Chapter 4: Smartphone Forensics
The most important consumer invention of twenty-first century is no doubt mobile phones. Since
then, it has become an indispensable part of our lives. Almost 8.6 billion mobile subscriptions
worldwide are estimated in the year of 2019 as compared to the less than 1 billion mobile
subscriptions in year 2000 [1]. As a result, smart phones are now a vast repository that contains
the most sensitive and private data of the user. This fact has given rise to the need of the smart
phone forensics to retrieve the user data from a mobile phone. This chapter will help us
understand the need of smartphone forensics, the challenges an examiner face during the
forensics process and forensics methods for the data extraction and data analysis for different
smartphone operating systems (OS).
1.1. Smartphone Forensics: Overview
Smartphone forensics is a branch of digital forensics which deals with the retrieval of the digital
evidence from mobile phones. The data acquisition process is critical in case of mobile phones.
Examiner can adopt different acquisition methods according to their requirement. Some forensic
tools require a communication vector for evidence collection, other collection techniques may
involve installing a bootloader prior to the extraction step.
A general forensic framework for mobile phones has mainly four phases: confiscation/seizure,
data acquisition, data analysis and reporting as shown in figure 4.1. Besides the data acquisition
and data analysis, confiscation is also a technical step that require proper handling of the mobile
phone. The mobile phones are mostly confiscated in faraday’s bags. These bags are of great
importance because they do not let the radio or electromagnetic waves to come inside hence
isolating the mobile phone from any service network [2]. For example, if the mobile phone
Figure 4.1: Forensic Framework for Smartphone Forensics
confiscated is in powered ON state, that means the criminal can easily send wipe command via
some Bluetooth connection, Wi-Fi access point or Telecommunication Network to erase the
important information. Faraday bag can in that case help to retain the important information.
Mobile phones usually show a dynamic behavior hence making it difficult for the forensic
examiners to acquire user data and perform articulative analysis on it. Different manufacturers
are there for mobile phones with different platforms. Hence making it difficult to have a single
framework for every mobile phone either it be a windows phone, an android phone, an iPhone or
a blueberry phone. There are a lot of other challenges too that an examiner face during the course
of forensic analysis of the mobile phone.
1.1.1. Challenges to smartphone Forensics process
Sometimes mobile forensics is taken as a part of a computer forensics, but due to the dynamic
behavior of the mobile phones the forensic process poses unique challenges to the examiner [3].
With different OS, and accessible nature of mobile phones make the acquisition and preservation
stage harder. Following are some challenges that examiner face during the smartphone forensic
process.
Hardware Differences:
The fact that the mobile phones have different types of the hardware is the most common
challenge to any examiner who is performing the digital forensics on a mobile phone. The
hardware of the mobile phone is important to be considered especially when it comes to preserve
the eMMC memory chip and microSD card.
The market is full with plethora of variants of the smartphones and their versions. Since the
introduction of iPhone, till date more than two dozen variant of it are in the market with different
versions. This is the data for only iPhone, for others like windows phones, android phones etc
have more severe data. With different manufacturing, it becomes difficult for the examiner to
perform the forensic process. For example, with such a huge number of mobile phones in the
market, it is really difficult to identify the actual manufacturer, version and model of the phone
by just looking at it. One way is to remove the battery and get this information but this can harm
the volatile data.
Mobile Operating System
An OS is the software part of the mobile device. As per the rules of the file system of the
particular OS, the examiner can retrieve the user data accordingly. Just like different mobile
hardware, correspondingly there are different OS working on mobile phones. The most common
are Google android, Apple iOS, SymbianOS, BlackberryOS and Windows Mobile.
Even sometimes, criminals use feature phone. Feature phones are special phones designed for the
customers having exclusive software and user interface. So, it becomes harder for a forensic
investigator to handle such phones for data extraction and preservation.
Mobile platform security
With the advancement in technology, the security of the user data has become a central debate
among the technology experts. The mobile phone users too are concerned about the security of
their data. Therefore, the manufacturers are adding strong security features to the smartphones to
protect the user data and the privacy. Although these security features are a good add-on for the
mobile phone users but these features are also creating difficulties for the forensic investigators
during the forensic process especially during the acquisition phase. For example, the new mobile
phones in the market have this feature of encryption. The investigator therefore needs to decrypt
the user data to extract it from the mobile device [4].
