Radhika Padmanabhan, K. Lobo, Mrunali Ghelani, D. Sujan, M. Shirole
{"title":"商业和开源移动设备取证工具的比较分析","authors":"Radhika Padmanabhan, K. Lobo, Mrunali Ghelani, D. Sujan, M. Shirole","doi":"10.1109/IC3.2016.7880238","DOIUrl":null,"url":null,"abstract":"With forensics playing such a crucial role in today's data-driven world, this paper addresses the need to explore the different mobile device forensic tools available. Open Source and Commercial tools are two domains in close contention, with contrasting considerations such as accessibility and security. This paper aims at performing a comparative analysis of the various commercial and open source mobile device forensic tools, with respect to predefined software parameters and by employing a cross-device and test-driven approach. The test scenarios are structured to assess whether the selected tools possess the capabilities of a holistic one, while responding to threats and scenarios pertaining to the digital realm. The Commercial Tools under consideration are MOBILedit! Forensic (including Phone Forensics Express) and Cellebrite's UFED Physical Analyzer, while the Open Source Tools are — The Sleuth Kit (including Autopsy) and SANS SIFT. The result of this paper is a comparison matrix, which could help in identifying the best-fit solution as per the need of the investigation. It could also indicate the degree to which open source tools are comparable to (or better than) their commercial counterparts, and answer questions like — Can open source tools be a suitable replacement for the proprietary tools? Can this in reality, be a feasible shift for the forensic industry?","PeriodicalId":294210,"journal":{"name":"2016 Ninth International Conference on Contemporary Computing (IC3)","volume":"15 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-08-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"20","resultStr":"{\"title\":\"Comparative analysis of commercial and open source mobile device forensic tools\",\"authors\":\"Radhika Padmanabhan, K. Lobo, Mrunali Ghelani, D. Sujan, M. Shirole\",\"doi\":\"10.1109/IC3.2016.7880238\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"With forensics playing such a crucial role in today's data-driven world, this paper addresses the need to explore the different mobile device forensic tools available. Open Source and Commercial tools are two domains in close contention, with contrasting considerations such as accessibility and security. This paper aims at performing a comparative analysis of the various commercial and open source mobile device forensic tools, with respect to predefined software parameters and by employing a cross-device and test-driven approach. The test scenarios are structured to assess whether the selected tools possess the capabilities of a holistic one, while responding to threats and scenarios pertaining to the digital realm. The Commercial Tools under consideration are MOBILedit! Forensic (including Phone Forensics Express) and Cellebrite's UFED Physical Analyzer, while the Open Source Tools are — The Sleuth Kit (including Autopsy) and SANS SIFT. The result of this paper is a comparison matrix, which could help in identifying the best-fit solution as per the need of the investigation. It could also indicate the degree to which open source tools are comparable to (or better than) their commercial counterparts, and answer questions like — Can open source tools be a suitable replacement for the proprietary tools? Can this in reality, be a feasible shift for the forensic industry?\",\"PeriodicalId\":294210,\"journal\":{\"name\":\"2016 Ninth International Conference on Contemporary Computing (IC3)\",\"volume\":\"15 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2016-08-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"20\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2016 Ninth International Conference on Contemporary Computing (IC3)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/IC3.2016.7880238\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 Ninth International Conference on Contemporary Computing (IC3)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IC3.2016.7880238","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Comparative analysis of commercial and open source mobile device forensic tools
With forensics playing such a crucial role in today's data-driven world, this paper addresses the need to explore the different mobile device forensic tools available. Open Source and Commercial tools are two domains in close contention, with contrasting considerations such as accessibility and security. This paper aims at performing a comparative analysis of the various commercial and open source mobile device forensic tools, with respect to predefined software parameters and by employing a cross-device and test-driven approach. The test scenarios are structured to assess whether the selected tools possess the capabilities of a holistic one, while responding to threats and scenarios pertaining to the digital realm. The Commercial Tools under consideration are MOBILedit! Forensic (including Phone Forensics Express) and Cellebrite's UFED Physical Analyzer, while the Open Source Tools are — The Sleuth Kit (including Autopsy) and SANS SIFT. The result of this paper is a comparison matrix, which could help in identifying the best-fit solution as per the need of the investigation. It could also indicate the degree to which open source tools are comparable to (or better than) their commercial counterparts, and answer questions like — Can open source tools be a suitable replacement for the proprietary tools? Can this in reality, be a feasible shift for the forensic industry?