verification of the
extracted data can be accomplished in several ways.
Comparing extracted data to the handset data
Check if the data extracted from the device matches the data displayed by the device.
The data extracted can be compared to the device itself or a logical report, whichever is
preferred. Remember, handling the original device may make changes to the only
evidence—the device itself.
Using multiple tools and comparing the results
To ensure accuracy, use multiple tools to extract the data and compare results.
Using hash values
All image files should be hashed after acquisition to ensure data remains unchanged. If
file system extraction is supported, the examiner extracts the file system and then
computes hashes for the extracted files. Later, any individually extracted file hash is
calculated and checked against the original value to verify the integrity of it. Any
discrepancy in a hash value must be explainable (for example, if the device was
powered on and then acquired again, thus the hash values are different).
The document and reporting phase
The forensic examiner is required to document throughout the examination process in
the form of contemporaneous notes relating to what was done during the acquisition
and examination. Once the examiner completes the investigation, the results must go
through some form of peer-review to ensure the data is checked and the investigation is
complete. The examiner's notes and documentation may include information such as
the following:
Examination start date and time
The physical condition of the phone
Photos of the phone and individual components
Phone status when received—turned on or off
Phone make and model
Tools used for the acquisition
Tools used for the examination
Data found during the examination
Notes from peer-review
The presentation phase
Throughout the investigation, it is important to make sure that the information extracted
and documented from a mobile device can be clearly presented to any other examiner
or to a court. Creating a forensic report of data extracted from the mobile device during
acquisition and analysis is important. This may include data in both paper and electronic
formats. Your findings must be documented and presented in a manner that the
evidence speaks for itself when in court. The findings should be clear, concise, and
repeatable. Timeline and link analysis, features offered by many commercial mobile
forensics tools, will aid in reporting and explaining findings across multiple mobile
devices. These tools allow the examiner to tie together the methods behind the
communication of multiple devices.
The archiving phase
Preserving the data extracted from the mobile phone is an important part of the overall
process. It is also important that the data is retained in a useable format for the ongoing
court process, for future reference, should the current evidence file become corrupt, and
for record keeping requirements. Court cases may continue for many years before the
final judgment is arrived at, and most jurisdictions require that data be retained for long
periods of time for the purposes of appeals. As the field and methods advance, new
methods for pulling data out of a raw, physical image may surface, and then the
examiner can revisit the data by pulling a copy from the archives.
Mobile devices are right in the middle of three booming technological trends: Internet of
Things, Cloud Computing, and Big Data. The proliferation of mobile technology is
perhaps the main reason, or at least one of the main reasons, for these trends to occur
in the first place. In 2015, 377.9 million wireless subscriber connections of smartphones,
tablets, and feature phones occurred in the United States.
Nowadays, mobile device use is as pervasive as it is helpful, especially in the context of
digital forensics, because these small-sized machines amass huge quantities of data on
a daily basis, which can be extracted to facilitate the investigation. Being something like
a digital extension of ourselves, these machines allow digital forensic investigators to
glean a lot of information.
Information that resides on mobile devices (a non-exhaustive list):
Incoming, outgoing, missed call history
Phonebook or contact lists
SMS text, application based, and?multimedia messaging content
Pictures, videos, and audio?files?and sometimes?voicemail messages
Internet browsing history, content, cookies, search history, analytics information
To-do lists, notes, calendar entries, ringtones
Documents, spreadsheets, presentation files and other user-created data
Passwords, passcodes, swipe codes, user account credentials
Historical geolocation data, cell phone tower related location data, Wi-Fi
connection information
User dictionary content
Data from various installed apps
System files, usage logs, error messages
Deleted data from all of the above
One good display of the real-life effectiveness of mobile forensics is the mobile device
call logs, and GPS data that facilitated solving the 2010 attempted bombing case in
Times Square, NY.
What is the mobile forensics process
Crimes do not happen in isolation from technological tendencies; therefore, mobile
device forensics has become a significant part of digital forensics.
Most people do not realize how complicated the mobile forensics process can be in
reality. As the mobile devices increasingly continue to gravitate between professional
and personal use, the streams of data pouring into them will continue to grow
exponentially as well. Did you know that 33,500 reams of paper are the equivalent of 64
gigabytes if printed? Storage capacity of 64 GB is common for today’s smartphones.
The mobile forensics process aims to recover digital evidence or relevant data from a
mobile device in a way that will preserve the evidence in a forensically sound condition.
To achieve that, the mobile forensic process needs to set out precise rules that will
seize, isolate, transport, store for analysis and proof digital evidence safely originating
from mobile devices.
Usually, the mobile forensics process is similar to the ones in other branches of digital
forensics. Nevertheless, one should know that the mobile forensics process has its own
particularities that need to be considered. Following correct methodology and guidelines
is a vital precondition for the examination of mobile devices to yield good results.
Among the figures most likely to be entrusted with the performance of the following
tasks are Forensic Examiners, Incident Responders, and Corporate Investigators.