Similarly, Application developers for mobile phones are more concerned about providing
privacy features to the user because of its high demand among the users. For example, “Secret
Chat” option of Telegram is been exploited by many criminals. Unlike any other messaging app,
this do not let cloud involvement in its operation and the data can only be accessed on the device
on which the app is installed and used.
Dynamic nature of evidence
Mobile phones have dynamic nature. The user data can be altered or moved intentionally or
unintentionally. For example, WhatsApp can be accessed using many devices and hence the data
can be altered, erased or moved using the access feature of the app.
Mobile phones some times also work in OFF state in background. For example, many
smartphones have this feature that alarm can work even in the OFF state. There is one another
challenge that digital forensic investigator face. When the state of mobile phone is changed, it is
a high chance that it can lose or modify some of its data.
Lack of resources
As discussed above that there are a lot of different manufacturers and variants of mobile phones.
Each have different hardware, OS, filesystem formats and other features. A single tool might not
be enough to perform forensic analysis on all of them. So, there must be multiple tools available
at the time of data acquisition and analysis. However, choosing the right tool is a very
challenging task. This applies not only to the software tools but also to the hardware ones like
cables etc. For example, some of the mobile require C-cables, some require micro-USB type-B
cables, some require iOS pin8 etc.
Legal issues
There is no doubt that the telecommunication system has made this world a small village. The
criminal activities are also spread across the borders due to the extended communication system.
Forensic examiners might face many multijurisdictional issues related to the mobile phone
seizure, data acquisition etc.
1.1.1. Evidence extraction process
The most technical job of any forensic process is the evidence extraction. For smartphone
forensics, there cannot be a single method for extraction due to different designs and features of
the mobile phones. Hence till date there is not a single standard framework for mobile forensics
especially the extraction procedure.
Detective Murphy has designed a general process of evidence extraction [6]. The performed the
extraction in nine steps. Following are those steps that can help to extract evidence from any type
of phone irrespective of their manufacturer or version.
1. Intake
The first step is the intake of the evidence. The documentation and paperwork are done in
this phase. Seizure of mobile phone must be performed with great care to avoid any data
alteration and removal. If the Mobile phone is turned ON, first try to break the passcode and
then disconnect the mobile phone for all the telecommunication services, Bluetooth, Wi-Fi
connection, infrared etc. after that place the mobile phone in a bag that can guard against any
radio or electromagnetic waves, for example, faraday’s bag.
2. Identification
The identification stage is to study the broad features about the mobile phones. This includes
the legal authority, the purpose of forensic examination, the model and make of the
smartphone, any external or removable storage or any other potential evidence.
a. Legal Authority: The forensic investigators must take into account the legal
jurisdiction on the mobile phone. For example, one of the legal procedures for mobile
seizure is providing warrant for it.
b. Forensic Examination Aim: The aim of the forensic examination must be documented
properly. It can help the investigator to know how much in-depth analysis is required and
what tools can help to perform the analysis. For example, if the aim is to only watch the
network data, then, Wireshark or Nmap can do the favor while if the memory analysis is
the purpose, then we need Sleuth Kit Autopsy tool.
c. The type of Smartphone: The make and model of smartphone is also very important to
perform the forensic analysis. For example, for iPhone, lightening pin8 has different sizes
for different models. Similarly, some androids support micro-USB type-B cable while
other support C-cables. Therefore, model name and manufacturer must be known.
d. Identification of external or removable storage: Some mobile phones have this feature to
extend the memory by inserting an external memory card like an SD card in the mobile
phone. In such cases, the card must be acquired and subject to traditional forensic
analysis.
e. Other potential evidences: The investigator must also think about any biological or
fingerprint evidences before the seizure of the mobile phone because otherwise these
evidences can get contaminated and hence result in a loss of important information.
3. Preparation
After the identification, a thorough research must be done about the identified make and
model of the mobile phone and decide tools and methods that can help in the Data acquisition
and Data analysis.
4. Isolation
The isolation of the mobile phone to be examined is very import. Mobile phones are
connected to the network Wi-Fi, telecommunication services, infrared connections, Bluetooth
etc that can alter the original data by adding messages, calls etc or can remove the data by
sending remote wipe commands. So, the in the first place, place mobile phone in an airplane
mode. But this step has some concerns. If the phone is pin or pattern locked, the phone first
needs to be unlocked which is yet another process. Also, some phones do support Wi-Fi
connections even on the airplane mode. Therefore, the best option is to place the mobile
phone in some bag that can stop it from connecting to any radio waves.
