Sunday, August 28, 2011

Touch Screens - Keeping them fingerprint free

Touch Screens - Keeping them fingerprint free

In my early thread about android dots locking the screen several possibilities were raised and, in particular, I happen to mention  "ii) using fingerprint tape on the touch-screen (so clean the screen regularly)"; that was mentioned in context with the theme of the discussion about avoiding your security access being breached by an unauthorised person.

After some highly active chats with people, nothing to precipitant of course, and not to put too fine a point upon it, the conversation (some of which was rather humorous) turned to prevention of *fingerprints, rather than cure of them. Various options were discussed, which had to be inexpensive:

- Wearing gloves. Ideas stretched (no pun intended) from Marigold Washing Up gloves to those Latex gloves. One would look pretty ridiculous, wouldn't one,  having to put on one's gloves everytime one wanted to use one's phone?

- False hand. Now, you see, this is exactly what I am talking about, people just wont be sensible :-). This led to thoughts about Kenny Everitt's character, the one with the giant hands, 'Brother Lee Love'. It was felt, after a long discussion and a few pints of larger, that hands like this would be OK in the boardroom but would be thoroughly inappropriate for use when sitting in a packed train carriage and tapping the passenger (in the next seat) on their face and body with hands this size and asking him/her to budge-up so one could use the touch screen phone. That was considered using poor ettiquette and simply bad form to do it. So let that be a lesson to you all, don't get on trains with big hands if you want to use your touch screen device.

   
- Cling-film. Oh yes, real classy! But it is cheap and it is disposable (but does it avoid fingerprints?). Could, though, cause a run on stock at the local supermarket due to frequent changes.

- Screen spray protection. Now it would have useful to find out more about any spray on products that prevented lipids build up on the screen, similar to this type of product Windshield Treatment

- Cover screen protection. The ones seen during research tended to show a plastic screen cover or film which might work if they do not retain fingerprint smudges or lipids residue on the cover screen of film.

- Stylus. Research reveals that there are over 15 million pages on google that refer to 'stylus'. Clearly, a bit of research refinement was necessary and I came away with these items for the purposes of the topic of this thread:

This stylus is called a 'capacitive stylus', and you can learn more about why they are used here 
 The photo is courtesy of htcaccessorystore

They can be used with resistive touch screen devices, such as HTC and so on:
Photo coutesy of engadget

From the styli research I came away with the notion that if "necessity is the mother of invention", (in fact we are told Plato actually said: "Necessity, who is the mother of invention") then styli are in need of it, apparently. I arrived at this opinion when one individual found you could make a free of charge capacitive stylus made from a "silvery-metallic looking antistatic film". OK, ok, I think I am following this. Enlightenment is just around the corner with a home made video. It is only an image, below, so follow the link to how-to-make-a-free-capacitive-stylus to watch the video. I found the author of the video waving his hands around alot and it is abit distracting when watching the video. Also, he finds it necessary to touch the screen with the hand not holding the home-made stylus, which could indicate a possible set back in avoiding fingerprints. Fair play to him, though, as it appear his find might just be a discovery of necessity of some sort, but that is just pure speculation on my behalf.



Having trawled the life and times of  these styli I happened to come across this little video gem (below) from someone using a home made version of capacitive stylus made from a "square of static bag". Two points to note. One point is that a outcome of using a capacitive stylus is that when used it cleans the screen at the same time, apparently. I had some difficulty in following that logic if the point in using a stylus is to avoid using fingers then where are the fingerprints to be revealed eg: the dots, pin, password? The second point might answer the former question as it seems the video is actually about preservation of fingerporints when a touch screen device is being examined and where the user has fingered his/her touch screen device.  I'll give at least one mark out of ten for effort for the handwritten statement of intent at the top of the paper which the author of the video helpful points out to refresh our memory of it. I'll leave all of you to judge how effective the technqiue is used by the video's author. Follow this link to preservation of fingerprints


So, luckily, having worked to bring the discussion back on topic about fingerprints, it would appear there is a world out deeply involved with 'mothers of inventions' working out how to avoid leaving fingerprints on touch screen devcies and another world working out how to preserve them. Moreover, use a stylus by all means, but you will need two if you wish to re-size the image on the touch screen. Finally, I and those raise observations take no responsibility for anyone using any of the observations above. If you have any suggestions you would like to add to this discussion on how to avoid or preserve fingerprints on touch screen devices send an email (to trewmte@gmail.com) along with your name and company and those details will be given as a by-line along with your suggestions. 

So there you have it.

