0% found this document useful (0 votes)
6 views49 pages

Chapter Six

Chapter 6 discusses mobile and embedded forensics, emphasizing the importance of understanding various devices for effective data collection and analysis. It covers the unique challenges posed by mobile phones and embedded systems, the phases of forensic investigation, and the significance of ensuring evidence integrity. The chapter also explores different acquisition methods, including physical and logical approaches, and highlights the need for continuous adaptation to evolving technology.

Uploaded by

okiruiku
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views49 pages

Chapter Six

Chapter 6 discusses mobile and embedded forensics, emphasizing the importance of understanding various devices for effective data collection and analysis. It covers the unique challenges posed by mobile phones and embedded systems, the phases of forensic investigation, and the significance of ensuring evidence integrity. The chapter also explores different acquisition methods, including physical and logical approaches, and highlights the need for continuous adaptation to evolving technology.

Uploaded by

okiruiku
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter 6:

Mobile and Embedded Forensics


Outlines

• Introduction
• Collection Phase
• Examination Phase
• Reverse Engineering and Analysis Applications
• Summary.

We are dedicated to Innovative Knowledge 2


Introduction
• Computing power has exponentially increased over the
years, following Moore’s Law, enabling the proliferation of
systems from supercomputers to medical implants.
• Electronic devices collect extensive data daily, from access
cards to GPS, which can serve as evidence in investigations.
• Mobile phones, with their multifunctionality and connectivity,
often contain the most substantial traces, though embedded
systems and IoT devices are also significant sources of
evidence.
• Industrial Control Systems (ICS), including SCADA software
and IoT devices, are emerging as critical areas for data
collection in legal and security contexts.

We are dedicated to Innovative Knowledge 3


Introduction
• The foundation of mobile and embedded forensics focuses
on understanding various devices, enabling the selection
of suitable methods for data collection and analysis.
• Mobile and embedded devices pose unique challenges
due to varying hardware standards, requiring a focus on
collection and examination stages in the forensic process.
• Methods, guidelines, and best practices evolve quickly,
requiring adaptability as technology and devices change.
• Here, examples of specific methods are discussed to
highlight the importance of understanding the underlying
technology for effective forensic investigation.

We are dedicated to Innovative Knowledge 4


Embedded Systems and Consumer Electronics
• An embedded system is a specialized computer system designed
for specific functions within constraints, combining software,
hardware, and sometimes mechanical components.
• Consumer electronics are everyday-use devices like mobile phones,
TVs, hi-fi systems, watches, and computers.
• Embedded systems have
limitations in power
consumption and
sturdiness.
• Storage space is often
limited, using flash memory
instead of hard drives.
• Some systems use ROM for
firmware and volatile
memory for dynamic data.

We are dedicated to Innovative Knowledge 5


Mobile Phones
• Mobile phones: resource-constrained (power, screen size, input methods)device.

• Mobile phones are a special case of embedded systems, small and pocket-sized with
constraints on screen size, power usage, and input methods.
• Smartphones are increasingly resembling general computer systems, with more
powerful and standardized operating systems and easier input/output interfaces.
• Modern smartphones enable tasks like web browsing, making presentations, and
writing books.
• Due to their unique challenges, mobile phones and devices are categorized
separately from other embedded systems.
• Mobile phones are widely used and considered highly personal devices.
• Mobile phone forensics is a key field, especially in criminal cases.
• Mobile phones function like general-purpose computers, with an OS, memory, and
CPU.
• The baseband processor handles radio transmissions and operates separately from
the phone’s main OS.

