Investigations, Practices and Procedures: Seizure-Forensic Examination-Evidence. Cellular and Satellite Telephones, Call Records-Billing Data, Cell Site Analysis. Telecomms. Computer and Network Analysis. GPS devices & Jammers, Cyber, IoT forensics.
Sunday, October 06, 2013
(U)ICC/(U)SIM Script Commands and Responses
The discussion under (U)ICC/(U)SIM Script Commands and Responses is one of a number that will appear to assist Diploma students with their course work.
http://sim2usim.blogspot.co.uk/2013/10/uiccusim-script-commands-and-responses.html
(U)ICC/(U)SIM Script Commands and Responses
GSM ICC/SIM script selecting Master File, Dedicated File and Elementary File
Reason for script test : defining an examination procedure to isolate and test a single elementary file; determine the EF's status, file structure, coding etc; conrroborate the ability of the (U)ICC/(U)SIM to action responses from commands sent to card; provide corroborating evidence of commands sent to the card to demonstrate evidential integrity (transparency of practices and procedures); testing the examination card reader is functioning correctly; QA procedures.
Script examination tool used : USIM Commander - http://www.quantaq.com/usimcommander.htm
Relevant Core Diplomas:-
Aims : MTEB Diploma for Mobile Evidence QA and Evidence Handling - Mobile Telephone Diploma Core CQAE1
Objectives : Device Maintenance and Calibration; Examination Procedure
Aims : MTEB Diploma for SIM and USIM Technology Examination - Mobile Telephone
Diploma Core CSUT2
Objectives : Your understanding of roles and responsibilities and the importance of
appropriate practices and procedures for SIM and USIM Technology
Examination for acquiring evidence.
Reference Standards :
GSM11.11/3GPP TS51.011/3GPP TS31.102,
GSM11.12,
GSM11.17/3GPP TS51.017/3GPP TS31.120/3GPP TS31.121/3GPP TS31.122,
GSM11.18/3GPP31.101,
EU MTEB Diploma Student Note : Remember to check with ETSI Standards e.g. TS102.221 etc
US MTEB Diploma Student Note : Diploma Students remember to check e.g. C.S0065-0 v1.0, C.S0074-0 v1.0, C.S0074-A v1.0, N.S0009-0 v1.0, S.R0095-0 v1.0 etc
Generically speaking, apart from GSMA and 3GPP, there is also 3GPP2 which also includes ARIB, CCSA, TIA TTA, TTC that all have conditions that can impact/influence results on (U)ICC/(U)SIM.
The discussion under (U)ICC/(U)SIM Script Commands and Responses is one of a number that will appear here to assist Diploma students with their course work.
The latest MTEB Diploma Modules Guide MTEdipl 2.2 can be downloaded here:
https://dl.dropboxusercontent.com/u/84491783/MTEdipl%202.2.pdf
Saturday, September 14, 2013
(U)SIM Examination (Physical) Pt1
We begin with GSM as this is the original starting place where examiners first learned about subscriber identity modules (SIM). There are many ways to learn about SIM: using a SIM reader tool is one way, receiving instruction during training that concentrates on the types of user and network data that can be harvested by examiners. An education and training process can equally include a training module or modules on the physical aspects of a card and identify, for the examiner, material parts of the SIM, the known routes to understanding electrical aspects, processing aspects, storage geometry and memory mapping, so on and so forth. The thinking here is analogous to the way in which there is an expectation that a computer examiner would understand HDD disc geometry, clusters and sectors, BIOS etc even before entering into the search and study of the 'content' that may be recorded on the disc. It is or should be the same for (U)SIM.
The SIM Card can be seen as a composition of at least three constituent parts:
- The physical card (the storage carrier).
- An integrated circuit card micro-processing chip (the operating system and content storage device).
- The subscriber identity module; an area of physical memory allocated at manufacturing for pre-market and post-market recording by the mobile network operator and SIM user.
- A fourth constituent part could be a Card with an etched antenna for RFID/NFC for use by (US)SIM (but this part is not included or discussed at this stage).
