The Different Data Extraction Methods for Mobile Devices
For several decades, pulling forensically-sound data from cell phones,
smartphones, and other personal devices was virtually impossible. Now,
mobile forensic analysts can extract live data from these electronics and
recover deleted passwords and files.
No matter if your law firm needs to extract pertinent information from a cell
phone, tablet, GPS unit, memory card, or other personal devices, our ESI
specialists are experts at retrieving mobile data. We use three methods for
gathering information from mobile devices: logical extraction, filesystem
extraction, and physical extraction.
An Explanation of Logical Extraction
Logical extraction is the process of pulling valuable information from a cell
phone, tablet, or another mobile device by communicating with the device’s
operating system using an Application Programming Interface (API).
Extracting data this way is easy and less time-consuming than the other
extraction methods. However, the logical extraction method cannot recover
deleted data or be used on locked devices.
If our digital forensics experts determine logical extraction will work on the
mobile device related to your case, we will use this process to extract data
such as call and text logs, passwords for active social media accounts, saved
photos and videos, and IMEI and ESN data. We’ll ensure the data is
preserved in its original state and is admissible in court.
An Overview of Filesystem Extraction
The filesystem extraction process is very similar to the logical extraction
process. The main difference is that filesystem extractions do not require an
API to access files on the mobile device’s internal memory. Because this
method allows direct access to the internal memory, forensic investigators
can pull all files from the memory, including database and system files. This
extraction method is helpful for analyzing file structure, web browsing
history, and app usage.
A filesystem extraction could help recover deleted data that was part of a
database, such as iMessages or Calendar events. The data is marked as
deleted in the database so that it is no longer visible to the user. However,
for a short period of time, the information is still intact and can be
recovered. Once the database performs routine maintenance, the data will
no longer be recoverable with filesystem extraction.
A Review of Physical Extraction
Physical extraction is a more complex method than logical extraction, but it
returns more results. Specifically, this method is useful for recovering
hidden or deleted information on mobile devices. Tools used during this
process will create bit-for-bit replicas of the content on the flash memory to
offer a clear picture of the digital evidence.
Using boot loaders, the UFED can bypass system locks and passcodes to
pull deleted passwords, files, photos, videos, text messages, call logs, GPS
tags, and more. The best part about a physical extraction is that there are
no signs of an investigation left behind after the extraction is complete. The
data is left forensically intact and untampered to ensure the investigation is
not compromised.
There are three types of extractions that may be performed on a mobile
device: logical, filesystem, and physical. The feasibility of these three types
of extractions depends upon the make, model and operating system of the
mobile device.
What is a Logical Extraction?
Logical Extraction is the quickest and most supported extraction method. In
a logical extraction, the forensic tools interact with the operating system of
the mobile device using an API (Application Programming Interface). This
API (Application Programming Interface) is tool that 7interacts with the
software of the mobile. There are two kinds of the Softwares in a mobile.
The first one is the base Software called its OS. Second class of Softwares
are installed to work as per the commands of the base Software i.e., the OS.
These second class Softwares are the applications or Apps. And the API
(Application Programming Interface) communicates with both the Softwares
i.e., the OS and the Apps.
The extractor can extract most of the live data on the device e.g. SMSs
(Short Messaging Service, commonly known as text messages), call logs,
MMS(Multimedia Messaging Service, which are generally text messages
with attachments or group text messages), Apps without password etc. The
extracted data is output into a readable format.
There is one interesting aspect of the Logical Extraction. Individual items
cannot be extracted, the whole class will be extracted. For example one can
choose to extract SMS data, but all SMS will be collected not just
conversations between specific people or phone numbers.
In Logical Extraction only the live data i.e. the data available in the device
will be extracted. Any password protected data or deleted data will not be
available to the Logical Extraction.
What is a Filesystem Extraction?
The filesystem extraction is more data extracting method if compared to the
Logical Extraction. In Logical Extraction the data of a device was extracted
with an an API (Application Programming Interface) and hence only that
much data could be extracted which was within the reach of that API.
In File System Extraction the data of the device is not approached through
an API and hence, the limitations of the API is not a bar here. On the other
hand the data is approached through the Forensic Tools used by the
extractor. Now the extractor can reach deeper levels of data.
In the File System Extraction the access to the data inside a device is direct
and without any API hence the Forensic Tools can extract all files present
in the internal memory including the database files, system files and logs.
