Hong-Kong, Mar Mobile Data in Legal Proceedings and methods for Extraction, Analysis and Delivering Yuval Ben-Moshe Forensics Technical Director
Relevance
Why Mobile ESI? A treasure trove of information User accounts Contacts Call history SMS Messages Messages Google Mail and Yahoo! Messenger Skype Chat History of Google Maps, Dynamic Dictionary Automatic Screen Shots Apps stored data Deleted
Mobile Evidence is Admissible in Court Sihlali v. South African Broadcasting Corporation, Ltd. (J700/08) [2010] ZALC Rash text message: "I Quit" Employment resignation by SMS text message was a legally-effective notice in “writing”
Mobile Evidence may need to be Preserved Regas Christou v. Beatport, LLC (D. Colo. January 23, 2013),Regas Christou v. Beatport Court sanctioned the defendants for taking “no steps to preserve text messages” leading to a spoliation sanction.
Concepts and Challenges of Mobile Device Forensics
Yet Another Computer
Not
Extraction Methods Logical Extraction File System Extraction Physical Extraction
Logical Extraction Results A well formatted report: Call logs, Contacts, SMS messages, Videos, Photos, Audio, Music
Logical Extraction File System Extraction Physical Extraction Extraction Methods
File System Extraction Results SMS, Contacts, Call Logs, MMS, Notes, Applications, Voice Mails, Calendar, Bluetooth, GPS, Notes, Bookmarks, Skype, Chat, Cookies, Facebook Content .plist files containing great forensic data ‘keychain-2.db’ - Networks the user connected to including Wi-Fi, VPN, Bluetooth and the Apple iTunes Store ID. Other databases contain information from Apps
Logical Extraction File System Extraction Physical Extraction Extraction Methods
Contacts Including Deleted
Detailed Call Log, Including Deleted
Skype Contacts Including Deleted
Application Usage Details
WiFi Access History
GPS Locations History
User Pattern Lock 2020
3->2->1->4->7->8->9 2121
Timeline Analysis
Graphical Timeline Analysis
Real life Case - Logical Vs Physical Additional evidence recovered using Physical: 22,000+ images 59 videos audio files 16,000+ locations 60+ chats (included Facebook and Skype) 30+ MMS text files
Changing the “Undue Burden” and Proportionality Equations Gathering information from mobile devices is easy and intuitive Mobile stored information has many unique artifacts; just one can tip your case The bar for “Undue burden” argument has been raised It is more likely to be “Proportionate”
UFED Touch
Decoding, Analysis & Reporting UFED Reader UFED Logical Analyzer UFED Physical Analyzer Multilingual User Interface Advanced Search Bookmarks and Tags Timeline view Multiple Project Instant Search Conversational View Generate and customized Reporting.ufd Support Watch List Hex Image view and search Advanced Carving Chain Manager Python Scripting Shell Advanced Decoding SQLite DB browser Installation License FreeUFED LogicalUFED Ultimate
Mobile Data as a Piece in the Puzzle Mobile data is only as valuable as it can be weighted within the whole dataset UFED output is already available for processing with: Exterro Fusion, Nuix, Palantir. More integration projects are on-going
Recap
RAPRAP
Richer Accessible Proportionate
Questions
Thank You Yuval Ben-Moshe