5. Processing
After securely seizing the device, the next step is to perform acquisition process. The most
feasible process is physical acquisition to extract the raw data. The physical acquisition can
be done in OFF state. Other acquisitions methods are logical acquisition, filesystem
acquisition etc that can be used if the physical acquisition fails to provide the required output.
6. Verification
The investigator then needs to verify the integrity of the extracted data. For the purpose the
data can be compared to the data of the mobile set by calculating the hash values for both of
them.
7. Documentation
The next step is to create a report of whole evidence extraction process. The report must
include, the method, the aim of evidence extraction, the mobile makes and build, state of the
phone, acquisition tools utilized etc.
8. Presentation
The findings during the forensic phase must be documented in a way that the results are
clear, concise, and the process can be repeatable.
9. Archiving
The last step for evidence extraction is the preservation of archiving state. It must be
preserved in a way that data remain intact through out the court proceedings and can be used
for the future references.
1.1.1. Practical Smartphone Forensics approaches
Smartphone forensics is a technical procedure as compared to the other types of digital forensics
due to vast variety of phones available in the market. Generally, the approaches used for the
smartphone forensics irrespective of their make and model are following
Computer Forensics Investigative Model (CFIM)
The model is a traditional forensic model that can also help as a base procedure for mobile
forensics [7]. This model has four main steps
1. Acquisition:
2. Identification
3. Evaluation
4. Admission
Investigative process for Digital Forensics Science
As compared to the CFIM, Investigative process for Digital Forensics Science is a detailed
process. The forensic framework is mainly for the computer forensics but it works well with
mobile forensics too. Following are the steps for this framework.
1. Identification
2. Collection
3. Preservation
4. Examination
5. Analysis
6. Presentation
1.2. Smartphone components
The smartphones have a lot of components that are of interest for the forensic investigators.
These components can contain imperative information regarding the crime. For example, SD
card or SIM card etc.
Embedded Multi-Media Card (eMMC)
The eMMC is kind of an external storage device. It provides extended storage from 1GB to 512
GBs. It stores non-volatile data. The forensic analysis of these chips can provide useful
information related to the crime.
Secure Digital (SD) card
Similar to eMMC chips, the SD cards are used to extend the memory of the mobile device. Its
performance is comparable with the eMMC. SD cards can easily be removed and can be inserted
to another phone to extract the data. The problem arises when it is secured with some password.
In that case there is a need to break the security of SD card first.
Subscriber Identity Module (SIM)
SIM card is a basic component of cellular phones and bear a lot of information about the
telecommunication service, network, user identity etc [8]. Besides this SIM cards also have a
small memory associated with it that is used to store the contact information of people. The file
system of SIM consists of three different formats. The first one is master file that is considered as
a root of the filesystem. Second is dedicated files that work as a directory to master files. The last
one is elementary file that contains data in structured form.
The SIM card contains sensitive information like service-related information, phonebook and
call information and messaging information that is stored in elementary files and has forensic
value. Some of that information is listed below
International mobile subscriber identity (IMSI)
Service provider name (SPN)
Mobile subscriber identification number (MSIN)
Mobile station international subscriber directory number (MSISDN)
Mobile country code (MCC)
Mobile network code (MNC)
Last dialed numbers (LDN)
Local area identity (LAI)
Temporary mobile subscriber identity (TMSI)
Memory Chip
Another component of the smartphone that can be used for the forensic analysis is the main
memory chip. Although this procedure is a difficult and expensive process and needs a lot of
care and experience. The memory chip is detached from the device by de-soldering it. Even a
small mistake at this point can lead to damage of the memory. Raw data recovered using this
method needs to be parsed and interpreted. Another problem with this method is that, mobile
phones have different types of memory chips that vary in size, circuit etc. so it is difficult to have
a same kind of memory card reader available at the time of forensics.
1.1. Types of Smartphones and forensic process
Earlier in this chapter, we have seen that smartphones are of many types with completely
different hardware and software. With difference in components and features, same framework
can be used for forensic purpose but each steps need special treatment for different smartphone
type especially evidence extraction and data analysis. In this section, these forensic steps are
discussed in detail to for different types of smartphones are discussed.
