Top Banner
Intro to Cell Phone Technology
155

Intro to Cell Phone Technology

Mar 26, 2022

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Intro to Cell Phone Technology

Intro to Cell Phone Technology

Page 2: Intro to Cell Phone Technology

Why mobile devices• Mobile forensics dominates the digital forensics landscape

• Some numbers:

– In America we have more than 317 million people and more than 327 million mobile devices. That means 103.1 devices per 100 people.

– 64 percent of American adults own a Smartphone

Page 3: Intro to Cell Phone Technology

Cellular technology

• What is a cell phone?

• What are its composite parts?

Page 4: Intro to Cell Phone Technology

Cellular technology

• How does the concept of cellular communication differ from earlier devices, such as CBs, radio telephones, etc?

• Simplex vs. half-duplex vs. duplex

Page 5: Intro to Cell Phone Technology

• Early radio-phones

• Single tower

• Large power source

• Few channels

• No hand-offs

Page 6: Intro to Cell Phone Technology

Cellular concept

• In the late 50’s engineers at Bell Labs developed a new theory – the cellular system

• Towers at the corners, transmitting in three directions, forming hexagonal cells

• Technology did not exist at that time to support the theory

Page 7: Intro to Cell Phone Technology
Page 8: Intro to Cell Phone Technology

Cellular concept

• And where are the towers located?

Page 9: Intro to Cell Phone Technology
Page 10: Intro to Cell Phone Technology

Cellular concept

• Three-sided towers, each side covering 120 degrees, to combine to cover a 360 degree circle

Page 11: Intro to Cell Phone Technology
Page 12: Intro to Cell Phone Technology

Cellular concept

• These cells work together to provide more complete coverage

• Much smaller range = less power needed by device = smaller battery = smaller device

• Frequency re-use

Page 13: Intro to Cell Phone Technology

Cellular concept

• As a mobile device reaches the limit of one tower’s range, and that tower’s signal weakens, the device is “handed off” to the next tower, as that tower’s signal grows stronger

• No need for action from user

Page 14: Intro to Cell Phone Technology

Cellular concept

• Keep in mind, this is a “concept”

• The reality can sometimes look very different

Page 15: Intro to Cell Phone Technology

Propagation map

Page 16: Intro to Cell Phone Technology

Cellular reality

• Sectors are often greater or less than 120 degrees

• Coverage may be affected by• Population

• Geography/Foliage

• Date/Time

• Etc.

Page 17: Intro to Cell Phone Technology

Cellular networks

• In a cellular network, only the last link is wireless

Page 18: Intro to Cell Phone Technology

Cellular networks

• The main control point of a large group of cell towers in one area, is the Mobile Telephone Switching Office (“switch”)

• May control thousands of individual cell sites

Page 19: Intro to Cell Phone Technology

MTSO

• When a cellular device is turned on, it locates a tower and identifies itself to its carrier

• The device transmits certain data to the network to authenticate itself to the network

Page 20: Intro to Cell Phone Technology

MTSO

• The device’s location is maintained by the MTSO, so that it knows where to find the device should someone wish to communicate with it

• The MTSO connects to the Public Switched Telephone Network, and transfer calls to that network to be relayed to the device it is calling

Page 21: Intro to Cell Phone Technology

Cell Tech

• Now, let’s explore some common cell phone terminology

• First, the “generations”…

Page 22: Intro to Cell Phone Technology

1G

• First Generation

• Analog technology

• Introduced in the 1980’s, and were eventually replaced by 2G technology

Page 23: Intro to Cell Phone Technology

Cell Phone Technology

• 1971 – AT&T submits proposal to FCC for advanced cellular service

• Finally approved in 1982.

• Meanwhile, elsewhere…

Page 24: Intro to Cell Phone Technology

1G

• First commercially automated network in 1G was NTT, in Japan, in 1979

• Followed in 1981 by the Nordic Mobile Telephone (NMT)

Page 25: Intro to Cell Phone Technology

1G• Finally, in 1983, AMPS comes to America.

• First network was in Chicago (Ameritech), followed by Washington DC.

Page 26: Intro to Cell Phone Technology

2G

• 2G technologies appear in the 1990’s

• With 2G, we switch from analog to digital.

