Showing posts with label examination procedure. Show all posts
Showing posts with label examination procedure. Show all posts

Sunday, October 06, 2013

(U)ICC/(U)SIM Script Commands and Responses

(U)ICC/(U)SIM Script Commands and Responses

The discussion under (U)ICC/(U)SIM Script Commands and Responses is one of a number that will appear to assist Diploma students with their course work.

http://sim2usim.blogspot.co.uk/2013/10/uiccusim-script-commands-and-responses.html

(U)ICC/(U)SIM Script Commands and Responses

(U)ICC/(U)SIM 3F00 7F10 6F4A

3GPP UICC/USIM script selecting Master File, Dedicated File and Elementary File





















GSM ICC/SIM script selecting Master File, Dedicated File and Elementary File






























Reason for script test : defining an examination procedure to isolate and test a single elementary file; determine the EF's status, file structure, coding etc; conrroborate the ability of the (U)ICC/(U)SIM to action responses from commands sent to card; provide corroborating evidence of commands sent to the card to demonstrate evidential integrity (transparency of practices and procedures); testing the examination card reader is functioning correctly; QA procedures. 

Script examination tool used : USIM Commander - http://www.quantaq.com/usimcommander.htm

Relevant Core Diplomas:-

Aims : MTEB Diploma for Mobile Evidence QA and Evidence Handling - Mobile Telephone Diploma Core CQAE1

Objectives : Device Maintenance and Calibration; Examination Procedure

Aims :  MTEB Diploma for SIM and USIM Technology Examination - Mobile Telephone
Diploma Core CSUT2

Objectives : Your understanding of roles and responsibilities and the importance of
appropriate practices and procedures for SIM and USIM Technology
Examination for acquiring evidence.

Reference Standards :
GSM11.11/3GPP TS51.011/3GPP TS31.102,
GSM11.12,
GSM11.17/3GPP TS51.017/3GPP TS31.120/3GPP TS31.121/3GPP TS31.122,
GSM11.18/3GPP31.101,

EU MTEB Diploma Student Note : Remember to check with ETSI Standards e.g. TS102.221 etc

US MTEB Diploma Student Note : Diploma Students remember to check e.g. C.S0065-0 v1.0, C.S0074-0 v1.0, C.S0074-A v1.0, N.S0009-0 v1.0, S.R0095-0 v1.0 etc

Generically speaking, apart from GSMA and 3GPP, there is also 3GPP2 which also includes ARIB, CCSA, TIA TTA, TTC that all have conditions that can impact/influence results on (U)ICC/(U)SIM.

The discussion under (U)ICC/(U)SIM Script Commands and Responses is one of a number that will appear here to assist Diploma students with their course work.

The latest MTEB Diploma Modules Guide MTEdipl 2.2 can be downloaded here:
https://dl.dropboxusercontent.com/u/84491783/MTEdipl%202.2.pdf


Saturday, September 14, 2013

(U)SIM Examination (Physical) Pt1

(U)SIM Examination (Physical) Pt1

We begin with GSM as this is the original starting place where examiners first learned about subscriber identity modules (SIM). There are many ways to learn about SIM: using a SIM reader tool is one way, receiving instruction during training that concentrates on the types of user and network data that can be harvested by examiners. An education and training process can equally include a training module or modules on the physical aspects of a card and identify, for the examiner, material parts of the SIM, the known routes to understanding electrical aspects, processing aspects, storage geometry and memory mapping, so on and so forth. The thinking here is analogous to the way in which there is an expectation that a computer examiner would understand HDD disc geometry, clusters and sectors, BIOS etc even before entering into the search and study of the 'content' that may be recorded on the disc. It is or should be the same for (U)SIM.

The SIM Card can be seen as a composition of at least three constituent parts:

- The physical card (the storage carrier).
- An integrated circuit card micro-processing chip (the operating system and content storage device).
- The subscriber identity module; an area of physical memory allocated at manufacturing for pre-market and post-market recording by the mobile network operator and SIM user.
 -  A fourth constituent part could be a Card with an etched antenna for RFID/NFC for use by (US)SIM (but this part is not included or discussed at this stage).
- etc

To enable test and inspection of these constituent parts GSM approved and adopted GSM11.17 to assist manufacturers, operators and service providers help formalise and uniform the test and inspection procedures rather than have a mish-mash of randomly selected tests for SIM cards submitted for use in GSM. The former is highly desirable as the goal of GSM has always be about interconnection-compatiblity and interconnection backward-compatibility. By way of illustration, a GSM SIM Card Phase 1 should still be able to be inserted into a GSM Phase 2+ mobile device and allow communications to take place, unless the operator or device manufacturer has declared and stated otherwise.

