首页> 外文OA文献 >Mobile phone: identifying configuration signatures of local devices absent from XRY
【2h】

Mobile phone: identifying configuration signatures of local devices absent from XRY

机译:移动电话:识别XRY中缺少的本地设备的配置签名

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Technology is rapidly expanding in to every part of daily life as evidenced by the increase in the number of new mobile phone devices appearing on the market while older models remain in use and are reused. The rapid emergence of different and new mobile devices presents challenges for mobile phone forensic investigation. Some models cannot be supported by mobile forensic tools and others have ways of preventing access. XRY is one of the best known mobile forensic tools and it is constantly updating signatures and producing new connectors to keep up with the market. However, the speed of new mobile devices’ release and the emergence of new designs will always result some being overlooked.The purpose of this research project is to conduct an investigation to identify some models on the New Zealand market that are not currently supported by XRY and to perform forensic extraction on one or two as well as a supported model. The research is to identify configuration signatures or characteristics of local mobile phone devices that are absent from the XRY database. The result was that four local mobile phone devices (test phones) that are sold and operate in New Zealand were located. Some of these models were manufactured specifically for local Network Service Providers. They were tested following a methodology derived from previous research literature including the use of practise standards and procedures for digital forensics.The research findings determine the capability of XRY 6.5 to extract data from these local mobile phone devices. As a result, two of these test devices (Phones 2 and 4) were not officially recognised by XRY and were absent from its database. Phones 1 and 3 were in the database. XRY was able to extract data from each test phone device (logical extraction) however not all the data was extracted. Thus, some of the test devices already recognised by the tool were not fully supported. XRY was able to extract most of the data from some test devices while others had incomplete data. Most of the deleted test data was not able to be recovered. A discussion of the findings indicates that local mobile phone devices can be supported by forensic tools such as XRY; however there are limitations due to each tool’s performance criteria. These local mobile phone devices can be included in the XRY’s list of supported device profiles and this research provides implications for digital forensic analysts about how these test phones can be recognised and supported. There are also further possible aspects for future work within this research area that can focus on improving the capability of forensic tools to conduct physical analyses for these local test phones.
机译:技术正在迅速扩展到日常生活的各个方面,这可以从市场上出现的新移动电话设备数量的增加中看出,而旧型号仍在使用和重复使用。不同和新的移动设备的迅速出现为手机法医调查提出了挑战。某些模型无法通过移动取证工具支持,而其他模型则具有阻止访问的方法。 XRY是最著名的移动取证工具之一,它不断更新签名并生产新的连接器以跟上市场。但是,新移动设备的发布速度和新设计的出现总是会被人们忽略。该研究项目的目的是进行调查,以找出新西兰市场上目前尚不支持XRY的某些型号并在一个或两个以及支持的模型上进行取证。该研究旨在确定XRY数据库中缺少的本地移动电话设备的配置签名或特征。结果,找到了在新西兰出售和运行的四个本地移动电话设备(测试电话)。其中一些模型是专门为本地网络服务提供商制造的。他们根据以前的研究文献中的方法进行了测试,包括使用实践标准和数字取证程序。研究结果确定了XRY 6.5从这些本地移动电话设备提取数据的能力。结果,这些测试设备中的两个(电话2和4)未被XRY正式认可,并且不在其数据库中。电话1和3在数据库中。 XRY能够从每个测试电话设备中提取数据(逻辑提取),但是并非所有数据都被提取。因此,该工具已识别的某些测试设备未得到完全支持。 XRY能够从某些测试设备中提取大多数数据,而其他一些则不完整。大多数删除的测试数据无法恢复。对调查结果的讨论表明,本地移动电话设备可以得到XRY等取证工具的支持。但是,由于每种工具的性能标准而有所限制。这些本地移动电话设备可以包含在XRY的受支持设备配置文件列表中,这项研究为数字法证分析师提供了有关如何识别和支持这些测试电话的启示。在此研究领域内,还有其他可能需要进一步研究的方面,它们可以专注于提高取证工具对这些本地测试电话进行物理分析的能力。

著录项

  • 作者

    Vasa Toma S.;

  • 作者单位
  • 年度 2013
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号