Until the next time, have a great August bank holiday.

* Lipophobicity & Oleophobic
* Indium tin oxide - one of the most widely used transparent conducting oxides
* Example of device using Oleophobic coating technology Ipad

Monday, August 22, 2011

TCP/IP, RFC and a few laughs along the way

TCP/IP, RFC and a few laughs along the way


For those of us who are constantly studying to keep up to date with technological advances or going on re-fresher courses to remind ourselves of things we thought we knew well, but had actually forgotten bits and pieces, it is the daunting amount of information to be read and absorbed that can be off-putting at times.  For example, I am currently on a re-fresher for TCP/IP (Transmission Control Protocol/Internet Protocol - TCP/IP_model) and just one of the documents I am reading runs to over 700 pages long. TCP/IP sounds very boring (and to most it probably is).

Given that the nitty-gritty of TCP/IP also appears technically demanding to understand (perhaps a bit like rocket science) one needs a sense of humour working in this arena if one is not to go ‘bonkers’ or become a total ‘anorak’ on the subject. Whilst reading the commentary on the standardisation bodies structure responsible for the creation of RFC (Request for Comments) IP Standards and proposals for RFC standards I was came across a couple of gems, which I found quite humorous.  To fully appreciate the humour, one needs first to have an appreciation of the aura of formality and control engendered around understanding standardisation and the bodies that assist in their creation.

As a very brief overview, because of the openness and perpetual renewal of TCP/IP, which is popular with developers and users alike, there is no overall governing body to issue directives and regulations for the Internet.  Control is mostly based on mutual co-operation. The Internet community is said to be organised and managed by the Internet Architecture Board (IAB). The IAB itself relies on the Internet Engineering Task Force (IETF) for issuing new Standards (RFCs) and the Internet Assigned Numbers Authority (IANA) for co-ordinating values shared among multiple protocols. RFC standards can be proposed by anyone; but the RFC Editor is responsible for reviewing and publishing new standards documents. The IETF itself is governed by the Internet Engineering Steering Group (IESG) and is further organised in the form of Areas and Working Groups where new specifications are discussed and new standards are proposed.

In order to have a new IP protocol approved as a standard, applicants have to submit a proposed specification to the IESG where it will be discussed and reviewed for technical merit and feasibility and also published as an Internet draft document. For Internet Protocol suite to evolve through the mechanism of Request for Comments (RFC) new protocols (mostly application protocols) are designed and implemented by researchers, and are brought to the attention of the Internet community identified in standard categories: 

Draft standard: There is a possibility that changes will be made in a draft protocol before it becomes a standard. 
Proposed standard: Revision of the protocol is likely. 
Experimental: A system should not implement an experimental protocol unless it is participating in the experiment and has co-ordinated its use. 
Informational: Protocols developed by other standard organisations, or vendors, or that are for other reasons outside the purview of the IAB may be published as RFCs
Historic: These are protocols that are unlikely to ever become standards, because they have been superseded by later developments or due to lack of interest.
Required: A system must implement the required protocols.
Recommended: A system should implement the recommended protocol.
Elective: A system may or may not implement an elective protocol. The general notion is that if you are going to do something like this, you must do exactly this.
Limited use: These protocols are for use in limited circumstances. This may be because of their experimental state, specialised nature, limited functionality, or historic state.
Not recommended: These protocols are not recommended for general use. This may be because of their limited functionality, specialised nature, or experimental or historic state.

The overall picture one gets, having glimpsed at this highly defined and controlled standardisation structure, is one of individuals feverishly working away solving technical conundrums with little room for levity. Well, apparently not. It was with a grinning surprise I found, amid all this rocket science, that some ‘techies’ have been allowed to let their imaginations run riot – presumably to defeat creeping techmadness, maybe?  Two protocols identified by the RFC Editor, and dated April 1st that are described at best as “impractical”:

RFC 1149 (dated 1990 April 1 - rfc1149) describes: A standard for the transmission of IP datagrams by avian carrier (carrier pigeon)
See also RFC 6214 – (rfc6214)

RFC 1437 (dated 1993 April 1 - rfc1437) describes: The Extension of MIME Content-Types to a New Medium (transmission of people by electronic mail).

Are these two impractical or just ahead of their time?

Thursday, August 18, 2011

Android DOTS - Locking the Screen

Android DOTS - Locking the Screen



I have received several emails following the earlier post iphones-common-password-usage-risks whether I had seen other studies or reports about security risks with the Locking the Screen (linking DOTS) feature in Android and similar featured mobile phones and what I thought.