From an examiner's viewpoint we would desire to know how those three constituent parts translate to the work we do? Some examples are set out below

Physical Card
Due to the form factors used in GSM we can make assessment to determine the supply chain and manufacturer of the card itself. We look at the card to see if has been cut down for use and any attempts of anonymity by removal of the SIM Serial Number (SSN) compared to manufacture polarisation techniques. Later 3G/LTE USIM Cards have undergone some changes since GSM's inception; the latter will be dealt at a later date.


 Image courtesy of wikipedia - http://en.wikipedia.org/wiki/Subscriber_Identity_Module

ICC Chip
Manufacturer and technical specification are important to determine a range of potential evidence, including release into the marketplace and technological and electronic capability. Clearly the geometry and memory mapping are important. There are various techniques to deal with a card with a damaged chip. One example is called 'acid-etching' used to gain access to the physical chip itself by removal of the outer protective coverings used in the manufacturing process. 

 
  Image courtesy of wikipedia - http://en.wikipedia.org/wiki/Subscriber_Identity_Module

Physical Memory
Determining geometry and memory mapping forms part of the testing and inspection process set out in GSM1117. We can use these procedures to formulate a forensic analysis programme, similar to the way in which computer forensic examiners seek to determine specifically data discovered and recovered from a particular memory location on the HDD and define the data from its binary and encoded states and any formatting that may be applicable to the data. That being so, would it be out of the question in SIM examination terms for the EFBCCH file to be formatted as .bmp?  Below are a set of powerpoint slides I have prepared so that examiners can comprehend procedures approved and adopted for test and inspection for GSM SIM Cards. Later on when we 3G/LTE (U)SIM this GSM starting point assists formulate how to identify differences between the various (U)SIM/LTE cards but equally identify expansion of technology services and content so the examination limit or avoid omissions during the investigative/evidential process.      













































Saturday, March 30, 2013

(U)SIM Examination (Physical) Pt1

(U)SIM Examination (Physical) Pt1

We begin with GSM as this is the original starting place where examiners first learned about subscriber identity modules (SIM). There are many ways to learn about SIM: using a SIM reader tool is one way, receiving instruction during training that concentrates on the types of user and network data that can be harvested by examiners. An education and training process can equally include a training module or modules on the physical aspects of a card and identify, for the examiner, material parts of the SIM, the known routes to understanding electrical aspects, processing aspects, storage geometry and memory mapping, so on and so forth. The thinking here is analogous to the way in which there is an expectation that a computer examiner would understand HDD disc geometry, clusters and sectors, BIOS etc even before entering into the search and study of the 'content' that may be recorded on the disc. It is or should be the same for (U)SIM.

The SIM Card can be seen as a composition of at least three constituent parts:

- The physical card (the storage carrier).
- An integrated circuit card micro-processing chip (the operating system and content storage device).
- The subscriber identity module; an area of physical memory allocated at manufacturing for pre-market and post-market recording by the mobile network operator and SIM user.
 -  A fourth constituent part could be a Card with an etched antenna for RFID/NFC for use by (US)SIM (but this part is not included or discussed at this stage).
- etc

To enable test and inspection of these constituent parts GSM approved and adopted GSM11.17 to assist manufacturers, operators and service providers help formalise and uniform the test and inspection procedures rather than have a mish-mash of randomly selected tests for SIM cards submitted for use in GSM. The former is highly desirable as the goal of GSM has always be about interconnection-compatiblity and interconnection backward-compatibility. By way of illustration, a GSM SIM Card Phase 1 should still be able to be inserted into a GSM Phase 2+ mobile device and allow communications to take place, unless the operator or device manufacturer has declared and stated otherwise.

From an examiner's viewpoint we would desire to know how those three constituent parts translate to the work we do? Some examples are set out below

Physical Card
Due to the form factors used in GSM we can make assessment to determine the supply chain and manufacturer of the card itself. We look at the card to see if has been cut down for use and any attempts of anonymity by removal of the SIM Serial Number (SSN) compared to manufacture polarisation techniques. Later 3G/LTE USIM Cards have undergone some changes since GSM's inception; the latter will be dealt at a later date.


 Image courtesy of wikipedia - http://en.wikipedia.org/wiki/Subscriber_Identity_Module

ICC Chip
Manufacturer and technical specification are important to determine a range of potential evidence, including release into the marketplace and technological and electronic capability. Clearly the geometry and memory mapping are important. There are various techniques to deal with a card with a damaged chip. One example is called 'acid-etching' used to gain access to the physical chip itself by removal of the outer protective coverings used in the manufacturing process. 