Page 27: Intro to Cell Phone Technology

Analog vs. Digital

• Analog-electronic transmissions accomplished by varying wavelength frequency or amplitude

• Digital-Refers to transmissions with data being sent as a “positive” or a “non-positive” (1 or 0)

Page 28: Intro to Cell Phone Technology

2G

• Benefits of digital– Compression

– Decreased radio power from handsets

– Reduces fraud

– Enhanced security

– Less interference

– Better penetration through buildings

Page 29: Intro to Cell Phone Technology

2G

• Disadvantages

– Decreased radio power from handsets

– Dropouts vs. Static

Page 30: Intro to Cell Phone Technology

2G

• However, the main benefit of digital networks is….

- Data transmission

Page 31: Intro to Cell Phone Technology

2G

• Several different 2G technologies emerged, using different digital protocols

– GSM

– CDMA

– TMDA

– IDEN

Page 32: Intro to Cell Phone Technology

2G

• 1991 – first GSM network, Radiolinja, in Finland.

Page 33: Intro to Cell Phone Technology

2.5G?

• 2.5G was just an increase in speed, which allowed things like MMS, email, web access.

Page 34: Intro to Cell Phone Technology

3G• First commercial 3G network (GSM) – NTT in

Japan, 2001

• First commercial 3G CDMA network – USA (Monet) and South Korea, 2002

• Second 3G network in USA – Verizon Wireless, July 2002.

Page 35: Intro to Cell Phone Technology

3G

• Primary difference between 2G and 3G –packet switching vs. circuit switching

Page 36: Intro to Cell Phone Technology

3G

• So what does this mean to us?

– Mobile internet access

– Video calls

– Streaming video

Page 37: Intro to Cell Phone Technology

3G

• Now, with increased transmission speeds, we begin to see mobile broadband modems

– PCMCIA, USB

– Wireless routers (MiFi)

Page 38: Intro to Cell Phone Technology

3G

• Devices begin to appear with embedded 3G data capability

– Netbooks

– Kindle, Nook, iPad, tablets

Page 39: Intro to Cell Phone Technology

3G

• 3G also makes possible the introduction of the “smart phone”.

– Apple

– Android

– Blackberry

– …and many others

Page 40: Intro to Cell Phone Technology

3G• 3G was slow to spread

– Some 2G networks were not compatible with the 3G technologies, so all equipment had to be replaced

– By 2007, only 9% of worldwide subscribers were using 3G

Page 41: Intro to Cell Phone Technology

4G

• Main difference between 3G and 4G is (theoretically) the elimination of circuit switching, resulting in an all IP-based network.

Page 42: Intro to Cell Phone Technology

4G

• Various 4G technologies

– HSPA+

– WiMax

– LTE

Page 43: Intro to Cell Phone Technology

4G

• International Telecommunications Union –sets standards for 4G

– All packet switched

– Transmission speeds of 1Gbp/s for stationary units, 100Mbp/s for moving units.

Page 44: Intro to Cell Phone Technology

4G

• 4G technologies should also support IPv6

– IPv4 vs. IPv6

Page 45: Intro to Cell Phone Technology

4G

• IPv4:

–32 bit

– Identified as numbers such as: 209.13.42.145

–Divided by periods

–4.3 billion IP addresses available

Page 46: Intro to Cell Phone Technology

4G

• IPv6:– 128 bit– Identified as letters and numbers such as

2001:db8:85a3::8a2e:370:7334

–Divided by colons–340 Undecillion, or 340 trillion trillion

trillion IP addresses available

Page 47: Intro to Cell Phone Technology

4G

• Current technologies do not meet 4G standards

• However, the ITU has stated that current technologies like LTE and WiMax, although they do not meet standards, could be called 4G, because they represent "a substantial level of improvement in performance and capabilities with respect to the initial third generation systems now deployed.”

Page 48: Intro to Cell Phone Technology

5G

• 5G-Fifth Generation of Wireless.

• Expected to be in place by 2020

• 1GB speed

• Very efficient

• Able to support large amounts of connections

Page 49: Intro to Cell Phone Technology

CDMA vs. GSM

• CDMA – Code Division Multiple Access

• GSM – Global System for Mobile Communication (actually, it’s Groupe SpécialMobile)

Page 50: Intro to Cell Phone Technology

CDMA vs. GSM

• CDMA – most popular technology in the United States

• GSM – most popular technology in the world

Page 51: Intro to Cell Phone Technology

CDMA vs. GSM

• Traditionally, one way to tell the difference was the presence of a SIM card

Page 52: Intro to Cell Phone Technology
Page 53: Intro to Cell Phone Technology

SIM Cards

• What can a SIM card contain?