We are dedicated to Innovative Knowledge 6


Telecommunication Networks
• Mobile devices connect to mobile networks, leaving
traces in the network infrastructure.
• Description of third- and fourth-generation networks.
• GSM network –
o consists of the radio subsystem (RSS), Network and Switching
Subsystem(NSS), and Operation Subsystem(OSS).
o Study the security systems at each component.
• RSS- consists of Mobile
stations, base
transceivers, and
controls.
• NSS- manages the
setup and routing
protocols.
• OSS- takes care of
maintenance and its
operation
We are dedicated to Innovative Knowledge 7
Mobile devices and embedded systems as
evidence
• Mobile devices and embedded systems can provide
evidence, like computers, but differ in storage methods.
• Computers use hard disks with standardized interfaces
for low-level access, while embedded systems use flash
memory without direct access.
• For computers, well-defined methods for data
acquisition and interpretation exist, whereas embedded
systems lack these, requiring continuous assessment of
methods.
• Ensuring evidence integrity and chain of custody is
crucial, with forensic investigators needing to calculate a
digital fingerprint (using SHA-2 or SHA-3) to preserve data
integrity.

We are dedicated to Innovative Knowledge 8


Malware and Security Considerations
• No computer system, including smartphones and
embedded systems, can be guaranteed to be malware-
free.
• SpyEye malware, with a mobile component called
Spitmo, targeted mobile banking and bypassed two-
factor authentication by stealing the mobile Transaction
Authentication Number (mTAN).
• Point-of-sale (PoS) terminals can be exploited through
physical modifications or malware to steal payment card
details.
• Stuxnet targeted industrial control systems causing
physical damage. Malware can also be introduced
during the design or manufacturing process, affecting
hardware functionality.
We are dedicated to Innovative Knowledge 9
Ontologies for Mobile and Embedded Forensics
• A conceptualization represents a simplified view of the world
for a specific purpose.
• An ontology explicitly specifies this conceptualization.
• Mobile and embedded forensics categorizations vary based
on the desired insights.
• First responder categorizations prioritize digital evidence
differently than advanced lab categorizations.
• A practical ontology for mobile and embedded forensics is
established, followed by three other literature-based
ontologies.
• The term “collection” refers to the forensic process phase,
while “acquisition” pertains to methods used within this phase.

We are dedicated to Innovative Knowledge 10


Ontologies for Mobile and Embedded Forensics…

• An Acquisition Method Ontology:


o Assessments and methods can be categorized to
better understand the data collection process.
o Two primary views of data collection are defined:
▪ the data view, focusing on system data and attributes, and
▪ the method view, addressing how the method impacts the
system and collected information.
o Both views are integral to the collection process: the
data view represents potential information, while the
method view realizes this potential.
o Selecting the best method involves aligning the
method with the desired information to be collected.

We are dedicated to Innovative Knowledge 11


Ontologies for Mobile and Embedded Forensics…
• Data View - Layers of Abstraction:
o Information exists at various abstraction layers within a system, visible or
accessible only at specific levels.
o Certain data, such as a File Allocation Table, is only interpretable at specific
abstraction layers.
o Interpretation is often easier at higher abstraction layers (e.g., file contents) than
at lower layers (e.g., disk sectors).
o Encryption restricts access to information at lower layers, requiring decryption or
acquisition when data is unencrypted.

• Trust:
o The trustworthiness of the system and abstraction layers are closely linked: higher
abstraction levels require trusting more of the underlying system.
o Physical-level acquisition minimizes reliance on the system, leaving only the
hardware of the chip beyond control.
o Logical acquisition relies on the running system, which may manipulate data, as
in the case of malware like rootkits.
o Direct acquisition methods (e.g., accessing RAM without the infected OS) can
provide more accurate data compared to relying on the compromised system.

We are dedicated to Innovative Knowledge 12


Ontologies for Mobile and Embedded Forensics…
• Data View - Volatility:
o Data volatility varies based on a storage medium, system necessity, and
allocation strategy.
o Data can persist for the system’s lifetime, remain active during operation, or be
cached temporarily.
o Discarded data may linger if memory reallocation is infrequent.
o Aggressive reallocation strategies can quickly overwrite discarded information.

• Method View – Layers of Abstraction:


o The method view categorizes data acquisition based on abstraction layers.
o Physical acquisition involves reading data directly from the storage medium.
o Logical acquisition accesses data through APIs on a running device, with
manual acquisition as another method.
o Intermediate levels include “pseudo-physical acquisition,” as defined by Coert
Klaver.