During the inquiry into a given crime involving mobile technology, the individuals in
charge of the mobile forensic process need to acquire every piece of information that
may help them later – for instance, device’s passwords, pattern locks or PIN codes.
Digital forensics operates on the principle that evidence should always be adequately
preserved, processed, and admissible in a court of law. Some legal considerations go
hand in hand with the confiscation of mobile devices.
There are two major risks concerning this phase of the mobile forensic process: Lock
activation (by user/suspect/inadvertent third party) and Network / Cellular connection.
Network isolation is always advisable, and it could be achieved either through 1)
Airplane Mode + Disabling Wi-Fi and Hotspots, or 2) Cloning the device SIM card.
Airplane mode
Mobile devices are often seized switched on; and since the purpose of their confiscation
is to preserve evidence, the best way to transport them is to attempt to keep them
turned on to avoid a shutdown, which would inevitably alter files.
Phone jammer
A Faraday box/bag and external power supply are common types of equipment for
conducting mobile forensics. While the former is a container specifically designed to
isolate mobile devices from network communications and, at the same time, help with
the safe transportation of evidence to the laboratory, the latter, is a power source
embedded inside the Faraday box/bag. Before putting the phone in the Faraday bag,
disconnect it from the network, disable all network connections (Wi-Fi, GPS, Hotspots,
etc.), and activate the flight mode to protect the integrity of the evidence.
Faraday bag
Last but not least, investigators should beware of mobile devices being connected to
unknown incendiary devices, as well as any other booby trap set up to cause bodily
harm or death to anyone at the crime scene.
Acquisition
/Identification + extraction/
The goal of this phase is to retrieve data from the mobile device. A locked screen can
be unlocked with the right PIN, password, pattern, or biometrics (Note that biometric
approaches while convenient are not always protected by the fifth amendment of the
U.S. Constitution). According to a ruling by the Virginia Circuit Court, passcodes are
protected, fingerprints not. Also, similar lock measures may exist on apps, images,
SMSs, or messengers. Encryption, on the other hand, provides security on a software
and/or hardware level that is often impossible to circumvent.
It is hard to be in control of data on mobile devices because the data is mobile as well.
Once communications or files are sent from a smartphone, control is lost. Although
there are different devices having the capability to store considerable amounts of data,
the data in itself may physically be in another location. To give an example, data
synchronization among devices and applications can take place directly but also via the
cloud. Services such as Apple’s iCloud and Microsoft’s One Drive are prevalent among
mobile device users, which leave open the possibility for data acquisition from there. For
that reason, investigators should be attentive to any indications that data may transcend
the mobile device as a physical object, because such an occurrence may affect the
collection and even preservation process.
Since data is constantly being synchronized, hardware and software may be able to
bridge the data gap. Consider Uber – it has both an app and a fully functional website.
All the information that can be accessed through the Uber app on a phone may be
pulled off the Uber website instead, or even the Uber software program installed on a
computer.
Regardless of the type of the device, identifying the location of the data can be further
impeded due to the fragmentation of operating systems and item specifications. The
open-source Android operating system alone comes in several different versions, and
even Apple’s iOS may vary from version to version. Another challenge that forensic
experts need to overcome is the abundant and ever-changing landscape of mobile
apps. Create a full list of all installed apps. Some apps archive and backup data.
After one identifies the data sources, the next step is to collect the information properly.
There are certain unique challenges concerning gathering information in the context of
mobile technology. Many mobile devices cannot be collected by creating an image and
instead they may have to undergo a process called acquisition of data. Thera are
various protocols for collecting data from mobile devices as certain design specifications
may only allow one type of acquisition.
The forensic examiner should make a use of SIM Card imagining – a procedure that
recreates a replica image of the SIM Card content. As with other replicas, the original
evidence will remain intact while the replica image is being used for analysis. All image
files should be hashed to ensure data remains accurate and unchanged.
Examination and analysis
As the first step of every digital investigation involving a mobile device(s), the forensic
expert needs to identify:
Type of the mobile device(s) – e.g., GPS, smartphone, tablet, etc.
Type of network – GSM, CDMA, and TDMA
Carrier
Service provider (Reverse Lookup)
The examiner may need to use numerous forensic tools to acquire and analyze data
residing in the machine. Due to the sheer diversity of mobile devices, there is no one-
size-fits-all solution regarding mobile forensic tools. Consequently, it is advisable to use
more than one tool for examination. AccessData, Sleuthkit, and EnCase are some
popular forensic software products that have analytic capabilities. The most appropriate
tool(s) is being chosen depending on the type and model of mobile device.
Timeline and link analysis available in many mobile forensic tools could tie each of the
most significant events, from a forensic analyst’s point of view.
All of the information, evidence, and other findings extracted, analyzed, and
documented throughout the investigation should be presented to any other forensic
examiner or a court in a clear, concise, and complete manner.