6.1 Mobile Security (Security Management issues) Flashcards
Describe the capabilities of a mobile device
Powerful computers & communication devices
Storage processing & other capabilities (location functions, camera / video, calendar, clock)
Very useful tools for work & social activity
What are the possible peculiar permission requests in terms of dangerous permissions?
CALL_Phone GET_Accounts INSTALL_Packages MANAGE_Accounts READ_Contacts WRITE_Contacts WRITE_Calendar
What are the possible peculiar permission requests in terms of initial findings?
Case of security apps
Case of children’s gaming apps
Case of gaming apps
What are the elements of a Feature Phone?
Fixed set of features
Handset capabilities can’t be added or improved
What are the elements of a Smartphone?
Capabilities can be improved
Customised via updates
Increases functionality
Where can (data) evidence be located?
Data can be physically stored in 3 different locations (SIM, Handset, Memory Card)
Some types of data can be found in more than 1 location (contacts on SIM & handset, pictures on handset & memory card)
Describe the Identification of mobile security
Securing & evaluating the scene (identify all related evidence)
- If the device is off, leave it off (remove battery - keep with the phone)
- If device is on, leave it on
- 1 Switch to airplane mode
- 2 Change autolock to never
- 3 Use cellular network isolation card to replace SIM card; put device in Faraday bag
- 4 Gather all password information
Describe the Preservation of mobile security
Mobile technology data = volatile (data can be lost by) User selective deletion App/OS updates Factory reset simple & effective Remote wipe capability
Deleted data may not be recoverable
Security on the device
Wear levelling of NAND technology
Describe the Collection of mobile security
Mobile devices need to be identified by the make, model, and service provider Logical imaging copies active file system (only the allocated data) from device to another file Physical acquisition creates a bit by bit copy of data storage - used to recover deleted data Acquisition tools (Paraben (SIM card), Encase, XRY, Oxygen)