 
  Image courtesy of wikipedia - http://en.wikipedia.org/wiki/Subscriber_Identity_Module

Physical Memory
Determining geometry and memory mapping forms part of the testing and inspection process set out in GSM1117. We can use these procedures to formulate a forensic analysis programme, similar to the way in which computer forensic examiners seek to determine specifically data discovered and recovered from a particular memory location on the HDD and define the data from its binary and encoded states and any formatting that may be applicable to the data. That being so, would it be out of the question in SIM examination terms for the EFBCCH file to be formatted as .bmp?  Below are a set of powerpoint slides I have prepared so that examiners can comprehend procedures approved and adopted for test and inspection for GSM SIM Cards. Later on when we 3G/LTE (U)SIM this GSM starting point assists formulate how to identify differences between the various (U)SIM/LTE cards but equally identify expansion of technology services and content so the examination limit or avoid omissions during the investigative/evidential process.      


















































Friday, February 17, 2012

Examination Techniques2: Android

Examination Techniques2: Android

To assist formulate a conclusion how a device (DUT) has been used examining apps the user has recently used may provide some useful clues. Recently used apps can be identified by holding down the 'home' button, a popup window is then released listing the last opened apps.

Examination Techniques1: iOS5 Safari Browsing

Examination Techniques1: iOS5 Safari Browsing

When conducting examinations it may be helpful to raise the observation that an investigator may wish to examine how the user has profiled the device (DUT) when in normal use - e.g. to determine browser settings under "Settings" a user can select "Private Browsing" which stops archive of browsing history.

Saturday, July 02, 2011

Windows Phone Apps reach new market levels

Windows Phone Apps reach new market levels

Back in 2006 Vodafone announced news to standardise handsets (here) and I commented then that it might be a good idea if users could profile their own handsets with the apps they actually use.  There is much market evidence to suggest the evolving mobile is moving in that direction. Android, Apple, Blackberry, Java and Symbian apps stores are a good example of this. The growth in mobile apps has not been limited to the five previously mentioned, Window Phone apps, too, are storming ahead with over 25,235 apps available.

There is a brief synopsis of the Windows Phone apps growth at winrumors. The chart below is courtesy of windowsphoneapplist.


windows phone 7 applications


Knowing these stats can be helpful but unless there is some inter-related commentary about the technology (so to speak) that links those stats to forensics, it can all become pretty meaningless. My take on those stats is they do present challenges that the mobile forensic community will need to adapt, sooner rather than later. There is a wealth of information in apps that cannot be gleaned from using many of the evidence recovery automated handset readers. This has happened because evidence tools may not have been designed for that purpose; recovering app info and the content they store.

Firstly, it is important to understand the distinction between apps accessible through interface/emulator tools, designed for app builders and programmers (so to speak), and those tools said to be designed for collecting evidence.

Secondly, it doesn't automatically follow that just because an examiner obtains an evidential physical dump from flash memory ( a ) the examiner has dumped everything from the correct component ( b ) that the dump's content will be 'visible' and 'legible' (PACE 1984) and 'intelligible' (DPA1984).

Holding such a view doesn't mean, nor is it intented to suggest, that I think there is an impossibility here that cannot be overcome. Do I think the mobile forensic communty, working together, will find the solutions? Yes, absolutely, naturally.

Sunday, April 24, 2011

Faraday containers found unsafe

Faraday containers found unsafe

A report that focuses on the results, following conducted practical tests, on the reliability of mobile phone shielding devices (eg 'faraday' containers) found the device shielding failed in a number of instances that the author of the report placed under test and did not prevent RF signalling reaching the test mobile phones inside the containers, the findings in this recently published paper suggests:

https://www.cerias.purdue.edu/assets/pdf/bibtex_archive/2010-27.pdf

The implications might require that an 'impact assessment' on evidence that is seized and placed in shielding devices at the scene of a crime and transported from Police Station to Police Station etc may need to be 'reconducted'. The findings in the report raise the notion whether published Guidelines advocating the use of shielding devices may now need to identify exactly the tests and research considered prior to adopting published policy on the use of shielding devices, although it is unclear at present whether that will happen at all.

Whilst the report dealt primarily with external factors (radio communications) and how the shielding devices  coped with them, it also includes some other influences shielding devices can have on touch screen mobile phones, for example.