File System Extraction can examine the file structure, the web browsing
including history and downloads and logins, usage of Apps, their history
and chats etc.
The most important part of a File System Extraction is the full access to the
database files on a mobile device. Numerous applications, such as
iMessage, SMS, MMS, Calendar and others, store their information in
database files. When a user deletes data that is part of a database, such as
SMS, the entry within this database is marked as deleted and is no longer
visible to the user. This deleted data remains intact within the database and
is recoverable until the database performs routine maintenance and is
cleaned up. Once this process occurs the data is no longer recoverable.
What is a Physical Extraction?
The Physical Extraction is the most inclusive kind of extraction. This is the
most extensive but least supported extraction method. Physical extraction is
least supported because getting full access to the internal memory of a
mobile device is completely dependent upon the operating system and
security measures employed by the manufacturer like Apple and Samsung.
The OS of Samsung phones is based on an open source system called
Android. It gives more access to the Forensic Tools. But there are some
other OS e.g. iOS, Symbian, BlackBerry, Kai OS, Windows Mobile,
Sailfish etc. which are not open source OS. Even the latest Forensic Tools
like Cellebrite cannot penetrate them. All iOS 7 onwards are difficult to
access the complete Physical Extraction of the device. Now iOS 11 onwards
are completely extraction proof OS.
A physical extraction from a mobile device shares the same basic concept as
the physical forensic imaging of a computer hard drive. A physical
extraction performs a bit-by-bit copy of the entire contents of the memory of
a device. This extraction allows for the collection of all live data and also
data that has been deleted or is hidden.
By having a bit-by-bit copy, deleted data can be potentially recovered .This
means that data that resides outside of the active user data and database
files, such as: images, videos, installed applications, location information,
emails, and more are able to be extracted and deleted versions of these
items may be recovered as well.
Methodology used by Forensic Experts
The Forensic Experts use different kinds of techniques to reach the
innermost data of your Mobile Phone. In Logical Extraction they use API
(Application Programming Interface) and in the remaining two extractions
i.e. the File System Extraction and the Physical Extraction they bypass the
OS of the device. This is done at a stage just before the OS of device starts
to set in. The stage is called BOOTLOADER.
Bootloader
The Bootloader is the first thing that starts up when a device is turned on.
At its most basic level, a Bootloader is the low-level software on your device
that allows the next Software on your device i.e. OS to run. Without a
Bootloader your OS will not run and you will not be able to see the Graphic
User Interface (GUI) on your mobile.
Forensic Tools
The Forensic Experts use their Forensic Tools to disturb the working of
Bootloader. In the normal course of working a Bootloader prompts the OS
to start. But the Forensic Tools used would give a command to the
Bootloader not to prompt the OS of the device rather they force their own
different OS to start and fetch the data available in device.
Data Extraction
Here, onwards everything depends upon the comparative penetrating
power of the tools employed by the Forensic Experts and the structure in
which the data of the device is kept in the internal memory i.e. the file
structure.
Even the latest tools are unable to fetch data from some closed source of
OS e.g. iOS, Symbian, BlackBerry.
Forensic Tools for Mobile Phone
Oxygen Forensic Detective
Oxygen Forensic Detective is capable of extracting data from a number of
different platforms, including mobile, IoT, cloud services, drones, media
cards, backups and desktop platforms.
It uses physical methods to bypass device security (such as screen lock) and
collects authentication data for a number of different mobile applications.
Oxygen is a commercial product distributed as a USB dongle.
Cellebrite UFED
Cellebrite offers a number of commercial digital forensics tools, but its
Cellebrite UFED claims to be the industry standard for accessing digital
data. The main UFED offering focuses on mobile devices, but the general
UFED product line targets a range of devices, including drones, SIM and SD
cards, GPS, cloud and more. The UFED platform claims to use exclusive
methods to maximize data extraction from mobile devices.
XRY
XRY is a collection of different commercial tools for mobile device forensics.
XRY Logical is a suite of tools designed to interface with the mobile device
operating system and extract the desired data. XRY Physical, on the other
hand, uses physical recovery techniques to bypass the operating system,
enabling analysis of locked devices.
