کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
457871 696071 2011 14 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
A comparison of forensic evidence recovery techniques for a windows mobile smart phone
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
A comparison of forensic evidence recovery techniques for a windows mobile smart phone
چکیده انگلیسی

Acquisition, decoding and presentation of information from mobile devices is complex and challenging. Device memory is usually integrated into the device, making isolation prior to recovery difficult. In addition, manufacturers have adopted a variety of file systems and formats complicating decoding and presentation.A variety of tools and methods have been developed (both commercially and in the open source community) to assist mobile forensics investigators. However, it is unclear to what extent these tools can present a complete view of the information held on a mobile device, or the extent the results produced by different tools are consistent.This paper investigates what information held on a Windows Mobile smart phone can be recovered using several different approaches to acquisition and decoding. The paper demonstrates that no one technique recovers all information of potential forensic interest from a Windows Mobile device; and that in some cases the information recovered is conflicting.


► A comparison is made of the results obtained from a variety of different toolkits used to examine a Windows Mobile memory image.
► Explores qualitative reports of information recovered from a Windows Mobile smart phone.
► Digital forensics investigators will be unsure which toolkit has produced the correct data-set from the device.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Digital Investigation - Volume 8, Issue 1, July 2011, Pages 23–36
نویسندگان
, , ,