It is impossible to read everything and many studies/report sometimes don't become available until some years after authors produce them.

My own analysis of the reports (at this stage) that I have seen thus far is that many of the comments about Locking the Screen privacy techniques generally identify that an author acknowledges the device has this privacy/security capability available and provides one method to reduce risk. Forensically speaking, authors also record the complications when the restricted access mode is activated when the device is presented for examination. These are useful comments, but are not fully supported by any indepth research to define common combination of DOTS used by users for their numerical choice of locking patterns. That is menat to be taken in context with the common choice of PINs as suggested by the post iphones-common-password-usage-risks.

The authors Aviv/Gibson/Mossop/Blaze/Smith in 2010 produced an informed and respected report on Screen Smudges that illustrated risks of pattern smudges on the mobile phone touch-screen being detected which refined earlier concerns in 2009 about smudging illustrated in posts on the Android - An Open Handset Alliance Project.

There are discussive science articles on the web about how secure are Android DOTS unlock_patterns regarding numerical choices for the locking code that, again, could provide useful material for more indepth forensic analysis and study. I could carrry on identifying material I have researched but that would merely produce, largely, similar and repetitous paragraphs of statements listing what I found available. However, risks to user touch-screen mobile phones may occur when considering entering unlock DOTS patterns, passwords and PINs and unauthorised access attacker or hackers gaze could potentially include the less troublesome methods to gain access using:

i) clandestine apps/progs (WORMs etc from download or P2P) that could record user entries on the touch-screens and storing the output [having fowarded to a memory cards etc] in a hidden file (so be aware of apps/progs on the handset - check eg file manager/root and change memory cards on a regular basis)
ii) using fingerprint tape on the touch-screen (so clean the screen regularly)
iii) shoulder-surfing the user's locking DOTS pattern (so the longer the pattern the harder it can be for the shoulder-surfer to memorise)

Wednesday, August 17, 2011

The Emperor's New Clothes

The Emperor's New Clothes

I was reminded recently of this Hans Christian Andersen tale that brought back memories of hearing it as a child. The hero in the tale is the child for speaking out because those who could have said something found it difficult until it became impossible for them not to say something (but by then it was too late).

The tale could have application to forensics and expert evidence. The focus on distinguishing illusion from reality is an important one and tasks all of us in our field of endeavour to ensure amongst other things:

i) opinion given doesn't simply repeat what others have stated for fear of stepping out of line or the threat of the use psychological intimidation of belittle to one's character
ii) to stand up and challenge, even where an awful lot money has been spent on methods or systems that are systemtically flawed or producing inaccurate statements
iii) not to leave a problem to others to highlight the reality of it ('truth will out') because it feels safe to pretend ignorance or suggesting that it was someone else's problem so not bothering to test the veracity of the method/system in use

Monday, August 15, 2011

Research: critiques of author recognition

Research: critiques of author recognition

With the high-profile Olympics less than 12-months away, the recent looting and rioting that involved the use of voicemail, instant messenging and web-based media and the approach to using "cybercrime" as the new-labelled tool to describe digital investigation and evidential seizure of alleged culpability, these research papers cover some useful ground that might be helpful in evaluating methodology previously unsuspected as fallible to error or mistake, and may have some useful application when applied in author recognition cases which might be relevant to evidence found on mobile phones and computers.

Authors vs. Speakers: A Tale of Two Subfields

The best part of Monday's post on the Facebook authorship-authentication controversy ("High-stakes forensic linguistics", 7/25/2011) was the contribution in the comments by Ron Butters, Larry Solan, and Carole Chaski. It's interesting to compare the situation they describe — and the frustration that they express about it — with the history of technologies for answering questions about the source of bits of speech rather than bits of text.


Practical Attacks Against Authorship Recognition Techniques

The use of statistical AI techniques in authorship recognition (or stylometry) has contributed to literary and historical breakthroughs. These successes have led to the use of these techniques in criminal investigations and prosecutions. However, few have studied adversarial attacks and their devastating effect on the robustness of existing classification methods. This paper presents a framework for adversarial attacks including obfuscation attacks, where a subject attempts to hide their identity imitation attacks, where a subject attempts to frame another subject by imitating their writing style. The major contribution of this research is that it demonstrates that both attacks work very well. The obfuscation attack reduces the effectiveness of the techniques to the level of random guessing and the imitation attack succeeds with 68-91% probability depending on the stylometric technique used. These results are made more significant by the fact that the experimental subjects were unfamiliar with stylometric techniques, without specialized knowledge in linguistics, and spent little time on the attacks. This paper also provides another significant contribution to the field in using human subjects to empirically validate the claim of high accuracy for current techniques (without attacks) by reproducing results for three representative stylometric methods.

