Midterm Exam Flashcards
What is Digital Forensics?
A branch of forensic science focusing on the recovery and investigation of raw data residing in electronic or digital devices.
Forensically Sound
Original Evidence has not been modified.
Difficult on mobile devices.
Procedures have to be tested, validated, and documented.
3 Main Categories of Mobile Forensics
Seizure.
Acquisition.
Examination/Analysis.
Biggest Challenges to Mobile Forensics
Data can be accessed, stored, and synchronized across multiple devices.
Difficulties in Obtaining Mobile Data: Devices
Hardware/OS differences.
Generic state of device.
Dynamic nature of devices.
Alteration of data/device.
Difficulties in Obtaining Mobile Data: Remote Access
Wipes and resets.
Communication shielding.
Difficulties in Obtaining Mobile Data: Resources
Lack of resources.
Lack of available tools.
Legal issues.
Difficulties in Obtaining Mobile Data: Security
Security features.
Anti-forensics techniques.
Passcode recovery.
Malicious programs.
Mobile Evidence Extraction Process: About
Extractions of each mobile device may differ.
A consistent examination process should be followed.
There is no well established standard process.
All methods used should be tested, validated, and
documented.
Mobile Evidence Extraction Process: Steps
Intake. Identification. Preparation. Isolation. Processing. Verification. Document and Reporting. Presentation. Archive.
Mobile Evidence Extraction Process: Intake
Starting phase.
Documents ownership information and the type of
incident the mobile device was involved in.
Outlines the type of data or information needed.
Developing specific objectives for each examination is the critical part of this phase.
Mobile Evidence Extraction Process: Identification
Legal authority. Goals of the examination. Make, model, and identifying information of device. Removable and external data storage. Other sources of potential evidence.
Mobile Evidence Extraction Process: Preparation
Research appropriate methods and tools to be
used on the particular mobile device.
Mobile Evidence Extraction Process: Steps: Isolation
Isolation before acquisition and examination of the device is important.
Multiple methods of isolation possible.
Some methods are more preferred than others.
Mobile Evidence Extraction Process: Processing
The phone should be acquired using a tested method
that is repeatable and as forensically sound as possible.
Physical acquisitions are most preferred.
Least amount of changes to the device.
File system or logical extractions next best methods.
Mobile Evidence Extraction Process: Verification
Verify the data in the extraction is accurate by comparing to data on the mobile device:
Comparing extracted data to the handset.
Using multiple tools and comparing results.
Using hash values.
Mobile Evidence Extraction Process: Documents and Reporting
Documentation should be done throughout the
examination process.
After examination is complete, peer-review results.
Mobile Evidence Extraction Process: Presentation
Information extracted and documented should be
able to be clearly presented.
Findings should be clear, concise, and repeatable
Some tools include features that can help explain
findings across multiple devices.
Mobile Evidence Extraction Process: Archive
Preserving extracted data is important.
Retained in a usable format.
Remember court cases can go on for years.
Digital forensics tools are always advancing.
4 Main Types of Operating Systems
Google Android.
Apple iOS.
RIM Blackberry.
Windows.
5 Levels of Mobile Forensics Tools
Manual Extraction. Logical Analysis. Hex Dump. Chip-off. Micro-Read.
3 Data Acquisition Methods
Manual.
Logical.
Physical.
5 General Rules of Evidence for Digital Evidence
Admissible. Authentic. Complete. Reliable. Believable.
Leading Operating System for Smart Phones
Android.
Easiest Way to Identify iDevice Hardware
Observing the model number displayed on the back of the device.
What is the iOS Filed System Built on?
HSF Plus.
HSF.
What are the 2 Partitions of the File System? iOS
System.
Data.
What was the Original iPhone OS Originally Called?
Alpine?
What was the Original iPhone OS Originally Called?
OS X.