Showing posts with label investigations. Show all posts
Showing posts with label investigations. Show all posts

Thursday, December 05, 2019

Update3 - HERREVAD Databases Geo Location Artefacts

This is the continuing/on-going research and discovery into HERREVAD Databases Geo Location Artefacts.

Back in 2017 little was known about HERREVAD and I posted at my blog my views that it had potential for cell site analysis and possible mobile user geographical location/s. I have found further materials on it in a useful web-article (Making Sense of OSINT Cell Tower Data for DFIR- https://osintcurio.us/2019/08/19/making-sense-of-osint-cell-tower-data-for-dfir/) where the investigator sets out the uses for the data from the HERREVAD database for the purposes as I have mentioned. So good to see my research continues to benefit criminal, civil and security investigations.

The last update was
Update2 - HERREVAD Databases Geo Location Artefacts
https://trewmte.blogspot.com/2019/05/update2-herrevad-databases-geo-location.html

Thursday, April 25, 2019

5G-NR False Base Stations (Part 2)

Going forward with further discussions about FBS (false base stations) considering detection and prevention approaches that can be taken to act as a deterrent against them or their use; it is inescapable thus unavoidable that readers need to be aware of the meanings of abbreviations and definitions adopted for 5G and the reason for my trewmte blog look-up reference. This doesn't suggest you shouldn't go and get the appropriate reference materials (https://www.3gpp.org/about-3gpp), but its easier to get people interested and engaged in a subject without further procedures needed to be followed.

For the record, the reference materials relevant to this discussion are the following 3GPP documents:

[1] 3GPP TS 33.501 5G; Security architecture and procedures for 5G System
[2] 3GPP TR 21.905: "Vocabulary for 3GPP Specifications"

TS = Technical Standards
TR= Technical Report

In [1] it includes the statement:  'For the purposes of the present document, the terms and definitions given in 3GPP TR 21.905 [2] and the following apply. A term defined in the present document takes precedence over the definition of the same term, if any, in 3GPP TR 21.905.' Hence why I refer below to the abbreviations and definitions in [1].

ABBREVIATIONS
5GC 5G Core Network
5G-AN 5G Access Network
5G-RAN 5G Radio Access Network
5G AV 5G Authentication Vector
5G HE AV 5G Home Environment Authentication Vector
AES Advanced Encryption Standard
AKA Authentication and Key Agreement
AMF Access and Mobility Management Function
AMF Authentication Management Field
NOTE: If necessary, the full word is spelled out to disambiguate the abbreviation.
ARPF Authentication credential Repository and Processing Function
AUSF Authentication Server Function
AUTN AUthentication TokeN
AV Authentication Vector
AV' transformed Authentication Vector
CP Control Plane
CTR Counter (mode)
CU Central Unit
DN Data Network
DNN Data Network Name
DU Distributed Unit
EAP Extensible Authentication Protocol
EMSK Extended Master Session Key
EPS Evolved Packet System
gNB NR Node B
GUTI Globally Unique Temporary UE Identity
HRES Hash RESponse
HXRES Hash eXpected RESponse
IKE Internet Key Exchange
KSI Key Set Identifier
LI Lawful Intercept
MN Master Node
MR-DC Multi-RAT Dual Connectivity
MSK Master Session Key
N3IWF Non-3GPP access InterWorking Function
NAI Network Access Identifier
NAS Non Access Stratum
NDS Network Domain Security
NEA NR Encryption Algorithm for 5G
NF Network Function
NG Next Generation
ng-eNB Next Generation Evolved Node-B
ngKSI Key Set Identifier in 5G
NIA NR Integrity Algorithm for 5G
NR New Radio
NSSAI Network Slice Selection Assistance Information
PDN Packet Data Network
PEI Permanent Equipment Identifier
QoS Quality of Service
RES RESponse
SCG Secondary Cell Group
SEAF SEcurity Anchor Function
SEG Security Gateway
SIDF Subscription Identifier De-concealing Function
SMC Security Mode Command
SMF Session Management Function
SN Secondary Node
SN Id Serving Network Identifier
SUCI Subscription Concealed Identifier
SUPI Subscription Permanent Identifier
TLS Transport Layer Security
UE User Equipment
UEA UMTS Encryption Algorithm
UDM Unified Data Management
UIA UMTS Integrity Algorithm
ULR Update Location Request
UP User Plane
UPF User Plane Function
USIM Universal Subscriber Identity Module
XRES eXpected RESponse

DEFINITIONS

Within the 3GPP Specifications under the heading 'Definitions' invariably the reader finds references to other specifications. A reference to a standard is helpful, but it is also even more helpful to know the identification of the technology or the system the specification relates. To this end 3GPP identify 20 subjects in its index of which 2 are historical references backdated to the start of GSM, which I have eliminate those from the table above, and focussed on 18 subjects most commonly referred to today.

So when you read a definition below that includes a reference to a specification, such as "Master node: As defined in TS 37.340" just look at the table above to determine the subject that is relevant to discussions about Master node, which in this case is 'Multiple radio access technology aspects 37 series'.

-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-
5G security context: The state that is established locally at the UE and a serving network domain and represented by the "5G security context data" stored at the UE and a serving network.
NOTE 1: The "5G security context data" consists of the 5G NAS security context, and the 5G AS security context for 3GPP access and/or the 5G AS security context for non-3GPP access.

NOTE 2: A 5G security context has type "mapped", "full native" or "partial native". Its state can either be "current" or "non-current". A context can be of one type only and be in one state at a time. The state of a particular context type can change over time. A partial native context can be transformed into a full native. No other type transformations are possible.


