Presentation is loading. Please wait.

Presentation is loading. Please wait.

Hong-Kong, Mar-03-05 Mobile Data in Legal Proceedings and methods for Extraction, Analysis and Delivering Yuval Ben-Moshe Forensics Technical Director.

Similar presentations


Presentation on theme: "Hong-Kong, Mar-03-05 Mobile Data in Legal Proceedings and methods for Extraction, Analysis and Delivering Yuval Ben-Moshe Forensics Technical Director."— Presentation transcript:

1 Hong-Kong, Mar-03-05 Mobile Data in Legal Proceedings and methods for Extraction, Analysis and Delivering Yuval Ben-Moshe Forensics Technical Director

2 Relevance

3 Why Mobile ESI?  A treasure trove of information User accounts Contacts Call history SMS Messages Messages Google Mail and Yahoo! Messenger Skype Chat History of Google Maps, Dynamic Dictionary Automatic Screen Shots Apps stored data  Deleted

4 Mobile Evidence is Admissible in Court  Sihlali v. South African Broadcasting Corporation, Ltd. (J700/08) [2010] ZALC  Rash text message: "I Quit"  Employment resignation by SMS text message was a legally-effective notice in “writing”

5 Mobile Evidence may need to be Preserved  Regas Christou v. Beatport, LLC (D. Colo. January 23, 2013),Regas Christou v. Beatport  Court sanctioned the defendants for taking “no steps to preserve text messages” leading to a spoliation sanction.

6 Concepts and Challenges of Mobile Device Forensics

7 Yet Another Computer

8 Not

9 Extraction Methods Logical Extraction File System Extraction Physical Extraction

10 Logical Extraction Results  A well formatted report:  Call logs, Contacts, SMS messages, Videos, Photos, Audio, Music

11 Logical Extraction File System Extraction Physical Extraction Extraction Methods

12 File System Extraction Results  SMS, Contacts, Call Logs, MMS, Notes, Applications, Voice Mails, Calendar, Bluetooth, GPS, Notes, Bookmarks, Skype, Chat, Cookies, Facebook Content .plist files containing great forensic data ‘keychain-2.db’ - Networks the user connected to including Wi-Fi, VPN, Bluetooth and the Apple iTunes Store ID. Other databases contain information from Apps

13 Logical Extraction File System Extraction Physical Extraction Extraction Methods

14 Contacts Including Deleted

15 Detailed Call Log, Including Deleted

16 Skype Contacts Including Deleted

17 Application Usage Details

18 WiFi Access History

19 GPS Locations History

20 User Pattern Lock 2020

21 3->2->1->4->7->8->9 2121

22 Timeline Analysis

23 Graphical Timeline Analysis

24 Real life Case - Logical Vs Physical  Additional evidence recovered using Physical:  22,000+ images  59 videos  1000+ audio files  16,000+ locations  60+ chats (included Facebook and Skype)  30+ MMS  3300+ text files

25 Changing the “Undue Burden” and Proportionality Equations  Gathering information from mobile devices is easy and intuitive  Mobile stored information has many unique artifacts; just one can tip your case  The bar for “Undue burden” argument has been raised  It is more likely to be “Proportionate”

26 UFED Touch

27

28 Decoding, Analysis & Reporting UFED Reader UFED Logical Analyzer UFED Physical Analyzer Multilingual User Interface Advanced Search Bookmarks and Tags Timeline view Multiple Project Instant Search Conversational View Generate and customized Reporting.ufd Support Watch List Hex Image view and search Advanced Carving Chain Manager Python Scripting Shell Advanced Decoding SQLite DB browser Installation License FreeUFED LogicalUFED Ultimate

29 Mobile Data as a Piece in the Puzzle  Mobile data is only as valuable as it can be weighted within the whole dataset  UFED output is already available for processing with: Exterro Fusion, Nuix, Palantir.  More integration projects are on-going

30 Recap

31

32 RAPRAP

33 Richer Accessible Proportionate

34 Questions

35 Thank You Yuval Ben-Moshe Yuvalbm@Cellebrite.com


Download ppt "Hong-Kong, Mar-03-05 Mobile Data in Legal Proceedings and methods for Extraction, Analysis and Delivering Yuval Ben-Moshe Forensics Technical Director."

Similar presentations


Ads by Google