We are dedicated to Innovative Knowledge 13


Ontologies for Mobile and Embedded Forensics…
• Data View - Alterations:
o The method view examines how the chosen method alters the system, either
physically or logically, with a grading scale to classify these changes.
o “No alteration”: Nothing will be changed.
o “Minor, detectable alteration”: This includes detectable physical or
logical changes to the system, such as cleaning connections,
breaking seals, or creating log entries.
o “Alternations not affecting evidence data”: Adding or modifying
the system without altering traces, such as removing parts, adding
software, or changing running programs without affecting user
data.
o “Alternations affecting evidence data”: it makes changes such as
user data or traces are changed.
o “Destructive alterations”: this is where traces are destroyed. It should
generally be avoided, but it might happen.

We are dedicated to Innovative Knowledge 14


Ontologies for Mobile and Embedded Forensics…
• Data View - repeatability:
o Repeatability of acquisition methods refers to whether two acquisitions yield the same
results.
o Flash memory acquisitions of a running system will likely produce different results, while
logical acquisitions (like a contact list) can yield identical results even after system changes.
o A repeatable method doesn’t mean the data remains unchanged; higher-level acquisitions
may show identical data, while physical acquisitions will differ due to system alterations at a
lower abstraction level.
o In experimental science, repeatability means consistent results in the same setup, while
reproducibility means obtaining the same results independently in different setups.

• Method View – cost:


o The cost of a method in achieving a goal is not limited to monetary costs.
o Involves checking resources in the pre-acquisition, in-acquisition, and post-acquisition of
resources.
o Resources may involve time, capital resources, and human resources.
o Cost assessment at each stage is also critical.

We are dedicated to Innovative Knowledge 15


Ontologies for Mobile and Embedded Forensics…

• Risk and summary:


o When performing a forensic acquisition of a device, we seek
to optimize the probability of acquiring all relevant traces
that can be used as evidence.
o Each view is described in the radar chart below.
o Abstraction layer – close to raw data is given scores 1 and 5 for
the details.
o Logical and physical alterations – 1 as no alteration and 5 as
very destructive.
o Repeatability – 5 if results after two different acquisitions at d/t
times are identical and 2 for different results.
o Cost is a collective score: 1 for the least resource needed, and 5
is very resource-demanding.

We are dedicated to Innovative Knowledge 16


Ontologies for Mobile and Embedded Forensics…

• Comparison between chip-off and manual inspection

We are dedicated to Innovative Knowledge 17


Ontologies for Mobile and Embedded Forensics…

• Technical qualities:
o Other categorizations and models of mobile and embedded forensics are
introduced in the next sections.
o One taxonomy focuses on technical qualities, specifically small-scale digital
device forensics, as proposed by Harill and Mislan (2007).
o Small-scale digital devices are a subset of embedded systems with a form
factor smaller than ordinary computers.
o This model categorizes devices into four different categories to aid in
recognizing them at a crime scene.
▪ Flash devices
▪ Magnetic devices
▪ Optical devices
▪ PC extension devices
o The first 3 are based on the storage device technology used,
and the fourth is based on the functionality of the device.

We are dedicated to Innovative Knowledge 18


Ontologies for Mobile and Embedded Forensics…

• Tools used for acquisition:


o Another way to categorize mobile and embedded forensics
is based on the tools used for data acquisition.
▪ Manual extraction: read the device manually
▪ Logical extraction: send commands to the device and acquire the
data.
▪ Hex dumping /JTAG: use debug interfaces or other methods to read
raw data
▪ Chip-off: remove the flash storage and read it directly.
▪ Micro read: reading the content of the individual gates on the silicon
die itself

We are dedicated to Innovative Knowledge 19


Ontologies for Mobile and Embedded Forensics…

• Data Acquisition Methods:


o The methods can be as follows:
▪ Manual acquisition
▪ Logical acquisition
▪ Physical acquisition
1. Physical acquisition involves reading the content of the flash memory chip
directly.
2. Logical acquisition uses the API to synchronize the phone’s contents with a
PC.
3. Manual acquisition involves using the user interface to acquire data.