5G AS security context for 3GPP access: The cryptographic keys at AS level with their identifiers, the Next Hop parameter (NH), the Next Hop Chaining Counter parameter (NCC) used for next hop access key derivation, the identifiers of the selected AS level cryptographic algorithms, and the counters used for replay protection.
NOTE 3: NH and NCC need to be stored also at the AMF during connected mode.

5G AS security context for non-3GPP access: The key KN3IWF, the cryptographic keys, cryptographic algorithms and tunnel security association parameters used at IPsec layer for the protection of IPsec SA.

5G Authentication Vector: a vector consisting of RAND, AUTN, XRES*, and KAUSF for the purpose of authenticating the UE using 5G AKA.
NOTE 3a: This vector is received by the AUSF from the UDM/ARPF in the Nudm_Authentication_Get Response.

5G Home Environment Authentication Vector: a vector consisting of RAND, AUTN, HXRES*, and KSEAF.
NOTE 3b: This vector is received by the SEAF from the AUSF in the Nausf_Authentication_Authenticate Response.

5G NAS security context: The key KAMF with the associated key set identifier, the UE security capabilities, and the uplink and downlink NAS COUNT values.
NOTE 4: The distinction between native 5G security context and mapped 5G security context also applies to 5G NAS security contexts. The 5G NAS security context is called "full" if it additionally contains the integrity and encryption keys and the associated identifiers of the selected NAS integrity and encryption algorithms.

activation of security context: The process of taking a security context into use.

anchor key: The security key KSEAF provided during authentication and used for derivation of subsequent security keys.


authentication vector: a vector consisting of CK, IK, RAND, AUTN, and XRES.


authentication data: 5G Authentication Vector or transformed authentication vector.


backward security: The property that for an entity with knowledge of Kn, it is computationally infeasible to compute any previous Kn-m (m>0) from which Kn is derived.
NOTE 5: In the context of KgNB key derivation, backward security refers to the property that, for a gNB with knowledge of a KgNB, shared with a UE, it is computationally infeasible to compute any previous KgNB that has been used between the same UE and a previous gNB.

CM-CONNECTED state: This is as defined in TS 23.501 [2].
NOTE5a: The term CM-CONNECTED state corresponds to the term 5GMM-CONNECTED mode used in TS 24.501

CM-IDLE state: As defined in TS 23.501.
NOTE5b: The term CM-IDLE state corresponds to the term 5GMM-IDLE mode used in TS 24.501.

current 5G security context: The security context which has been activated most recently.
NOTE5c: A current 5G security context originating from either a mapped or native 5G security context can exist simultaneously with a native non-current 5G security context.

forward security: The fulfilment of the property that for an entity with knowledge of Km that is used between that entity and a second entity, it is computationally infeasible to predict any future Km+n (n>0) used between a third entity and the second entity.
NOTE 6: In the context of KgNB key derivation, forward security refers to the property that, for a gNB with knowledge of a KgNB, shared with a UE, it is computationally infeasible to predict any future KgNB that will be used between the same UE and another gNB. More specifically, n hop forward security refers to the property that a gNB is unable to compute keys that will be used between a UE and another gNB to which the UE is connected after n or more handovers (n=1 or more).

full native 5G security context: A native 5G security context for which the 5G NAS security context is full according to the above definition.
NOTE6a: A full native 5G security context is either in state "current" or state "non-current".

Mapped 5G security context: An 5G security context, whose KAMF was derived from EPS keys during interworking and which is identified by mapped ngKSI.

native 5G security context: An 5G security context, whose KAMF was created by a run of primary authentication and which is identified by native ngKSI.


non-current 5G security context: A native 5G security context that is not the current one.
NOTE 7: A non-current 5G security context may be stored along with a current 5G security context in the UE and the AMF. A non-current 5G security context does not contain 5G AS security context. A non-current 5G security context is either of type "full native" or of type "partial native". partial native 5G security context: A partial native 5G security context consists of KAMF with the associated key set identifier, the UE security capabilities, and the uplink and downlink NAS COUNT values, which are initially set to zero before the first NAS SMC procedure for this security context.
NOTE 8: A partial native 5G security context is created by primary authentication, for which no corresponding successful NAS SMC has been run. A partial native context is always in state "non-current".

RM-DEREGISTERED state: This is as defined in TS 23.501.
NOTE8a: The term RM-DEREGISTERED state corresponds to the term 5GMM-DEREGISTERED mode used in TS 24.501.

RM-REGISTERED state: As defined in TS 23.501.
NOTE8b: The term RM-REGISTERED state corresponds to the term 5GMM-REGISTERED mode used in TS 24.501.

subscription identifier: The SUbscription Permanent Identifier (SUPI) is defined in TS 23.501.


subscription identifier de-concealing function: The Subscription Identifier De-concealing Function (SIDF) service offered by the network function UDM in the home network of the subscriber responsible for de-concealing the SUPI from the SUCI.


subscription concealed identifier: A one-time use subscription identifier, called The SUbscription Concealed Identifier (SUCI), which contains the concealed subscription identifier, e.g. the MSIN part of SUPI, and additional non-concealed information needed for home network routing and protection scheme usage.

security anchor function: The function that serves as the anchor for security in 5G.

subscription credential(s): The set of values in the USIM and the ARPF, consisting of at least the long-term key(s) and the subscription identifier SUPI, used to uniquely identify a subscription and to mutually authenticate the UE and 5G core network.

transformed authentication vector: an authentication vector where CK and IK have been replaced with CK' and IK'.

UE security capabilities: The set of identifiers corresponding to the ciphering and integrity algorithms implemented in the UE.
NOTE 9: This includes capabilities for NG-RAN and 5G NAS, and includes capabilities for EPS, UTRAN and GERAN if these access types are supported by the UE.

