Professional Documents
Culture Documents
ISSWorldEurope200/
(C) Oxygen Software, 2000-2008 http://www.oxygen-forensic.com
Purposesofphoneforensics
Extractingcompleteandunalteredinformationfrom cellphones,smartphones,PDAetc. ! AnalyAingextractedinformationandfinding evidences. ! Preparingforensicreportsthatcanbepresentedin acourt. ! Provingdataauthenticity.
!
Smartphonesmarketgrowth
Source:Canalys estimates,Jcanalys.comltd,200/
Cellphonesevolution
8 years ago
Phonebook
Nowadays
Phonebook Tasks
Calendar
Notes Speeddials
Speeddials
Callergroups Eventlog Personalsettings forcontacts Galleryfiles Oava applicationsand games Profiles Messages LifeBlog
Callshistory
SMSmessages
Monophonic melodies
3okia5667
Generalphone information
RCSOxygenSoftware,2000200/ http://www.oxygenforensic.com
Communicationprotocolsevolution
AT=
Contacts RsimpleS,calls, SMS,filesU, settingsU Veryslow Dependson implementation Developedfor synchroniAation
3okia>?@S
Almostall information Undocumented Notfor smartphones Dependson implementation Developedfor synchroniAation
B?CD
Contacts, calendar,files Dependson implementation Developedfor filesandobjects exchange
SyncML
Contacts, organiAer, settings, messagesU Developedfor synchroniAation
9777
977:
RCSOxygenSoftware,2000200/ http://www.oxygenforensic.com
Smartphonesandstandardprotocols
Thestrikingdiscrepancybetweendataextractedbystandard logicalforensictoolsand protocolsanddatawhichisstoredinthedevicesandcanbeusedforforensic investigationsisquiteobvious.
Generalphone information Phonebook Caller groups Eventlog Gallery files Multiplecontact fieldsofthe sametype Profiles Tasks Calendar Notes Speeddials
Deletedmessages information
Howtoextractinformation]
Thereare3waystogetforensicinformationfromsmartphones:logicalanalysis, physicalanalysisandusingaspecialagentapplicationworkinginsidesmartphoneOS
Logicalanalysis
Veryfewinformation canbeextracted
Easytoperform EasytoanalyAe Affordablesoftware, nospecialhardware needed
Physicalanalysis
Allinformationcan beextracted
Hardtoperform VeryhardtoanalyAe Expensivesoftware, specialhardware needed
AnalysisusingAgent application
Mostofthe informationcanbe extracted
Easytoperform EasytoanalyAe Affordablesoftware, nospecialhardware needed
RCSOxygenSoftware,2000200/ http://www.oxygenforensic.com
Agentapplicationusage
WeatOxygenSoftwareuseanagentapplicationapproach.TheAgentworksinsidea smartphone,hasaccesstoalldeviceAPIsandimplementscustomcommunication protocoltoextractalmostallforensicinformationneeded
Generalphone information
Phonebook
Caller groups Eventlog Gallery files Multiplecontact fieldsofthe sametype Profiles
Tasks
Calendar Notes
Speeddials
Deletedmessages information
Dataauthenticityandotherconcerns
Does1u00ingagen0in0osmar012onec2angei0sinforma0ionI No.Smartphoneshavedifferentmemoryareasfordataandapplications.
Are02ereano02erJay0oeK0rac0fullinforma0ionfromsmar012onesI Yes,withrestrictions 8 physicalanalysis. L2a0informa0ioncanbeeK0rac0e8byagen0a11lica0ionI AlltheinformationavailablefornativeOSapplications. L2a0informa0ioncanno0beeK0rac0e8byagen0a11lica0ionI Memorydumpsandprotectedsystemfiles8 usuallythisinformationscarcelyusefulfor forensicanalysis. L2a0are02emaina8van0agesofusingagen0a11lica0iona11roac2I ExtractingcompleteinformationandpresentingitinastructuredandeasytoanalyAeway. Allthis8 usingstandardcables/adaptersandwithaffordableprice. Isagen0a11lica0ionable0orea88ele0e8informa0ionI Ifthisinformationisstoredbyoperatingsystem 8 yes.Forexample,OxygenForensicSuite readsinformationaboutSMSmessagesrecentlydeletedfromphonememory.
RCSOxygenSoftware,2000200/ http://www.oxygenforensic.com
Interestedinmoredetails]
OxygenSoftware Feodosiyskaya st.1,Moscow, 11`21a,Russia Phones: +1R/``S9OeYGENRUSAS +44020/133/4g0 RUKS +`49g22292`/RRussiaS
www.oxygensoftware.com www.oxygenforensic.com
RCSOxygenSoftware,2000200/ http://www.oxygenforensic.com