Thursday, July 28, 2011

M2M Crime

M2M Crime

In the last discussion (mobile-markets) a reference was made to M2M (machine-to-machine) market stats. Yesterday's article from 'pcworld' about hackers using mobile communications for war texting to unlock car doors (war_texting) should provide useful material to study about M2M for MTEB Students to identify 'potential' crime activity and where evidence maybe generated. Send your finalised report (pdf), for marking, by email please.

Saturday, July 23, 2011

Mobile Markets: Nokia 'Mobile Man'...it tells of a story

Mobile Markets: Nokia 'Mobile Man'...it tells of a story

This excellent construction, made up entirely of mobile phones, is Nokia's collaborative project with Beijing postal service to encourage recycling of mobile phones that can be handed in at post offices, according to the news article at news.cnet.com.   


It's great to see projects like, which tend to draw promotions using creative and talented ideas demonstrating the evolving and transforming world of mobile phones and its market places. Back in 2007 I posted on another creative work cellphone-transformer, which, yet again, shows a design that captures the imagination displaying the versatile uses to which a mobile phone might be put.

The business and ecomonic philosophy that resides behind these creative images equally tells of a story of growth and success. If recycling is happening then, perhaps, that is as a likely consequence of mobile ubiquity taking hold. That is a nice statement, but can I back it up?  I don't have my finger on every financial and market research pulse, but, apart from anecdotal references, there are various stats out there from the market research firms. Indeed, back in 2008 I blogged (staggering-figures-for-mobile-phone) on the state of the mobile data market when the economic downturn (which appears to have started in 2007 so we are led to believe) had got a firmer grip on global markets. In 2010 the stats still showed extraordinary figures (text.it), although the exact detail where all this activity occurs to generate such figures may not be obvious. It may be compelling to want to know how many consumers send text and mms messages (see OFCOM website for stats), but that is not the full picture. There are the other data markets in business to consider, such as the M2M market place (winwin) and comments by industry pundits on the mobile payments market (cellular-news).

It is useful to see how industry people collate information and bring amassed facts together in order to express their views and vision on what all the facts mean to them in aggregrate. An example of this can be seen in Tomi Ahonen's enthusiastic commentary found in Insiders Guide To Mobile (lulu) with references to trillion dollar market, over 4 billion users and the segmented factors when drawn together identified to him what is forecast for mobile. A view of one segment of the mobile phone market, apps, is simply a further illustration of information to be sourced to underpin market trends (windows-phone-apps-reach-new-market), another is sales and market penetration, such as Apple's iPhone outrageously outstanding sales growth.

If I removed from the context of the above commentary discussion about modern technology, and simply focussed on what an image might communicate, I could have been talking about social, cultural and economic life that might have been depicted by way of an 18th/19th century painting (irrespective of whether the painting is by an impressionist or not). Whilst the image above may not be an old master piece, the image still has a story to explicitly convey and that, in forensic terms, requires understanding all or part of any implicit subtext the image can also communicate.

My forensic skills, acquired over the years, meant that my reaction to seeing this image (even though photo/art imagery is not my subject), was to look at it as evidence and then set out to see what I could deduce from there. In reality we do this everyday in our work. We see a SIM card. We then want to know what it is and what is inside. In order to know what we are dealing with we need to know how it works and what can be held inside and whether all or part thereof can be revealed. Moreover, we need to know what amounts to 'conformance' and within that framework which conforming element is 'mandatory' and which is 'optional'. Once we have that background we can then begin to understand what is 'non-conforming' and/or 'unusual'. This path can equally be taken when dealing with mobile phones and RF investigations.

In conclusion, the subtext of this discussion can be revealed. However mobile phones maybe presented to the world, it is our job in forensics not to change that messsage, but to break down the presentation into its various building block elements in order that we know how each piece works and then how the pieces fit together and work and cooperate together.  This is because a true forensic standard requires of the individual to obtain knowledge by way of commentary, appropriate training, standards, specs and investigation, that includes examination and testing (trial and error), which is one side of the coin. The other side of this coin is knowing what the 'thing' in its final state is intended to do, which requiries understanding of the market place it which the 'thing' is to be adopted.  Using skills and techniques like these provide for a rich source of experience, too. Essentially, learning to bring all the pieces that are needed into play and being able to demonstrate that identifies the forensic examiner working with a well hone, self-principled approach of high standard.

