Showing posts with label mobile phone forensics. Show all posts
Showing posts with label mobile phone forensics. Show all posts

Monday, June 25, 2012

Hidden data battery investigations

Hidden data battery investigations

Due to a common embedded controller found in Lithium Ion (Li-Ion) and Lithium
Polymer batteries and used in a large number of MacBook, MacBook Pro, and MacBook Air laptop computers it is possible when the battery is 'unsealed' to conceal data in its memory.

To avoid data being lost at the next boot up of the laptop, by setting the unsealed battery's embedded contoller into Boot ROM mode (factory setting stage) charging cannot function and pass information to the flash and overwrite the hidden data.

A perpetrator could therefore transport hidden data and/or pass data in the battery to another person/laptop. If the laptop/battery are seized before the hidden data has been extracted and the examiner switches on the laptop, the battery's memory can be re-written causing loss of the hidden data - a cross between a trojan horse and dead-man's trap.

It is possible to brick the battery giving the impression the battery is a dud. An examiner may not think to consider the battery as memory storage and disregard the battery during investigation.

Thursday, July 28, 2011

M2M Crime

M2M Crime

In the last discussion (mobile-markets) a reference was made to M2M (machine-to-machine) market stats. Yesterday's article from 'pcworld' about hackers using mobile communications for war texting to unlock car doors (war_texting) should provide useful material to study about M2M for MTEB Students to identify 'potential' crime activity and where evidence maybe generated. Send your finalised report (pdf), for marking, by email please.

Saturday, July 02, 2011

Windows Phone Apps reach new market levels

Windows Phone Apps reach new market levels

Back in 2006 Vodafone announced news to standardise handsets (here) and I commented then that it might be a good idea if users could profile their own handsets with the apps they actually use.  There is much market evidence to suggest the evolving mobile is moving in that direction. Android, Apple, Blackberry, Java and Symbian apps stores are a good example of this. The growth in mobile apps has not been limited to the five previously mentioned, Window Phone apps, too, are storming ahead with over 25,235 apps available.

There is a brief synopsis of the Windows Phone apps growth at winrumors. The chart below is courtesy of windowsphoneapplist.


windows phone 7 applications


Knowing these stats can be helpful but unless there is some inter-related commentary about the technology (so to speak) that links those stats to forensics, it can all become pretty meaningless. My take on those stats is they do present challenges that the mobile forensic community will need to adapt, sooner rather than later. There is a wealth of information in apps that cannot be gleaned from using many of the evidence recovery automated handset readers. This has happened because evidence tools may not have been designed for that purpose; recovering app info and the content they store.

Firstly, it is important to understand the distinction between apps accessible through interface/emulator tools, designed for app builders and programmers (so to speak), and those tools said to be designed for collecting evidence.

Secondly, it doesn't automatically follow that just because an examiner obtains an evidential physical dump from flash memory ( a ) the examiner has dumped everything from the correct component ( b ) that the dump's content will be 'visible' and 'legible' (PACE 1984) and 'intelligible' (DPA1984).

Holding such a view doesn't mean, nor is it intented to suggest, that I think there is an impossibility here that cannot be overcome. Do I think the mobile forensic communty, working together, will find the solutions? Yes, absolutely, naturally.

Friday, April 09, 2010

Seminar on GSM Standards Updated

Seminar on GSM Standards Updated
.
Updated for Seminar on GSM Standards (previous link):
http://trewmte.blogspot.com/2010/03/seminar-on-gsm-standards.html
.
It doesn't appear easy to take in the mobile telephone technical standards and that the numerous standards that are out there add an additional layer of perceived complexity.
.
To address this particular matter and demonstrate that dealing with technical standards is far easier than is imagined, as part of the presentation at the Seminar on GSM Standards, diagrams will be shown that reference common elements dealt with during examination. The diagrams are to demonstrate that it is far easier to address technical issues starting with a GSM perspective than it is jumping in at the deep end trying to understand 3G and work backwards.
.
One of the illustrations to be presented at the Seminar (shown below) relates to UICC with SIM and USIM environments. At the Seminar the illustration will be completed with identification of the relevant technical standards that should ease perceived complexity issues with UICC with SIM/USIM environment using this identification process.
.
.
UICC with SIM/USIM environments there are over 80 standards that can be referred to, but an examiner only need start with knowing approximately 20 technical standards at first instance and then expand into the other standards. Be sure of what I am saying here. You need to know the standards that exist and have a copy. Reading standards is not though a matter the Seminar will be addressing, but some helpful tips will be provided.

