Smartphones as Distributed Witnesses for Digital Forensics
Smartphones have become an integral part of people’s lives. Their wide range of capabilities and support of diverse applications result in a wealth of data being stored in smartphone memory. Although tools are available to extract and view the data stored in smartphones, no comprehensive process exists for event reconstruction using the extracted data. Data in smartphones is typically stored in SQLite databases and can, therefore, be easily transformed. To perform event reconstruction, multiple SQLite databases have to be integrated. This paper proposes a novel mobile event reconstruction process that allows for event reconstruction by querying the integrated SQLite databases collected from multiple smartphones. The process can create detailed accounts of the events that took place before, during and after an incident.
KeywordsSmartphones event reconstruction distributed databases
- 1.AccessData, Mobile Phone Examiner Plus (MPE+), Lindon, Utah (www.accessdata.com/products/digital-forensics/mobile-phone-examiner).
- 3.A. Caithness, The Forensic Implications of SQLite’s Write Ahead Log, CCL Group, Stratford-upon-Avon, United Kingdom (www.cclgroupltd.com/the-forensic-implications-of-sqlites-write-ahead-log), 2012.Google Scholar
- 4.E. Casey, Digital Evidence and Computer Crime, Elsevier, Waltham, Massachusetts, 2011.Google Scholar
- 5.F. Cohen, Digital Forensic Evidence Examination, Fred Cohen & Associates, Livermore, California, 2009.Google Scholar
- 7.A. Elmagarmid, M. Rusinkiewicz and A. Sheth (Eds.), Management of Heterogeneous and Autonomous Database Systems, Morgan Kaufmann Publishers, San Francisco, California, 1999.Google Scholar
- 8.M. Eltabakh, Data Integration, CS561-Spring 2012, Department of Computer Science, Worcester Polytechnic Institute, Worcester, Massachusetts (http://web.cs.wpi.edu/~cs561/s12/Lectures/IntegrationOLAP/DataIntegration.pdf), 2012.Google Scholar
- 9.Forensic Science Central, Crime Scene and Accident Scene Reconstruction (www.forensicsciencecentral.co.uk/reconstruction.shtml), 2005.
- 11.P. Gladyshev, Formalizing Event Reconstruction in Digital Investigations, Ph.D. Dissertation, Department of Computer Science, University College Dublin, Dublin, Ireland, 2004.Google Scholar
- 13.H. Halvorsen, Structured Query Language, Department of Electrical Engineering, Information Technology and Cybernetics, Telemark University College, Porsgrunn, Norway (http://home.hit.no/~hansha/documents/database/documents/Structured%20Query%20Language.pdf, 2012Google Scholar
- 15.MD’s Technical Sharing, Raw access to SMS/MMS database on Android phones (http://minhdanh2002.blogspot.com/2012/02/raw-access-to-sms-database-on-android.html), February 14, 2012.
- 16.J. Morris, Crime Analysis Charting: An Introduction to Visual Investigative Analysis, Palmer Enterprises, Loomis, California, 1982.Google Scholar
- 17.Oxygen Forensics, Oxygen Forensic Suite, Alexandria, Virginia (www.oxygen-forensic.com/en).
- 18.M. Ozsu and P. Valduriez, Principles of Distributed Database Systems, Springer, New York, 2011.Google Scholar
- 20.P. Patodi, Database Recovery Mechanism for Android Devices, Ph.D. Dissertation, Department of Computer Science and Engineering, Indian Institute of Technology Bombay, Bombay, India, 2012.Google Scholar
- 21.M. Prasad and Y. Satish, Reconstruction of events in digital forensics, International Journal of Engineering Trends and Technology, vol. 4(8), pp. 3460–3467, 2013.Google Scholar
- 22.B. Schneier, Attack trees, Dr. Dobb’s Journal of Software Tools, vol. 24(12), pp. 21–29, 1999.Google Scholar
- 23.SQLite, About SQLite, Charlotte, North Carolina (www.sqlite.org/about.html).
- 24.SQLite, The SQLite Database File Format, Charlotte, North Carolina (www.sqlite.org/fileformat.html).
- 25.SQLite, Write-Ahead Logging, Charlotte, North Carolina (www.sqlite.org/wal.html), 2013.
- 26.P. Stephenson, Modeling of post-incident root cause analysis, International Journal of Digital Evidence, vol. 2(2), 2003.Google Scholar
- 27.The iPhone Wiki, Messages (http://theiphonewiki.com/wiki/Messages), August 16, 2013.
- 28.viaForensics, viaExtract, Oak Park, Illinois (http://viaforensics.com).