CAINE
CAINE (Computer Aided Investigative Environment) is the Linux distro
created for digital forensics. It offers an environment to integrate existing
software tools as software modules in a user-friendly manner. This tool is
open-source.
SANS SIFT
SIFT is another open-source Linux virtual machine that aggregates free
digital forensics tools. This platform was developed by the SANS Institute
and its use is taught in a number of their courses.
SANS SIFT
SIFT is another open-source Linux virtual machine that aggregates free
digital forensics tools. This platform was developed by the SANS Institute
and its use is taught in a number of their courses.
HELIX3
HELIX3 is a live CD-based digital forensic suite created to be used in
incident response. It comes with many open-source digital forensics tools,
including hex editors, data carving and password-cracking tools. If you want
the free version, you can go for HELIX3 2009 R 1. After this release, this
project was taken over by a commercial vendor. So, you need to pay for the
most recent version of the tool.
This tool can collect data from physical memory, network connections, user
accounts, executing processes and services, scheduled jobs, Windows
Registry, chat logs, screen captures, SAM files, applications, drivers,
environment variables and internet history. Then it analyzes and reviews
the data to generate the compiled results based on reports.
The Manual Extraction techniques (Level 1), comprises merely of recording
information from the mobile phone screen while utilizing user interface.
Logical Extraction methods or the Level 2 are usually utilized regularly and
slightly technical, calling for the beginner-level or new user training.
The Hex Dumping or the JTAG Extraction techniques (Level 3), a working
“physical acquisition” of the mobile memory in situ, mostly calls for
advanced or sophisticated training.
Chip-Off methods (Level 4) comprises of removal of the physical memory
from mobile phone to the extraction of data, which necessitates or calls for
extensive or broad range training in the electronic engineering as well as
file system forensics.
Micro Read methods (Level 5) comprises of utilization of high-powered
microscope in viewing the physical state of the gates. These methods are
the most invasive, sophisticated, technical, expensive, and time-consuming
of all the methodologies.
Understanding the Pros and Cons
Based on7https://articles.forensicfocus.com/2014/10/28/extracting-data-
from-dump-of-mobile-devices-running-android-operating-system/,7there exist
different benefits and drawbacks for carrying out extraction forms at every
layer.
For instance, the hex dumping permits the deleted objects as well as any
data remnants in existence to be assessed (such as the in unallocated file
system space of the unallocated memory), which would otherwise be
inaccessible via the utilization of the logical acquisition techniques.
Nonetheless, extracted device figures call for parsing, decoding, and
decryption. The logical acquisition techniques, though a bit limited than the
Hex Dumping or the JTAG techniques, have benefits in that these system
data arrangements are at higher levels of the abstractions and they are
quite more comfortable for the tool in rendering and extracting.
The variances are as a result of underlying diversion in between the
memory as viewed by the procedure through operating system facilities,
versus the memory as viewed in the raw form by processors or other
hardware elements.
From the broader range of situations such as the form of data required,
available tools, urgency, time available and so forth, the examiner or
assessor might choose a particular level to start their assessment. It is
significant to understand that once the level is utilized, other levels might
be impossible. For instance, after conducting the chip-off, lower level, might
not be at any point look physically possible.
The forensic assessor ought to be aware of or informed of such problems
and carry out the suitable level of the extraction correspond with some of
their experiences and training. With every technique, the data might always
be modified or destroyed in case a specific procedure or tool is improperly
used. The risk of destruction and alterations rises in line with specific
levels.
Therefore, appropriate mentoring and training are crucial in accessing the
highest rate of success for the analysis and extraction of data in mobile
phones.
Manual Extraction
The manual extraction technique of the data comprises of viewing data
components contained in the mobile phones. Some of the content contained
on LCD screen calls for manual manipulation of the keyboard, touchscreen
or buttons in viewing contents on the mobile phones. The information
retrieved might be reported through external cameras.
7Following up on7http://www.foodqualitynews.com/Lab-Technology/Analytik-
Jena-tech-now-available-for-manual-extraction, at this extraction level, it is
impossible to recover deleted information. Some tools have been developed
to provide the capacity of categorizing and documenting information
reported more swiftly.
However, in case there is a relatively massive amount of the information or
data, manual extraction could be time-consuming or wasting, and data
contained within the mobile device might be inadvertently overwritten,
modified or deleted due to assessment. The manual extractions turn out to
be increasingly hectic and perhaps unattainable whenever encountering
missing or broken LCD screen or missing or damaged keyboard interface.
