The Experts below are selected from a list of 660 Experts worldwide ranked by ideXlab platform
Shahzad Saleem - One of the best experts on this subject based on the ideXlab platform.
-
a method and a case study for the selection of the best available tool for Mobile Device Forensics using decision analysis
Digital Investigation, 2016Co-Authors: Shahzad Saleem, Oliver Popov, Ibrahim BaggiliAbstract:The omnipresence of Mobile Devices (or small scale digital Devices - SSDD) and more importantly the utility of their associated applications for our daily activities, which range from financial transactions to learning, and from entertainment to distributed social presence, create an abundance of digital evidence for each individual. Some of the evidence may be a result of illegal activities that need to be identified, understood and eventually prevented in the future. There are numerous tools for acquiring and analyzing digital evidence extracted from Mobile Devices. The diversity of SSDDs, types of evidence generated and the number of tools used to uncover them posit a rather complex and challenging problem of selecting the best available tool for the extraction and the subsequent analysis of the evidence gathered from a specific digital Device. Failing to select the best tool may easily lead to incomplete and or improper extraction, which eventually may violate the integrity of the digital evidence and diminish its probative value. Moreover, the compromised evidence may result in erroneous analysis, incorrect interpretation, and wrong conclusions which may eventually compromise the right of a fair trial. Hence, a digital Forensics investigator has to deal with the complex decision problem from the very start of the investigative process called preparatory phase. The problem could be addressed and possibly solved by using multi criteria decision analysis. The performance of the tool for extracting a specific type of digital evidence, and the relevance of that type of digital evidence to the investigative problem are the two central factors for selecting the best available tool, which we advocate in our work. In this paper we explain the method used and showcase a case study by evaluating two tools using two Mobile Devices to demonstrate the utility of our proposed approach. The results indicated that XRY (Alt1) dominates UFED (Alt2) for most of the cases after balancing the requirements for both performance and relevance.
-
testing framework for Mobile Device Forensics tools
The Journal of Digital Forensics Security and Law, 2014Co-Authors: Maxwell Anobah, Shahzad Saleem, Oliver PopovAbstract:The proliferation of Mobile communication and computing Devices, in particular smart Mobile phones, is almost paralleled with the increasing number of Mobile Device Forensics tools in the market. Each Mobile Forensics tool vendor, on one hand claims to have a tool that is best in terms of performance, while on the other hand each tool vendor seems to be using different standards for testing their tools and thereby defining what support means differently. To overcome this problem, a testing framework based on a series of tests ranging from basic Forensics tasks such as file system reconstruction up to more complex ones countering antiforensic techniques is proposed. The framework, which is an extension of an existing effort done in 2010, prescribes a method to clearly circumscribe the term support into precise levels. It also gives an idea of the standard to be developed and accepted by the forensic community that will make it easier for Forensics investigators to quickly select the most appropriate tool for a particular Mobile Device.
-
evaluating and comparing tools for Mobile Device Forensics using quantitative analysis
Digital Forensics and Cyber Crime. 4th International Conference ICDF2C 2012 Lafayette IN USA October 25-26 2012 Revised Selected Papers, 2013Co-Authors: Shahzad Saleem, Oliver Popov, Oheneba Kwame AppiahkubiAbstract:Scientific development and progress in the fields of computer science, information technology and their related disciplines, have transformed our world into a “digital world”. Omnipresent digital Devices and e-services running on numerous versions of pervasive e-infrastructures generate a wealth of electronically stored information (ESI) from which we can extract a great deal of potential digital evidence.Digital evidence is sometimes even more revealing than its traditional counterpart, but at the same time it is very fragile and volatile in nature. Preserving the integrity of digital evidence is therefore of major concern, especially when it comes from purportedly illegal, illicit and malicious activities. The acquisition and analysis of digital evidence are also crucial to the functioning of the digital world, regardless of the positive or negative implications of the actions and activities that generated the evidence. All stakeholders should have the right to be assured of the accuracy of the digital Forensics process and the people involved in it. Currently they surrender these rights and have to trust the process and the individuals carrying it out. They do not have any guarantee that intentional or unintentional conduct or modification will not affect the outcome of the forensic process, which might compromise their other human rights as a consequence, such as their right to liberty and even their right to life. Protecting basic human rights by ensuring the correctness of the entire Forensics process, and its output in the form of digital evidence, is thus a point of concern. The “right to a fair trial” given in Article 6 of the European