There have previously been mixed reviews about shielding devices and their impact on seized evidence that is left switched ON within shielding containers:

http://www.forensicfocus.com/index.php?name=Forums&file=viewtopic&t=3914
http://www.forensicfocus.com/index.php?name=Forums&file=viewtopic&t=4277&postdays=0&postorder=asc&start=0 

If a mobile phone is already OFF, or is switched OFF at the point of seizure, then such shielding devices shouldn't be necessary at that particular juncture.

Thursday, December 30, 2010

Apple sued over iPad and iPhone app 'data leaks'

Apple sued over iPad and iPhone app 'data leaks'

The BBC article doesn't mention it, but it would be helpful to know what personal data is being captured by web-based companies etc. In the wrong hands captured personal data for MSISDN could be used, by pinging from the internet, to cache polled MSISDNs for their IMSIs etc.  The equipment is out there to do it and has been for many years.

With credit card details being included within suggested secure apps for UICC cards, it is not difficult to imagine a rogue poll and de-tanking event occuring that goes unnoticed because it appears like the modern unobtrusive location updating procedure or another procedure and the user may only know about it after the data is missing.

Should that event happen it is what is termed as a "Mobile Cybercrime". The relevance being, making use of the singular term cybercrime as a title is highly misleading because you need a science and an operable technology in which the event needs to activate and commission. Mobile communications is a science and a technology (a damned fine science and technology they are, too).     

http://www.bbc.co.uk/news/technology-12089225

Friday, July 31, 2009

Cellphone Examination and Myths

Cellphone Examination and Myths
.
There are still, surprisingly, many who still promulgate myths by unwittingly conducting examinations in a particular way or use a product/device for cellphone examination to combat a particular perceived problem.
.
I am launching this discussion thread, which will be updated from time to time, to identify cellphone examination myths. In doing so, it is not aimed at a criticising an individual, manufacurer's product or someone selling a service. The point of the discussion is to allow people to make informed decisions as opposed to buying into a particular mythology. Do remember, I am not telling you what you should or should not do, it is your choice, my comments are only intended as helpful observations.
.
CELLPHONE CLOCKS
There is a claim the examiner should examine the cellphone first before examining the SIM Card. Two myths that are still circulating today (a) is that by removing the SIM Card from the phone that is switched OFF the handset clock will be lost, (b) and using a Faraday shield or RF dampening field can help prevent that. I find this rather surprising to apply these myths as a reason for creating a universal principle that handsets should be examined first and using Faraday/RF is the optimum choice for containment and examinations. To me these myths are nothing more than over exaggerated examination procedures. They transfer the skills away from the human to expecting the device and postulated procedure to be capable of coping with everyday common scenarios.
.
Most mobile phones today have a memory system with an on-board battery to keep data live for period of time after the external battery has been removed or the clock data along with an offset stored in flash to calculate the clock upon power up and intialisation to give the time. It is true that there are some phones (but not every phone) that can lose the clock setting when the SIM is removed, so the use of a particular examination procedure should be on a case by case basis. User-defined clocks can be quite unreliable as well and in most cases (but not all) does the clock setting of the handset ever feature as a prominent piece of evidence.
.
Additionaly, Faraday/RF Dampening do not influence the clock at all unless of course as is becoming more popular the user has activated the handset to use the mobile network clock, in which case Faraday/RF Dampening would have a detrimental effect by losing the clock timing on the handset whilst the handset in an isolation containment.
.
Any special procedures needed for very serious crime or terrorism, it is understandible that the use of a particular containment field might be needed. Majority of mobile phone seizures and recovery are pretty bog-standard occasions, so why would anyone leave a mobile phone switched ON in a containment bag where there is a high degree of chance that the bag could be knocked and potentially a key being pressed generating and/or altering data on the phone.
.
FARADAY/RF DAMPENING - LOSING DATA
For road traffic accidents, using containiment bag methodology for seized or recovered switch ON cellphones can be problematical because location data can be lost by isolation in a containment field whether that be mobile network data and/or where GPS data.
.
FARADAY/RF DAMPENING - WIPING DATA
Many of the high-end, sophisticated smart phones like Blackberry may have security policies in place whereby a prolonged absence from the radio network can force a lock and/or data wipe.
.
FARADAY/RF DAMPENING - IMSI
SIM cards have the ability to store up to a number of IMSIs, which are commonly used where countries have multiple network operators on a State by State basis. Roaming users may have a choice to use one or several IMSIs whilst roaming in another State or Country. Activating a particular IMSI can require selection of a profile and pressing the "SEND" key to inform the network of an altered state of subscriber identity, a response from the network can be requird for that change to take affect. The protocol in some handsets has been designed to wait for the response from the newtork to be received before the IMSI change takes place inside the SIM releasing the profile to the handset. Consequently, revealing data for a particular IMSI profile might not be possible.
.
FEEDBACK
If anyone wants to contribute to this myths discussion send an email to me with your observations. If you want to debunk my debunking then by all means do so, I am always willing to learn.