We are dedicated to Innovative Knowledge 20


Collection Phase
• The forensic process includes multiple phases including collection and
examination in mobile and embedded forensics.
• Acquisition methods can be logical (using standard interfaces) or
physical (bypassing device software controls).
• Acquisition methods vary based on the data type, technical resources,
and device-specific protocols, with some being destructive to the
device.
• Continuous research and understanding of method strengths and
weaknesses are essential to optimize data acquisition from embedded
devices. Hence, we will get the most valuable information in the
processes.
o The risks associated with the collection process step;
o To appraise different acquisition methods and assess their strengths
and weaknesses;
o The difference between physical, logical, and pseudo-physical
acquisitions; and
o The technology used in embedded devices.
We are dedicated to Innovative Knowledge 21
Collection Phase…
1. Special Considerations for Embedded Systems and
Mobile Devices:
o Functionality: reveals the device’s purpose, operation, and
potential data storage.
o Stored Data: What data does the device store? This ties to its
functionality, which can be inferred from its user interface and
expected capabilities, including both obvious and underlying
data required for its functions.
o Storage Media: Consider the storage type (volatile or
nonvolatile) and capacity to determine handling. Volatile
storage requires the device to stay powered, while storage size
hints at potential data volume.
o Security Measures: security risks when reading or acquiring
data from smartphones, encryption, temper-resistant
technology, and details of security implementations.
o Communication Ports and Protocols: Understanding the device’s
communication ports and protocols is crucial, as each offers
unique advantages and drawbacks for data acquisition,
requiring careful selection for forensic soundness.
We are dedicated to Innovative Knowledge 22
Collection Phase…
2. Handling Electronics - ESD: ESD is a discharge of electricity
between two electrically charged objects when the objects are
in close enough proximity for the charge to flow freely.
3. First Contact: Begin by understanding how the device functions,
what data it stores, and how to acquire it. Start the examination
by considering key questions.
o Are there any hazards with handling the device? Blood or other bodily
fluids?
o Are there any physical traces that should be preserved? (fingerprints,
Biological materials
o Is the device broken in any way, with scratches, broken interfaces, …
o State of the device? On, off, sleeping, or in another state? Is power
connected?
o If the device is on, what is on the screen? network? Lock screen?
o Is the internal clock on the device correct?
o Is there any information on the device that is valuable?
We are dedicated to Innovative Knowledge 23
Collection Phase…
4. Physical Acquisition: Physical acquisition of
embedded systems involves extracting raw data
from flash memory, akin to imaging a hard drive.
However, challenges arise as flash memory is often
soldered onto PCBs or inside SoC packages, and
systems tightly restrict data access, increasing the
risk of altering evidence. Two approaches:
a. Remove the memory and read the contents through
auxiliary hardware.
b. Acquire the whole system while the system is in.

We are dedicated to Innovative Knowledge 24


Collection Phase…
4.1. Chip-off/ in vitro Acquisition: it is about reading data
from flash memory without interference from OS and
firmware. Two main steps:
a. Remove the chip: get the IC chipped off the PCB and read on a
separate reader. It needs careful treatment of the chip as it may
lose the stored data in the process.
b. Acquire the whole system while the system is in.

• This method helps to get data from


the low layer of abstraction, and it
alters the physical device.
• It doesn’t affect the logical
information of the device and it gives
reproducible results.
• The cost is high, so it needs
investment.
We are dedicated to Innovative Knowledge 25
Collection Phase…
4.2. JTAG/In-System Acquisition: it is a Joint Test Action
Group standard that tests the device for its test for
functionality: The standard states three test levels.
a. IC level: IC testing and built-in self-tests
b. PCB level: board testing and production testing.
c. Module or system level: testing of higher-level systems.
• This method collects data at a higher
layer of abstraction than chip-off.
• It affects physical devices.
• It doesn’t affect the data much.
• It can be repeatable and cheaper
than chip-off.
• The cost is high, as it needs skills and
the post-acquisition cost is also high,
We are dedicated to Innovative Knowledge 26
Collection Phase…
5. Logical Acquisition of Data: it is about the logical
acquisition utilizing the device’s standard interfaces
and protocols while powered on.
a. Manual inspection: inspect for the logical extraction(ports,
touchscreen, view info on screen…)
b. SIM acquisition: it is an
embedded system with its own
microcontroller, RAM, and flash
storage. Collect the UICC
applications, ICCID, PIN, PUK,
and other information.
c. SIM Replacement: once,
collected, ensure that it will not
connect to the other network.
Make it on flight mode.
We are dedicated to Innovative Knowledge 27
Collection Phase…
5. Logical Acquisition of Data : it is about the logical acquisition
utilizing the device’s standard interfaces and protocols while
powered on.
d. Device Backup: inspect for the backup locations enabled on the phone.
Google, iCloud, and other backup locations. Encryptions used and
others.
e. USB Mass Storage: Check if SUB mass storage protocols are enabled.