UE 5G security capability: The UE security capabilities for 5G AS and 5G NAS.
Master node: As defined in TS 37.340.

ng-eNB: As defined in TS 38.300.

Secondary node: As defined in TS 37.340.

AS Secondary Cell security context: This context consists of the cryptographic keys for SN (KUPenc), the identifier of the selected AS SC level cryptographic algorithm and counters used for replay protection.
-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-


IN CLOSING
It may not seem obvious just yet from all the abbreviation and definitions (above) but they will be discussed in future Parts of these blog discussions. In relation to false base stations the standards, specifications and reports are not merely concerned with detecting and preventing their usage, but equally to have concern if such FBSs were to successful create a trap for genuine UEs and act as a conduit MiTM (man-in-the-middle) attack would the FBSs be able to decrypt and decipher encrypted signalling and communications directed between the Network and UE?

For the moment, at least, in one webpage and without tracking down and downloading the complete standard, readers can see at a glance on this look-up page 5G security references and what 3GPP intends how they should be understood.

Monday, April 22, 2019

5G-NR False Base Stations (Part 1)

This is my first technology post for a while at trewmte blogspot as my time in research now extends to 5G-NR; network investigations; connected cars and autonomous vehicles; drones; in addition to existing digital forensics, smartphone examinations and cell site analysis. I have a number new insights and revelations for readers this year about the aforementioned subjects. So I will be more active on the blog.

5G False Base Stations (Part 1)
With 5G-NR (new radio) now in limited use and operators in pursuit to increase its usage and, at some point, replace 2G and 3G, it has not escaped the notice of those creating mobile and data networks the need for security. Given the slew of research into networks and devices susceptible to MiTM (man-in-the-middle) attacks it isn't a surprise to find forum conversations about possible attacks by 5G-NR false base stations.

As a quick technical reference for a 5G-NR base station it is defined by "gNB" = g that it is directing communications and signalling to a 5G network via an NB = Node B (the base station). This quick reference does not replace or take precedence over the definition 5G-NR base station as recorded in the 3GPP Standards; so always refer to the standards as your reference point as my comments are evangelistic-observations on the subject and those observations are made to quickly shoehorn readers into this discussion.

Other Side of the Coin
Some may think that little has been done by network operators/standards bodies confirming measures taken to assuage mobile users that once a false base station is in use (MiTM) that nothing can be done and an attack or crime succeeds un-impeded. This is not only wrong and misguided viewpoint, worst still it would be untrue. As an example of just one deployable security method there is a case for active participation (not visible to the mobile user) between the UE (user equipment) and the network termed "UE-assisted network-based detection of false base station".

Preamble
The UE in RRC_CONNECTED mode sends measurement reports to the network in accordance with the measurement configuration provided by the network. These measurement reports have security values in being useful for detection of false base stations or SUPI/5G-GUTI catchers (as an example IMSI catchers). Mobile network operators, using an implementation specific process/procedure, may choose UEs or tracking areas or duration for which measurement reports are to be analysed for detection of false base station. So measurement reports from UEs can be used for detection of false base station, and some additional actions thereafter.

What Type of Content is in a Measurement Report
Examples given are the received-signal strength and location information in measurement reports can be used to detect a false base station that attract UEs which it does by transmitting signal with higher power than those genuine base stations surrounding the UEs.

Measurement reports can also be used to detect a false base stations that replays genuine information blocks (MIB/SIB) without modification. In order to detect a false base station which replays modified version of broadcast information to prevent victim UEs from switching back and forth between itself and genuine base stations (e.g. modifying neighbouring cells, cell reselection criteria, registration timers, etc. to avoid the so called ping-pong effect), information on broadcast information can be used to detect inconsistency from the deployment information.

It is known a false base station which uses inconsistent cell identifier or operates in inconsistent frequency than the deployment of the genuine base stations can be detected respectively by using the cell identifier or the frequency information in the measurement reports.

Moreover, MiTM attackers deploying a false base station may deploy rogue UEs to assist in the attack by attempting to trick the network. Measurement reports collected from multiple UEs in an area can be used to filter out incorrect reports sent by a potential rogue UE.

It doesn't automatically follow when reading forum posts or discussions about attackers and false base stations that they (both) are somehow undetectable.

I will be posting more on this subject given this is Part 1).

Wednesday, June 22, 2016

Vacancy - Senior Evidence Handling Analyst

If you are interested in getting into Corporate investigations evidence handling, here is a good opportunity. Contact: Scott Barlow Corporate Recruiter at Epiq Systems.

https://epiqsystems.tms.hrdepartment.com/jobs/1103/Senior-Evidence-Handling-AnalystLondon-London

Senior Evidence Handling Analyst
Job Code : 1103
Division : Epiq eDiscovery Solutions (EDS)
Location : London London UK EC2R 8DU
Job Type : Full Time
Career Level : Experienced (Non-Manager)
Education : Bachelor's Degree
Category : Legal
Job Description :

The Senior Evidence Handling Analyst works as a member of the Operations team within Epiq's Electronic Discovery division in London, UK.  This is a role for someone who has developed a high level of expertise and experience particularly in the left-hand side of the EDRM operational workflow as practiced at Epiq Systems.  The purpose of this position is to provide hands-on operational support, pass on expertise to associates, support learning and development, ensure best practices and quality standards are applied and adhered to, whilst also acting as an individual contributor within Operations on the full range of activities and tasks applicable to evidence collection, handling and management.