Friday, May 15, 2009

Undercover Officer Down, how might SIM Access Control Class help? Part 1

PART 1: Undercover Officer Down, how might SIM Access Control Class help?
.
The following is a scenario created to help examiners and experts know more about how to determine what data in SIM/USIM elementary files can mean and to appreciate what is required to be understood before examining SIM/USIM and giving evidence. Computer forensics has made a significant contribution to data recovery that can be used for harvesting data from mobile telephones and SIM cards, however data recovery is only one element of mobile telephone evidence and is not ‘the evidence’ to be considered in isolation to everything else.
.
Moreover, an examiner and an expert are expected to usefully advise with respect to investigations where data obtained from mobile telephones and SIMs/USIMs are involved, so, here to, this scenario will hopefully open examiners' and experts' eyes to new ways of considering data. What the law of evidence wants to know is, provided the data recovered is not a problem, what does the data actually mean and how should it be interpreted.
.
Scenario
An undercover officer working has infiltrated a criminal organisation involved in drugs and people trafficking. The undercover officer needs to keep details and seek answers without blowing his cover. The situation is always life threatening. The officer is required to report back by mobile phone to Control every 7-14 days.
.
PC0001 on patrol in the Shopping Mall sees a known drug dealer in the doorway of a Supermarket with an unknown IC1 female handing over a package. PC0001 calls and waits for back up before approaching. A stop and search is then conducted using the appropriate procedures under PACE 1984. A quantity of drugs is found, large bundle of money, along with two mobile telephones which were all subsequently put into evidential containers and the two individuals are carted off in the wagon to the local nick.
.
The alleged crime of drug selling (given the quantity seized) is fairly low down the scale and the money found was £1,780.00, but compared with other crimes wasn’t high and so priority won’t be given to this case over other cases in the system. The mobile phones are sent away for examination. The person assigned to deal with the examination of the mobile telephone and SIM card conducts a quick level examination for subscriber details, mobile telephone number, SIM serial number/ICCID, phonebook and text messages. Before starting examining the mobile telephone the examiner becomes ill and doesn’t complete the work.
.
The examination would need to be passed to another examiner who would have to start from scratch as the next examiner could not possibly give evidence about someone else’s work for the new examiner would have no knowledge about the previous examination. By chance the new examiner chosen for the work had just come back from Greg Smith’s TrewMTE SIM Card training course where he had undergone deep level training into being a professional examiner and taught about ethical working practices, understanding the symbiotic relation with other mobile telephone devices and network elements, technical standards, working practices and SIM Card examination and data investigation etc (well alright, but it is only a modest promotion about me).
.
The new examiner conducted a fresh examination, starting with the SIM Card. Having been trained to look for evidence of activity and indicators about the potential user of the SIM card, the new examiner immediately contacted the Senior Officer where PC0001 was stationed. The new examiner, having been trained to identify certain data and corroborate the finding with reference material to ensure the meaning of the data, explained to the Senior Officer that he was examining a mobile telephone SIM Card that may belong to someone in the Security Services and that if he, at the local level, was examining this SIM then it could mean there was a man [undercover] down in the field?
.
Asked why the new examiner might suspect this, he referred to the recent training he had had and had identified from a mandatory data file in the SIM Card an elementary file titled EFACC (Access Control Class). The SIM had recorded Access Class 12 which is referenced as “Security Services”. The examiner also informed the Senior Officer that he had acquired from the SIM the subscriber details and mobile telephone number but was not authorised to access personal details. The examiner also mentioned that as ex-British Army he had field experience and should “intel” suggest there may be a “man down” that he would rely on all efforts to be made to rescue him, he therefore considered the user of the SIM (being examined) would equally rely on the same.
.
The Senior Officer took the details and immediately set in motion a priority search. The details the new examiner had given to the Senior Officer had proven correct and were linked to an officer on field ops. It transpired the office had not been in contact for 14 days. Because of the work involved MI5 were called in for their superior network of intelligence and, given the nature of the criminal organisation, every school boys heroes were sent in, the SAS, to conduct ground surveillance, attack, capture and rescue. The undercover officer was rescued, badly beaten, bleeding and barely alive, but alive nonetheless.
.
To clear up some loose ends to this scenario: How did the drug dealer come to be in possession of the undercover officer's mobile phone? The undercover officer had been rumbled by the gang and when running away, before the gang captured him, he had thrown it away and working on the long shot he hoped that someone would find it and hand it in. The drug dealer had found it, assumed it had been dropped by a passer-by and considered it could provide anonymity for drug dealing. There is a separate story about other evidence the mobile tied to the drug dealer, but this scenario is about saving an important life.
.
So what can be learned from the above scenario and what facts are known:
.
a) that the examiner as fact needs proper training to know what data can be significant
b) that as a statement of fact there is an elementary file in SIM called EFACC (Access Control Class)
c) that as a statement of fact the elementary file EFACC (Access Control Class) can be assigned to a User with an Access Class 12 assigned to “Security Services”
d) the examiner should know the limitations of the tools s/he works with before using them
e) the examiner to have the tools that actually reveal the information that is significant
f) that a proper and full examination of a SIM is an absolute requirement rather than merely the examiner conducting a dumbed-down check, only looking at certain data sets
g) that checking the findings immediately following a SIM read is essential
h) to communicate straightaway of the potential for life threatening situations or national security
i) that “priority” check means “speed and instantly” and not manyarna
.
In part 2 it will identify the full 16 Access Classes, look at Class 12 technical elements for Access Control Class, how it works, its uses and its limitations. What will become abundantly clear, if Part 1 and Part 2 are only dealing with Access Class 12 what can be learned about all the other Access Classes? More importantly, why has proper checking about Access Control Class and other EFs in SIM Cards not become standard practice?