Assessment of Deice backup method Assessment of USB Mass Storage method

We are dedicated to Innovative Knowledge 28


Collection Phase…
6. Somewhere b/n Physical and Logical: it is when we acquire
data from the device from one level below the file system and
above the Flash translation layer (FTL).
a. Root Access: get the root from the OS layer.
b. Boot Access: get access to the location from which the device boots.
c. Encryption keys: get the encryption keys used if the data are encrypted.
d. Flasher tools: if there are memory flushing tools ready to apply, apply flasher
tools and apply chip-off as before.

Assessment of the root method Assessment of the boot code method Assessment of the flasher box method

We are dedicated to Innovative Knowledge 29


Examination Phase
• Data interpretation involves two approaches:
o top-down, starting from the embedded OS perspective, rebuilding
structures like file systems or protocols, and
o bottom-up, prioritizing interesting data and interpreting it later.
• Carving focuses on identifying patterns matching known
structures, while keyword search finds specific known
information and analyzes its context.
• Cross-referencing interpreted data with external sources or
investigative hypotheses is crucial to verify accuracy.
• Errors in hypotheses, external sources, or assumptions often
arise and require correction during analysis. It helps us to
learn:
o How data is stored on the flash memory
o Flash translation layers and file systems
o Carving and keyword search.

We are dedicated to Innovative Knowledge 30


Examination Phase…
1. Top Down: Flash Translation Layer (FTL):
o Acquire data from a hard drive by removing it, using a
write blocker, and creating a bit-by-bit copy with an
integrity hash.
o Use programs to interpret the partition table and file
systems in the copied image to avoid altering the data.
o This method reveals deleted files and hidden data, like
those obscured by rootkits.
o Mobile phone memory involves a flash translation layer
between raw flash memory and the file system driver,
requiring an understanding of NAND flash memory.
• Erase blocks, pages,
and spare areas.

We are dedicated to Innovative Knowledge 31


Examination Phase…
2. Top Down: Flash File Systems:
o FTL advantage: Filesystems don’t need to know the flash memory
layout; some filesystems integrate FTL functionality.
o Examples of flash-specific filesystems include YAFFS, JFFS, JFFS2,
and UBIFS.
o SquashFS is a compressed filesystem for static data, useful for
reverse-engineering OS or applications but not for storing user
data or logs.
o Flash filesystems include wear-leveling algorithms and bad block
management, often storing management data in the OOB area.

File systems on top of FTL and a flash-


aware file system
We are dedicated to Innovative Knowledge 32
Examination Phase…
3. Carving:
o It is a method that looks for data that fits into known file
structures or other data structures and interprets the data in light
of these structures.
o To locate a file type, search for its known file header and ensure
the rest of the file follows.
o Storage type matters: Hard drives prioritize sequential access for
speed, while flash drives focus on maximizing lifespan without
latency for nonsequential access.
o Data size impacts fragmentation: Smaller records (e.g., SMS PDUs
under 200 bytes) are less likely to fragment, while larger files
(e.g., videos spanning many pages) have higher fragmentation
probability.
o Common structures in mobile/embedded devices include SMS
PDUs and SQLite databases.
We are dedicated to Innovative Knowledge 33
Examination Phase…
4. Bottom-Up: Keyword Search:
o Keyword Search: is a search for content that matches one or
more keywords, parts of keywords, or keyword patterns.
o Keyword searches help locate relevant data using names,
words, places, or dates but must balance avoiding false
positives and false negatives.
o Adjust keyword specificity to refine search results based on the
case context.
o Distinction: Keyword searches match known data while carving
identifies structures matching known patterns, including regex
searches.
o Packed data (e.g., Base64, ZIP) may require unpacking before
keyword searches; tools like Bulk Extractor can automate this but
face limitations like fragmentation and block size constraints.

