Vehicular Infotainment Forensics: Collecting Data and Putting It Into Perspective
Total Page:16
File Type:pdf, Size:1020Kb
VEHICULAR INFOTAINMENT FORENSICS 0 Vehicular Infotainment Forensics: Collecting Data and Putting It into Perspective Jesse Lacroix University of Ontario Institute of Technology MSc Computer Science Thesis Author Note This thesis reports the general findings of what is stored long-term on a vehicle’s infotainment system and a reflection on how the data could be used. All funding provided by the Natural Sciences and Engineering Research Council (NSERC). Correspondence address: 8-3374 Muskoka Street, Washago, ON, L0K 2B0. Important note: I have been employed as a Digital Forensic Analyst/Investigator for the Ontario Provincial Police since June 2016. © Jesse Lacroix 2017 VEHICULAR INFOTAINMENT FORENSICS 1 Abstract In today’s transportation system, countless numbers of vehicles are on the road and later generations have become mobile computers. Vehicles now have embedded infotainment systems that enable user-friendliness and practicability with functions such as a built-in global positioning system, media playback device and application interface. Smartphones and laptops can connect to them through Bluetooth and WiFi for all sorts of utilities. This enables data flow between a user’s device and the infotainment system and because of this interaction, data remnants are kept on these embedded devices. It is important to determine what type of data is stored long term since this information reflects a user’s activity and potential personal information. In terms of forensics, this data could be used to solve criminal activities if a vehicle was suspected of being an accessory to a crime; raising general awareness about this topic is important due to the potential sensitive information circulated. This main objective of this thesis is to demonstrate what types of information are stored on infotainment systems, how it can be acquired and the implications and contributions of the collected data in relation to the overall field of digital forensics. Keywords: digital forensics, internal vehicle components, embedded devices, infotainment systems, vehicular forensics VEHICULAR INFOTAINMENT FORENSICS 2 Overall Contribution This collaborated effort and thesis was made with the ultimate goal of identifying what types of information and data are stored on vehicular infotainment systems for its extended use, may it be for legal or personal use; we hope to positively contribute to the overall field of digital forensics, to law enforcement and raising general awareness about the data that is circulated and kept on these platforms. We also hope this work and thesis can be used as a baseline or reference for future research efforts in regards to vehicular and mobile digital forensics as well as the internal electronic components of vehicles and interactions with infotainment systems. The goal is to educate and showcase all relevant acquired data, its application and a framework to follow when interacting with such systems as well as validating that such data exists and can be put to use in the overall field of digital forensic. VEHICULAR INFOTAINMENT FORENSICS 3 Acknowledgments I would like to take the time to thank the Ontario Provincial Police’s Technological Crime Unit (OPP TCU) and Special Constable Jeremy Dupuis, the Office of the Privacy Commissioner of Canada (OPC), John Fledderus from Whitby OWASCO’s Audi/Volkswagen dealership, Dr. Rajen Akalu of the University of Ontario Institute of Technology (UOIT) and Jason Whelan, a former student of the University of Ontario Institute of Technology, for their assistance with this project in giving us help and access to many resources including forensic images for analysis, software and hardware for acquisition processes as well as funding. I would especially like to thank my supervisor from the University of Ontario Institute of Technology, Dr. Khalil El-Khatib, for his continued patience, guidance and resources that enabled me to do this project to the best of my abilities. VEHICULAR INFOTAINMENT FORENSICS 4 Contents Abstract ............................................................................................................................... 1 Overall Contribution ........................................................................................................... 2 Acknowledgments............................................................................................................... 3 List of Figures ..................................................................................................................... 9 List of Tables ....................................................................................................................... 9 Chapter I – Vehicular Infotainment Forensics: Collecting Data and Putting It into Perspective .................................................................................................................................... 10 Chapter II – VANETs and Vehicle Internal Network Buses/Components ........................ 14 2.1 State of Transportation System ............................................................................... 14 2.2 Internal Communication Buses ............................................................................... 18 2.3 VANET Security Challenges................................................................................... 21 Chapter III – Understanding Forensic Analysis ................................................................ 29 3.1 Digital Forensics Model .......................................................................................... 29 3.2 Provincial Implications and Processes .................................................................... 31 3.2.1 Legal Force Elements ...................................................................................... 34 3.2.2 Case Law Example. ......................................................................................... 35 3.3 Digital Forensic Processes ...................................................................................... 36 3.3.1 Extraction Types. ............................................................................................. 37 3.3.2 Live Memory Acquisition. ............................................................................... 38 VEHICULAR INFOTAINMENT FORENSICS 5 3.3.3 Network Related Forensics. ............................................................................. 40 3.4 Challenges in Digital Forensics .............................................................................. 42 3.4.1 Anti-Forensics. ................................................................................................. 46 3.5 Mobile Forensics ..................................................................................................... 48 3.5.1 Mobile Forensics Overview ............................................................................. 48 3.5.2 Windows Mobile Forensics Overview ............................................................. 54 3.5.3 Cloud-based Forensics ..................................................................................... 57 3.6 Android Forensics ................................................................................................... 59 3.6.1 Android Forensics Overview ........................................................................... 60 3.6.2 Instant Messaging Forensics ............................................................................ 66 3.6.3 Locational Data ................................................................................................ 72 3.7 Vehicular Forensics ................................................................................................. 73 3.7.1 Forensic Potential of Infotainment Systems .................................................... 74 3.7.2 Forensic Challenges in Mobile Ad Hoc Networks .......................................... 77 3.7.3 Recent Vehicular Forensic Efforts ................................................................... 80 Chapter IV – Vehicular Infotainment Forensic Findings .................................................. 84 4.1 Research Objective ................................................................................................. 84 4.2 Targeted Infotainment Systems ............................................................................... 88 4.3 Acquisition Methods ............................................................................................... 89 4.4 Acquisition Methods and Observed Data ............................................................... 90 VEHICULAR INFOTAINMENT FORENSICS 6 4.4.1 Audi/Volkswagen Acquisition Method ............................................................ 90 4.4.2 2013 Volkswagen Passat Data (Previously Owned) ........................................ 91 4.4.3 2014 Volkswagen Touareg Data (Previously Owned) ..................................... 92 4.4.4 2012 Audi Q5 Data (Previously Owned) ......................................................... 93 4.4.5 2014 Audi Q7 Data (New) ............................................................................... 94 4.4.6 OEM Infotainment Systems Acquisition Method ............................................ 95 4.4.7 2012 Ford Fiesta SYNC Generation I – Physical Acquisition Data ................ 97 4.4.8 2013 Ford Focus SYNC Generation II – Physical Acquisition Data ............... 99 4.4.9 2013 Ford F-150 SYNC Generation II – Logical/File System Acquisition Data ............................................................................................................................................