For MTEB students, the summer recess is now here. Sure, have a great time and relax and enjoy the break, but don't waste valuable time. Great people strive in life because they want to go beyond what has already been achieved. Take time out from relaxing to bring together the exposure you have had to mobile knowledge and experience you have acquired, thus far. Select a particular line of investigative enquiry and see how far you get with it. I have identified some links above to illustrate a way forward or choose a different subject matter; remember to be able to demonstrate the primary basics of 'bush' methodology.

Tuesday, July 19, 2011

iPhones: Common Password Usage Risks

iPhones: Common Password Usage Risks


In the current climate of news about the use of PINs/Passwords to gain unauthorised access to mobile content and voicemail accounts, an interesting study published by an app developer identifying common iPhone passwords. The article identifies the ten most common pin/passwords determined from the study:


"Formulaic passwords are never a good idea, yet 15% of all passcode sets were represented by only 10 different passcodes (out of a possible 10,000). The implication? A thief (or just a prankster) could safely try 10 different passcodes on your iPhone without initiating the data wipe. With a 15% success rate, about 1 in 7 iPhones would easily unlock--even more if the intruder knows the users’ years of birth, relationship status, etc." most common iphone passcodes

Whilst password predicability may not be ground breaking news, this study just might be a useful insight that highlights that iphone mobile phone users appear to make predictable choices when selecting a pin/password and may persuade users to look more carefully at their choice of handset pin/password in current use.

Sunday, July 03, 2011

HTML5: holds a future for and after other mobile apps

HTML5: holds a future for and after other mobile apps

I have just written about mobile apps and forensics (windows-phone-apps-reach-new-market) because it is here and now and requires attention. An aspect of Forensics though is equally not being blinked to future trends. The question of future trends was asked by the House of Commons Science and Technology Committee in their recent report cmselect 855. It is really worth the time and effort to download and read this report.

HTML5 is a future trend and one that has already started to take hold. As nebusiness's The Journal pointed out (http://www.nebusiness.co.utechnology-leap-set-to-make-apps-redundant) "HTML5 builds on the technology of the existing internet but, as every web user knows, if you lose your connection, you lose your work. With HTML5 you don’t – you can go from connected to disconnected and never notice: files can be saved locally and remotely when needed, just like normal apps. Quietly, we’re starting to see more HTML5 apps, like that of the FT, which work on all devices. The FT app is amazing. Try it out. It’s all in HTML5 and as good as, if not better, than a native iPhone app."

With HTML5 there is a sense that forensics might see improvement in interpreting data that could be properly rendered for viewing; currently this can require other apps to assist that process. Moreover, vast quantities of unintelligible random code and data which could not be rendered by handsets can be found during physical dumps that no one really makes sense to identify what it is. Were unravelling and decoding of random code/data to be explained in itself it still might not explicitly or implicity confirm whether the handset user could see/access rendered versions of that code and data on the handset screen or select content by using the handset UI. HTML5 may yet assist in solving some of these issues, so is it a future trend forensic practitioners should be aware?

Well, I think it is something that cannot be excluded largely due to the fact it is at present being used, mobile browsers are making use of it and widely used mobile handsets support or portions of it in e.g. Apple's iOS 4.2, Android, Samsung, Nokia and so on.

So what can HTML5 do for mobile web browsing?
Well, it helps standardise those issues which had previously been problematical to mobile web browsing and, for mobile web developers, to get testable, cross-platform and standards-based interface for developing content that, prior to HTML5, required _fit_the_need_of_the_technology_ methods or proprietory APIs to achieve the level of rendering needed for rich content and browsing.

HTML5 and Forensics
It opens up the door for new or improved evidence. Do remember, particularly for those readers not involved with forensics, evidence doesn't necessarily mean recovered data that is detrimental or that some massive spying operation is in progress. Mobile HTML5 could have benefits to assist retain data that could help resolve a dispute, track a missing person and so on. Location awareness, localised data caching when mobile connectivity is lost and a range of other features that I shall be discussing later on.

What is possible to say at this stage, omitted data previously breaking the chain of causation needed for forensic evaluation may well be greatly assisted by HMTL5 but without a forensic examiner having to put, metaphorically speaking, all his/her sought artefact-eggs into one evidential-methodology basket. Nice !

