The growing need for on-scene triage of mobile devices

被引:30
作者
Mislan, Richard P. [1 ]
Casey, Eoghan [2 ]
Kessler, Gary C. [3 ]
机构
[1] Purdue Univ, Coll Technol, Dept Comp & Informat Technol, Ctr Educ Res Informat Assurance & Secur, W Lafayette, IN 47907 USA
[2] Johns Hopkins Univ, Informat Secur Inst, Baltimore, MD 21218 USA
[3] Edith Cowan Univ, Sch Comp & Informat Sci, Churchlands, WA 6018, Australia
关键词
Mobile device forensics; Cell phone forensics; On-scene triage inspection; Mobile device technician;
D O I
10.1016/j.diin.2010.03.001
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The increasing number of mobile devices being submitted to Digital Forensic Laboratories (DFLs) is creating a backlog that can hinder investigations and negatively impact public safety and the criminal justice system. In a military context, delays in extracting intelligence from mobile devices can negatively impact troop and civilian safety as well as the overall mission. To address this problem, there is a need for more effective on-scene triage methods and tools to provide investigators with information in a timely manner, and to reduce the number of devices that are submitted to DFLs for analysis. Existing tools that are promoted for on-scene triage actually attempt to fulfill the needs of both on-scene triage and in-lab forensic examination in a single solution. On-scene triage has unique requirements because it is a precursor to and distinct from the forensic examination process, and may be performed by mobile device technicians rather than forensic analysts. This paper formalizes the on-scene triage process, placing it firmly in the overall forensic handling process and providing guidelines for standardization of on-scene triage. In addition, this paper outlines basic requirements for automated triage tools. (C) 2010 Elsevier Ltd. All rights reserved.
引用
收藏
页码:112 / 124
页数:13
相关论文
共 23 条
[1]  
ACPO, 2008, GOOD PRACT GUID COMP
[2]  
[Anonymous], 2009, WORLD POP DAT SHEET
[3]  
BISCHOFF L, 2009, CELLPHONE SEARCHES
[4]   What does "forensically sound" really mean? [J].
Casey, Eoghan .
DIGITAL INVESTIGATION, 2007, 4 (02) :49-50
[5]   Investigation Delayed Is Justice Denied: Proposals for Expediting Forensic Examinations of Digital Evidence [J].
Casey, Eoghan ;
Ferraro, Monique ;
Nguyen, Lam .
JOURNAL OF FORENSIC SCIENCES, 2009, 54 (06) :1353-1364
[6]  
*CTIA, 2009, WIR ASS ANN SEM WIR
[7]  
DELAITRE A, 2008, 7516 NISTIR
[8]   Forensic feature extraction and cross-drive analysis [J].
Garfinkel, Simson L. .
DIGITAL INVESTIGATION, 2006, SUPPL. (71-81) :S71-S81
[9]  
Gershowitz A., 2008, IPHONE MEETS 4 AMEND
[10]  
JANSEN W, 2006, SPECIAL PUBLICATION