Essential Job Responsibilities
 
  • Utilise proprietary software applications, 3rd party forensic and eDiscovery applications, electronic discovery and data recovery processes.
  • Participate in evidence collections; handle and create evidential media in a legally defensible manner.
  • Work closely with team members to troubleshoot issues (prior to escalation to operations senior management and/or IT/Development), research software and/or techniques to solve problems, and carry out complex data analysis tasks.
  • Communicate and collaborate with other company departments.
  • Generate reports from various database platforms for senior management.
  • Become a subject-matter expert (SME) in the left-hand side of the EDRM as practiced at Epiq Systems. Make SME available by consulting on projects, planning meetings, client requirements and solution design as required.
  • Create and lead training sessions for Associates in SME areas as requested by Management. Be responsible for the creation and management of Standard Operating Procedures (SOPs) for their SME areas, including but not limited to policies, procedures, workflows and work instructions. Ensure reference documentation is maintained and easily findable. Contribute to the development and implementation of a Knowledge Management (KM) strategy.
  • Manage, drive, and implement department initiatives around planning, documentation, procedures and Continuous Improvement, and ensure compliance with policies, procedures and work instructions.
  • Promote the company’s culture and values through leadership-by-example, group interaction, and frequent one-on-one coaching with associates at every level.
Job Requirements :

Requirements for the role include:
 
  • At least three years’ experience working in an industry-related role that is review-based, deadline driven and outcome oriented including a solid understanding of the data collection, processing, litigation support and document review processes.
  • Hands-on experience with industry standard forensic software, maintenance of chain of evidence and handling of evidential media.
  • Willingness to travel up to 25% of the time in support of onsite evidence collections, including overseas.
  • Must possess a strong desire to learn new skills.
  • Must display excellent verbal and written communication.
  • Must work well in a team environment but also independently.
  • Demonstrable experience implementing process improvement and compliance.
  • Must have a demonstrable ability to effectively lead and manage the productivity of the team, incidents, and drive to problem resolutions.
  • Must be able to facilitate solutions across departments and teams in a collaborative manner.
  • Must be able to anticipate and prevent problems while assisting in managing incidents to resolution.
  • Experience of working under tight deadlines in a fast-paced environment.
  • Strong communication, situational awareness and organizational agility skills.
  • Must be self-directed and foster initiative in others.
  • Must be able to translate larger business goals into actionable items for their team.
  • Demonstrable experience with training and developing team members using an inspirational and motivational approach that aligns with Epiq’s unique organizational culture.
Education & Experience
 
  • Bachelor’s degree in Computer Science, Business Management or a closely related field of study or an equivalent combination of education and experience, OR;
  • A degree or certification in law or a legal field (complemented by suitable technical expertise)
Preferred Requirements/Certifications
 
  • Experience of collaborating across shifts is desirable.
  • A solid understanding of all Microsoft Office applications, Windows, Mac, Linux, server OS, hardware & networking.
  • Familiarity with the eDiscovery industry – Electronic Discovery Reference Model (EDRM), technology, global legal framework and competitive landscape.
  • Knowledge of litigation support software, including any of the following: DocuMatrix, Relativity, Concordance, Summation, Ipro, Ringtail, and Introspect.
  • Deep experience of computer forensics, collections and evidence handling – including formal certifications if available.
Leadership Competencies
 
  • Coaching for Results - Provides timely guidance and feedback to help others strengthen specific knowledge and/or skill areas necessary to accomplish specific objectives or tasks; helps to clarify the situation and expected behaviors; provides instruction and opportunities for observation; provides on-going feedback and reinforcement
  • Managing Performance - Ensures that associates have clear goals and objectives, expectations and measures of success for projects and tasks; clearly assigns or delegates responsibility for tasks and assignments; monitors the process of work as well as progress toward completion and final results; provides specific performance feedback, both positive and corrective, as soon as possible after event
  • Developing Others - Provides support and direction towards the development of individuals’ knowledge and skills to effectively facilitate their accomplishment of both current and future job responsibilities; partners with individuals on identifying and setting development goals; helps to identify development opportunities as part of the plan; provides continuous feedback on performance and progress and assists in the adjustment of development plans; ensures management team adheres to business defined talent management practices and procedures
  • Fosters Teamwork - provides opportunities for people to learn to work together as a team; promotes cooperation with other departments; recognizes and encourages the behaviors that contribute to teamwork, continuous support and removal of barriers, appropriately involves team members in decisions and leverages unique talents of the team
  • Empowering Others - Gives people latitude to make decisions based on their level and area of responsibility and level of knowledge and skills; encourages individuals and groups to set their own goals, consistent with business goals; expresses confidence in the ability of others to be successful; encourages groups to resolve problems on their own; avoids prescribing a solution
About Epiq

Epiq Systems solves problems faced by the legal profession in managing high volume, complex electronic data. We serve corporations and law firms around the world in practice areas spanning bankruptcy, litigation, class action, mass tort, antitrust, investigations and regulatory compliance.
Epiq combines proprietary software, deep subject matter expertise and a global infrastructure to assist clients with the technology requirements for their most important and complex matters. Our clients include top worldwide law firms, corporate legal departments, government agencies and trustees.
We strive for a cohesive, collaborative environment that focuses on group achievement.

Epiq is a NASDAQ listed company (EPIQ) with over 1400 associates worldwide. Epiq operates globally with key offices in Hong Kong, Kansas City (corporate headquarters), London, New York, Phoenix, Shanghai (data center only), Tokyo, Toronto and Washington, D.C.