Saturday, July 02, 2011

Windows Phone Apps reach new market levels

Windows Phone Apps reach new market levels

Back in 2006 Vodafone announced news to standardise handsets (here) and I commented then that it might be a good idea if users could profile their own handsets with the apps they actually use.  There is much market evidence to suggest the evolving mobile is moving in that direction. Android, Apple, Blackberry, Java and Symbian apps stores are a good example of this. The growth in mobile apps has not been limited to the five previously mentioned, Window Phone apps, too, are storming ahead with over 25,235 apps available.

There is a brief synopsis of the Windows Phone apps growth at winrumors. The chart below is courtesy of windowsphoneapplist.


windows phone 7 applications


Knowing these stats can be helpful but unless there is some inter-related commentary about the technology (so to speak) that links those stats to forensics, it can all become pretty meaningless. My take on those stats is they do present challenges that the mobile forensic community will need to adapt, sooner rather than later. There is a wealth of information in apps that cannot be gleaned from using many of the evidence recovery automated handset readers. This has happened because evidence tools may not have been designed for that purpose; recovering app info and the content they store.

Firstly, it is important to understand the distinction between apps accessible through interface/emulator tools, designed for app builders and programmers (so to speak), and those tools said to be designed for collecting evidence.

Secondly, it doesn't automatically follow that just because an examiner obtains an evidential physical dump from flash memory ( a ) the examiner has dumped everything from the correct component ( b ) that the dump's content will be 'visible' and 'legible' (PACE 1984) and 'intelligible' (DPA1984).

Holding such a view doesn't mean, nor is it intented to suggest, that I think there is an impossibility here that cannot be overcome. Do I think the mobile forensic communty, working together, will find the solutions? Yes, absolutely, naturally.

Monday, June 27, 2011

iCloud MobileMe Quota Storage

iCloud MobileMe Quota Storage

As with most things in the digital world and examining evidence, it is essential for an examiner to understand the way in which a product or service works and the options that brings, as opposed to only considering the stored data that is discovered upon initial examination.

There has been alot of discussions in the forensic community about iCloud and its impact on off-device storage access and examination. Interesting to note then that MobileMe storage quotas are in place, as recently observed:

http://www.macrumors.com/2011/06/20/if-you-use-all-your-icloud-storage-apple-sends-you-this-email/


If the user only wants to keep to the 5GB limit and doesn't delete data and the devcie storage is equally full, is newer data automatically deleted or stored elsewhere? I only raise the point because with increased data flowing in and out of mobile phones, this could impact on data connected to one issue being spread across several storage locations. 

Monday, June 06, 2011

D-Day 6th June

D-Day 6th June




I mentioned today's important date to a number of people. Quite a few had forgotten the date and mainly the younger generation didn't know about events that took place on this date back in 1944.



For anyone who may have missed it or might want to know more, here are some links providing the historical background.

NORMANDY LANDINGS
British Legion Remembrance d-day-65
Wikipedia Normandy Landings
Britannica DDay
Remembrance D-Day.html
Lifeformation D-Day


SCHOOL CHILDREN (CBBC)
BBC/CBBC D-Day



Friday, June 03, 2011

Update on Forensic Webblog Posts

Update on Forensic Webblog Posts

Cell Site Analysis
http://cellsiteanalysis.blogspot.com/
-------------------------------------
Radio Survey Field Notes
CSA Training Explanatory Diagram
iOS 4.3.3 deletion of Location Cache
Requesting Cell Site Data

Forensic Mobile Examination
http://forensicmobex.blogspot.com
---------------------------------
Handset Examination in 1995
sn0wbreeze unthethering Windows iPhones
Symbian OS v9.4, Series 60 rel. 5


Examination and Evidence from SIM and USIM Cards
http://sim2usim.blogspot.com
----------------------------
Answer To Reset (ATR)
Blackberry Forensic Analysis


Billing & Call Detail Record Analysis
http://cdranalysis.blogspot.com/
--------------------------------
Vodafone CDR data
Mobile Evidence CDR/Billing Course
Call Detail Record (CDR) GSM Mobile Telephone Call

ABOUT THE BLOGS

Mobile Telephone Blogs Approved Access Only

I have endeavoured to be free with sharing knowledge and information over many years through my blogs, but given the changing economy, UK and global events and advancements in forensics, the nature of the technical content, new developments and examination techniques and legal information will only be accessible to approved law enforcement personnel, security specialists and authorised individuals. The following blogs are now approved access only:

Cell Site Analysis
http://cellsiteanalysis.blogspot.com

Forensic examination and evidence from SIM an USIM
http://sim2usim.blogspot.com

Forensic examination and evidence from Mobile and Smart Phones
http://forensicmobex.blogspot.com

Forensic analysis of Billing and CDR Records
http://cdranalysis.blogspot.com/

Mobile Telephone Evidence (http://trewmte.blogspot.com) will of course remain an open.

