An empirical comparison of data recovered from mobile forensic toolkits

被引:9
作者
Glisson, William Bradley [2 ]
Storer, Tim [1 ]
Buchanan-Wollaston, Joe [1 ]
机构
[1] Univ Glasgow, Sch Comp Sci, Glasgow G12 8QQ, Lanark, Scotland
[2] Univ Glasgow, Sch Humanities, Glasgow G12 8QQ, Lanark, Scotland
关键词
Digital forensics; Empirical comparison; Data recovery; Mobile devices; Smartphones; CHALLENGES; TRUST; PHONE;
D O I
10.1016/j.diin.2013.03.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Mobile devices are increasingly being used as a source of digital evidence in criminal investigations. Mobile forensic toolkit manufacturers have responded to this trend by developing recovery methods capable of recovering evidence from the ever growing range of mobile device models. However, there is a considerable amount of concern as to the reliability of evidence produced from forensic software, with a number of authors documenting difficulties verifying evidence when it is obtained. This paper reports on a comparison of data recovered by a selection of software based methods available in three mobile device forensic toolkits. The results provide the first empirical evidence that there is considerable variation in results between recovery methods in terms of the proportion of data recovered from different devices by different toolkits. In addition, the results suggest that a forensics investigator will face serious challenges verifying the data recovered using one method using the data recovered by another. (c) 2013 Elsevier Ltd. All rights reserved.
引用
收藏
页码:44 / 55
页数:12
相关论文
共 38 条
[1]  
Allen T, 2008, GSM MOBILE DEVICE AS
[2]  
Andrews J, 2003, KERNEL BACK DOOR ATT
[3]  
[Anonymous], 2011, ENCASE FOR PROD
[4]  
[Anonymous], FIND REG MARK EV MAY
[5]  
[Anonymous], 2011, Android Forensics Investigation, Analysis, and Mobile Security for Google Android
[6]  
Ball C, 2008, PRODUCT REV ELECT DA
[7]  
Bratus S, 2010, LECT NOTES COMPUT SC, V6101, P396, DOI 10.1007/978-3-642-13869-0_29
[8]  
Carrier B., 2002, Open source digital forensics tools: The legal argument
[9]  
Cellebrite, 2011, UN FOR EX DEV PROD
[10]   An analysis of the accuracy and usefulness of Vinetto, Pasco and Mork.pl [J].
Childs, Dave ;
Stephens, Paul .
INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2009, 2 (02) :182-198