Saturday, March 19, 2016

Emergency Cases - Smartphone Examination


Capturing the target subject's smartphone activities is not as easy as is thought, as we are all finding out with the current Apple and law enforcement debacle.  The Apple case though is not the norm as the two opposing sides are fighting about the "right to access". The public are engaged with this story that continues to unfold as to what "Privacy" actual means, should terrorism enjoy the comfort of privacy and so on. However, there is a sub-text going on here (as well) concerning examination procedures for smartphones and methodology in emergency cases. Having been involved with mobile phone evidence in criminal and civil proceedings for over 30-years I can tell you it isn't as easy at all.

Consider the current Apple case (and the articles still keep coming) and mistakes that are said to have occurred. The - TECH INSIDER - reported (http://www.techinsider.io/apple-the-fbi-screwed-up-san-bernardino-investigation-2016-2)

"The fact that the password was reset means that Apple was unable to retrieve info from the iPhone's unencrypted iCloud backup like it has for past investigations, according to reporters Apple spoke with. If the password hadn't somehow been reset while in law enforcement custody, the FBI likely wouldn't need Apple to create a tool that lets it brute force hack the iPhone's lock screen passcode and gain access to the device's encrypted contents."

It is the words "password hadn't somehow" that has significance for me because in those words it doesn't take account of the intense situation people are operating under, speed of investigation operations, timescales, prevention for potential further attacks and pressure to resolve the case etc.  So the sub-text here is learning from adverse outcomes in emergency cases. Put on hold demands for back-door access as the golden cure because, in itself, it is not. There can be a plethora of superlative elements that will be sifted, considered and discarded where found not  to be relevant. For elements that may be relevant they still need to be sifted, considered and conceptualised.

From a range of materials I use in my training courses I use the following which I originated back in 2006 (and I published it back in 2010).


Primer(C now) = Point in time and Space (which is a constant reference point) in the present tense when the examiner is contacted for an investigation and from which the examiner uses to look back in time at and into the future regarding mobile telephone evidence.
.
(T) = Time is the timeline, limited by how far the examiner can see into the past and future based upon discovery.
.
(S) = Space is the space line that is used as a constant reference point from which all other events occurring in space can be considered based upon discovery (seizure of device, chain of custody of an exhibit etc)
.
(F) = Future relates to things that have yet to happen (future events). This is based upon things that maybe discovered from the time the examiner is contacted
.
(F d) = F d represents, as far as possible, thus not set to a specific period of time, how far into the future the examiner can identify events beyond which no further discovery is possible.
.
(PU usage) = Past User usage (below Blue line represents past recorded events, and below the red dotted line events unfolding during and after investigation)
.
(PR usage) = Past Record usage (below Blue line represents past recorded events, and below the red dotted line events unfolding during and after investigation)

The proposition in Smith Diag 1 is intended to represent, by use of visualization, how mobile telephone usage can be investigated. The diagram tests your powers of observation and, more importantly, your depth of knowledge. So do not be fooled by what you believe to be my poor graphics skills. I deliberately intended that (PU usage) area to be shown larger than the (PR usage) area in order to suggest more data may be found in the mobile telephone than maybe obtained from the network records. That is because not all activity on a mobile telephone leads to activity in the radio and fixed mobile network. Network records are not limited to billing records therefore issues associated with cell site analysis also need to be considered. It does not automatically follow there shall be parity between data obtained from the mobile telephone and the network records and vice versa. The diagram below (Smith Diag 2) represents a number of suggested data elements commonly arising during an investigation.


The third diagram (Smith Diag 3) uses the classic representation of Time (T) and Space (S). Use of a Time line may be obvious but the Space line may not be so obvious. The point of using Space is as a determinate for e.g. the seized exhibit in the examiner's possession. Let's say the examiner receives the mobile telephone exhibit on the 30th March 2008 at 3.00pm. The exhibit was seized 10th March 2008 at 11.00am. So, the examiner has two facts to work with (a) the exhibit in the laboratory (in time and space) and (b) the exhibit seized at a location from premises or person (in time and space).. So at the point the examiner has initial Contact (C now) with the exhibit then past events can now start to be determined. By way of illustration, following examination let’s say the examiner finds that the data recovered from the device reveals activity not connected with Space where the mobile telephone was seized at (b). Space would therefore be highly relevant, because (i) the examiner would need to demonstrate that as a fact and (ii) to demonstrate the separation in Space between each of the locations (a) laboratory, (b) the seizure, and the intervening factor between (a) and (b). This may be supported, for instance, by the last location and frequency details stored on the SIM card or may be the handset has GPS or one of the smartphone mapping system that might be set to automatic logging.


Have a go at designing one of these diagrams and show how you would handle the Apple phone (in this case) - the seizure and examination procedure. Just as a heads up F d is intended to represent a text message in the future that has been sent but not yet delivered to the target's handset. So how would you know if a text message is pending and who would you have to cooperate with to get that information (and the text content too)?

Hope this helps.

Exploration - missing the micro-evidence

If you are new to or have all but forgotten the humble (U)SIM Card now maybe as good time as any to refresh on the physical state of (U)SIM Card, in particular the hardware, so to speak.

