Windows Phone 7: Implications for Digital Forensic Investigators
Total Page:16
File Type:pdf, Size:1020Kb
Windows Phone 7 : Implications For Digital Forensic Investigators YUNG ANH LE B.E. (Manukau Institute Of Technology, NZ) A thesis submitted to the Graduate Faculty of Design and Creative Technologies AUT University in partial fulfilment of the requirements for the degree of Masters of Forensic Information Technology School of Computing and Mathematical Sciences Auckland, New Zealand 2012 ii Declaration I hereby declare that this submission is my own work and that, to the best of my knowledge and belief, it contains no material previously published or written by another person nor material which to a substantial extent has been accepted for the qualification of any other degree or diploma of a University or other institution of higher learning, except where due acknowledgement is made in the acknowledgements. ........................... Signature iii Acknowledgements This thesis was conducted at the Faculty of Design and Creative Technologies in the school of Computing and Mathematical Sciences at Auckland University of Technology, New Zealand. Support was received from many people throughout the duration of the thesis. Firstly I would like to thank my mother Van and my father Tai both of whom provided support and encouragement during the course of the thesis project as well as throughout my entire post graduate study. I would like to thank my thesis supervisors Mr. Petteri Kaskenpalo and Dr Brian Cusack for their exceptional support and guidance throughout the thesis project. Mr Kaskenpalo provided me with the freedom to explore research directions and choose the routes that I wanted to investigate. Mr Kaskenpalo's encouragement, excellent guidance, creative suggestions, and critical comments that have greatly contributed to this thesis. Mr Kaskenpalo, I would like to thank you very much for your supervision. I enjoyed our discussions and have learned a great deal from you. I also would like to thank Dr. Brian Cusack, who kindly agreed to being my supervisor at very short notice. Dr. Cusack provided me great guidance and mentoring, without which this thesis would not have been possible. I would like to thank my good friend Simon Lowther who helped me greatly during the thesis project with his help and support, even to the most unreasonable of requests. I would like to thank my friend and fellow MFIT student Jon Pearse for his aid and insights on both matters for digital forensics, and matters non digital forensics. Finally I would like to thank my former fellow MFIT student and MFIT lab supervisor Thomas Laurenson, who's skill and knowledge about forensics helped me when the thesis was going wrong, and who's conversations on life helped me when the thesis was going right. iv Abstract Windows Phone 7 (WP7) is the latest smart phone Operating System (OS) from Microsoft (MS) replacing the previous MS smart phone OS Windows Mobile (WM) 6.5. WP7 was redesigned completely and was not based on a previous version, unlike WM6 which was based on WM5 and so on. Because WP7 was redesigned and not based on WM, WP7 has many differences compared with WM in terms of underlying hardware and software as well as the user interface and how the phone communicates with a PC. Much research has been done on WM forensics and as a result forensics tools and techniques for WM have been established. Due to the changes implemented in WP7, the established WM forensic tools and techniques may be unable to work with WP7. Literature on WM forensics and WP7 were reviewed and identified the compatibility of the WM forensic tools and techniques with WP7 was not known, and hence leaving a gap between the WM forensics literature and WP7. The research question of "What forensic data can be extracted from a WP7 phone using current tools and techniques used to extract forensic data from WM phones?" and a hypothesis was defined. A methodology was defined in order to conduct the research to answer the research question and test the hypothesis. The research was conducted in five phases. Phase one uses the literature review and the reviews of similar published studies to establish the current WM forensic tools and techniques, and what data can be extracted from a WM phone using the WM forensic tools and techniques. Phase two used the data extracted from the WM phone as a template to generate test data which was loaded onto a WP7 phone. Phase three applied the established WM forensic tools and techniques to the WP7 phone in order to extract the test data from the phone. Phase four compared the results of the data extracted from the WP7 phone with the data extracted from the WM phone. Phase five evaluated the compatibility of the WM forensic tools and techniques based on the results from Phase four. The research findings showed that of the WM forensic tools and techniques tested, only one tool was able to successfully acquire any data from the WP7 phone. However the data acquired from the WP7 phone is much less than what could be acquired from a WM phone using the same tool. The remaining WM forensic tools and techniques tested were either unable to acquire data from v the WP7 phone or yielded inconclusive results. Based on the research findings, the majority of the WM forensic tools and techniques are not able to extract any data from WP7, and the WM forensic tool which can extract data from WP7 is able to extract much less data than from WM. vi Table of Contents Declaration .......................................................................................................................... ii Acknowledgements ............................................................................................................ iii Abstract ........................................................................................................................... iv Table of Contents ............................................................................................................... vi List Of Tables ..................................................................................................................... x List of Figures .................................................................................................................... xi List of Abbreviations ........................................................................................................ xii Chapter One: Introduction 1.0 INTRODUCTION .................................................................................................... 1 1.1 PROBLEM AREA ................................................................................................... 2 1.2 MOTIVATION ......................................................................................................... 3 1.3 STRUCTURE OF THESIS ...................................................................................... 3 Chapter Two: Literature Review 2.0 INTRODUCTION .................................................................................................... 6 2.1 DIGITAL FORENSIC INVESTIGATION PROCEDURE ..................................... 7 2.2 A BRIEF HISTORY OF WINDOWS PHONE........................................................ 9 2.2.1 Backwards Compatibility .......................................................................... 11 2.2.2 Windows Mobile Platform Fragmentation ................................................ 11 2.2.3 Windows Mobile User Experience ............................................................ 12 2.3 WINDOWS PHONE 7 ........................................................................................... 13 2.3.1 Synchronisation ......................................................................................... 13 2.3.2 Hardware ................................................................................................... 14 2.3.3 Software ..................................................................................................... 18 2.4 WINDOWS MOBILE FORENSICS ...................................................................... 22 2.4.1 Windows Mobile Hardware ....................................................................... 23 2.4.2 Windows Mobile Forensic Acquisition ..................................................... 24 2.4.3 Mobile Forensic Tools And Techniques .................................................... 26 2.5 SUMMARY OF ISSUES AND PROBLEM AREAS ............................................ 28 2.6 LATEST DEVELOPMENT IN WINDOWS PHONE 7 ........................................ 29 2.7 CONCLUSION ...................................................................................................... 31 vii Chapter Three: Methodology 3.0 INTRODUCTION .................................................................................................. 32 3.1 REVIEW OF SIMILAR PUBLISHED STUDIES ................................................. 32 3.1.1 Introduction To Windows Mobile Forensics ............................................. 33 3.1.2 Windows Mobile Advanced Forensics: An Alternative To Existing Tools ................................................................................................................... 34 3.1.3 Windows Mobile Advanced Forensics ...................................................... 35 3.1.4 Forensic Data Acquisition From Cell Phones Using JTAG Interface ....... 37 3.1.5 A Comparison Of Forensic Evidence Recovery Techniques For A Windows Mobile Smart Phone .................................................................. 38 3.2 RESEARCH QUESTION AND HYPOTHESIS ..................................................