官术网_书友最值得收藏!

  • Practical Mobile Forensics
  • Rohit Tamma Oleg Skulkin Heather Mahalik Satish Bommisetty
  • 227字
  • 2021-06-24 16:38:58

The processing phase

Once a phone has been isolated from communication networks, the actual processing of the mobile phone begins. One of the challenges that you will face in this phase is identifying which tools to use, as this is affected by a variety of factors such as price, ease of use, applicability, and so on. Mobile forensic software is highly expensive, and unlike with computer forensics, you may sometimes have to use multiple tools to access data. While selecting a tool, ensure that it has built-in features to maintain forensic integrity. Maintaining forensic integrity requires a tool that packages collected data in a format that probably cannot be easily modified or altered.

The phone should be acquired using a tested method that is repeatable and is as forensically sound as possible. Physical acquisition is the preferred method as it extracts the raw memory data and the device is commonly powered off during the acquisition process. On most devices, the smallest number of changes occur to the device during physical acquisition. If physical acquisition is not possible or fails, an attempt should be made to acquire the filesystem of the mobile device. A logical acquisition should always be performed as it may contain only the parsed data and provide pointers to examine the raw memory image. These acquisition methods are discussed in detail in later chapters.

主站蜘蛛池模板: 古田县| 阜新| 大城县| 通州区| 宜川县| 阜新市| 禹城市| 德保县| 庆城县| 江孜县| 峨山| 搜索| 扶余县| 宝兴县| 三原县| 麻城市| 梁平县| 务川| 新巴尔虎右旗| 天津市| 稻城县| 常宁市| 阳曲县| 斗六市| 鄂州市| 黑龙江省| 贡嘎县| 南投县| 永春县| 长岭县| 武山县| 绥德县| 荥经县| 凤城市| 宜州市| 屏边| 平和县| 喀什市| 遵义市| 湟中县| 卫辉市|