In addition, many obstacles take place whenever the mobile device is
sometimes configured in displaying languages unknown to an assessor,
which might result in difficulties in fruitful menu navigation.
Logical Extraction
Logical extraction of data is performed through the device's designated API
(Application Programming Interface), available from the device vendor. The
connectivity in between the mobile phone and forensic workplace is usually
accomplished with a connection utilizing either wired such as RS-232 or
USB or wireless such as WiFi, Bluetooth or IrDA) connections. Generally,
the assessor must be fully aware of some of the issues linked with a
selection of particular connectivity techniques since diverse connection
forms as well as related protocols might leads to data or information being
modified or diverse forms or types of the information being extracted.
Upon the connection, the UFED is said to load significant API in the mobile
phones. The UFED later make the read-only API calls in requesting the
relevant information from devices. Later devices provide replies to the valid
or appropriate requests in extracting designated content from operating
systems utilizing the relevant set of the commands. This implies that the
data extraction components communicated with the mobile phone’s
operating system requesting relevant information from this system. Such
procedure enhances acquisition of relevant or most live data within the
mobile phone, in a readable format as well as in forensically sound mean.
The form of the data comprises of call logs, phone details, passwords,
phonebook entries, videos, apps data from the Android devices, SMS, audio
files, SIM deleted call logs, images and so forth. In most scenarios, the
logical extraction is impossible for the locked devices.
Additionally, logical extraction technique is technically quicker and more
comfortable for the tool to operate, since it is mostly limited to the amount
of the data it could extract, unlike the physical extraction techniques.
Within a specific market, the Cellebrite’s tools usually enhance logical
extraction from the broadest range of the devices, memory cards, phones,
portable GPS devices as well as tablets produced with the Chinese chipsets.
Hex Dumping as well as the JTAG
The Hex Dumping as well as the JTAG extraction techniques usually afford
forensic assessors a more direct admittance to raw information recorded
within the memory. The chief problem with such extraction technique is the
capacity of the provided tool in decoding and parsing captured data or
information. In addition, provision of logical views of the file system as well
as reporting on the other information remnants externally from the file
system to forensic assessor might be challenging. For instance, all the
information in a provided flash memory might not necessarily be acquired
since numerous tools like flasher boxes might just be capable of extracting
particular sections of the memory. The techniques utilized at such level
need connectivity such as WIFI or cable between the mobile phone and
forensic workplace.
Bases on7https://articles.forensicfocus.com/2014/10/28/extracting-data-
from-dump-of-mobile-devices-running-android-operating-system/,-the Hex
Dumping approach is a more frequently utilized technique at such level.
Such comprises of uploading modified bootloaders in a protected area of the
memory such as the RAM on mobile phones. The upload procedure is
usually achieved by connecting the mobile phone’s data port to the flasher
box, and later flasher box is connected to the forensic workplace. Numerous
commands are then sent from flasher box to mobile phone in order to place
the device in diagnostic mode. After it is turned in the diagnostic mode,
flasher box then captures all of the memory and later send the information
gathered to the forensic workplace through similar communications line
utilized for upload. Some of the flasher boxes usually function in this
manner, or they might utilize a proprietary edge for the memory
extractions. Uncommon scenarios exist where the extractions could be
achieved through WiFi techniques.
A good number of the producers are said to support JTAG standards that
describes common test interface for memory, processor as well as the other
semiconductors chips. The forensic assessors could communicate with the
JTAG-compliant element by using some particular purpose individual
programmer component in probing the defined test points such as the
Wil05. Generally, the JTAG testing unit could be utilized in requesting
memory addresses from JTAG-compliant constituent and accepting a role
for rendition and storage.
The JTAG offers the specialists other avenues for the imaging devices which
are mostly locked or the devices which might have minor damages and
could not be appropriately interfaced otherwise. Such technique comprises
of attaching the cable from the workplace to mobile phone’s JTAG interface
as well as accessing the memory through phone’s microprocessor in
producing images. The JTAG extractions vary from the Hex Dumping where
it is usually invasive as the access to connection regularly need assessors to
dismantle most or some of the devices in obtaining admittance in
establishing wiring connections.