Convention as an umbrella principle that affects the Forensics process, is one example of the protection of basic human rights.In digital Forensics there are principles and models on the top (theoretical basis), acting as a platform on abstract and generic level, in the middle, there are policies and practices and at the bottom, there are technical procedures and techniques. During this research we worked to solve the above mentioned problems, concentrating on all three layers, by extending the abstract models, defining best practice, and by providing new technical procedures employing latest technology. Our work also helps to implement organisational policies.The research was undertaken in two cycles, starting with an exploration of the theoretical basis and continuing to procedures and techniques. The methods used to preserve the integrity of digital evidence were explored and evaluated in the first cycle. A new technical model called PIDESC[1] was thus proposed. This can preserve the integrity of digital evidence by orchestrating both software- and hardware-based security solutions. The model was evaluated in terms of time and cost. The results suggest that the gains outweigh the additional cost and time. The increase in time is a constant negligible factor of only half a millisecond on average. In the next cycle we built on our knowledge and extended the theoretical basis on an abstract and generic level to preserve the integrity of digital evidence and to protect basic human rights as overarching umbrella principles (2PasU[2]). We then developed specific solutions, including a formal method to select the best Mobile Device Forensics tool, and developed a guide for best practices to fulfil the requirements of preservation and protection. Finally, we mapped the solutions to the proposed extended model with 2PasU, putting all the research into its context in order to pave the way for future work in this domain.[1] Protecting Digital Evidence Integrity by Using Smart Cards[2] Preservation and Protection as Umbrella Principles
-
formal approach for the selection of a right tool for Mobile Device Forensics
International Conference on Digital Forensics, 2013Co-Authors: Shahzad Saleem, Oliver PopovAbstract:Small scale digital Devices (SSDD) have had a profound impact on the way we interact with the world around us. Penetration of these Devices especially Mobile phones has almost reached to their satu ...
-
evaluating and comparing tools for Mobile Device Forensics using quantitative analysis
International Conference on Digital Forensics, 2012Co-Authors: Shahzad Saleem, Oliver Popov, Oheneba Kwame AppiahkubiAbstract:In this paper we have presented quantitative analysis technique to measure and compare the quality of Mobile Device Forensics tools while evaluating them. For examiners, it will provide a formal mathematical base and an obvious way to select the best tool, especially for a particular type of digital evidence in a specific case. This type of comparative study was absent in both NIST’s evaluation process and our previous work (Evaluation of Some Tools for Extracting e-Evidence from Mobile Devices). We have evaluated UFED Physical Pro 1.1.3.8 and XRY 5.0. To compare the tools we have calculated Margin of Error and Confidence Interval (CI) based on the proportion of successful extractions from our samples in different scenarios. It is followed by hypothesis testing to further strengthen the CI results and to formally compare the accuracy of the tools with a certain level of confidence.
Paulo Simoes - One of the best experts on this subject based on the ideXlab platform.
-
current and future trends in Mobile Device Forensics a survey
ACM Computing Surveys, 2018Co-Authors: Konstantia Barmpatsalou, Tiago Cruz, Edmundo Monteiro, Paulo SimoesAbstract:Contemporary Mobile Devices are the result of an evolution process, during which computational and networking capabilities have been continuously pushed to keep pace with the constantly growing workload requirements. This has allowed Devices such as smartphones, tablets, and personal digital assistants to perform increasingly complex tasks, up to the point of efficiently replacing traditional options such as desktop computers and notebooks. However, due to their portability and size, these Devices are more prone to theft, to become compromised, or to be exploited for attacks and other malicious activity. The need for investigation of the aforementioned incidents resulted in the creation of the Mobile Forensics (MF) discipline. MF, a sub-domain of digital Forensics, is specialized in extracting and processing evidence from Mobile Devices in such a way that attacking entities and actions are identified and traced. Beyond its primary research interest on evidence acquisition from Mobile Devices, MF has recently expanded its scope to encompass the organized and advanced evidence representation and analysis of future malicious entity behavior. Nonetheless, data acquisition still remains its main focus. While the field is under continuous research activity, new concepts such as the involvement of cloud computing in the MF ecosystem and the evolution of enterprise Mobile solutions—particularly Mobile Device management and bring your own Device—bring new opportunities and issues to the discipline. The current article presents the research conducted within the MF ecosystem during the last 7 years, identifies the gaps, and highlights the differences from past research directions, and addresses challenges and open issues in the field.
Oliver Popov - One of the best experts on this subject based on the ideXlab platform.