- etc
To enable test and inspection of these constituent parts GSM approved and adopted GSM11.17 to assist manufacturers, operators and service providers help formalise and uniform the test and inspection procedures rather than have a mish-mash of randomly selected tests for SIM cards submitted for use in GSM. The former is highly desirable as the goal of GSM has always be about interconnection-compatiblity and interconnection backward-compatibility. By way of illustration, a GSM SIM Card Phase 1 should still be able to be inserted into a GSM Phase 2+ mobile device and allow communications to take place, unless the operator or device manufacturer has declared and stated otherwise.
From an examiner's viewpoint we would desire to know how those three constituent parts translate to the work we do? Some examples are set out below
Physical Card
Due to the form factors used in GSM we can make assessment to determine the supply chain and manufacturer of the card itself. We look at the card to see if has been cut down for use and any attempts of anonymity by removal of the SIM Serial Number (SSN) compared to manufacture polarisation techniques. Later 3G/LTE USIM Cards have undergone some changes since GSM's inception; the latter will be dealt at a later date.
Image courtesy of wikipedia - http://en.wikipedia.org/wiki/Subscriber_Identity_Module
ICC Chip
Manufacturer and technical specification are important to determine a range of potential evidence, including release into the marketplace and technological and electronic capability. Clearly the geometry and memory mapping are important. There are various techniques to deal with a card with a damaged chip. One example is called 'acid-etching' used to gain access to the physical chip itself by removal of the outer protective coverings used in the manufacturing process.
Image courtesy of wikipedia - http://en.wikipedia.org/wiki/Subscriber_Identity_Module
Physical Memory
Determining geometry and memory mapping forms part of the testing and inspection process set out in GSM1117. We can use these procedures to formulate a forensic analysis programme, similar to the way in which computer forensic examiners seek to determine specifically data discovered and recovered from a particular memory location on the HDD and define the data from its binary and encoded states and any formatting that may be applicable to the data. That being so, would it be out of the question in SIM examination terms for the EFBCCH file to be formatted as .bmp? Below are a set of powerpoint slides I have prepared so that examiners can comprehend procedures approved and adopted for test and inspection for GSM SIM Cards. Later on when we 3G/LTE (U)SIM this GSM starting point assists formulate how to identify differences between the various (U)SIM/LTE cards but equally identify expansion of technology services and content so the examination limit or avoid omissions during the investigative/evidential process.
Saturday, March 30, 2013
(U)SIM Examination (Physical) Pt1
We begin with GSM as this is the original starting place where examiners first learned about subscriber identity modules (SIM). There are many ways to learn about SIM: using a SIM reader tool is one way, receiving instruction during training that concentrates on the types of user and network data that can be harvested by examiners. An education and training process can equally include a training module or modules on the physical aspects of a card and identify, for the examiner, material parts of the SIM, the known routes to understanding electrical aspects, processing aspects, storage geometry and memory mapping, so on and so forth. The thinking here is analogous to the way in which there is an expectation that a computer examiner would understand HDD disc geometry, clusters and sectors, BIOS etc even before entering into the search and study of the 'content' that may be recorded on the disc. It is or should be the same for (U)SIM.
The SIM Card can be seen as a composition of at least three constituent parts:
- The physical card (the storage carrier).
- An integrated circuit card micro-processing chip (the operating system and content storage device).
- The subscriber identity module; an area of physical memory allocated at manufacturing for pre-market and post-market recording by the mobile network operator and SIM user.
- A fourth constituent part could be a Card with an etched antenna for RFID/NFC for use by (US)SIM (but this part is not included or discussed at this stage).
- etc
To enable test and inspection of these constituent parts GSM approved and adopted GSM11.17 to assist manufacturers, operators and service providers help formalise and uniform the test and inspection procedures rather than have a mish-mash of randomly selected tests for SIM cards submitted for use in GSM. The former is highly desirable as the goal of GSM has always be about interconnection-compatiblity and interconnection backward-compatibility. By way of illustration, a GSM SIM Card Phase 1 should still be able to be inserted into a GSM Phase 2+ mobile device and allow communications to take place, unless the operator or device manufacturer has declared and stated otherwise.
