File Download
Supplementary
-
Citations:
- Appears in Collections:
postgraduate thesis: A forensic analysis approach to smartphones from a criminal investigation perspective
Title | A forensic analysis approach to smartphones from a criminal investigation perspective |
---|---|
Authors | |
Issue Date | 2015 |
Publisher | The University of Hong Kong (Pokfulam, Hong Kong) |
Citation | Kong, Y. [江以藻]. (2015). A forensic analysis approach to smartphones from a criminal investigation perspective. (Thesis). University of Hong Kong, Pokfulam, Hong Kong SAR. Retrieved from http://dx.doi.org/10.5353/th_b5760967 |
Abstract | Ever since the introduction of new functionalities like social networking and instant messaging, there has been a remarkably growth in the number of smartphone users. This innovative communication method also increases the likelihood for deploying smartphones, in view of its diversity and anonymous nature, as portable devices used in criminal activities. Thus, the objective of this research is to identify and review proper technical approaches in conducting forensic examinations on smartphones. The term, mobile device forensics denotes the recovery of digital evidence or data stored on a mobile device by any method or scheme that is forensically sound. This is a two-stage process which comprised of data extraction and analysis. Most of the forensic toolkits being used to gain access to a phone’s internal memory are developed by forensic companies who design their own programs and acquisition methods. So far these toolkits have not been independently verified or tested for full memory acquisition. Accordingly, in the first part of this thesis, research experiments will be carried out to evaluate if the smartphone backup option, physical extraction using custom boot loader or the equipment specifically build to facilitate the invasive task of JTAG (Joint Task Action Group) acquisition can be used to acquire data and at the same time preserve the integrity of such digital evidence. The latter half of the thesis will examine the acquired data by means of various decoding software to determine their relevancy to forensic investigations. Test results are also cross-evaluated by commercial forensic tools so as to make a comparison on their effectiveness and completeness in analyzing the extracted data. The ultimate goal is to ensure digital data so recovered by mobile forensic tools can be adduced as reliable evidence in court proceedings. Some drawbacks of the mobile forensic toolkits and procedures will also be highlighted. For instance, it is considered that there is no single tool or method which is capable of acquiring all necessary evidence from various smartphone models. Lastly, this thesis will conclude with a synopsis of findings and the future work planned in this area. |
Degree | Master of Philosophy |
Subject | Computer crimes - Investigation |
Dept/Program | Computer Science |
Persistent Identifier | http://hdl.handle.net/10722/226754 |
HKU Library Item ID | b5760967 |
DC Field | Value | Language |
---|---|---|
dc.contributor.author | Kong, Yu-cho | - |
dc.contributor.author | 江以藻 | - |
dc.date.accessioned | 2016-06-30T04:24:04Z | - |
dc.date.available | 2016-06-30T04:24:04Z | - |
dc.date.issued | 2015 | - |
dc.identifier.citation | Kong, Y. [江以藻]. (2015). A forensic analysis approach to smartphones from a criminal investigation perspective. (Thesis). University of Hong Kong, Pokfulam, Hong Kong SAR. Retrieved from http://dx.doi.org/10.5353/th_b5760967 | - |
dc.identifier.uri | http://hdl.handle.net/10722/226754 | - |
dc.description.abstract | Ever since the introduction of new functionalities like social networking and instant messaging, there has been a remarkably growth in the number of smartphone users. This innovative communication method also increases the likelihood for deploying smartphones, in view of its diversity and anonymous nature, as portable devices used in criminal activities. Thus, the objective of this research is to identify and review proper technical approaches in conducting forensic examinations on smartphones. The term, mobile device forensics denotes the recovery of digital evidence or data stored on a mobile device by any method or scheme that is forensically sound. This is a two-stage process which comprised of data extraction and analysis. Most of the forensic toolkits being used to gain access to a phone’s internal memory are developed by forensic companies who design their own programs and acquisition methods. So far these toolkits have not been independently verified or tested for full memory acquisition. Accordingly, in the first part of this thesis, research experiments will be carried out to evaluate if the smartphone backup option, physical extraction using custom boot loader or the equipment specifically build to facilitate the invasive task of JTAG (Joint Task Action Group) acquisition can be used to acquire data and at the same time preserve the integrity of such digital evidence. The latter half of the thesis will examine the acquired data by means of various decoding software to determine their relevancy to forensic investigations. Test results are also cross-evaluated by commercial forensic tools so as to make a comparison on their effectiveness and completeness in analyzing the extracted data. The ultimate goal is to ensure digital data so recovered by mobile forensic tools can be adduced as reliable evidence in court proceedings. Some drawbacks of the mobile forensic toolkits and procedures will also be highlighted. For instance, it is considered that there is no single tool or method which is capable of acquiring all necessary evidence from various smartphone models. Lastly, this thesis will conclude with a synopsis of findings and the future work planned in this area. | - |
dc.language | eng | - |
dc.publisher | The University of Hong Kong (Pokfulam, Hong Kong) | - |
dc.relation.ispartof | HKU Theses Online (HKUTO) | - |
dc.rights | This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License. | - |
dc.rights | The author retains all proprietary rights, (such as patent rights) and the right to use in future works. | - |
dc.subject.lcsh | Computer crimes - Investigation | - |
dc.title | A forensic analysis approach to smartphones from a criminal investigation perspective | - |
dc.type | PG_Thesis | - |
dc.identifier.hkul | b5760967 | - |
dc.description.thesisname | Master of Philosophy | - |
dc.description.thesislevel | Master | - |
dc.description.thesisdiscipline | Computer Science | - |
dc.description.nature | published_or_final_version | - |
dc.identifier.doi | 10.5353/th_b5760967 | - |
dc.identifier.mmsid | 991019898629703414 | - |