1.1.1. Android Forensics
The most common type of mobile phone for today’s user is an android phone. The data
acquisition techniques can be of three types for android phones. Following are those three
acquisition types.
Manual Data Acquisition
The manual data acquisition is when the investigator accesses the mobile device manually using
the user interface. As result access to the call log, SMS log, app data images documents etc. the
only drawback is that this method do not let to access data that is inaccessible by the OS or in
user interface mode. This method must be the last option when forensic process is carried out
because only a little information can be collected through it.
Logical Data Acquisition
In this method of data acquisition, the data can be acquired via interaction with the OS or
accessing the filesystem of the device. Although root access is not necessary but it can help to
acquire the maximum of information otherwise which is not possible. The logical data
acquisition does not acquire the deleted data.
Physical Data Acquisition
This is the most beneficial process for the data acquisition. Investigator can acquire all the
information, bit by bit from the hard drive, even the deleted files. The only drawback is that it
takes much longer time as compared to the logical extraction.
Acquisition can also be done by de-mounting the memory chip, which is known as chip-off
method but this technique is a very difficult way to acquire data without any damage.
FTK imager is the most common acquisition tool used for the Android Phone forensics. For
analysis just like iOS device, Sleuth kit autopsy is the best option available.
1.1.2. iOS Device forensics
The first step of the forensic procedure is to acquire the data from the device. The data
acquisition can be done at logical, physical and file system level. The acquisition process will be
discussed in detail in the later in the chapter. For iOS devices, it is better to perform physical
acquisition first because it can recover bit by bit data from the device and hence can recover
maximum data. For jailbroken devices, the device is connected to a mac book for live analysis
using the secure shell (SSH). Similarly, iTunes, and iCloud are also a great source of data in case
of iPhones. Elcomsoft Phone Breaker can be used to extract data from the cloud.
Forensic tools can help the investigator to perform the acquisition and analysis of the data more
promptly. There are many commercial and open-source tools available in the market that can
help to perform data acquisition and data analysis easily. Following are some acquisition tools
that can help in iOS device forensics.
1. Oxygen Forensic Detective
It is an all-in-one forensic platform. It can do both acquisition and analysis of the user data. It
supports logical acquisition, physical acquisition and file system extraction. The tool is not
an open source and falls under a commercial toolkit.
2. Cellebrite UFED Physical Analyzer
This tool is a commercial tool with a free trial of 30 days. The tool is best for advanced
logical acquisition for filesystem and physical acquisition. The tool is also useful to create
reports in different formats like. xlxs, .pdf etc
3. Blacklight
Blacklight is also a commercial tool with 30 days free trial. The tool is best to parse different
acquisition files of iOS devices and their backups.
4. Magnet ACQUIRE
Magnet ACQUIRE is a free tool for iOS and android device acquisition. The tool is fast way
to acquire data images from the smartphones.
5. Elcomsoft iOS Forensic Toolkit (EIFT)
This toolkit is a complete package for the iOS devices. The tool can acquire data as well as
analyse it. EIFT is good with devices not more than 32 bits. With iPhones having 64 bit
(iPhone 6 and more advanced versions) needs jailbreaking first to acquire data.
Data analysis is relatively an easier task if the data is been acquired properly. Many tools are
available that can help to examine the data. The most common is Sleuth Kit Autopsy that can
analyse the memory. NMAP is another important tool to analyse the network associated with the
iOS device.
1.1.3. Windows Phones
The data acquisition in the case of Windows phone is a challenging task because these phones
are more secure and the forensic tools that are available commercially and free do not provide
easy solution for it. Chip-off method is some times used for the windows phone, but as discussed
in section 4.2 that removing the memory chip is quite a challenging task and need much care and
expertise. Therefore, the biggest challenge for windows phone is acquiring the data. Some useful
tools for the data acquisition of the windows phone are as follow:
1. Cellebrite UFED
2. Oxygen Forensic Detective
3. FTK Imager
The first two tools are commercially available and to use them the phone must be in a root state
or a jailbroken state. FTK imager is an open-source tool to acquire the data but still this can be
done only when the device is in root state. One other way to acquire data is from third part
applications. Third party applications are installed on the windows phones and artifacts can be
collected from them.
1.1.4. Blackberry
Blackberry not releasing its new versions regularly now but still people use it and is the favorite
among the criminals. Blackberry is more an email purpose phone and was designed by keeping
in mind the business personalities. There are not so many tools available for the forensic process
of the blackberry. Yet some of them are following.