• Phonebook

• Call logs

• Speed dial

• SMS messages

Page 54: Intro to Cell Phone Technology

SIM cards

• What must a SIM card contain?

• The IMSI

Page 55: Intro to Cell Phone Technology
Page 56: Intro to Cell Phone Technology

ICCID

• Integrated Circuit Card ID (ICCID) – a 19 to 20 digit serial number for a SIM card used to securely store the IMSI number for a subscriber.

• The ICCID is also called the SIM Serial Number.

• It is stamped on the SIM card.

Page 57: Intro to Cell Phone Technology

SIM cards

• New 4G phones from both GSM and CDMA providers will contain a SIM card

• Some older CDMA phones may contain a SIM card to make them “Global” or “World” phones

Page 58: Intro to Cell Phone Technology

CDMA

• Verizon

• Sprint

• US Cellular

Page 59: Intro to Cell Phone Technology

GSM

• AT&T

• T-Mobile

Page 60: Intro to Cell Phone Technology

• What about Tracfone?

• What about Cricket?

Page 61: Intro to Cell Phone Technology

The progression:

1G 2G 3G 4G

CDMAone CDMA200 LTE

Analog

GSM UMTS LTE

Page 62: Intro to Cell Phone Technology

CDMA Identifiers

• Electronic Serial Number (ESN) - The unique identification number embedded in a wireless phone by the manufacturer. Each time a call is placed, the ESN is automatically transmitted to the base station so the wireless carrier's mobile switching office can check the call's validity. MINs and ESNs can be electronically checked to help prevent fraud.

Page 63: Intro to Cell Phone Technology

ESN

Page 64: Intro to Cell Phone Technology

• Mobile Equipment Identifier (MEID) - a globally unique 56-bit identification number for a physical piece of CDMA equipment. MEID’s replaced ESN’s after the original ESN scheme being depleted in 2008.

[email protected]

Page 65: Intro to Cell Phone Technology
Page 66: Intro to Cell Phone Technology
Page 67: Intro to Cell Phone Technology

ESN / MEID

• Many times you will still see providers use the term ESN even thought the number will actually be the MEID.

• These numbers specifically identify the device

Page 68: Intro to Cell Phone Technology

GSM Identifiers

• International Mobile Equipment Identifier (IMEI)-A unique 15-digit number that serves as the serial number of the GSM handset. The IMEI appears on the label located on the back of the phone, and uniquely identifies that device

Page 69: Intro to Cell Phone Technology

GSM Identifiers

• International Mobile Subscriber Identifier (IMSI)-A unique 15-digit number which designates the subscriber. It is stored on the SIM card, and identifies the account holder.

Page 70: Intro to Cell Phone Technology

IMSI

• The first 3 numbers identify the country code, for example the US is code 310.

• The next 3 number will identify the carrier code, for example AT&T code is 410. T-Mobile is code 026.

• Therefore an AT&T IMSI will begin with 310410

Page 71: Intro to Cell Phone Technology

IMEI and IMSI from an AT&T record

Page 72: Intro to Cell Phone Technology

Other important identifiers• Mobile Identification Number (MIN)-Unique identifier that

can be used to identify a cellular phone by the network. The MIN and ESN are both transmitted to the network to assist with authentication.

• Mobile Directory Number (MDN)- The actual number a person would dial to reach a specific phone. (This is your phone number)

Page 73: Intro to Cell Phone Technology

Current relevant operating systems

• iOS

• Android

• Blackberry

• Windows

Page 74: Intro to Cell Phone Technology

iOS

• Apple’s Mobile Operating System.

– Simply called iPhone OS prior to June 2010.

– Based off of the Mac OS

– iPhone, iPad, iPod Touch.

– Currently up to 9.2+

– Forensically:

–DB, SQL and Plists

Page 75: Intro to Cell Phone Technology

Jailbreak

• Some people “jailbreak” iOS devices to allow for greater control and a larger amount of Apps.

• Allows “Root Access” of the device.

• Gives the user greater access to many apps that are not available through the App store.

