A Novel Method for Windows Phone Forensics
نویسندگان
چکیده
Mobile forensics is a branch of cyber forensics which helps in extracting evidence from mobile devices. A variety of software tools are available from different vendors for performing the acquisition and analysis of handheld devices ranging from basic phones to smart phones. From an investigator’s point of view, information like call log, sms, mms, contacts, multimedia and other user related files are the important artifacts that have to be extracted and analyzed from such devices. The commercially available software tools have different capabilities in extracting these data depending on the make and model of the device under investigation. This research paper emphasizes on the forensic analysis of one of the popular smart phone operating systems named Windows Phone. Windows Phone is relatively a new smart phone operating system with the potential to become one of the major smart phone platforms in the near future. This research paper discusses about the feasibility of conducting a logical acquisition on the device and details the artifacts that can be extracted from the device.
منابع مشابه
Windows Phone 7 from a Digital Forensics' Perspective
Windows Phone 7 is a new smartphone operating system with the potential to become one of the major smartphone platforms in the near future. Phones based on Windows Phone 7 are only available since a few months, so digital forensics of the new system is still in its infancy. This paper is a first look at Windows Phone 7 from a forensics’ perspective. It explains the main characteristics of the p...
متن کاملForensics Analysis On Smart Phones Using Mobile Forensics Tools
The role of mobile devices (cell phones and smart phones) becomes an integral part of everyone’s life, which also leads to criminal activities like hacking, Smishing, SMS spoofing etc. Digital evidence in mobile phone has attempted to delete the data by criminal. Information from mobile phones is useful for investigators to learn about user information. In this paper, a novel method is performi...
متن کاملA comparison of forensic evidence recovery techniques for a windows mobile smart phone
Acquisition, decoding and presentation of information from mobile devices is complex and challenging. Device memory is usually integrated into the device, making isolation prior to recovery difficult. In addition, manufacturers have adopted a variety of file systems and formats complicating de-coding and presentation. A variety of tools and methods have been developed (both commercially and in ...
متن کاملA Consistency Study of the Windows Registry
This paper proposes a novel method for checking the consistency of forensic registry artifacts by gathering event information from the artifacts and analyzing the event sequences based on the associated timestamps. The method helps detect the use of counter-forensic techniques without focusing on one particular counter-forensic tool at a time. Several consistency checking models are presented t...
متن کاملWindows Mobile advanced forensics
Windows CE (at this moment sold as Windows Mobile) is on the market for more than 10 years now. In the third quarter of 2009, Microsoft reached a market share of 8.8% of the more than 41 million mobile phones shipped worldwide in that quarter. This makes it a relevant subject for the forensic community. Most commercially available forensic tools supporting Windows CE deliver logical acquisition...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2015