Top Banner
Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age
25

Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

Dec 21, 2015

Download

Documents

Walter Owen
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

Obstacles & Opportunities in Mobile Forensic Collections

October 2, 2014

Evidence Collection in the Mobile Age

Page 2: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

Trend: Mobile Device Ownership is Rising

© Elysium Digital 2014 2

Source: Pew Research Center (Internet & American Life Project)

Page 3: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

3

Trend: Increasing Use of Smartphones

© Elysium Digital 2014

Source: Pew Research Center (Internet & American Life Project)

Page 4: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

4

Trend: BYOD Popularity Increasing

© Elysium Digital 2014

Bring Your Own Device (BYOD) Support

Source: Good Technology Corporation. Good Technology’s 2nd Annual State of BYOD Report. (n=100)

Page 5: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

5

Mobile: It is the Wild, Wild West of Tech

© Elysium Digital 2014

• Similar to early PC landscape– More Devices– More Varieties– More Connectivity– More Users

• Results in– Lack of Standards– Unsettled Marketplace

Image sources: www.securitypronews.com, www.gospotcheck.com

Page 6: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

6

Types of Devices

© Elysium Digital 2014

Cellphones

Smartphones

Tablets

Page 7: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

7

Agenda

© Elysium Digital 2014

• Traditional Computer Forensics• Mobile Collections Obstacles• Mobile Collections Opportunities• Other Issues• Quick Takeaways

Page 8: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

8© Elysium Digital 2014

Traditional Computer Forensics

Page 9: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

9

Traditional Computer Forensics:Non-volatile Storage

© Elysium Digital 2014

• Disk Drive & Solid State Drive (SSD)– “File” Abstraction – Blocks under the

abstraction

Page 10: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

10

Traditional Computer Forensics: Files

© Elysium Digital 2014

• Files

• File-level operations

• Internal metadata

Page 11: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

11

Traditional Computer Forensics: Filesystems

© Elysium Digital 2014

• Filesystem– Organizational system – Implemented in both storage structure & process– Examples: FAT, inodes

• Filesystem metadata– Creation time– Modification time– Access time

Page 12: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

12

Traditional Computer Forensics: “Hidden” Data

© Elysium Digital 2014

• Block Reuse Principles– Conserve cycles– Conserve I/O traffic

• Breaking through the Abstraction– File slack– Deleted files

Page 13: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

13© Elysium Digital 2014

Mobile Forensics: Obstacles

Page 14: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

14

Mobile Forensics: Obstacles

© Elysium Digital 2014

• Designed for Loss / Theft• Modified by Carriers• Analysis software is less mature• Deleted data & metadata• Truncated email

Page 15: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

15© Elysium Digital 2014

Mobile Forensics: Opportunities

Page 16: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

16

Mobile Evidence Collection: Opportunities (1/3)

© Elysium Digital 2014

• Opportunities from Common Practices– Devices not centrally managed – Data policies not implemented– Data remains on old devices– Data is maintained in backups

Page 17: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

17

Mobile Evidence Collection: Opportunities (2/3)

© Elysium Digital 2014

• Opportunities from Types of Data– Locational data available– Network connection information available

Page 18: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

18

Mobile Evidence Collection: Opportunities (3/3)

© Elysium Digital 2014

• Opportunities yielded by the process– Broadening scope of discovery– Helping to find the “digital packrat”

Page 19: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

19

Mobile Evidence Collection: Spoliation

© Elysium Digital 2014

• Devices viewed as a private, personal accessory• Spoliation 10x increase over laptops• Can yield obstacles and opportunities

Page 20: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

20

Mobile Evidence Collection: Other Issues

© Elysium Digital 2014

• Cloud backups• Encrypted backups• Commingled personal data

Page 21: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

21

Mobile Evidence Collection: Quick Takeaways (1/4)

© Elysium Digital 2014

Trends:– Mobile device usage increasing– Mobile evidence issues multiplying– Mobile evidence collection increasingly complex

Source: Pew Research Center (Internet & American Life Project)

Source: Good Technology Corp. 2nd Annual State of BYOD Report. (n=100)

Page 22: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

22

Mobile Evidence Collection: Quick Takeaways (2/4)

© Elysium Digital 2014

Checklist: Collecting a Smartphone– Get the smartphone– Get it fast– Turn on airplane mode ASAP– Obtain charging device– Keep battery charged– Obtain password / unlock code– If Blackberry, have company/owner unlock it– Send device & charger to mobile forensics expert

Page 23: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

23

Mobile Evidence Collection: Quick Takeaways (3/4)

© Elysium Digital 2014

Secure Confidential & Proprietary Data– Strong & enforced IT policy– Password protection or encryption– Watermarks, print banners, or hidden identifiers– Usage restrictions (print, copy, etc.)

Page 24: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

24

Mobile Evidence Collection: Quick Takeaways (4/4)

© Elysium Digital 2014

Geographic information not limited to Carriers– XIF data records geographic location of pictures– Pictures themselves can document location– Network connections are tracked and can be mapped back to

geographic locations

Page 25: Obstacles & Opportunities in Mobile Forensic Collections October 2, 2014 Evidence Collection in the Mobile Age.

25© Elysium Digital 2014

Q&A / Discussion

Have a matter involving mobile evidence collection? Ask.

Didn’t understand that? Ask.

Want more info? Ask.

Christian HicksPresident, Elysium Digital

[email protected]

617-621-3100 x100