Page 76: Intro to Cell Phone Technology

Android

• Developed in 2003

• Acquired by Google in 2005.

– Forensically DB, SQL and XML

– Uses the Linux Kernel.

– Similar to iOS devices, many people

want more control, and therefore

“root” the device.

Page 77: Intro to Cell Phone Technology

Android Flavors

• Cupcake (1.5)

• Donut (1.6)

• Éclair (2.0 – 2.1)

• Froyo (2.2)

• Gingerbread (2.3x)

• Honeycomb (3.1 – 3.2)

• Ice Cream Sandwich (4.0)

• Jelly Bean (4.1 – 4.3)

• KitKat (4.4)

• Lollipop (5.0 – 5.1)

• Marshmallow (6.0)

Page 78: Intro to Cell Phone Technology

Blackberry

• Formerly Research in Motion, now Blackberry Limited

– Distributes Blackberry devices.

– Based in Waterloo Canada.

Page 79: Intro to Cell Phone Technology

Blackberry

• Had many government and business contracts

• Strengths were security and handling of email

• Failed to keep up with trends

•Went from 43% market share in 2010 to 1.3% in 2015

• Blackberry 10

Page 80: Intro to Cell Phone Technology

Windows

• Microsoft entry into the smartphone market.

– Windows 8 was designed to integrate the Mobile Devices and the PC’s.

– Lumia series handsets

–Nokia handset running Windows OS

Page 81: Intro to Cell Phone Technology

Windows and Nokia

• On February 11, 2011 Nokia announced that it was migrating away from Symbian towards Windows.

• On September 2, 2013 it was announced that Microsoft was purchasing Nokia’s mobile division for 7.2 billion dollars.

Page 82: Intro to Cell Phone Technology

Number portability

• What is number portability, and why is it important to our investigation?

Page 83: Intro to Cell Phone Technology

Mobile device investigations in 2015

–Mobile forensics vs. traditional computer forensics

–The two aspects of investigating mobile devices

Page 84: Intro to Cell Phone Technology

Mobile digital forensics

• Hardware and software

• Recoverable data

– Feature phones

– Smartphones

Page 85: Intro to Cell Phone Technology
Page 86: Intro to Cell Phone Technology

Application data• What are applications?

• What do they allow us to do?

• What types of devices use them?

• What type of information do they retain?

Page 87: Intro to Cell Phone Technology

Applications

• Some applications can wipe a device remotely

Page 88: Intro to Cell Phone Technology
Page 89: Intro to Cell Phone Technology

There are a large number of applications which give us enhanced communication capabilities

Applications

Page 90: Intro to Cell Phone Technology

Applications

• Other applications allow users to conduct voice communications over the internet.

Page 91: Intro to Cell Phone Technology

• Let’s take a quick look at some application files that might hold important evidence

Page 92: Intro to Cell Phone Technology

WiFi connections…

Page 93: Intro to Cell Phone Technology

Kik messages…

Page 94: Intro to Cell Phone Technology

eBay searches…

Page 95: Intro to Cell Phone Technology

Wikipedia searches…

Page 96: Intro to Cell Phone Technology

Facebook friends…

Page 97: Intro to Cell Phone Technology

…and Facebook messages

Page 98: Intro to Cell Phone Technology

• These application files can provide a detailed account of the device owner’s activity

Page 99: Intro to Cell Phone Technology

Backup files• Is a backup the same as a sync?

• What types of devices create backups?

• Where do backup files get stored?

• What types of data are in backup files?

Page 100: Intro to Cell Phone Technology

iOS device backups are created using iTunes:

Page 101: Intro to Cell Phone Technology

Where do you find iOS backups?

Page 102: Intro to Cell Phone Technology
Page 103: Intro to Cell Phone Technology

If you do not have the phone

• Open the backup folder and locate the files named:

• Info.plist

• Manifest.plist

Page 104: Intro to Cell Phone Technology
Page 105: Intro to Cell Phone Technology

Info and Manifest

• Simply open each of them with Notepad and take a look:

Page 106: Intro to Cell Phone Technology

Info.plist

Page 107: Intro to Cell Phone Technology
Page 108: Intro to Cell Phone Technology
Page 109: Intro to Cell Phone Technology
Page 110: Intro to Cell Phone Technology
Page 111: Intro to Cell Phone Technology
Page 112: Intro to Cell Phone Technology

Manifest.plist

Page 113: Intro to Cell Phone Technology
Page 114: Intro to Cell Phone Technology
Page 115: Intro to Cell Phone Technology
Page 116: Intro to Cell Phone Technology

And even a list of your apps

Page 117: Intro to Cell Phone Technology
Page 118: Intro to Cell Phone Technology

Oxygen Forensic Suite

Page 119: Intro to Cell Phone Technology

iPhone backups

• What if we don’t have forensic software?