1. MSAB-XRY
The tool is a data retrieval program use for mobile phones to recover the information. This
tool is commercially available.
2. MOBIL edit
This is a tool used for mobile content management, data recovery and data investigation.
3. Oxygen
This is also a commercially available tool and is used to do both the jobs that is data
acquisition and data analysis.
1.2. Forensic Acquisition Concepts of Smartphones
By far we have reached to this point that the most challenging task is to acquire data in case of
the mobile forensics. There are many different ways other than logical and physical acquisition
available for the purpose. In this section, forensic acquisition concepts will be discussed in detail.
1.2.1. Logical Acquisition
As the name suggests, logical acquisition is the data acquisition from the logical storage. It
includes files and directories that reside on the filesystem. It is quick way to acquire data. The
drawback is that this cannot capture the deleted files. There are many forensic tools available for
the logical acquisition.
1.2.2. File System Acquisition
This type of data acquisition is also known as advanced logical acquisition. The investigator gets
access to the filesystem and hence can acquire more data as compared to the logical acquisition.
This process is helpful mostly in iOS devices where the device is not a jailbroken. The only
difference from the physical acquisition is that it let the investigator to acquire the data from the
user data partition and do let him to access the system data. Cellebrite UFED is a common tool
that can help perform file system acquisition.
1.2.3. Physical Acquisition
Physical acquisition of the data is the best data acquisition technique but it takes lots of time. It
creates a bit-by-bit clone of the hard drive. One thing must keep in the mind, this type of data
acquisition is not the copy pasting technique because coping the hard drive mean only coping
those data resources that are available by the OS. But the physical acquisition, even acquire the
deleted data files. There two types of physical acquisition
1. Hardware-Based Physical Acquisition
In this type hardware components are removed from the device for example, in chip off
method memory chip is removed to acquire data. This method does not require root access.
2. Software Based Physical Acquisition
The software acquisition does not cause any harm to the memory but require root privilege.
Tools like Smart Phone Forensic System Professional (SPF Pro) can be used to acquire the
data.
1.2.4. Advanced Acquisition Methods and Techniques
There are many methods other than the traditional acquisition techniques that can be used in
mobile forensics to acquire data. Following are some of them.
1. JTAG (Joint Test Action Group).
The technique requires to connect to the Standard test access points (TAPs) on device and
instruct the device to transfer the memory to an integrated chip (IC).
2. In System Programming (ISP)
The process involves the in destructive removal of the memory chip from the device.
3. Thermal kinetic Chip-OFF
The technique requires to de-solder the memory chip by applying heat. In this process data
might get lost. So require a lot of care.
References:
[1] “Mobile subscriptions worldwide 1993-2021,” Statista. [Online]. Available:
[Link]
%20total%20number%20of%20mobile
[2] A. Lennox-Steele and A. Nisbet, “A forensic examination of several mobile device
Faraday bags & materials to test their effectiveness,” pp. 34–41, 2016, doi:
10.4225/75/58a550b153635.
[3] V. L. L. Thing, K.-Y. Ng, and E.-C. Chang, “Live memory forensics of mobile phones,”
Digital Investigation, vol. 7, pp. S74–S82, Aug. 2010, doi: 10.1016/[Link].2010.05.010.
[4] A. Fukami, R. Stoykova, and Z. Geradts, “A new model for forensic data extraction from
encrypted mobile devices,” Forensic Science International: Digital Investigation, vol. 38, p.
301169, Sep. 2021, doi: 10.1016/[Link].2021.301169.
[5] H. Mahalik, R. Tamma, and S. Bommisetty, Practical Mobile Forensics, Second. UK:
Packt Publising Ltd, 2016.
[6] C. A. Murphy, “Developing Process for Mobile Device Forensics.” [Online]. Available:
[Link]
[7] Y. Yusoff, R. Ismail, and Z. Hassan, “Common Phases of Computer Forensics
Investigation Models,” International Journal of Computer Science and Information Technology,
vol. 3, no. 3, pp. 17–31, Jun. 2011, doi: 10.5121/ijcsit.2011.3302.
[8] N. Ibrahim, N. A. Naqbi, F. Iqbal, and O. Alfandi, “SIM Card Forensics: Digital
Evidence,” Annual ADFSL conference on Digital Forensic security and Law, 2016.