From an examiner's viewpoint we would desire to know how those three constituent parts translate to the work we do? Some examples are set out below
Physical Card
Due to the form factors used in GSM we can make assessment to determine the supply chain and manufacturer of the card itself. We look at the card to see if has been cut down for use and any attempts of anonymity by removal of the SIM Serial Number (SSN) compared to manufacture polarisation techniques. Later 3G/LTE USIM Cards have undergone some changes since GSM's inception; the latter will be dealt at a later date.
Image courtesy of wikipedia - http://en.wikipedia.org/wiki/Subscriber_Identity_Module
ICC Chip
Manufacturer and technical specification are important to determine a range of potential evidence, including release into the marketplace and technological and electronic capability. Clearly the geometry and memory mapping are important. There are various techniques to deal with a card with a damaged chip. One example is called 'acid-etching' used to gain access to the physical chip itself by removal of the outer protective coverings used in the manufacturing process.
Image courtesy of wikipedia - http://en.wikipedia.org/wiki/Subscriber_Identity_Module
Physical Memory
Determining geometry and memory mapping forms part of the testing and inspection process set out in GSM1117. We can use these procedures to formulate a forensic analysis programme, similar to the way in which computer forensic examiners seek to determine specifically data discovered and recovered from a particular memory location on the HDD and define the data from its binary and encoded states and any formatting that may be applicable to the data. That being so, would it be out of the question in SIM examination terms for the EFBCCH file to be formatted as .bmp? Below are a set of powerpoint slides I have prepared so that examiners can comprehend procedures approved and adopted for test and inspection for GSM SIM Cards. Later on when we 3G/LTE (U)SIM this GSM starting point assists formulate how to identify differences between the various (U)SIM/LTE cards but equally identify expansion of technology services and content so the examination limit or avoid omissions during the investigative/evidential process.
Friday, February 17, 2012
Examination Techniques2: Android
To assist formulate a conclusion how a device (DUT) has been used examining apps the user has recently used may provide some useful clues. Recently used apps can be identified by holding down the 'home' button, a popup window is then released listing the last opened apps.
Examination Techniques1: iOS5 Safari Browsing
When conducting examinations it may be helpful to raise the observation that an investigator may wish to examine how the user has profiled the device (DUT) when in normal use - e.g. to determine browser settings under "Settings"
Saturday, July 02, 2011
Windows Phone Apps reach new market levels
Back in 2006 Vodafone announced news to standardise handsets (here) and I commented then that it might be a good idea if users could profile their own handsets with the apps they actually use. There is much market evidence to suggest the evolving mobile is moving in that direction. Android, Apple, Blackberry, Java and Symbian apps stores are a good example of this. The growth in mobile apps has not been limited to the five previously mentioned, Window Phone apps, too, are storming ahead with over 25,235 apps available.
There is a brief synopsis of the Windows Phone apps growth at winrumors. The chart below is courtesy of windowsphoneapplist.
Knowing these stats can be helpful but unless there is some inter-related commentary about the technology (so to speak) that links those stats to forensics, it can all become pretty meaningless. My take on those stats is they do present challenges that the mobile forensic community will need to adapt, sooner rather than later. There is a wealth of information in apps that cannot be gleaned from using many of the evidence recovery automated handset readers. This has happened because evidence tools may not have been designed for that purpose; recovering app info and the content they store.
Firstly, it is important to understand the distinction between apps accessible through interface/emulator tools, designed for app builders and programmers (so to speak), and those tools said to be designed for collecting evidence.
Secondly, it doesn't automatically follow that just because an examiner obtains an evidential physical dump from flash memory ( a ) the examiner has dumped everything from the correct component ( b ) that the dump's content will be 'visible' and 'legible' (PACE 1984) and 'intelligible' (DPA1984).
Holding such a view doesn't mean, nor is it intented to suggest, that I think there is an impossibility here that cannot be overcome. Do I think the mobile forensic communty, working together, will find the solutions? Yes, absolutely, naturally.
