Outline Introduction Method FAT Walker Xarver Investigation Conclusion
Research Project 2: Forensic Challenge
Axel Puppe & Joeri Blokhuis June 30, 2010
Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge
Research Project 2: Forensic Challenge Axel Puppe & Joeri - - PowerPoint PPT Presentation
Outline Introduction Method FAT Walker Xarver Investigation Conclusion Research Project 2: Forensic Challenge Axel Puppe & Joeri Blokhuis June 30, 2010 Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge Outline
Outline Introduction Method FAT Walker Xarver Investigation Conclusion
Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge
Outline Introduction Method FAT Walker Xarver Investigation Conclusion
Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge
Outline Introduction Method FAT Walker Xarver Investigation Conclusion Digital Forensic Research Workshop (DFRWS)
◮ University researchers ◮ Computer forensic examiners ◮ Analysts
Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge
Outline Introduction Method FAT Walker Xarver Investigation Conclusion Scenario
◮ Evidence connecting
◮ Evidence of the receipt
◮ Recovery of any other
Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge
Outline Introduction Method FAT Walker Xarver Investigation Conclusion What information can be expected in a mobile phone?
◮ Log ◮ Phone calls ◮ Text messages ◮ Calendar ◮ Appointments ◮ Reminders ◮ Birthdays ◮ Address book
◮ Multimedia files ◮ Audio ◮ Video ◮ Photos ◮ Documents
◮ Browser ◮ History ◮ Cache ◮ Bookmarks ◮ E-mail ◮ Sent ◮ Received ◮ Drafts ◮ Deleted ◮ Account settings ◮ Instant messaging Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge
Outline Introduction Method FAT Walker Xarver Investigation Conclusion
◮ FAT Walker ◮ Xarver Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge
Outline Introduction Method FAT Walker Xarver Investigation Conclusion Standard Forensic tools
Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge
Outline Introduction Method FAT Walker Xarver Investigation Conclusion FAT
◮ On physical memory dumps ◮ Filenames/Extension, MAC times
◮ Initial research ◮ Possible user behaviour on the phone ◮ Last created files ◮ Build an absolute path (depending on the parent and current
Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge
Outline Introduction Method FAT Walker Xarver Investigation Conclusion Screenshot
◮ Only two distinct MAC times
◮ Clear gap from 2008 to 2010 ◮ Top files created since 2010: JPG, BIN, DAT and XML.
Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge
Outline Introduction Method FAT Walker Xarver Investigation Conclusion XML
Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge
Outline Introduction Method FAT Walker Xarver Investigation Conclusion XML
◮ Sim Cards ◮ Databases ◮ Open Office XML ◮ Mobile phone (Android) applications ◮ And more. . .
◮ Read raw data ◮ Build XML tree ◮ Deal with damaged XML ◮ Gives offsets of original data Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge
Outline Introduction Method FAT Walker Xarver Investigation Conclusion Screenshot Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge
Outline Introduction Method FAT Walker Xarver Investigation Conclusion Combining the tools Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge
Outline Introduction Method FAT Walker Xarver Investigation Conclusion Xarver results
◮ Subjects: Look at this, This?, Contact, . . .
◮ Subjects: Buy, Engine, Payment, . . .
◮ Email address ◮ Username ◮ Password ◮ And more. . .
Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge
Outline Introduction Method FAT Walker Xarver Investigation Conclusion Pictures Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge
Outline Introduction Method FAT Walker Xarver Investigation Conclusion Conclusion
◮ Found emails + pictures
◮ Suspected email (subject: ‘payment’)
◮ Individuals yes, Companies/Bank account(s) nothing so far. . . Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge
Outline Introduction Method FAT Walker Xarver Investigation Conclusion Questions
Axel Puppe & Joeri Blokhuis Research Project 2: Forensic Challenge