The flasher boxes are usually small components mostly designed with the
aim of upgrading or servicing the mobile phones. The material acquisitions
usually call for the use of the flasher boxes in facilitating the extraction of
the data. These flasher boxes assist forensic assessors by communicating
clearly with mobile phones utilizing the diagnostic protocol in
communicating with memory chips. Such communication might make use of
the mobile phone’s operating system or might bypass it together and
communicate to a memory chip that is Jon10. The flasher boxes are usually
accompanied by the software in order to simplify data extraction working in
line with hardware. Numerous flasher box packages offer added
responsibility of recovering the passwords from mobile memory as they do
in most configurations. Though the acquisition technique varies in between
the flasher boxes, the general procedure is utilized.
Some of the drawbacks of using the flasher boxes comprise of:
Rebooting of devices is regularly needed to start the extraction; this
might result in authentication mechanisms in activating prevention of
further analysis.
Numerous flasher boxes retrieved data within encrypted format
necessitating assessor to use either the software produced by the in
decrypting data or might need reverse engineering data encryption
scheme.
A good number of the mobile models fail to offer acquisition of whole
memory range in a provided mobile phone. Only particular ranges
might be availed for specific mobile phones.
Flasher box software usually has numerous buttons with almost
similar names. Such confusion might lead experienced assessor
pressing wrong or erasing the contents from the phone rather than
dumping their memory chip.
The absence of proper documentation on the utilization of flasher
boxes is most common. The extraction techniques or approaches are
regularly shared on the forums which are mostly supported by
vendors and are moderated by most seasoned users.7 Therefore,
caution ought to be undertaken whenever advice is offered since not
all data offered are accurate.
The forensic utilization: almost all the flasher box models were not
necessarily designed with forensic utilizations as all its projected
purpose. The assessor should be proficient in the of the flasher boxes
and ought to comprehend appropriate function and use of the flasher
box.
In spite of all the aforementioned limitations, utilization of the flasher
box models is a crucial option for numerous forensic scenarios.
Appropriate training, understanding, experience how tools function is
crucial.
A broad range of the technical professionals as well as appropriate training
is needed for analyzing and extracting the binary images with such
techniques, comprising of connecting and locating to the JTAG ports,
creating some customized boot-loaders as well as recreating the file
systems.
Chip-Off
Based on
https://securitycommunity.tcs.com/infosecsoapbox/articles/2015/11/04/
mobile-forensics-data-acquisition-methods, the Chip-Off techniques are
described as the acquisition of the data or information directly from the
mobile phone’s flash memory. Such extraction calls for physical deletion of
the flash memory.
The Chip-Off offers the assessors with a capacity of creating binary images
of the detached chip. In offering assessor with information or data in
adjoining dualistic format files, the wearing-leveling algorithm should be the
converse engineered.
Once comprehensively complete, binary images might be examined. Such
form of the acquisition is usually closely linked with the physical imaging as
the hard disk drive as in the traditional digital forensics. Comprehensive
training is necessary to conduct extractions at such level successfully. The
Chip-Off extractions are usually challenging on the basis of the full range of
the chip forms, a myriad of the raw data forms, and risk of the causing
physical impairment to chip during extraction procedures. As a result of
complexities linked with the Chip-Off, the JTAG extraction is relatively more
common.
Micro Read
The Micro Read comprises of recording of physical observation of gates on
NOR or NAND chip with the utilization of electron microscope. Because of
extreme technicalities which are involved while carrying out the Micro
Read, such level of the acquisition could just be tried for relatively higher
profile scenarios equal to the national security crisis once all the other
acquisition methods are drained. At this level, the successful acquisition
would call for the team of professionals, an in-depth comprehension of the
proprietary data, time and proper equipment. There is hardly any public law
enforcement body in the US conducting acquisition at such level. Presently,
no Micro Read tools are commercially available.
Bibliography
Gerber, M. and von Solms, R (2005). "Management of risk in the
information age."
Johnston, A.C. & Warkentin, M., 2010. Fear Appeals and Information
Security Behaviors: An Empirical Study.
NIST. (2009). "Recommended Security Controls for Federal Information
Systems and Organizations."
Shedden, P., Ruighaver, A.B., Ahmad, A., (2006) Risk Management
Standards ‐ The Perception of Ease of Use.
Tipton HF, Krause M. Information security management handbook.
Auerbach Publications; 2007.