We are dedicated to Innovative Knowledge 34


Examination Phase…
5. Technical Deep-Dive: FTL from Nokia 7610
Supernova:
o The Nokia 7610 Supernova (2008) used a proprietary
Intelligent System Architecture (ISA) OS with the Series 40
platform.
o Its flash memory is split into two partitions: one for static
data (e.g., bootloader) and another for dynamic data,
with each erase block being 131,072 bytes long.
o Erase blocks and pages include headers indicating their
status (in use, free, or deleted) and page indices for data
organization.
o By scanning, identifying used pages, and sorting indices, a
FAT partition can be reconstructed from the second
partition’s data.
o Its FTL layout differs from standard schemes, as the driver
controls the layout. See the details from the book.
We are dedicated to Innovative Knowledge 35
Examination Phase…
6. Technical Deep-Dive: Flash File System - YAFFS:
o YAFFS Overview: “Yet Another Flash File System” is a log-
structured file system designed for NAND flash, with YAFFS2
supporting larger devices. Data and metadata are sequentially
written, enabling recovery by scanning stored data without
additional structures like FATs.
o Object-Based Design: Each file system entity (file, directory, link,
etc.) is an object with a unique object ID. Allocation units
(chunks) span one or more flash memory pages.
o Sequential Writing: Chunks are sequentially written within blocks,
with a sequence number assigned to maintain chronological
order. Chunk data includes sequence number, object ID, chunk
ID, and ECC data.
o Metadata: The first chunk of a file (ChunkID 0) contains an object
header with metadata like type, timestamps, filename, and size.
Alignment of fields depends on implementation details.

We are dedicated to Innovative Knowledge 36


Examination Phase…
7. Technical Deep-Dive: Structure – SMS PDU:
o SMS Formats: SMS messages are often stored in raw format (SMS
PDU). Two main types are SMS-DELIVER (received messages) and
SMS-SUBMIT (sent messages). Other defined types include reports
and commands.
o Transmission Process: SMS messages pass through an SMSC,
which stores and attempts delivery for a predefined time before
discarding undelivered messages.
o PDU Details: Key fields in SMS PDUs include:
▪ TP-MTI: Specifies message type.
▪ TP-VPF: Indicates the size of the validity period field (TP-VP).
▪ Address Fields: Include address length, type, and value.
Length is in semi-octets (nibbles), with padding for odd
lengths.
o Timestamp and Clues: The TP-VP field in absolute format may
provide a timestamp; otherwise, relative timing is inferred. Testing
on similar devices is advised for accuracy.
We are dedicated to Innovative Knowledge 37
Examination Phase…
8. Technical Deep-Dive: Structure – SQLite3 Database:
o SQLite Use in Mobile Devices: SQLite3 databases are
common in Android devices for storing user and app data,
utilizing a documented format with well-defined data
structures.
o Database Structure: Databases consist of equally sized
pages (2ⁿ bytes), with optional rollback journals (”-journal”)
or write-ahead logs (”.WAL”) for handling changes. Both
files may contain valuable data.
o Header Information: The first 100 bytes of the header
include page size, change counters, database size
(optional), schema changes, and encoding (e.g., UTF-8).
o Data Storage: SQLite employs B-trees, where table B-trees
store data in leaf nodes and inner nodes only contain keys
for lookup, facilitating organized data storage and
retrieval.

