Getting forensics data off of smartphones and tablets can be tough, experts say
Network World - Trying to get computer forensics data out of mobile smartphones and tablets in order to conduct investigations is hard -- often much harder than on PCs, laptops or Macs -- and experts say that forensics tools need to improve.
"The investigation tools for mobile are not at the same level of granularity you can get on tools for desktops," says David Nardoni, director of mobile-device investigations at consultancy Pricewaterhousecooper. Other experts agree, and also note that the BYOD trend only adds to the problem.
IN THE NEWS: Symantec targets partners to develop better mobile security
Forensics experts say they want to do both "physical" and "logical" acquisition of data. This means grabbing operating system files, device memory and other technical information, plus personal email or documents or phone data. They typically need a PIN code to access the device. But the state of the art in computer forensics tools and the proliferation of mobile devices all makes this hard. And unlike with Windows-based computers, for example, you can't just take out the hard drive, they note.
There are mobile-device forensics tools out there, such as Ufed from Cellebrite, the Katana Forensics tool Lantern, Blacklight Forensics Software, Paraben's Device Seizure, and Micro Sytemation's XRY. But they aren't comprehensive in the exact make and model of Google Android, Apple iOS device or other mobile device models they can tackle, says Darren Hayes, a professor at Pace University who teaches computer forensics courses.
It's all a bit hit-and-miss, and Hayes estimates that less than 40% of the smartphone models out there today can be imaged. The way that Android manufacturers have fragmented that operating system is a factor, and on the Apple iOS side, the security is proving so effective that bypassing the PIN is a challenge for investigators, he notes.
This comes at a time when both corporate examiners who conduct this forensics work, as well as law enforcement, have greater need than ever to get accurate, complete images off mobile devices as part of an investigation that will hold up under legal scrutiny.
Hayes notes that law enforcement officials are known to be meeting with Apple and manufacturers of Android mobile devices to talk about the issues. So far there's been little indication of any answers, he says.
Andrew Hoog, co-founder and chief investigative officer at Chicago-based startup viaForensics, which specializes in mobile-device forensics services, agrees that the fragmentation of the Android operating system -- there are now well over 800 Android devices without the same OS -- contributes to the forensics problem. Android is generally easier to break into than Apple iOS, though, he adds.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Security Empowers Business Every magazine article, presentation or blog about the topic seems to start the same way: trying to scare the living daylights out of...
- Business Assureance Technology Infographic IT Leaders See security as barrier to enabling employees. However with new Business assurance technology you are able to give Continuity, Agility, and...
- Beyond Data Migration Best Practices This guide is designed to help understand the best practices associated with email and other migration types - providing best practice guidance from...
- ESG: The Contemporary Value of Virtual Storage Appliances: HP renews its focus with StoreVirtual VSA A good virtual storage appliance (VSA) can simultaneously make good business sense and deliver operational value by allowing users to avoid the additional...
- Live Webcast
Get an Integrated Approach to Data Management - This KnowledgeVault Exchange is your one-stop resource center for designing a winning data management strategy with quantifiable top-line gains and bottom-line savings.
- Live Webcast
Becoming An Analytics Driven Organization - Join us on Tuesday, June 18, 2013, 11:00 AM EDT and learn how your agency can create an analytics culture that will enable...
- Becoming An Analytics Driven Organization Join us on Tuesday, June 18, 2013, 11:00 AM EDT and learn how your agency can create an analytics culture that will enable...
- 3 Reasons Why Sepaton is the World's Fastest Backup Solution Leading analyst, Storage Switzerland learns how Sepaton backs up and deduplicates massive data volumes while maintaining the industry's fastest performance - all in... All Data Center White Papers | Webcasts