-
a method and a case study for the selection of the best available tool for Mobile Device Forensics using decision analysis
Digital Investigation, 2016Co-Authors: Shahzad Saleem, Oliver Popov, Ibrahim BaggiliAbstract:The omnipresence of Mobile Devices (or small scale digital Devices - SSDD) and more importantly the utility of their associated applications for our daily activities, which range from financial transactions to learning, and from entertainment to distributed social presence, create an abundance of digital evidence for each individual. Some of the evidence may be a result of illegal activities that need to be identified, understood and eventually prevented in the future. There are numerous tools for acquiring and analyzing digital evidence extracted from Mobile Devices. The diversity of SSDDs, types of evidence generated and the number of tools used to uncover them posit a rather complex and challenging problem of selecting the best available tool for the extraction and the subsequent analysis of the evidence gathered from a specific digital Device. Failing to select the best tool may easily lead to incomplete and or improper extraction, which eventually may violate the integrity of the digital evidence and diminish its probative value. Moreover, the compromised evidence may result in erroneous analysis, incorrect interpretation, and wrong conclusions which may eventually compromise the right of a fair trial. Hence, a digital Forensics investigator has to deal with the complex decision problem from the very start of the investigative process called preparatory phase. The problem could be addressed and possibly solved by using multi criteria decision analysis. The performance of the tool for extracting a specific type of digital evidence, and the relevance of that type of digital evidence to the investigative problem are the two central factors for selecting the best available tool, which we advocate in our work. In this paper we explain the method used and showcase a case study by evaluating two tools using two Mobile Devices to demonstrate the utility of our proposed approach. The results indicated that XRY (Alt1) dominates UFED (Alt2) for most of the cases after balancing the requirements for both performance and relevance.
-
testing framework for Mobile Device Forensics tools
The Journal of Digital Forensics Security and Law, 2014Co-Authors: Maxwell Anobah, Shahzad Saleem, Oliver PopovAbstract:The proliferation of Mobile communication and computing Devices, in particular smart Mobile phones, is almost paralleled with the increasing number of Mobile Device Forensics tools in the market. Each Mobile Forensics tool vendor, on one hand claims to have a tool that is best in terms of performance, while on the other hand each tool vendor seems to be using different standards for testing their tools and thereby defining what support means differently. To overcome this problem, a testing framework based on a series of tests ranging from basic Forensics tasks such as file system reconstruction up to more complex ones countering antiforensic techniques is proposed. The framework, which is an extension of an existing effort done in 2010, prescribes a method to clearly circumscribe the term support into precise levels. It also gives an idea of the standard to be developed and accepted by the forensic community that will make it easier for Forensics investigators to quickly select the most appropriate tool for a particular Mobile Device.
-
evaluating and comparing tools for Mobile Device Forensics using quantitative analysis
Digital Forensics and Cyber Crime. 4th International Conference ICDF2C 2012 Lafayette IN USA October 25-26 2012 Revised Selected Papers, 2013Co-Authors: Shahzad Saleem, Oliver Popov, Oheneba Kwame AppiahkubiAbstract:Scientific development and progress in the fields of computer science, information technology and their related disciplines, have transformed our world into a “digital world”. Omnipresent digital Devices and e-services running on numerous versions of pervasive e-infrastructures generate a wealth of electronically stored information (ESI) from which we can extract a great deal of potential digital evidence.Digital evidence is sometimes even more revealing than its traditional counterpart, but at the same time it is very fragile and volatile in nature. Preserving the integrity of digital evidence is therefore of major concern, especially when it comes from purportedly illegal, illicit and malicious activities. The acquisition and analysis of digital evidence are also crucial to the functioning of the digital world, regardless of the positive or negative implications of the actions and activities that generated the evidence. All stakeholders should have the right to be assured of the accuracy of the digital Forensics process and the people involved in it. Currently they surrender these rights and have to trust the process and the individuals carrying it out. They do not have any guarantee that intentional or unintentional conduct or modification will not affect the outcome of the forensic process, which might compromise their other human rights as a consequence, such as their right to liberty and even their right to life. Protecting basic human rights by ensuring the correctness of the entire Forensics process, and its output in the form of digital evidence, is thus a point of concern. The “right to a fair trial” given in Article 6 of the European Convention as an umbrella principle that affects the Forensics process, is one example of the protection of basic human rights.In digital Forensics there are principles and models on the top (theoretical basis), acting as a platform on abstract and generic level, in the middle, there are policies and practices and at the bottom, there are technical procedures and techniques. During this research we worked to solve the above mentioned problems, concentrating on all three layers, by extending the abstract models, defining best practice, and by providing new technical procedures employing latest technology. Our work also helps to implement organisational policies.The research was undertaken in two cycles, starting with an exploration of the theoretical basis and continuing to procedures and techniques. The methods used to preserve the integrity of digital evidence were explored and evaluated in the first cycle. A new technical model called PIDESC[1] was thus proposed. This can preserve the integrity of digital evidence by orchestrating both software- and hardware-based security solutions. The model was evaluated in terms of time and cost. The results suggest that the gains outweigh the additional cost and time. The increase in time is a constant negligible factor of only half a millisecond on average. In the next cycle we built on our knowledge and extended the theoretical basis on an abstract and generic level to preserve the integrity of digital evidence and to protect basic human rights as overarching umbrella principles (2PasU[2]). We then developed specific solutions, including a formal method to select the best Mobile Device Forensics tool, and developed a guide for best practices to fulfil the requirements of preservation and protection. Finally, we mapped the solutions to the proposed extended model with 2PasU, putting all the research into its context in order to pave the way for future work in this domain.[1] Protecting Digital Evidence Integrity by Using Smart Cards[2] Preservation and Protection as Umbrella Principles
-
formal approach for the selection of a right tool for Mobile Device Forensics
International Conference on Digital Forensics, 2013Co-Authors: Shahzad Saleem, Oliver PopovAbstract:Small scale digital Devices (SSDD) have had a profound impact on the way we interact with the world around us. Penetration of these Devices especially Mobile phones has almost reached to their satu ...
