Event Reconstruction of Indonesian E-Banking Services on Windows Phone Devices
In this paper, a digital investigation of electronic (e)-banking services on the Windows Phone platform of nine Indonesian banks is undertaken. In the experiments, banking transactions (balance check, funds transfer and phone credit purchase) are performed using a Nokia Lumia 625. The digital evidence resulting from these transactions is acquired and analyzed using mobile forensic tools from Cellebrite and Micro Systemation AB. In order to reconstruct the transaction events, evidence objects are identified and related events are sequenced. Specifically, the findings relating to mobile banking activities identify eight digital evidence objects (SMS, email, call log, contact, media file, network packets, location and installed apps), and a physical object (account book - obtained from a physical investigation). Investigation questions of who, what, when and how are answered from the acquired evidence and the event sequence diagrams. The findings contribute to a better understanding of available mobile banking evidence on Windows Phone devices.
KeywordsForensic science Digital forensics Investigative techniques Event reconstruction Windows phone forensics Digital evidence E-banking Indonesian banks
- 1.Understanding Worldwide Attitudes, Behaviours and Trends in Mobile Content and Commerce. https://mobileecosystemforum.com/programmes/analytics/mef-country-report-indonesia/mef-country-report-indonesia-download/
- 2.Operating System Market Share. https://www.netmarketshare.com/operating-system-market-share.aspx
- 4.Johnson, C.: Failure in Safety-Critical Systems: A Handbook of Incident and Accident Reporting. Glasgow University Press, Scotland (2003)Google Scholar
- 6.Chanajitt, R., Viriyasitavat, W., Choo, K.-K.R.: Forensic analysis and security assessment of Android m-banking apps. Aust. J. Forensic Sci. 1–17 (2016)Google Scholar
- 10.Carrier, B., Spafford, E.H.: Getting physical with the digital investigation process. Int. J. Digit. Evid. 2(2), 1–20 (2003)Google Scholar