Sunday, April 24, 2011
Faraday containers found unsafe
A report that focuses on the results, following conducted practical tests, on the reliability of mobile phone shielding devices (eg 'faraday' containers) found the device shielding failed in a number of instances that the author of the report placed under test and did not prevent RF signalling reaching the test mobile phones inside the containers, the findings in this recently published paper suggests:
https://www.cerias.purdue.edu/assets/pdf/bibtex_archive/2010-27.pdf
The implications might require that an 'impact assessment' on evidence that is seized and placed in shielding devices at the scene of a crime and transported from Police Station to Police Station etc may need to be 'reconducted'. The findings in the report raise the notion whether published Guidelines advocating the use of shielding devices may now need to identify exactly the tests and research considered prior to adopting published policy on the use of shielding devices, although it is unclear at present whether that will happen at all.
Whilst the report dealt primarily with external factors (radio communications) and how the shielding devices coped with them, it also includes some other influences shielding devices can have on touch screen mobile phones, for example.
There have previously been mixed reviews about shielding devices and their impact on seized evidence that is left switched ON within shielding containers:
http://www.forensicfocus.com/index.php?name=Forums&file=viewtopic&t=3914
http://www.forensicfocus.com/index.php?name=Forums&file=viewtopic&t=4277&postdays=0&postorder=asc&start=0
If a mobile phone is already OFF, or is switched OFF at the point of seizure, then such shielding devices shouldn't be necessary at that particular juncture.
Thursday, December 30, 2010
Apple sued over iPad and iPhone app 'data leaks'
The BBC article doesn't mention it, but it would be helpful to know what personal data is being captured by web-based companies etc. In the wrong hands captured personal data for MSISDN could be used, by pinging from the internet, to cache polled MSISDNs for their IMSIs etc. The equipment is out there to do it and has been for many years.
With credit card details being included within suggested secure apps for UICC cards, it is not difficult to imagine a rogue poll and de-tanking event occuring that goes unnoticed because it appears like the modern unobtrusive location updating procedure or another procedure and the user may only know about it after the data is missing.
Should that event happen it is what is termed as a "Mobile Cybercrime". The relevance being, making use of the singular term cybercrime as a title is highly misleading because you need a science and an operable technology in which the event needs to activate and commission. Mobile communications is a science and a technology (a damned fine science and technology they are, too).
http://www.bbc.co.uk/news/technology-12089225
Friday, July 31, 2009
Cellphone Examination and Myths
Friday, May 15, 2009
Undercover Officer Down, how might SIM Access Control Class help? Part 1
Undercover Officer Down, how might SIM Access Control Class help? Part 1
Wednesday, February 11, 2009
Exploding Cell Phone Battery
.
A reminder for examiners to take care when examining mobile phones that require recharging the battery before examining the device. The horror story of a man's who had his neck artery burst by the exploding mobile phone in his breast pocket and died. Prior to putting it in his pocket the man had recharged the battery. Production line (bang it on, bang it out) mobile telephone examinations are potentially at high risk and a risk assessment procedure may need to be put in place to avoid loss of fingers or limbs or disfigurement. Insurance companies may need to be made aware of this potential high risk.
.
http://www.telegraph.co.uk/news/worldnews/asia/china/4452360/Exploding-mobile-phone-kills-man-in-China.html
.
Last year Vinny Parmar produced a document (see link below) about counterfeit mobile telephones and it is by no means certain whether these devices are using batteries that may explode.
.
http://trewmte.blogspot.com/2008/11/counterfeit-mobile-phones.html
.
Moreover, some people are apt to placing their mobile telephone in more unusual places about their person. Whether the person is smuggling or something else the exploding battery provides a stark reminder that they may put their life at risk.
.
http://trewmte.blogspot.com/2006/11/whats-this.html
.
Thanks to Richard Putnam for sending to me the Telegraph newspaper online link.
.
UPDATE: A further Telegraph online article has been written regarding the above exploding battery. Apparently, this second news article suggests it was a bullet from a home made gun that had cause the accident. However both Telegraph online articles are not referenced to each other so it is only an assumption that they both may be referring to the same incident.