Miat-wm5: Forensic Acquisition for Windows Mobile Pocketpc
نویسندگان
چکیده
A PocketPC equipped with phone capabilities could be seen as an advanced smartphone, providing more computational power and available resources. Even though several technologies have emerged for PDAs and Smartphones forensic acquisition and analysis, only few technologies and products are capable of performing forensic acquisition on PocketPC platform; moreover they rely on proprietary protocols, proprietary cable-jack and proprietary operating systems. This paper presents the Mobile Internal Acquisition Tool for PocketPC devices. The approach we propose in this paper focuses on acquiring data from a mobile device’s internal storage memory, copying data to an external removable memory (like SD, mini SD, etc.). Such task is performed without the need of connecting the device to PC. Thanks to this, forensic operators could avoid to travel with luggage plenty of one-on-one tools for every single mobile device. Finally, we will show some experimental results, comparing this methodology with standard products on real world devices.
منابع مشابه
Windows Mobile advanced forensics
Windows CE (at this moment sold as Windows Mobile) is on the market for more than 10 years now. In the third quarter of 2009, Microsoft reached a market share of 8.8% of the more than 41 million mobile phones shipped worldwide in that quarter. This makes it a relevant subject for the forensic community. Most commercially available forensic tools supporting Windows CE deliver logical acquisition...
متن کاملA comparison of forensic evidence recovery techniques for a windows mobile smart phone
Acquisition, decoding and presentation of information from mobile devices is complex and challenging. Device memory is usually integrated into the device, making isolation prior to recovery difficult. In addition, manufacturers have adopted a variety of file systems and formats complicating de-coding and presentation. A variety of tools and methods have been developed (both commercially and in ...
متن کاملA Novel Method for Windows Phone Forensics
Mobile forensics is a branch of cyber forensics which helps in extracting evidence from mobile devices. A variety of software tools are available from different vendors for performing the acquisition and analysis of handheld devices ranging from basic phones to smart phones. From an investigator’s point of view, information like call log, sms, mms, contacts, multimedia and other user related fi...
متن کاملLive Memory Acquisition for Windows Operating Systems:
Cover Page and Abstract Tools and Techniques for Analysis The live acquisition of volatile memory (RAM) is an area in digital forensics that has not garnered much attention until most recently. The importance of the contents of physical memory has always taken a back seat to what is considered more important – the contents of physical media. However, a great deal of information can be acquired ...
متن کاملA Forensically Sound Adversary Model for Mobile Devices
In this paper, we propose an adversary model to facilitate forensic investigations of mobile devices (e.g. Android, iOS and Windows smartphones) that can be readily adapted to the latest mobile device technologies. This is essential given the ongoing and rapidly changing nature of mobile device technologies. An integral principle and significant constraint upon forensic practitioners is that of...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2008