Undercover Officer Down, how might SIM Access Control Class help? Part 1

PART 1: Undercover Officer Down, how might SIM Access Control Class help?
.
The following is a scenario created to help examiners and experts know more about how to determine what data in SIM/USIM elementary files can mean and to appreciate what is required to be understood before examining SIM/USIM and giving evidence. Computer forensics has made a significant contribution to data recovery that can be used for harvesting data from mobile telephones and SIM cards, however data recovery is only one element of mobile telephone evidence and is not ‘the evidence’ to be considered in isolation to everything else.
.
Moreover, an examiner and an expert are expected to usefully advise with respect to investigations where data obtained from mobile telephones and SIMs/USIMs are involved, so, here to, this scenario will hopefully open examiners' and experts' eyes to new ways of considering data. What the law of evidence wants to know is, provided the data recovered is not a problem, what does the data actually mean and how should it be interpreted.
.
Scenario
An undercover officer working has infiltrated a criminal organisation involved in drugs and people trafficking. The undercover officer needs to keep details and seek answers without blowing his cover. The situation is always life threatening. The officer is required to report back by mobile phone to Control every 7-14 days.
.
PC0001 on patrol in the Shopping Mall sees a known drug dealer in the doorway of a Supermarket with an unknown IC1 female handing over a package. PC0001 calls and waits for back up before approaching. A stop and search is then conducted using the appropriate procedures under PACE 1984. A quantity of drugs is found, large bundle of money, along with two mobile telephones which were all subsequently put into evidential containers and the two individuals are carted off in the wagon to the local nick.
.
The alleged crime of drug selling (given the quantity seized) is fairly low down the scale and the money found was £1,780.00, but compared with other crimes wasn’t high and so priority won’t be given to this case over other cases in the system. The mobile phones are sent away for examination. The person assigned to deal with the examination of the mobile telephone and SIM card conducts a quick level examination for subscriber details, mobile telephone number, SIM serial number/ICCID, phonebook and text messages. Before starting examining the mobile telephone the examiner becomes ill and doesn’t complete the work.
.
The examination would need to be passed to another examiner who would have to start from scratch as the next examiner could not possibly give evidence about someone else’s work for the new examiner would have no knowledge about the previous examination. By chance the new examiner chosen for the work had just come back from Greg Smith’s TrewMTE SIM Card training course where he had undergone deep level training into being a professional examiner and taught about ethical working practices, understanding the symbiotic relation with other mobile telephone devices and network elements, technical standards, working practices and SIM Card examination and data investigation etc (well alright, but it is only a modest promotion about me).
.
The new examiner conducted a fresh examination, starting with the SIM Card. Having been trained to look for evidence of activity and indicators about the potential user of the SIM card, the new examiner immediately contacted the Senior Officer where PC0001 was stationed. The new examiner, having been trained to identify certain data and corroborate the finding with reference material to ensure the meaning of the data, explained to the Senior Officer that he was examining a mobile telephone SIM Card that may belong to someone in the Security Services and that if he, at the local level, was examining this SIM then it could mean there was a man [undercover] down in the field?
.
Asked why the new examiner might suspect this, he referred to the recent training he had had and had identified from a mandatory data file in the SIM Card an elementary file titled EFACC (Access Control Class). The SIM had recorded Access Class 12 which is referenced as “Security Services”. The examiner also informed the Senior Officer that he had acquired from the SIM the subscriber details and mobile telephone number but was not authorised to access personal details. The examiner also mentioned that as ex-British Army he had field experience and should “intel” suggest there may be a “man down” that he would rely on all efforts to be made to rescue him, he therefore considered the user of the SIM (being examined) would equally rely on the same.
.
The Senior Officer took the details and immediately set in motion a priority search. The details the new examiner had given to the Senior Officer had proven correct and were linked to an officer on field ops. It transpired the office had not been in contact for 14 days. Because of the work involved MI5 were called in for their superior network of intelligence and, given the nature of the criminal organisation, every school boys heroes were sent in, the SAS, to conduct ground surveillance, attack, capture and rescue. The undercover officer was rescued, badly beaten, bleeding and barely alive, but alive nonetheless.
.
To clear up some loose ends to this scenario: How did the drug dealer come to be in possession of the undercover officer's mobile phone? The undercover officer had been rumbled by the gang and when running away, before the gang captured him, he had thrown it away and working on the long shot he hoped that someone would find it and hand it in. The drug dealer had found it, assumed it had been dropped by a passer-by and considered it could provide anonymity for drug dealing. There is a separate story about other evidence the mobile tied to the drug dealer, but this scenario is about saving an important life.
.
So what can be learned from the above scenario and what facts are known:
.
a) that the examiner as fact needs proper training to know what data can be significant
b) that as a statement of fact there is an elementary file in SIM called EFACC (Access Control Class)
c) that as a statement of fact the elementary file EFACC (Access Control Class) can be assigned to a User with an Access Class 12 assigned to “Security Services”
d) the examiner should know the limitations of the tools s/he works with before using them
e) the examiner to have the tools that actually reveal the information that is significant
f) that a proper and full examination of a SIM is an absolute requirement rather than merely the examiner conducting a dumbed-down check, only looking at certain data sets
g) that checking the findings immediately following a SIM read is essential
h) to communicate straightaway of the potential for life threatening situations or national security
i) that “priority” check means “speed and instantly” and not manyarna
.
In part 2 it will identify the full 16 Access Classes, look at Class 12 technical elements for Access Control Class, how it works, its uses and its limitations. What will become abundantly clear, if Part 1 and Part 2 are only dealing with Access Class 12 what can be learned about all the other Access Classes? More importantly, why has proper checking about Access Control Class and other EFs in SIM Cards not become standard practice?