Page 120: Intro to Cell Phone Technology

How can we tell what type of file this is?

Page 121: Intro to Cell Phone Technology

In Notepad

Page 122: Intro to Cell Phone Technology

File Signature (header and footer)

Page 123: Intro to Cell Phone Technology

…and then open it with an appropriate tool

Page 124: Intro to Cell Phone Technology
Page 125: Intro to Cell Phone Technology

– How are we going to get our backup file from the subject computer?

• Just boot it up and copy it out?

– What are we going to use to examine our backup file?

Page 126: Intro to Cell Phone Technology

• Again, great information, but it doesn’t do us any good if we don’t collect it, and if we don’t know how to examine it

Page 127: Intro to Cell Phone Technology

Defeating passcodes

• Different solutions for different devices, and different version of the mobile operating systems

• Some carry inherent risks

Page 128: Intro to Cell Phone Technology
Page 129: Intro to Cell Phone Technology

Lockdown plist

• The Lockdown plist is created by an iOS device on a “Trusted” computer system. It is NOT part of the backup process. So a back up is NOT required.

Page 130: Intro to Cell Phone Technology
Page 131: Intro to Cell Phone Technology

Lockdown Plist

• To unlock the device using the lockdown plist, we copy it from the bad guy’s computer and import it into our forensic software.

Page 132: Intro to Cell Phone Technology
Page 133: Intro to Cell Phone Technology
Page 134: Intro to Cell Phone Technology
Page 135: Intro to Cell Phone Technology
Page 136: Intro to Cell Phone Technology
Page 137: Intro to Cell Phone Technology

The IP Box

Page 138: Intro to Cell Phone Technology

A pattern locked Android device…

Page 139: Intro to Cell Phone Technology

Bypassing passcodes

• Be aware of the capabilities of your tools, and the risks that they may carry

Page 140: Intro to Cell Phone Technology

Call detail records

• What are call detail records?

• How do we obtain them?

Page 141: Intro to Cell Phone Technology

Provider records

• Will include call detail records

• May include SMS and data usage, depending on the provider

• May include “historical handset location data”

Page 142: Intro to Cell Phone Technology

Provider Records• What can we get from the Wireless Services Provider?

• Call detail logs• Originating cell site (Latitude and Longitude)• Terminating cell site• Cell site sector Azimuth• Direction of call (incoming or outgoing)• Calling number• Dialed number• Call duration• Data usage• Location of cell towers

Page 143: Intro to Cell Phone Technology

• Subscriber information (Name, address, etc)

• SMS information (Text or just sender and receiver?)

• ESN / MEID, MIN, MDN, IMEI, IMSI of target phone.

• Tower dump

• Definitions

• Reports of Lost / stolen phone

• Type of phone

• If prepaid, where purchased?

• Status

• Other phones on the same account

• Cell sites at the time of the incident (Not current)

• PCMD / RTT / Historical Handset Location(Maybe?)

• Contents of the Cloud

Page 144: Intro to Cell Phone Technology

What are we hoping to discern from CDRs?

• Historical location

• Possible pattern of movement

Page 145: Intro to Cell Phone Technology
Page 146: Intro to Cell Phone Technology

AT&T Call Detail Records

Page 147: Intro to Cell Phone Technology

Records from a theft incident

Page 148: Intro to Cell Phone Technology

And the map of those calls

Page 149: Intro to Cell Phone Technology

Historical handset location

• Available from several providers

• More precise location than cell site/sector

• Is it GPS?

Page 150: Intro to Cell Phone Technology
Page 151: Intro to Cell Phone Technology
Page 152: Intro to Cell Phone Technology
Page 153: Intro to Cell Phone Technology
Page 154: Intro to Cell Phone Technology

Historical handset location

• Be aware of the accuracy of this information

• Do not over-rely on it