We are dedicated to Innovative Knowledge 38


Examination Phase…
9. Technical Deep-Dive: Timestamps:
o Time Challenges in Digital Forensics: Device clocks are not
globally synchronized, and timestamp differences can
arise from independent adjustments and time settings.
o Time Zone and Region: Timestamps need to be associated
with the correct time zone (offset from UTC) and time
region, including daylight saving time (DST) details.
o Clock Comparison: Investigators should compare device
clocks with a precise reference clock to hypothesize the
actual time, especially if discrepancies arise during the
acquisition.
o Timestamp Formats: Several timestamp formats exist, with
common ones used in mobile devices and SQLite
databases. Java timestamps in SQLite, for example, are
stored as 6-byte big-endian numbers.
We are dedicated to Innovative Knowledge 39
Reverse Engineering and Analysis of
Applications
• Reverse Engineering: is a method for finding out how
something works, how it is assembled, or what its
functionality is.
• Many devices store data used by applications, which
commercial products often cannot interpret.
• In such cases, forensic analysis involves reverse-
engineering the data to understand its structure.
• Reverse-engineering tasks often align with the questions
asked during forensic investigations.
• The section provides an introduction to reverse
engineering but does not cover all aspects of the field.
o Methods used for reverse engineering and
o A few targets of reverse engineering.

We are dedicated to Innovative Knowledge 40


Reverse Engineering and Analysis of
Applications…
1. Methods: Reverse engineering of digital information is typically
divided into three methods—black box testing, static code
analysis, and runtime analysis
1. Black Box Testing:
▪ Testing with Known Data: Using an identical test device, investigators
can replicate actions (e.g., calling numbers, and sending texts) and
compare the acquired data with known information to interpret data
structures.
▪ Alternative Comparison: If no test device is available, data from the
seized device can be compared with known data from other sources
like phone service provider traffic or GPS locations.
▪ Limitations: This method requires assumptions about data storage and
may not reveal all information. Flags or protocol values might be
misinterpreted.
▪ Fuzzing: A black-box testing method where random data is fed into
application buffers to provoke unexpected states, which may expose
bugs or exploitable vulnerabilities.

We are dedicated to Innovative Knowledge 41


Reverse Engineering and Analysis of
Applications…
1. Methods: Reverse engineering of digital information is typically divided into three methods—black box
testing, static code analysis, and runtime analysis
2. Static Code Analysis:

▪ It involves analyzing binary machine code or source code without executing it, using
techniques like disassembling, decompiling, and reviewing source code.

▪ Disassembling: Translates machine code into human-readable assembly code, making it


understandable to humans.

▪ Decompiling: Reconstructs machine code into higher-level programming language patterns,


similar to reverse compilation, though not identical to the original source code.

▪ Source Code Review: Involves examining the source code itself for comments, function
purposes, programming errors, and data structures.
3. Runtime Analysis:
▪ It involves analyzing a program while it’s executing, typically using a debugger or emulator.

▪ Debugger Use: A debugger helps find errors (bugs) in code, map functionality, and
weaknesses, and inspect the program state by setting breakpoints.

▪ Breakpoints: Can be set at specific instructions, memory addresses, or conditions to pause


execution and step through the program.

▪ Other Analysis Methods: Includes tracking changes made by the program, such as files it
touches, resources it accesses, and network activity.

We are dedicated to Innovative Knowledge 42


Reverse Engineering and Analysis of
Applications…
2. Targets: We can categorize the targets of reverse
engineering to help understand the data
available in a forensic investigation, though this
list is not exhaustive.
1. Program Functionality: find out what the program
does, what data it handles, and how it communicates
with other programs or networks.
2. Data Structure: interpretation of the data found.
3. Protocols: what standards the program uses for
communication
4. Encryption: how strong the encryption algorithm is, the
key handling routines, and how to access encrypted
data.
We are dedicated to Innovative Knowledge 43
Summary
• Importance of Evidence Integrity and Chain of Custody: Ensuring
evidence integrity and chain of custody is crucial in mobile and
embedded forensics to maintain the reliability and authenticity of
evidence.
• Challenges in Collection and Examination: Mobile and embedded
devices often have specialized, proprietary interfaces and limited
functionality, requiring customized methods for assessment.
• Device Assessment: Investigators must evaluate devices for
functionality, stored data, storage media, security measures, and
communication protocols to identify relevant evidence.
• Handling Unknown Devices: Caution is needed when handling
unknown devices due to potential health hazards, electrostatic risks,
and the need to preserve physical evidence like fingerprints and DNA.

