A Review of Mobile Forensic Investigation Process Models

被引:28
作者
Al-Dhaqm, Arafat [1 ,2 ]
Abd Razak, Shukor [1 ]
Ikuesan, Richard Adeyemi [3 ]
Kebande, Victor R. [4 ]
Siddique, Kamran [5 ]
机构
[1] Univ Teknol Malaysia UTM, Sch Comp, Fac Engn, Skudai 81310, Malaysia
[2] Aden Community Coll, Dept Comp Sci, Aden, Yemen
[3] Community Coll Qatar, Sch Informat Technol, Dept Cyber & Networking Secur, Sci & Technol Div, Doha, Qatar
[4] Malmo Univ, Comp Sci & Media Technol Dept, S-21118 Malmo, Sweden
[5] Xiamen Univ Malaysia, Informat & Commun Technol Dept, Sch Elect & Comp Engn, Kuala Lumpur 43900, Malaysia
关键词
Smart phones; Analytical models; Unified modeling language; Tools; Digital forensics; Mobile forensics; investigation process model; digital forensics; GENERAL COLLECTION METHODOLOGY; DATA-ACQUISITION; SMART PHONE; READINESS; MEMORY; DESIGN; TOOL;
D O I
10.1109/ACCESS.2020.3014615
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Mobile Forensics (MF) field uses prescribed scientific approaches with a focus on recovering Potential Digital Evidence (PDE) from mobile devices leveraging forensic techniques. Consequently, increased proliferation, mobile-based services, and the need for new requirements have led to the development of the MF field, which has in the recent past become an area of importance. In this article, the authors take a step to conduct a review on Mobile Forensics Investigation Process Models (MFIPMs) as a step towards uncovering the MF transitions as well as identifying open and future challenges. Based on the study conducted in this article, a review of the literature revealed that there are a few MFIPMs that are designed for solving certain mobile scenarios, with a variety of concepts, investigation processes, activities, and tasks. A total of 100 MFIPMs were reviewed, to present an inclusive and up-to-date background of MFIPMs. Also, this study proposes a Harmonized Mobile Forensic Investigation Process Model (HMFIPM) for the MF field to unify and structure whole redundant investigation processes of the MF field. The paper also goes the extra mile to discuss the state of the art of mobile forensic tools, open and future challenges from a generic standpoint. The results of this study find direct relevance to forensic practitioners and researchers who could leverage the comprehensiveness of the developed processes for investigation.
引用
收藏
页码:173359 / 173375
页数:17
相关论文
共 159 条
[1]  
Adeyemi IR, 2014, 2014 INTERNATIONAL SYMPOSIUM ON BIOMETRICS AND SECURITY TECHNOLOGIES (ISBAST), P198, DOI 10.1109/ISBAST.2014.7013121
[2]   Observing Consistency in Online Communication Patterns for User Re-Identification [J].
Adeyemi, Ikuesan Richard ;
Razak, Shukor Abd ;
Salleh, Mazleena ;
Venter, Hein S. .
PLOS ONE, 2016, 11 (12)
[3]  
Ahmed R, 2013, IJARCCE, V2, P1019
[4]  
Al Barghouthy NB, 2014, INT CONF NEW TECHNOL
[5]  
Al Marzougy M, 2013, L N INST COMP SCI SO, V114, P239
[6]   Forensic analysis of social networking applications on mobile devices [J].
Al Mutawa, Noora ;
Baggili, Ibrahim ;
Marrington, Andrew .
DIGITAL INVESTIGATION, 2012, 9 :S24-S33
[7]  
Al-Dhaqm A., 2016, J TEKNOLOGI, V78
[8]   Categorization and Organization of Database Forensic Investigation Processes [J].
Al-Dhaqm, Arafat ;
Abd Razak, Shukor ;
Dampier, David A. ;
Choo, Kim-Kwang Raymond ;
Siddique, Kamran ;
Ikuesan, Richard Adeyemi ;
Alqarni, Abdulhadi ;
Kebande, Victor R. .
IEEE ACCESS, 2020, 8 :112846-112858
[9]  
Al-Dhaqm A, 2018, 2018 IEEE CONFERENCE ON APPLICATION, INFORMATION AND NETWORK SECURITY (AINS 2018), P75, DOI 10.1109/AINS.2018.8631468
[10]   CDBFIP: Common Database Forensic Investigation Processes for Internet of Things [J].
Al-Dhaqm, Arafat ;
Razak, Shukor ;
Othman, Siti Hajar ;
Choo, Kim-Kwang Raymond ;
Glisson, William Bradley ;
Ali, Abdulalem ;
Abrar, Mohammad .
IEEE ACCESS, 2017, 5 :24401-24416