To assist that refresh process, below are links to previously published materials that investigators and examiners might find useful:

http://trewmte.blogspot.co.uk/2013/09/usim-examination-physical-pt1.html
http://trewmte.blogspot.co.uk/2013/09/usim-examination-physical-pt2.html

It has been noted that such is the sophistication of attackers skillsets in areas, e.g. in-card listening devices, the skillsets applied borders on high-academic results that to the untrained eye could miss a forgery. [Images courtesy of Houda Ferradi, Rémi Gérau d, David Naccache, and Assia Tria: When Organized Crime Applies Academic Results. A Forensic Analysis of an In-Card Listening Device]

 
 
Hope this helps

Saturday, January 04, 2014

Tracing Packet Switch (PS) Users

Investigations into mobile activity tend largely to concentrate on recovering data from the user handset, mast (tower) data and call records. The core network (CN) is less well understood and therefore picking through a GSM/3GPP standard can often assist in understanding the identity and form of tarried/empheral data surviving in a network. The standard to be used for this discussion is:

3GPP TS 25.413 V12.0.0 (2013-12)
3rd Generation Partnership Project;
Technical Specification Group Radio Access Network;
UTRAN Iu interface
Radio Access Network Application Part (RANAP) signalling
(Release 12)


Now with an investigation underway initial enquiries lead to an active smartphone user operating in the pack switched (PS) domain. The target under surveillance requires the investigator to combine visual logs and the use of the of the handset. Unlike CS, packet data communications requires a range of information BUT for the purposes of the current investigation understanding the services being used and the geographical area where services are being obtained the trainee investigator can start with understanding what can be learned from:

Cell ID - Cell Identity
C-ID - Common Identity
IMEI - International Mobile Equipment Identity

IMSI - International Mobile Subscriber Identity
IPAddress - Internet Protocol Address
SAI - Service Area Identifier

SAP - Service Access Point
LAI  - Location Area Identifier
RNC - Radio Network Controller

RNS  - Radio Network Subsystem

Some examples of trainee investigation elements for consideration:

Para 8.16.1

The purpose of the Common ID procedure is to inform the RNC about the permanent NAS UE Identity (i.e. IMSI) of a user. This is used by the RNC e.g. to create a reference between the permanent NAS UE identity of the user and the RRC connection of that user for UTRAN paging co-ordination. The procedure may also be used to provide the SNA Access Information IE to the RNC or to provide the Management Based MDT Allowed IE to the RNC or to provide the Management Based MDT PLMN List IE to the RNC.


Para 8.17.2

If Trace Collection Entity IP Address IE is included and if the MDT Configuration IE is also included then the RNC shall, if supported, store the Trace Collection Entity IP address and use it when transferring Trace records, otherwise if MDT Configuration IE is not included, the RNC may use the Trace Collection Entity IP address when transferring trace records.


Para 8.35.2
When the transferred information in the Information Transfer Type IE relates to a Trace Session in the RNC, the Trace Activation Indicator IE indicates whether the Trace Session identified by the Trace Reference IE is activated or deactivated in the RNC. In case the Trace Session is activated, the Equipments To Be Traced IE gives the Equipment Identity of the UEs that the RNC has to trace. If the Trace Recording Session Reference IE, Trace Collection Entity IP Address IE, the IMSI IE and optionally the Serving Cell Identifier IE are included in the message, the CN shall take the information into account for anonymization of MDT data (TS 32.422 [10]).
 
The purpose of this brief discussion is to illustrate mobile networks naturally hold surviving data in the network for a range of reasons to enable the network to a have uniformed approach for the objective of operational performance, enquiry and, equally, to trace user terminals and roaming user terminals active in or obtaining services from a network.

Tuesday, January 22, 2013

S**T Talker

No doubt most of us, one time or another, have experienced a deja vu moment. A feeling of fleetingly living the same life-experience again. I think moments like this are summed up brilliantly by Pink Floyd in the words of the song Comfortably Numb:

"When I was a child
I caught a fleeting glimpse
Out of the corner of my eye

I turned to look but it was gone
I cannot put my finger on it now
The child is grown
The dream is gone
I... Have become comfortably numb
"

Anyway, I digress slightly, but hope it conveys what I was thinking, feeling when I was listening to a Music Radio Station, I believe it was Magic 105.4, and the people in the studio were having a laugh and messing around with an american female 1970s style electronically synthesized voice. You may recall the sort of thing if you had seen repeats of early versions of Department S, Mission Impossible, Ironside and so on and those voice distortion devices that were placed against the phone mic to disguide the voice of the caller.  It was at this moment, when I heard it on the radio that my mind was racing, where had I heard something similar in electronic voice alteration/manipulation? Having racked my my mind for a few days I realised that it reminded me of a computer program called Shit Talker.  I unreservedly apologies to readers of this blog, I am not being offensive, it is the name of the program.

Although we had some laughs in the office; believe it or not, it is relevant to investigations when checking out hoax and other types of calls. Of course, today, with voice detection and recognition techniques these type of programs do not present a problem. But if, sometime, you want to have a laugh in the company of friends then the program is still available http://unaesthetic.net/st/dl.shtml . I wouldn't use it on the phone though, it isn't a good idea.

Monday, January 21, 2013

Smartphone BYOD

Smartphone BYOD

The article about Application Performance Management highlights five factors to influence APM in 2013. Approaching APM not from the service angle (end-to-end interoperability) but what the user gains from it is an uncertainty with BYOD (e.g. mobile tablet etc), as stated by the article. BYOD is not simply about browsing habit to prove an issue or trend but whether such devices are used (a) as company property? (b) what work material is available? (c) is that on-site access or off-site access? (d) are external private access points accessible? (e) are there, regarding (d), obligations to reveal? .....and so on

During the heady parts of the recession, and even now, many companies operational costs and write down (depreciation) on operational assets (phones, computers etc) have been slimlined and moved some obligations on to staff to use their own smartphones and tablets, thus the company also realises reductions in capital expenditure by avoiding mobile services contracts, too.