-
evaluating and comparing tools for Mobile Device Forensics using quantitative analysis
International Conference on Digital Forensics, 2012Co-Authors: Shahzad Saleem, Oliver Popov, Oheneba Kwame AppiahkubiAbstract:In this paper we have presented quantitative analysis technique to measure and compare the quality of Mobile Device Forensics tools while evaluating them. For examiners, it will provide a formal mathematical base and an obvious way to select the best tool, especially for a particular type of digital evidence in a specific case. This type of comparative study was absent in both NIST’s evaluation process and our previous work (Evaluation of Some Tools for Extracting e-Evidence from Mobile Devices). We have evaluated UFED Physical Pro 1.1.3.8 and XRY 5.0. To compare the tools we have calculated Margin of Error and Confidence Interval (CI) based on the proportion of successful extractions from our samples in different scenarios. It is followed by hypothesis testing to further strengthen the CI results and to formally compare the accuracy of the tools with a certain level of confidence.
Novelino Yona Pribadi Lukito - One of the best experts on this subject based on the ideXlab platform.
-
comparison of data acquisition technique using logical extraction method on unrooted android Device
International Conference on Information and Communication Technology, 2016Co-Authors: Novelino Yona Pribadi Lukito, Fazmah Arif Yulianto, Erwid Musthofa JadiedAbstract:Acquisition data method on Mobile Device Forensics's activity divided into two method: physical and logical extraction where each of these method has their own advantages and disadvantages. On Unrooted Android Device that have limited privilege, Logical Extraction method is used to acquire data on the Device. Technique on the Logical Extraction method to acquire the data include AFLogical, SDcard Imaging, Android Backup Analysis, and proprietary applications for Mobile Device Forensics activity such as Oxygen-Forensics. These four technique has its own acquisition technique with different capability to capture the data on the Device and different activity while the acquisition data is performed. Problem in using Logical Extraction on unrooted android Device is choosing right technique for data acquisition that can be used for digital evidences. Because of that problem, it's necessary to analyze several techniques on Logical Extraction method by comparing quantity of data that can be acquired and how intrusive activities performed on the Device to be able to determine better acquisition technique. Best technique is technique that can acquire enough data that needed as a digital evidence without damaging the integrity of the evidence itself. On the capability to capture the data, we found that Android Backup analysis is the best technique to capture application artifact, SDCard Imaging is the best technique to captured external memory data, and Commercial provider using Oxygen-Forensics is the best technique to capture other system files data with limited privilege. Finally with proving the communication log on Steam apps, after comparing all technique in Logical Extraction in safetyness (rooting or install application activities) and data captured aspect, we found that using Android Backup Analysis technique is the best technique for unrooted without doing rooting activity or installing application because of Android Backup Analysis itself is analyze the backup that created from the phone from android debug bridge which the backup store some application data on the phone. We use Steam apps case study as our proof of concept.