Wednesday, February 11, 2009

Exploding Cell Phone Battery

Exploding Cell Phone Battery

.
A reminder for examiners to take care when examining mobile phones that require recharging the battery before examining the device. The horror story of a man's who had his neck artery burst by the exploding mobile phone in his breast pocket and died. Prior to putting it in his pocket the man had recharged the battery. Production line (bang it on, bang it out) mobile telephone examinations are potentially at high risk and a risk assessment procedure may need to be put in place to avoid loss of fingers or limbs or disfigurement. Insurance companies may need to be made aware of this potential high risk.
.
http://www.telegraph.co.uk/news/worldnews/asia/china/4452360/Exploding-mobile-phone-kills-man-in-China.html
.
Last year Vinny Parmar produced a document (see link below) about counterfeit mobile telephones and it is by no means certain whether these devices are using batteries that may explode.
.
http://trewmte.blogspot.com/2008/11/counterfeit-mobile-phones.html
.
Moreover, some people are apt to placing their mobile telephone in more unusual places about their person. Whether the person is smuggling or something else the exploding battery provides a stark reminder that they may put their life at risk.
.
http://trewmte.blogspot.com/2006/11/whats-this.html
.
Thanks to Richard Putnam for sending to me the Telegraph newspaper online link.

.

UPDATE: A further Telegraph online article has been written regarding the above exploding battery. Apparently, this second news article suggests it was a bullet from a home made gun that had cause the accident. However both Telegraph online articles are not referenced to each other so it is only an assumption that they both may be referring to the same incident.

http://www.telegraph.co.uk/news/worldnews/asia/china/4522915/Man-killed-by-exploding-phone-shot-himself.html

Tuesday, December 02, 2008

Nokia 6233 Clock

Nokia 6233 Clock
I have mentioned Vinny Parmar's name on this webblog previously. Vinny has just sent to me an email setting out a quirk that he has noted with the Nokia 6233 Clock.
.
Vinny Parmar, Lead Forensic Examiner:
"Basically I was working on a Nokia 6233. I used XRY and Oxygen Phone Manager (OPM) to read the data. No issues with the content as far as the text was concerned. XRY, as always, advanced the time of each SMS by 1 hour and Oxygen did not, howvever Oxygen did not pull off the SMSC associated with each SMS.
.
"Now your asking so what was the issue, well let me tell you. After the read I proceeded with a manual verification of the date\times for each SMS. What I noticed was that although Oxygen pulled of the dates\times there was a slight issue in what was displayed, for example: An SMS received - OPM listed the date\time as 15/05/08 15:51:49, the handset displayed this as 15/05/08 03:51:49.
.
"As far as the verification goes, one would assume that the correct time was as reported by the handset which was 03:51:49 which would suggest AM due to the format. However what I noticed was that when I checked the date\time format setting on the handset this turned out to be set to the 12 hour clock, but the handset did not display what I was expecting, which was the AM or PM prefix?
.
"So after a little adjustment with the handset, changed the format to 24hr clock all the SMS date\time were now displayed exactly as displayed by OPM. My suspicions were also confirmed by the content of messages and the suspects involved, they are school kids, so I couldn't really see SMS transmissions being sent/received at 3am. So, in essence, the above would suggest that as examiners we may need to consider adjusting the date\time format setting on a handset to confirm the correct format. Most of the handsets which are set to the 12-hour clock tend to display the appropriate prefix of AM or PM but for some unknown reason this was not the case with the Nokia 6233. This certainly requires further research."