We are dedicated to Innovative Knowledge 44


Summary…
• Record details such as power state, physical appearance, user
interface data, and clock settings before working on a device.
• Categorizing Forensic Methods: Methods are categorized by two views:
the data view (attributes like abstraction, trust, volatility) and the
method view (factors like abstraction, alterations, repeatability, and
cost).
• Data Acquisition Methods: Includes logical acquisition (using user
interfaces and APIs), physical acquisition (imaging raw data), and
pseudo-physical acquisition (interpreted data layers).
• Data Examination: Post-acquisition, data examination involves
interpreting how data is stored and its meaning, often requiring
assumptions and educated guesses. Flash memory uses wear leveling
to manage writing across memory, and specific filesystems may include
flash management functions.
• Reverse Engineering: This involves discovering unknown system details
through methods like black-box testing, static analysis, and runtime
analysis.

We are dedicated to Innovative Knowledge 45


Excercises
Answer the following questions. The questions don’t necessarily have one
correct answer as they may be based on different assumptions.
1. Which OSs exist for mobile and embedded systems?

2. What should we consider before picking up an electronic device at the


scene of a crime?

3. What is managed flash?

4. A text message has been received on an encrypted mobile phone. From


the system view, in which layers of abstraction does the message exist,
and where is it readable? What can we say about the trust we have to
place in the system for each case? What about the volatility of the data?

5. A non-technical police officer calls in from the scene of the crime during a
search. The search team has found several phones; one is on, and they want
to know how to handle these. What are your recommendations? How will
your assumptions affect your advice, and can new information from the
search team change or improve your advice?
We are dedicated to Innovative Knowledge 46
Excercises…
6. In a drug case, you suspect there has been communication between two suspected
ringleaders, as both know about the delivery and pickup. The lawful interception has
not seen any direct communication between these suspects: no SMS, calls, or direct
data streams. You suspect they have used their smartphones to communicate. What do
you think you can find on their phones? How would you start looking for their
communication? Anything you can do before the suspects are brought in? How would
you acquire the data from the phones? And how would you search for traces?

7. The handling of evidence is an important consideration. The crime scene investigator


has found a phone on the scene of the crime and suspects that there is crucial
evidence in the phone. The phone seems to have some droplets inside the cracked
screen. He hands you the phone and says that due to the importance of the digital
evidence, you should acquire the data first, and then the other forensic experts will look
for fingerprints and biological traces after you are finished. How should you handle the
device? What should you do in order to minimize the health hazards? And how to
minimize the impact you leave on the other traces?

8. Continuing the case in question 4: you know you can read the eMMC contents with
JTAG for this phone. What is the best way to handle the digital evidence from the
acquisition in order to ensure the evidence integrity and the chain of custody for the
acquired data? How should the checksums be computed, and how should they be
stored? What about the storage solution?

We are dedicated to Innovative Knowledge 47


Excercises…
9. What is a flash translation layer, why does NAND memory often include this, and
which type of information does the FTL need to work? Why isn’t an FTL always
needed in addition to a file system for storing data on flash memory?

10. Compare two or more of the acquisition methods in light of the acquisition
method ontology described in the lecture. What are the differences between the
methods, and which type of data matches the methods?

11. What Is the difference between rooting a device to acquire the flash memory and
acquiring the flash memory with a bootloader? Discuss: which method is best to
use if the device has storage encryption enabled, and which method is best for
evidence in RAM? Which method would you prefer if you suspect that malware is
running on the device?

12. During an ordinary day, in which mobile or embedded systems do you think you
leave traces? How can this information be collected? Can this information be
used to strengthen or weaken an alibi? What else can this information tell?

We are dedicated to Innovative Knowledge 48


.
Thank you very much!

We are dedicated to Innovative Knowledge 49

You might also like