Android Forensics
Presented by
[Link]
Assistant Professor
Department of Computer Science & Engineering
SETHU INSTITUTE OF TECHNOLOGY
Reference Book: Chuck Easttom, “An In-depth Guide to Mobile Device Forensics”, First
Edition, CRC Press, 2022.
Department of CSE, SIT 3/8/2020
Android Forensics
Items you should attempt to recover from a mobile
device include the following:
• Call history
• Emails, texts, and/or other messages
• Photos and videos
• Phone information
• Global positioning system (GPS) information
• Network information
Department of CSE, SIT
Android Forensics
One group that is at the forefront of digital forensics procedures
is the Scientific Working Group on Digital Evidence
([Link]
SWGDE provides guidance on many digital forensics topics.
Related to mobile device forensics, SWGDE provides a general
overview of the types of phone forensic investigations:
Mobile Forensics Pyramid – The level of extraction and analysis
required depends on the request and the specifics of the
investigation. Higher levels require a more comprehensive
examination, additional skills and may not be applicable or
possible for every phone or situation.
Each level of the Mobile Forensics Pyramid has its own
corresponding skill set.
Department of CSE, SIT
Android Forensics
The levels are
1. Manual – A process that involves the manual operation of
the keypad and handset. display to document data present in
the phone’s internal memory.
2. Logical – A process that extracts a portion of the file
system.
3. File System – A process that provides access to the file
system.
4. Physical (Non-Invasive) – A process that provides
physical acquisition of a phone’s data without requiring
opening the case of the phone.
Department of CSE, SIT
Android Forensics
5. Physical (Invasive) – A process that provides physical
acquisition of a phone’s data requiring disassembly of
the phone providing access to the circuit board (e.g.,
JTAG).
6. Chip-Off – A process that involves the removal and
reading of a memory chip to conduct analysis.
7. MicroRead – A process that involves the use of a
high-power microscope to provide a physical view of
memory cells.
Department of CSE, SIT
Forensic Procedures
It is also important to have the appropriate tools for the
examination. The United States National Institute of
Standards (NIST) provides guidance on this issue.
The NIST-sponsored CFTT – Computer Forensics Tool
Testing Program ([Link] provides a
measure of assurance that the tools used in the
investigations of computer-related crimes produce valid
results.
Testing includes a set of core requirements as well as
optional requirements. It is a good idea to refer to these
standards when selecting a tool.
Department of CSE, SIT
Forensic Procedures
NIST also provides general guidelines on how to write a
report for a mobile device forensic report.
The guidelines are of what to include are:
• Descriptive list of items submitted for examination,
including serial number, make, and model.
• Identity and signature of the examiner.
• The equipment and setup used in the examination.
• Brief description of steps taken during examination,
such as string searches, graphics image searches, and
recovering erased files.
Department of CSE, SIT
Forensic Procedures
• Supporting materials, such as printouts of particular
items of evidence, digital copies of evidence, and chain of
custody documentation.
Details of findings:
• Specific files related to the request.
• Other files, including deleted files, that support the
findings.
• String searches, keyword searches, and text string
searches.
• Internet-related evidence, such as website traffic
analysis, chat logs, cache files, email, and news group
activity.
Department of CSE, SIT
Forensic Procedures
• Graphic image analysis.
•Indicators of ownership, which could include program
registration data.
• Data analysis.
• Description of relevant programs on the examined items.
• Techniques used to hide or mask data, such as
encryption, steganography, hidden attributes, hidden
partitions, and file name anomalies.
Report conclusions
Department of CSE, SIT
Department of CSE, SIT 6/8/2020
3/8/2020
Department of CSE, SIT 6/8/2020
3/8/2020