* NIST publication discusses extracting data from mobile devices
endif; ?>Readers who are corporate information security officers investigating possible violations of policy, and law enforcement officials investigating possible crimes, may need to extract data from the multipurpose devices that are, curiously, still referred to as “mobile phones.”
For an example of how these devices are much more than phones, see the Nokia Web site, which shows checkboxes for selecting devices equipped with:
* Bluetooth technology
* Camera (basic)
* Camera (2 megapixels or more)
* Downloadable ring tones
* FM radio
* Games
* Multimedia messaging
* MP3 player
* Speakerphone
* Video recorder
* Voice dialing
* Web browser
When suspects use such devices, searching them for evidence becomes as necessary as searching their (other) computers.
As I mentioned in previous columns, there’s a new set of draft documents from the Computer Security Resource Center of the U.S. National Institute of Standards and Technology (NIST). SP 800-101, “Guidelines on Cell Phone Forensics” “outlines general principles and provides technical information intended to aid organizations evolve appropriate policies and procedures for preserving, acquiring, and examining digital evidence found on cell phones.”
Authors Wayne Jansen and Rick Ayers have prepared a 98-page document with the following structure:
1. Introduction
2. Background
3. Forensic tools
4. Procedures and principles
5. Preservation
6. Acquisition
7. Examination and analysis
8. Reporting
9. References
Appendix A. Acronyms
Appendix B. Glossary
Appendix C. Generic acquisition overview
Appendix D. Standardized call records
Appendix E. Online forensic resources for mobile devices
Appendix C is an 11-page guide showing a generalized data-extraction process packed with screenshots from a variety of data-acquisition tools. It has the following subsections:
1. Connection identification
2. Device identification
3. Data selection
4. Acquisition
5. Phonebook entries
6. Call log entries
7. Message entries
8. Calendar entries
9. (U)SIM {UMTS [Universal Mobile Telecommunications System] Subscriber Identity Module}data
10. Picture entries
11. Searching
12. Reporting
This work is a solid introduction to the terminology, tools and methods for forensic analysis of mobile communications devices; it will serve a wide range of users including instructors and students in industry and academic courses that focus on digital forensic investigations. I will certainly be recommending it as a reference in the upcoming Digital Forensics Investigations elective of the Norwich University Master of Science in Information Assurance program.