The criteria for authorised access to blogs:

a) Law Enforcement
b) Security Services (MI5, MI6, CID, SB, FBI....)
b1) Security Specialists - a proveable record in security for
networks, digital forensics, handsets, SIM, CDR etc
c) Authorised individuals

Thursday, June 02, 2011

Radio Survey Field Notes

Radio Survey Field Notes

The CSA Training Explanatory Diagram illustrated (previous thread) some of the codes identified in the broadcast radio identities. At this stage the examiner/expert might want to get an early indicator of what this information could mean when attributed to other knowledge, previously acquired, about the target location of interest where radio test measurements are scheduled to be conducted.   

Of course, if you have a keen eye you will note the document is not acquainted with complete pre-profiled cell site details. These details are excluded for a reason, which I shall come onto later. For now it is useful to analyse the Explanatory Diagram content and cross-reference it with the Radio Survey Field Notes.

Some questions:

- What sort of  information do you think can be taken for granted that need not be included into the Field Notes that is in the Explanatory Notes?
- What identities are absence by their omission from the Field Notes that are in the Explanatory Diagram?
- Do you think those identities should be in the field notes?

The purpose of pushing these points is that often evidence is omitted and examiners/experts will certainly need that information to hand when preparing for their opinion, writing a report and giving evidence.  

Wednesday, June 01, 2011

CSA Training Explanatory Diagram

CSA Training Explanatory Diagram

Given the huge range of knowledge and information needed for Cell Site Analysis (CSA) I have spent a considable amount of time creating many training sheets for the courses. The explanatory diagram below represents just some basic information acquired from radio tests and the meaning of the codes shown in the test screens.
This training document forms part of the procedure of a step-by-step guide in a long, long line of steps an trainee examiner will undertake and aids the trainee grasp the basics. Later the trainee will be shown additional information that isn't shown in the above diagram to extend knowledge and understanding.

Soon the examiner will come to realise that when I started out in an early thread in this blog identifying the elements in the GSM Radio DNA Bracelet I had a reason for doing that.  The data displayed in the screens (like the ones above) occur as a consequence of being assigned to one or more of the logical channels identified in the GSM Radio DNA Bracelet delivered by the physical channels of the radio system.

Monday, May 30, 2011

iOS 4.3.3 deletion of Location Cache

iOS 4.3.3 deletion of Location Cache

Apple responded in April 2011 to concerns in the marketplace about location data that enables a user to be tracked without their knowledge or without knowing such a mechanism existed in the iPhone:

http://www.apple.com/pr/library/2011/04/27location_qa.html

By 3rd May 2011 an early fix was suggested would be available pending the outcome of Beta tests. That the fix would deal with location backups to iTunes when Location Services was switched OFF.  

On the 5th May the promised iOS patch to resolve the iPhone location tracking went live and reduced the size of the cache of information that had been backed up. Noticeable the cache file is now considerable smaller, however the size of the update to do that was over 650 megabytes.


Loss of evidence in the cache is one observation and another is with Location Services switched OFF on the handset this may impact on historical and current Cell Site Analysis investigations.

Answer To Reset (ATR)

Answer To Reset (ATR)

It is an endless investigation when dealing with SIM/USIM. The intention of this discussion is to highlight discoveries that you may not be aware. In this instance ATR is the first data read from every SIM/USIM and can provide potentially useful information to an investigation or when making analysis about end-to-end (SIM to Network) mobile telephone evidence.  

What might be interpreted from first eight bytes of an ATR recovered? From research, this is an interpretation of the ATR from a particular manufacturer's GSM SIM:

[B1][B2][B3][B4][B5][B6][B7][B8]
3B....34...11...00...6B...C?..16...0?

Byte 6 - options
3B 34 11 00 6B C2 16 0? normal SIM+OTA
3B 34 11 00 6B C3 16 0? SIM-Toolkit (STK) SIM

Byte 7
16 EEPROM size (16K)

Byte 8 - options
3B 34 11 00 6B C? 16 01 GSM security algorithm
3B 34 11 00 6B C? 16 02
3B 34 11 00 6B C? 16 03
3B 34 11 00 6B C? 16 0A

  
As interpretation of the ATR can be possible, do all SIM ATRs follow the same identification process or when personalised uniquely characterise the ATR to instruct the handset/network with similar information about the SIM's technical profiling but identified at different byte locations in the ATR string?

