商业和开源移动设备取证工具的比较分析

Radhika Padmanabhan, K. Lobo, Mrunali Ghelani, D. Sujan, M. Shirole
{"title":"商业和开源移动设备取证工具的比较分析","authors":"Radhika Padmanabhan, K. Lobo, Mrunali Ghelani, D. Sujan, M. Shirole","doi":"10.1109/IC3.2016.7880238","DOIUrl":null,"url":null,"abstract":"With forensics playing such a crucial role in today's data-driven world, this paper addresses the need to explore the different mobile device forensic tools available. Open Source and Commercial tools are two domains in close contention, with contrasting considerations such as accessibility and security. This paper aims at performing a comparative analysis of the various commercial and open source mobile device forensic tools, with respect to predefined software parameters and by employing a cross-device and test-driven approach. The test scenarios are structured to assess whether the selected tools possess the capabilities of a holistic one, while responding to threats and scenarios pertaining to the digital realm. The Commercial Tools under consideration are MOBILedit! Forensic (including Phone Forensics Express) and Cellebrite's UFED Physical Analyzer, while the Open Source Tools are — The Sleuth Kit (including Autopsy) and SANS SIFT. The result of this paper is a comparison matrix, which could help in identifying the best-fit solution as per the need of the investigation. It could also indicate the degree to which open source tools are comparable to (or better than) their commercial counterparts, and answer questions like — Can open source tools be a suitable replacement for the proprietary tools? Can this in reality, be a feasible shift for the forensic industry?","PeriodicalId":294210,"journal":{"name":"2016 Ninth International Conference on Contemporary Computing (IC3)","volume":"15 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-08-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"20","resultStr":"{\"title\":\"Comparative analysis of commercial and open source mobile device forensic tools\",\"authors\":\"Radhika Padmanabhan, K. Lobo, Mrunali Ghelani, D. Sujan, M. Shirole\",\"doi\":\"10.1109/IC3.2016.7880238\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"With forensics playing such a crucial role in today's data-driven world, this paper addresses the need to explore the different mobile device forensic tools available. Open Source and Commercial tools are two domains in close contention, with contrasting considerations such as accessibility and security. This paper aims at performing a comparative analysis of the various commercial and open source mobile device forensic tools, with respect to predefined software parameters and by employing a cross-device and test-driven approach. The test scenarios are structured to assess whether the selected tools possess the capabilities of a holistic one, while responding to threats and scenarios pertaining to the digital realm. The Commercial Tools under consideration are MOBILedit! Forensic (including Phone Forensics Express) and Cellebrite's UFED Physical Analyzer, while the Open Source Tools are — The Sleuth Kit (including Autopsy) and SANS SIFT. The result of this paper is a comparison matrix, which could help in identifying the best-fit solution as per the need of the investigation. It could also indicate the degree to which open source tools are comparable to (or better than) their commercial counterparts, and answer questions like — Can open source tools be a suitable replacement for the proprietary tools? Can this in reality, be a feasible shift for the forensic industry?\",\"PeriodicalId\":294210,\"journal\":{\"name\":\"2016 Ninth International Conference on Contemporary Computing (IC3)\",\"volume\":\"15 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2016-08-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"20\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2016 Ninth International Conference on Contemporary Computing (IC3)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/IC3.2016.7880238\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 Ninth International Conference on Contemporary Computing (IC3)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IC3.2016.7880238","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 20

摘要

鉴于取证在当今数据驱动的世界中扮演着如此重要的角色,本文探讨了探索不同移动设备取证工具的必要性。开源工具和商业工具是两个竞争激烈的领域,它们在可访问性和安全性等方面有着截然不同的考虑。本文旨在对各种商业和开源移动设备取证工具进行比较分析,涉及预定义的软件参数,并采用跨设备和测试驱动的方法。测试场景是结构化的,以评估所选工具是否具有整体工具的功能,同时响应与数字领域相关的威胁和场景。正在考虑的商业工具是MOBILedit!法医(包括电话取证Express)和Cellebrite的UFED物理分析仪,而开源工具是-侦探工具包(包括尸检)和SANS SIFT。本文的结果是一个比较矩阵,它可以帮助根据调查的需要确定最适合的解决方案。它还可以表明开源工具与商业工具的可比性(或优于)程度,并回答诸如—开源工具能否成为专有工具的合适替代品?在现实中,这对法医行业来说是一个可行的转变吗?
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Comparative analysis of commercial and open source mobile device forensic tools
With forensics playing such a crucial role in today's data-driven world, this paper addresses the need to explore the different mobile device forensic tools available. Open Source and Commercial tools are two domains in close contention, with contrasting considerations such as accessibility and security. This paper aims at performing a comparative analysis of the various commercial and open source mobile device forensic tools, with respect to predefined software parameters and by employing a cross-device and test-driven approach. The test scenarios are structured to assess whether the selected tools possess the capabilities of a holistic one, while responding to threats and scenarios pertaining to the digital realm. The Commercial Tools under consideration are MOBILedit! Forensic (including Phone Forensics Express) and Cellebrite's UFED Physical Analyzer, while the Open Source Tools are — The Sleuth Kit (including Autopsy) and SANS SIFT. The result of this paper is a comparison matrix, which could help in identifying the best-fit solution as per the need of the investigation. It could also indicate the degree to which open source tools are comparable to (or better than) their commercial counterparts, and answer questions like — Can open source tools be a suitable replacement for the proprietary tools? Can this in reality, be a feasible shift for the forensic industry?
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信