官术网_书友最值得收藏!

  • Practical Mobile Forensics
  • Rohit Tamma Oleg Skulkin Heather Mahalik Satish Bommisetty
  • 201字
  • 2021-06-24 16:38:58

The verification phase

After processing the phone, you need to verify the accuracy of the data extracted from the phone to ensure that data has not been modified. The verification of the extracted data can be accomplished in several ways:

  • Comparing the extracted data to the handset data: Check whether the data extracted from the device matches the data displayed by the device if applicable. The data extracted can be compared to that on the device itself or a logical report, whichever is preferred. Remember, handling the original device may make changes to the only evidence—the device itself.
  • Using multiple tools and comparing the results: To ensure accuracy, use multiple tools to extract the data and compare results.

  • Using hash values: All image files should be hashed after acquisition to ensure that data remains unchanged. If filesystem extraction is supported, you can extract the filesystem and then compute hashes for the extracted files. Later, any individually extracted file hash is calculated and checked against the original value to verify the integrity of it. Any discrepancy in hash values must be explicable (for example, the device was powered on and then acquired again, so the hash values are different).

主站蜘蛛池模板: 喜德县| 龙口市| 徐州市| 饶河县| 夏邑县| 米易县| 赞皇县| 昌吉市| 宁陕县| 榆社县| 五寨县| 额敏县| 中宁县| 平昌县| 梁平县| 精河县| 丰县| 镇坪县| 卢龙县| 循化| 左贡县| 南乐县| 泰宁县| 澎湖县| 蒲城县| 尚义县| 进贤县| 钦州市| 西宁市| 崇礼县| 吴旗县| 拉孜县| 平山县| 搜索| 忻城县| 汝南县| 莒南县| 阿坝县| 白河县| 繁峙县| 根河市|