-
Perbandingan Teknik Akuisisi Data Mobile Device Forensics dengan Metode Logical Extraction pada Unrooted Android Device
Universitas Telkom, 2016Co-Authors: Novelino Yona Pribadi LukitoAbstract:Metode akuisisi data pada aktivitas Mobile Device Forensics dibagi menjadi dua yaitu Physical dan Logical Extraction dimana masing-masing metode tersebut memiliki teknik akuisisi data masing-masing. Pada perangkat android yang memiliki hak akses terbatas (unrooted android Device) digunakan metode Logical Extraction untuk akusisi data pada perangkat tersebut. Pada metode Logical Extraction ini terdapat beberapa teknik akuisisi data untuk mengambil data yang ada pada perangkat tersebut untuk dijadikan barang bukti digital antara lain AFLogical, SDcard Imaging, Android Backup Analysis, dan menggunakan aplikasi komersil yang sudah dipublikasikan untuk aktivitas Mobile Device Forensics seperti Oxygen-Forensics. Masalah yang muncul pada penggunaan metode Logical Extraction pada unrooted android Device terdapat pada pemilihan teknik yang tepat untuk akuisisi data untuk mendapatkan data yang cukup untuk dijadikan barang bukti tanpa merusak integritas dari perangkat tersebut. Untuk itu sangat perlu dilakukan analisa terhadap beberapa teknik pada metode Logical Extraction kemudian dilakukan perbandingan data yang dapat diambil serta seberapa banyak aktivitas yang dilakukan pada perangkat untuk dapat menentukan teknik akuisisi apa yang lebih baik pada metode ini dimana teknik tersebut dapat mengambil data yang cukup yang diperlukan sebagai barang bukti digital tanpa merusak integritas dari barang bukti tersebut. Dengan perbandingan teknik pada metode Logical Extraction untuk membuktikan studi kasus log komunikasi aplikasi Steam pada smartphone, didapatkan data bahwa teknik Android Backup Analysis melakukan akuisisi data dari segi data aplikasi tanpa melakukan aktivitas rooting maupun instalasi aplikasi sehingga dengan demikian merupakan teknik terbaik untuk menyelesaikan studi kasus tersebut. Kata kunci : Mobile Device Forensics, Unrooted Android Device, AFLogical, SDcard Imaging, Android Backup Analysis, Oxygen-forensic
Konstantia Barmpatsalou - One of the best experts on this subject based on the ideXlab platform.
-
current and future trends in Mobile Device Forensics a survey
ACM Computing Surveys, 2018Co-Authors: Konstantia Barmpatsalou, Tiago Cruz, Edmundo Monteiro, Paulo SimoesAbstract:Contemporary Mobile Devices are the result of an evolution process, during which computational and networking capabilities have been continuously pushed to keep pace with the constantly growing workload requirements. This has allowed Devices such as smartphones, tablets, and personal digital assistants to perform increasingly complex tasks, up to the point of efficiently replacing traditional options such as desktop computers and notebooks. However, due to their portability and size, these Devices are more prone to theft, to become compromised, or to be exploited for attacks and other malicious activity. The need for investigation of the aforementioned incidents resulted in the creation of the Mobile Forensics (MF) discipline. MF, a sub-domain of digital Forensics, is specialized in extracting and processing evidence from Mobile Devices in such a way that attacking entities and actions are identified and traced. Beyond its primary research interest on evidence acquisition from Mobile Devices, MF has recently expanded its scope to encompass the organized and advanced evidence representation and analysis of future malicious entity behavior. Nonetheless, data acquisition still remains its main focus. While the field is under continuous research activity, new concepts such as the involvement of cloud computing in the MF ecosystem and the evolution of enterprise Mobile solutions—particularly Mobile Device management and bring your own Device—bring new opportunities and issues to the discipline. The current article presents the research conducted within the MF ecosystem during the last 7 years, identifies the gaps, and highlights the differences from past research directions, and addresses challenges and open issues in the field.
-
a critical review of 7 years of Mobile Device Forensics
Digital Investigation, 2013Co-Authors: Konstantia Barmpatsalou, Dimitrios Damopoulos, Georgios Kambourakis, Vasilios KatosAbstract:Mobile Device Forensics (MF) is an interdisciplinary field consisting of techniques applied to a wide range of computing Devices, including smartphones and satellite navigation systems. Over the last few years, a significant amount of research has been conducted, concerning various Mobile Device platforms, data acquisition schemes, and information extraction methods. This work provides a comprehensive overview of the field, by presenting a detailed assessment of the actions and methodologies taken throughout the last seven years. A multilevel chronological categorization of the most significant studies is given in order to provide a quick but complete way of observing the trends within the field. This categorization chart also serves as an analytic progress report, with regards to the evolution of MF. Moreover, since standardization efforts in this area are still in their infancy, this synopsis of research helps set the foundations for a common framework proposal. Furthermore, because technology related to Mobile Devices is evolving rapidly, disciplines in the MF ecosystem experience frequent changes. The rigorous and critical review of the state-of-the-art in this paper will serve as a resource to support efficient and effective reference and adaptation.