Friday, March 21, 2008

Mobile Calls on Aeroplanes

Mobile Calls on Aeroplanes
.
Back in November 2006 I wrote here at trewmte.blogspot a brief piece regarding "Switch On, Update, Lose Evidence":
.
.
The discussion thread related to the same but more indepth discussion in "Switch On, Update, Lose Evidence" that could be found in MTE (Mobile Telephone Evidence) Newsletter - copy of the May 2006 Newsletter can be downloaded here:
.
.
The purpose of the indepth discussion related to how evidence can be corrupted and contaminated where poor Seizure, Handling and Examination Procedures had been adopted. The discussion illustrated where a user with a mobile telephone steps off an aeroplane and the attempt to discover where the mobile phone had been used.
.
I had been aware for some years before I wrote the MTE Newsletter article that Airline companies were looking at and developing ways passengers could use their mobile phones on planes. At the time of writing the article it wasn't too difficult to imagine that "Switch On, Update, Lose Evidence" implicitly gave a heads up as early as May 2006 to pay attention to formulating various procedures for mobile telephone evidence at airports. Importantly, the indepth discussion wasn't then and isn't now intended to suggest victimising everyone who gets off a plane holding a mobile phone as being involved with something suspicious.
.
It would appear that the MTE Newsletter advanced warning though was well placed, for it now appears March 20th 2008 that according to BBC online middle east news that "Dubai-based airline Emirates has become the first commercial airline to allow passengers to make mobile phone calls during flights. Emirates said the first permitted mobile phone call was made on a flight between Dubai and Casablanca.":
.
.
The technology behind Emirates being able to offer mobile calls on their flights originates from http://www.aeromobile.net using pico-cell radio access technology inflight:
.
"AeroMobile allows the use of GSM phones and can also support GPRS mobile data (for BlackBerry’s etc), Wi-Fi, CDMA and 3G/UMTS. AeroMobile comprises an aircraft cabin ‘pico cell’ system that interfaces with the aircraft’s air-to-ground communications systems, typically a satellite-based system. Once transmitted to the ground, signals are sent to AeroMobile’s ground system and on to the destination mobile phone and telecoms networks around the world."
.
Evidentially, this could be very interesting but the use of mobile phones on planes may seem problematical at first. But we will cope, we always do. The evidence from the device shouldn't be too much of a problem although issues of dead-man's trap should always be considered. Equally of interest will be usage, call records and cell site analysis. The latter, cell site analysis, should prove thought provoking, for is there sovereignty on an aeroplane? If there is not (and sovereighty is only applicable to airspace) and a call starts and terminates within the same airspace the sovereignty of which belongs to country XYZ then there may well be some jurisdictional issues to deal with. However, given the confines of the plane's cabin it may well be difficult for a user, if you follow my drift, to suggest that when the call was made s/he wasn't in the plane, but somewhere in the neighbourhood.