NIST guidelines on cell phone forensics

Opinion
Sep 28, 20062 mins

* NIST publication discusses extracting data from mobile devices

Readers who are corporate information security officers investigating possible violations of policy, and law enforcement officials investigating possible crimes, may need to extract data from the multipurpose devices that are, curiously, still referred to as “mobile phones.”

For an example of how these devices are much more than phones, see the Nokia Web site, which shows checkboxes for selecting devices equipped with:

* Bluetooth technology

* Camera (basic)

* Camera (2 megapixels or more)

* Downloadable ring tones

* FM radio

* Games

* Multimedia messaging

* MP3 player

* Speakerphone

* Video recorder

* Voice dialing

* Web browser

When suspects use such devices, searching them for evidence becomes as necessary as searching their (other) computers.

As I mentioned in previous columns, there’s a new set of draft documents from the Computer Security Resource Center of the U.S. National Institute of Standards and Technology (NIST). SP 800-101, “Guidelines on Cell Phone Forensics” “outlines general principles and provides technical information intended to aid organizations evolve appropriate policies and procedures for preserving, acquiring, and examining digital evidence found on cell phones.”

Authors Wayne Jansen and Rick Ayers have prepared a 98-page document with the following structure:

1. Introduction

2. Background

3. Forensic tools

4. Procedures and principles

5. Preservation

6. Acquisition

7. Examination and analysis

8. Reporting

9. References

Appendix A. Acronyms

Appendix B. Glossary

Appendix C. Generic acquisition overview

Appendix D. Standardized call records

Appendix E. Online forensic resources for mobile devices

Appendix C is an 11-page guide showing a generalized data-extraction process packed with screenshots from a variety of data-acquisition tools. It has the following subsections:

1. Connection identification

2. Device identification

3. Data selection

4. Acquisition

5. Phonebook entries

6. Call log entries

7. Message entries

8. Calendar entries

9. (U)SIM {UMTS [Universal Mobile Telecommunications System] Subscriber Identity Module}data

10. Picture entries

11. Searching

12. Reporting

This work is a solid introduction to the terminology, tools and methods for forensic analysis of mobile communications devices; it will serve a wide range of users including instructors and students in industry and academic courses that focus on digital forensic investigations. I will certainly be recommending it as a reference in the upcoming Digital Forensics Investigations elective of the Norwich University Master of Science in Information Assurance program.