Saturday, May 28, 2011

Evolving Cell Site Analysis (CSA)

Evolving Cell Site Analysis (CSA)

In 23 years of dealing with a range of cellular radio systems TACS, GSM and WCDMA and, lately, a little of LTE, in addition to NFC work, generates a measured confidence in dealing with change when it occurs.

The word 'Re-farming' of 900 MHz , largely a play word, the core of which is based upon re-allocation of spectrum from one technology and service to another (eg GSM TDMA to 3G WCDMA), and local inter-operator roaming (Orange and T-Mobile) are two such changes to which CSA is exposed. These changes are, though, nothing more than evolution in a innovation driven and commercially challenging market place. Knowledge doesn't simply disappear overnight because these changes have occurred.

Operator and spectrum imposed changes appear to have generated perhaps understandable concerns, but the premise of these concerns might actually be based upon misconceptions about how those changes impact on cell site analysis. Concerns, such as, a no-can do approach; a patch fix is needed; the notion that is all you are going to get; to a loss of evidence with the introduction of changes, are a variety I have heard. The introduction of Everything Everywhere is another good example in point. Many of the constraints currently being purveyed in the marketplace would require ignoring a considerable body of information.



Photo courtesy of www.dailymail.co.uk article-0-001097AB00000258-251_468x315.jpg

Don't Panic Mr Mainwaring!! Simply running out with a piece of test equipment and having a few shots at a target, chatting with several people or referring to comments on the web really isn't appropriate qualification for the matter under scrutiny when one is not fully certain of (figuratively speaking) the enemy.

Cell site analysis doesn't suffer from evidential menigitis just because changes take place, as there are a huge range of factors and information that need to be considered first when making a diagnosis of the matter in order to determine a prognosis.

Thursday, May 19, 2011

Aggregated SIM

Aggregated SIM

Interesting news story out of  Reuters that has been posted by many website that states that Apple has proposed a standardized SIM card smaller than those it currently uses in the iPhone and iPAD in order to be able to produce thinner devices, an Orange executive told Reuters on Tuesday. The news story also mentions Apple having gone along the Standards path and approached ETSI (European Telecommunications Standards Institute) and a hint that something could be seen as early as next year.

http://www.reuters.com/article/2011/05/17/us-summit-orange-apple-idUSTRE74G4WY20110517

This is SIM card developmental news and fascinating to watch as SIM and the microprocessor electronic card (ICC/UICC) that it uses takes further steps on its evolutionary journey.  We already know some of the form factors for ICC/UICC:

The integrated and non-integrated examples
Photobucket

A closer look at an integrated example
Photobucket

When SIM (subscriber identity module) cards were introduced for GSM (global systems for mobile) communication devices (handset/terminal devices) ETSI standardised the ID-1 format which was an ISO-size card as defined in the international standard ISO-7816 and commonly referred to as a 'credit card' size. A plug-in size (the size of a 'postage stamp') was also introduced and these designs are commonly seen in the standard GSM11.11. Distinctively, the shape, size and operational performance of the card means that the card, called an ICC- integrated circuit card (or Universal ICC following the introduction of 3G-WCDMA cellular radio) - should be distinguished from the SIM module, which is itself a programmable area on the card.   However, a further card size emerged and was defined in the 2004-03 ETSI standard TS 102.221 as "mini-UICC". It should be noted that where I have mentioned GSM11.11 this standard refers to the use of SIM cards with GSM technology and services. The lineage of GSM SIM and its standards are linked to ETSI standards including TS 102.221 and, of course, ISO standards. A similar path can be trod when dealing with U-ICC/U-SIM.

As for Apple's suggested development, what we don't know at this stage is what the aggregated SIM (but I think I might want to read that as form factor and size) will look like or its content for that matter. We can only guess at this stage.

Sunday, May 08, 2011

Forensic Mobile Examination Posts

Forensic Mobile Examination Posts

Latest posts at: http://forensicmobex.blogspot.com/

Nokia s40 Forensic Analysis - Call Release
Deleted Text Messages 3GS iPhones
Blackberry Forensic Analysis

The criteria for authorised access to cell site analysis blog is either:

a) Law Enforcement
b) Security Services (MI5, MI6, CID, SB, FBI....)
b1) Security Specialists - a proveable record in security for
networks, digital forensics, handsets, SIM, CDR etc
c) Authorised individuals (people whom I know)