Strange that so much effort and money has been spent and is being spent on cybercrime detection and prevention and yet the more likely statistic as to where an ICT attack would occur seems not to be determined from yet another market survey but plain, good old-fashioned common sense. If employees bring their own devices to work employers cannot legislate as to what happens whilst at work. If employers don't pay for communications devices/services because they want to turn an operating profit or 'twinkle' before their shareholders then it is not difficult to comprehend, from a security point of view, that smartphones are potential carries of 'digital infection' that are deliberately being allowed to propagate with BYOD. National societies have watched over the last two decades at the decay in common-sense and seen the removal of barriers that locked pandora's box shut. Why have the barriers been taken away? For the sake of emotional gratification of earning a short-term profit, globalisation and commercialisation that required reduction and removal of local barriers originally put in place by mandatory regulation.  

The task for digital investigators is to now re-engage with digital access policies in companies and discover the implemented and evolving communications route plan.

http://www.apmdigest.com/compuwares-top-5-apm-predictions-for-2013

Additional research

zdnet - http://www.zdnet.com/byod-mobile-workers-thumbing-nose-at-it-security-7000003519/

Forbes - http://www.forbes.com/sites/markfidelman/2012/05/02/the-latest-infographics-mobile-business-statistics-for-2012/
 

 Network World - http://www.networkworld.com/news/2012/061912-byod-20somethings-260305.html

Sunday, October 28, 2012

LTE, Test Trials and Cell Site Analysis

LTE, Test Trials and Cell Site Analysis

There are some strange views floating around that cell site analysis is highly difficult or impossible now we have moved from GSM and 3G on to LTE, with it being so new that there is uncertainty.  I can imagine that LTE may cause speculation because LTE hasn't been sufficiently rolled out in the UK and it may appear there is no mature facts or figures upon which to rely. But, infact, there are facts and figures that have been generated in refining the LTE system for roll out and, of course, that knowledge benefits cell site analysis.

Back in 2009 mobile operator Telefonica O2 started conducting LTE test trials in Slough Berkshire UK. Throughput data quantification, radio test measurements, surveys, etc created a plethora of statistical information which O2 used in planning its LTE network.  



Those tests included a variety of known components required for analysis, which can be seen in the 'Key' legend.


Consideration of LTE requires tests to be conducted not only with a static analysis and assessment approach but also distance and velocity analysis and assessment approach, too. That is apart from the environmental considerations. For CSA that means drive tests alone are not good enough; nor using passive radio test measurement devices could fulfil the requirements of an analysis and assessment approach to comprehend an LTE service at a particular location. TrewMTE blog readers may recall I gave a helpful tip about looking at data and location here: Data Usage in Cell Site Analysis - http://trewmte.blogspot.co.uk/2012/08/data-usage-in-cell-site-analysis.html.

Of course, consideration of the particapting RF transceiver elements present the same requirement for cell site analysis to understand the arrangements at the base station for LTE as it did for GSM/3G.

TrewMTE blog readers may also recall that I set out a series of discussions about Cell Site Identification presented as primers:

Mini Course in Cell Site Identification (Pt1)
http://trewmte.blogspot.com/2011/12/mini-course-in-cell-site-identification.html

Mini Course in Cell Site Identification (Pt2)
http://trewmte.blogspot.com/2011/12/mini-course-in-cell-site-identification_31.html

Mini Course in Cell Site Identification (Pt3.s1)
http://trewmte.blogspot.co.uk/2012/01/mini-course-in-cell-site-identification.html

I have completed the last primers in the series above and was going to publish them, having given readers sufficient time to go away and research/study the earlier parts. However, this matter needed airing first, due to misconceptions that are floating about out there. I shall publish the other primers later on.

Do remember, I have used the term 'cell site' to capture readers' imaginations to immediately link readers' thoughts towards cell site analysis (CSA). However, cell site can be used to mean e.g. a GSM cell site, a 3G NodeB or a LTE eNode. 

To leave the user device out of any analysis would be to precide over an incomplete investigation. Readers will note in Cell Site Identification Part 1 an illustration was given linking devices and components that are required for consideration when investigating/researching during CSA. The MS (handset/SIM) forms part of the investigation. O2 LTE test trials equally identified two devices used for their tests.

The experienced investigator will immediately see that the devices in the image above, used during test trials, do not of themselves fit immediately with the common scenarios of mobile phone usage and cell site analysis. However, as is known it is only fairly recently that LTE enabled smartphones have been launched. An LTE investigative approach to considering a particular device used in a particular case requires identification of handsets, dongles and server devices. Moreover, identification of devices that switch between transmission technologies is also a must.

Orange and Vodka - mixing mobile networks (shaken, not stirred) -
http://trewmte.blogspot.co.uk/2010/05/orange-and-vodka-mixing-mobile-networks.html

Examination Techniques3: Blackberry Bold -
http://trewmte.blogspot.co.uk/2012/03/examination-techniques3-blackberry-bold.html

Diplomas: Mobile Telephone Evidence (MTEdipl) -
http://trewmte.blogspot.co.uk/2010/05/diplomas-mobile-telephone-evidence.html

Sunday, September 02, 2012

Catching the IMSI Catchers

 
IMSI catcher catcher”—a device designed to snoop on the snoopers, 
sniffing out anyone operating an IMSI catcher in a given location.

Spying has been going on since one human wanted to know what another human was doing or saying. A common-sense expectation of modern Government is to limit or place a choke on how spying is conducted and, importantly, who can do it (spying, that is). Sadly, the warnings (loss of privacy, unlawful interception etc) to not allow 'pandora's box' [http://en.wikipedia.org/wiki/Pandora%27s_box] to be opened rather than apply pro-active controls appears to be have ignored those warnings as some form of  'cry wolf ' [http://en.wikipedia.org/wiki/Cry_Wolf], particularly if those warnings had merit afterall. It comes as no surprise then to find a recent news report indicating spying devices such as IMSI grabbers/catchers now creating concern that such devices could be in use in the criminal community: [imsi_catchers_criminals_law_enforcement_using_high_tech_portable_devices_to_intercept_communications_.html]

The development of IMSI catchers is not a recent development. Indeed, in a number of long running court battles (that I have been following for some years) a recent 2012 Court of Appeal Patent decision concluded [http://www.bailii.org/ew/cases/EWCA/Civ/2012/7.html] that shed light on the development of a particular IMSI Catcher. On the three cases they set out a history of development dates that uncover that this IMSI Catcher prototypes and the finished product appeared before (as a time reference) the Omagh Bombing of 1998.