.
With GSM SIM there are over 40 standards that can be referred to, but knowing approximately 8 technical standards to start with can help kick start getting to the other standards and the realisation that dealing with technical standards need not be a daunting task at all, particularly as acquiring majority of the standards are free, as well.

Friday, March 19, 2010

Seminar on GSM Standards

Seminar on GSM Standards
.
It is clear that associated with mobile phone examination to obtain evidence that examiners must read the GSM Standards to understand the data evidence and whether the devices used acquire the data. The concern amongst examiners still exists because there are so many Standards current and historical and each providing variations on obtaining evidence and interpretation that it is a daunting task to know where to start. Would it be worth having a one-day seminar in the UK to go through the GSM Standards. Standards can change 2-3 times a year and presenting the information at a seminar would assist in getting across important facts and guide through how to get to the appropriate information in them. I wont be charging for my time to prepare the presentation and present the findings.

.
So that delegates can attend free of charge I am also looking for:
.
1) Sponsor (to pay) for the Seminar room/hall
2) A location must be near to a central train station (not requiring loads of train changes)
3) Sponsor (to pay) for the teas/coffee and sandwiches etc
4) Exhibitors at the Seminar
.
Can you send some feedback whether you are interested in attending or sponsoring.

UPDATE: Seminar on GSM Standards

Objectives


Upon completion of the seminar, the participant should:


• Understand the GSM Standards development and legal references

• Be aware of GSM system standards relevant to the examination or investigation

• Have an awareness of GSM interfaces to comprehend symbiotic relationships for call/data tracing

• To know where to look to attribute identity conventions

• Know availability of standards

There are five presentation modules:

1) Introduction

2) GSM System Standards

3) GSM Specified Interfaces (10 + 1)

4) Identifier Conventions

5) Access to Standards

Monday, August 31, 2009

Forensic Focus Interviews

Forensic Focus Interviews
.
Forensic Focus regularly interviews well known personalities from the world of computer and mobile phone forensics.
.
This month it was my turn:
.
Mobile Telephone Expert Witness, 29/08/09
.
Readers of trewmte.blogspot may also want to read the Interviews of past personalities, available at the link below:
.
  • Sean McLinden, Outcome Technology Associates, Inc. - 21/07/09
  • Graham Brown-Martin, Digital Safety Conference - 12/06/09
  • Lee Whitfield, Forensic 4cast - 10/06/09
  • Robert Botchek, President & Founder – Tableau, LLC - 09/06/09
  • Dr Chris Pamplin, Editor – UK Register of Expert Witnesses - 31/05/09
  • Ben Levitan, US Telecommunications Expert Witness - 08/05/09
  • Nick Furneaux, MD CSITech & Director, Bright Forensics - 07/05/09
  • Jan Collie, The Digital Detective - 24/04/09
  • Professor Tony Sammes, Cranfield University - 31/03/09
  • Simon Biles, Thinking Security - 27/11/08
  • Gene Spafford, CERIAS - 12/09/08
  • Paul Wright, City of London Police - 05/09/08
  • Jonathan Krause, Forensic Control - 27/08/08
  • Ian Kennedy, Forensic Consultant & Open University Lecturer - 14/07/08
  • Matt Shannon, Founder and Chief Software Architect F-Response - 19/06/08
  • David Sullivan, Appointments-UK - 28/04/08
  • Stefan Fleischmann, CEO X-Ways Software Technology AG - 27/02/08
  • John Patzakis, Guidance Software - 28/06/07
  • Harlan Carvey - 07/03/07