官术网_书友最值得收藏!

The processing phase

Once a phone has been isolated from communication networks, the actual processing of the mobile phone begins. One of the challenges that you will face in this phase is identifying which tools to use, as this is affected by a variety of factors such as price, ease of use, applicability, and so on. Mobile forensic software is highly expensive, and unlike with computer forensics, you may sometimes have to use multiple tools to access data. While selecting a tool, ensure that it has built-in features to maintain forensic integrity. Maintaining forensic integrity requires a tool that packages collected data in a format that probably cannot be easily modified or altered.

The phone should be acquired using a tested method that is repeatable and is as forensically sound as possible. Physical acquisition is the preferred method as it extracts the raw memory data and the device is commonly powered off during the acquisition process. On most devices, the smallest number of changes occur to the device during physical acquisition. If physical acquisition is not possible or fails, an attempt should be made to acquire the filesystem of the mobile device. A logical acquisition should always be performed as it may contain only the parsed data and provide pointers to examine the raw memory image. These acquisition methods are discussed in detail in later chapters.

主站蜘蛛池模板: 德格县| 罗平县| 顺平县| 亳州市| 固镇县| 高台县| 泌阳县| 交口县| 陕西省| 永德县| 铜梁县| 蒙城县| 丹棱县| 淳安县| 翁源县| 双辽市| 怀化市| 泸西县| 汾阳市| 沙河市| 朝阳县| 慈利县| 昆明市| 怀仁县| 镇江市| 泌阳县| 宜州市| 日喀则市| 博白县| 尚义县| 图片| 舟曲县| 旬阳县| 通山县| 阜阳市| 城市| 佛冈县| 长岛县| 鄂托克前旗| 南通市| 探索|