IMSI grabbers/catchers present a huge potential for privacy rights abuses if one considers the pace at which mobile technology is causing redundancy of fixed landline phones and fixed PCs [http://www.itpro.co.uk/642538/cios-ring-desk-phone-death-knell] and unlawful interception at one end of the scale. At the other end of the scale IMSI grabbers/catchers could undermine serious crime investigations (where investigating officers might have their contact details tapped etc).

The fight back against invasion of privacy has taken amplified recently through the annoucement of a new development of a prototype that has been dubbed the "IMSI Catcher Catcher" [http://twitter.com/e3i5/status/197753799606153216/photo/1] as shown in the image above and that might provide the solid proof privacy campaigners seek to uncover. But this device could equally backfire if those investigating officers in the field are being tracked in the operation of IMSI Catching.

The above represents a tip of the iceberg material that is available through research about devices development for the express intent of obtaining subscriber identity and other personal information without the subscriber/user knowledge or consent where a man-in-the-middle attack has taken place [http://en.wikipedia.org/wiki/Man-in-the-middle_attack].

Sunday, May 20, 2012

Evidence is one thing, Understanding is another

Evidence is one thing, Understanding is another

I like Nokia. They were in at the beginning and presented the World with options, and so many walked behind, in their footsteps.  The Nokia 110 and 112 still hasn't stopped the examiner from seeing potential evidence:


Seeing through the eyes of experienced examiners:


Mobile phones - understanding their contribution to evidence.

Wednesday, November 30, 2011

CDR Toll Ticket

CDR Toll Ticket

Essential to any police inquiry and/or investigation is the availability of mobile network call detail records. Significantly, the data to be found in a CDR usually contains far more detail than data produced in eg compilation records; the latter data being selected based upon the 'subjective' mindset of the person creating the compilations.

Toll Ticket Enquiry is very different from Toll Ticket Analysis as the latter document only extrapolates those fields of data chosen by the person eg making selective choices from data stored in a database; thus an unsuspecting officer with little-to-no-experience may have no concept of the range of fields of data available that could be useful to an inquiry and investigation. Thus any objectivity by the officer to form an appropriate opinion or conclusion might be blocked.     

I have produced below scanned headers from two Vodafone Toll Ticket Enquiry CDRs both dated in February 1998. Both of the headers come from genuine Toll Ticket Enquiry CDRs, the first is for a Toll Ticket relating to call traffic on 13-02-98 on Vodafone's analogue TACS mobile network and produced on the 24-02-98. The second Toll Ticket relates to call traffic on 13-02-98 on Vodafone's digital GSM mobile network and produced on the 21-02-98.  Both were served in evidence in a murder case, thus in the public domain. The scanned headers below do not contain any personal data.  


Vodafone's Toll Ticket Enquiry CDR (TACS)



Vodafone's Toll Ticket Enquiry CDR (GSM)

It is entirely consistent that as an expert I would seek these CDRs in cases (as I did in the above case) in order that I can properly and appropriately advise those who instruct. The two Toll Ticket Enquiry CDRs represent a useful historical guide of events in 1998. It is noteworthy to mention that the GSM and TACS records illustrate the position of a single mobile network operator running two different radio transmission mobile networks at the same time. Moreover, such a feat did not limit or prevent the operator capturing data for CDRs relating to call traffic from its switches (EMX/MSC). Note also the duration of time between the dates of the call traffic CDRs and the production of them. Thus any inquiry or investigation into serious crime in 1998 would or should have had access to such records. So when reading the transcripts from eg two Appeals involving the same case  ( NIHC/QB/2009/50NICA/2011/33 ) and Toll Ticket is mentioned by name, the above provides the reader with some insight as to the data that can be recorded in such CDRs.


Today, of course, CDRs from mobile operators may have changed with respect to the identified fields of data in them or by design due to the system that produced them. I have shown examples elsewhere. Historically and like today the CDRs referred to should not contain fields of data that would compromise security of an operator's secure protocols, encryption keys etc.  Toll Ticket or other types of CDRs are ideal for evidence and provided there is completeness in the data (as opposed to subjective content imported into compilation records) then CDRs are essential to call record analysis (CRA) and cell site analysis (CSA).

Historical and current material on this subject and other subjects are included in my training courses for police and examiners to assist inquiries and investigation to make the best use of data and, as equally as important, how to interpret such data.

Friday, November 18, 2011

Taping Business Mobile Phone Calls - Part 2

Taping Business Mobile Phone Calls - Part 2

Last year the FSA (Financial Services Authority) published its consultation document concerned with recording mobile communications within the finanical services industry http://trewmte.blogspot.com/2010/04/taping-business-mobile-phone-calls.html. I also produced a list of additional statutory and regulatory links to materials about call recording.

The FSA has now concluded their consultation and published CP10/17 which can be downloaded here:

http://www.fsa.gov.uk/pubs/policy/ps10_17.pdf

"2.28 What constitutes ‘reasonable steps’ is fundamentally principles-based, meaning that we are not prescriptive about what we expect from firms to be compliant. Each firm must decide what it deems necessary and reasonable to comply with the taping provisions."