
Practical Forensic Analysis of Artifacts on iOS and Android Devices: Investigating Complex Mobile De
Mohammed Moreb
Résumé
You'll walkthrough the various phases of the mobile forensics process for both Android and iOS-based devices, including forensically extracting, collecting, and analyzing data and producing and disseminating reports. Practical cases and labs involving specialized hardware and software illustrate practical application and performance of data acquisition (including deleted data) and the analysis of extracted information. You'll also gain an advanced understanding of computer forensics, focusing on mobile devices and other devices not classifiable as laptops, desktops, or servers.
This book is your pathway to developing the critical thinking, analytical reasoning, and technical writing skills necessary to effectively work in a junior-level digital forensic or cybersecurity analyst role.
What You'll Learn
- Acquire and investigate data from mobile devices using forensically sound, industry-standard tools
- Understand the relationship between mobile and desktop devices in criminal and corporate investigations
- Analyze backup files and artifacts for forensic evidence
Forensic examiners with little or basic experience in mobile forensics or open source solutions for mobile forensics. The book will also be useful to anyone seeking a deeper understanding of mobile internals.
Chapter 1
Introduction to Mobile Forensic Analysis
- The Importance of Mobile Forensic Analysis
- Understanding mobile forensics
- Challenges in mobile forensics
- Tools used for mobile forensics
- The mobile phone evidence extraction process
- Examination and analysis
- Rules of evidence
- Practical Mobile Forensic
- Summary
Chapter 2
Introduction to IOS Forensics
- IOS Boot Process
- IOS Architecture
- IOS Security
- Understanding Jailbreaking
- Data Acquisition from iOS Devices
- Data Acquisition from iOS Backups
- iOS Data Analysis and Recovery
- Mobile Forensics Investigation Challenges on iOS
- iOS Forensic Tools
- Summary
Chapter 3
Introduction to Android Forensics
- Understanding Android
- Application framework
- Android runtime
- Linux Kernel
- Android Forensic Setup and Pre-Data Extraction Techniques
- Android Data Extraction Techniques
- Android Data Analysis and Recovery
- Android App rooting process and techniques
- Summary
Chapter 4
Forensic I nvestigations of P opular A pplications on Android and iOS platforms
- Introduction
- Case & Investigator Details
- Investigations of Facebook Messenger and WhatsApp applications
- Details of the device seized for examination
- Results and Analysis
- Summary
Chapter 5
Forensic Analysis of Telegram Messenger on iOS and Android Smartphones Case Study
- Introduction
- Literature Review
- Methodology and Experiment Setup
- Evidences Acquisition
- Evidences Processing and Analysis
- Results
- Summary
Chapter 6
Detecting Private Data Leaks O ver Mobile Applications U sing Mobile Forensic Techniques
- Introduction
- Legal Issues Regarding the Local Electronic Crimes Law & Mobile Forensics
- Details of the reporting agency and tools used in the examination
- Description of steps taken during examination
- Chain of custody documentation
- Details of findings or issues identified
- Evidence recovered during the examination, ranging from chat messages
- Images captured during the examination
- Examination and analysis information
- Summary
Chapter 7
Impact of iPhone Jailbreaking on User Data Integrity in Mobile Forensics
Introduction
Mobile Forensics
User Data Integrity in Mobile Forensics
Jailbreaking's affect on iOS
Data acquisition
Logical acquisition
Filesystem acquisition
Experiment Details and Tools
Results
Data Extraction
Extracted data before jailbreak
Extracted data after jailbreak
Summary
Chapter 8
The I mpact of C ryptocurrency M ining on Mobile Devices
- Introduction
- Cryptocurrency mining
- Measurement and work mechanism
- Tools, programs, and applications used in cryptocurrency mining
- Experiment and analogy by iPhone 6s
- Experiment and analogy by LG g5
- Results and Analysis
- Summary
Chapter 9
Mobile Forensic Investigation for WhatsApp
- Introduction
- WhatsApp Architecture
- WhatsApp Experiment
- Tools used in the seizure process
- Analysis Stage
- Examination on a backup taken by iTunes
- Examination on a backup taken from the connected device
- Forensic Tools comparison
- Summary
Chapter 10
Cloud Computing Forensics: Dropbox Case Study
- Introduction
- Cloud Computing Forensics
- Cloud forensic challenges
- Dropbox cloud storage
- Implementation Details
- Seating Tools and Environment
- Magnet axiom forensics program
- MobileEdit express forensics tool
- FinalMobile forensics tool
- Results and Analysis
- Programs and tools
- Experiments
- Summary
Chapter 11
Malware Forensics for Volatile and nonVolatile Memory in Mobile Devices
- Introduction
- Mobile Malware Forensic
- Smartphone Volatile Memory
- Mobile Devices Case Details
- Development and Experiment
- Logical acquisition using Axiom process
- Physical acquisition output in finalmobile forensics
- Investigating from the non-volatile memory
- Evaluate Forensic tools usage in this case
- Summary
Chapter 12
Mobile F orensic for KeyLogger Artifact
- Introduction
- Mobile KeyLogger
- Methodology and case study setup
- Mobile Malware and Spyware
- Evidence recovered during the examination
- Evidence recovered using Magnet ACQUIRE
- Examination and analysis KeyLogger result
- Summary
Chapter 1 3
Digital Evidence Identification Methods for Mobile Devices with Facebook Messenger
- Introduction
- Mobile messenger apps
- Mobile operating system architecture
- Experiment Tools
- Evidence and scene security
- Evidence isolation
- Data Acquisition
- FBM Data analysis using Magnet AXIOM Examine
- FBM Data analysis using Belkasoft
- FBM Data analysis using DB Browser for SQLite
- Recover deleted evidence from SQLite Property Lists
- Reporting
- Summary
Mohammed Moreb, Ph.D. in Electrical and Computer Engineering. Expertise in Cybercrimes & Digital Evidence Analysis, specifically focusing on Information and Network Security, with a strong publication track record, work for both conceptual and practical wich built during works as a system developer and administrator for the data center for more than 10 years, config, install, and admin enterprise system related to all security configuration, he improved his academic path with the international certificate such as CCNA, MCAD, MCSE; Academically he teaches the graduate-level courses such as Information and Network Security course, Mobile Forensics course, Advanced Research Methods, Computer Network Analysis and Design, and Artificial Intelligence Strategy for Business Leaders.
Dr. Moreb recently founded a new framework and methodology specialized in software engineering for machine learning in health informatics named SEMLHI which investigates the interaction between software engineering and machine learning within the context of health systems. The SEMLHI framework includes four modules (software, machine learning, machine learning algorithms, and health informatics data) that organize the tasks in the framework using a SEMLHI methodology, thereby enabling researchers and developers to analyze health informatics software from an engineering perspective and providing developers with a new road map for designing health applications with system functions and software implementations.
Caractéristiques techniques
PAPIER | |
Éditeur(s) | Apress |
Auteur(s) | Mohammed Moreb |
Parution | 15/04/2022 |
Nb. de pages | 515 |
EAN13 | 9781484280256 |
Avantages Eyrolles.com
Consultez aussi
- Les meilleures ventes en Graphisme & Photo
- Les meilleures ventes en Informatique
- Les meilleures ventes en Construction
- Les meilleures ventes en Entreprise & Droit
- Les meilleures ventes en Sciences
- Les meilleures ventes en Littérature
- Les meilleures ventes en Arts & Loisirs
- Les meilleures ventes en Vie pratique
- Les meilleures ventes en Voyage et Tourisme
- Les meilleures ventes en BD et Jeunesse