Test Results For Mobile Device Acquisition Tool: XRY/ XACT .

2y ago
11 Views
3 Downloads
447.25 KB
20 Pages
Last View : 14d ago
Last Download : 3m ago
Upload by : Joao Adcock
Transcription

XRY/XACT v6.10.1Test Results for Mobile Device Acquisition ToolSeptember 26, 2014

This report was prepared for the Department of Homeland Security Science and Technology Directorate CyberSecurity Division by the Office of Law Enforcement Standards of the National Institute of Standards and Technology.For additional information about the Cyber Security Division and ongoing projects, please visit www.cyber.st.dhs.gov.

September 2014Test Results for Mobile Device Acquisition Tool:XRY/XACT v6.10.1

ContentsIntroduction . 1How to Read This Report . 11 Results Summary . 22 Mobile Devices . 43 Testing Environment. 53.1 Execution Environment . 53.2 Internal Memory Data Objects. 53.3 UICC Data Objects . 74 Test Results. 84.1 Android Mobile Devices. 94.2 iOS Mobile Devices. 114.3 Feature Phones . 144.4 Universal Integrated Circuit Cards (UICCs). 16September 2014iiXRY/XACT v6.10.1

IntroductionThe Computer Forensics Tool Testing (CFTT) program is a joint project of theDepartment of Homeland Security (DHS), the National Institute of Justice (NIJ), and theNational Institute of Standards and Technology Law Enforcement Standards Office(OLES) and Information Technology Laboratory (ITL). CFTT is supported by otherorganizations, including the Federal Bureau of Investigation, the U.S. Department ofDefense Cyber Crime Center, U.S. Internal Revenue Service Criminal InvestigationDivision Electronic Crimes Program, and the U.S. Department of Homeland Security’sBureau of Immigration and Customs Enforcement, U.S. Customs and Border Protectionand U.S. Secret Service. The objective of the CFTT program is to provide measurableassurance to practitioners, researchers, and other applicable users that the tools used incomputer forensics investigations provide accurate results. Accomplishing this requiresthe development of specifications and test methods for computer forensics tools andsubsequent testing of specific tools against those specifications.Test results provide the information necessary for developers to improve tools, users tomake informed choices, and the legal community and others to understand the tools’capabilities. The CFTT approach to testing computer forensics tools is based on wellrecognized methodologies for conformance and quality testing. Interested parties in thecomputer forensics community can review and comment on the specifications and testmethods posted on the CFTT Web site (http://www.cftt.nist.gov/).This document reports the results from testing XRY/XACT v6.10.1 across supportedAndroid and iOS devices and a feature phone. The images captured from the test runs areavailable at the CFREDS Web site (http://www.cfreds.nist.gov).Test results from other tools can be found on the DHS S&T-sponsored digital forensicsweb page, http://www.cyberfetch.org/.How to Read This ReportThis report is divided into four sections. Section 1 identifies and provides a summary ofany significant anomalies observed in the test runs. This section is sufficient for mostreaders to assess the suitability of the tool for the intended use. Section 2 identifies themobile devices used for testing. Section 3 lists testing environment, the internal memoryand Universal Integrated Circuit Cards (UICC) data objects used to populate the mobiledevices and associated media. Section 4 provides an overview of the test case resultsreported by the tool. The full test data is availableat http://www.cftt.nist.gov/mobile devices.htm.

Test Results for Mobile Device Acquisition ToolTool Tested:Software Version:XRY/XACTv6.10.1Supplier:Micro Systemation IncAddress:5300 Shawnee Road Suite 100Alexandria VA 22312Tel:Fax:WWW:(703) 750-0068(888) 395-9027http://www.msab.com1 Results SummaryXRY/XACT is designed for perform a secure forensic extraction of data from a widevariety of mobile devices, such as smartphones, GPS navigation units, 3G modems,portable music players and the latest tablet processors.The tool was tested for its ability to acquire active and deleted data from the internalmemory of supported mobile devices and UICCs. Except for the following anomalies, thetool acquired all supported data objects completely and accurately for all mobile devicestested.Presentation: Readability and completeness of Personal Information Management (PIM) data(i.e., graphic files associated with address book entries, non-Latin address bookentries) were not reported. (Devices: Galaxy S3, Galaxy S4, Galaxy S5, GalaxyNote3, HTC One, Nexus4, Samsung Rugby 3)Equipment / Subscriber related data: Subscriber related data (i.e., MSISDN) were not reported. (Devices: Galaxy S3,Galaxy S4, Galaxy S5, Galaxy Note3, HTC One, Nexus4) The MEID was not reported (Device: iPad Air, iPad Mini)Personal Information Management (PIM) data: Memo entries were not reported. (Devices: Galaxy S3, Galaxy S4, Galaxy S5,Galaxy Note3, HTC One, Nexus4)EMS messages: Text messages containing more than 160 characters were not reported. (Device:Samsung Rugby 3)MMS messages: Incoming and outgoing audio and picture messages were not reported. (Device:Samsung Galaxy Note3)September 2014Page 2 of 16XRY/XACT v6.10.1

Non-Latin Character Presentation: Address book entries containing non-Latin characters were not reported in thegenerated report. (Devices: Galaxy S3, Galaxy S4, Galaxy S5, Galaxy Note3, HTCOne, Nexus4, Samsung Rugby 3)Physical Acquisition: Acquisitions of recoverable deleted data remnants (i.e., graphic, audio, videofiles) were not recovered. (Device: Galaxy S3, Galaxy S4)For more test result details see section 4.September 2014Page 3 of 16XRY/XACT v6.10.1

2 Mobile DevicesThe following table lists the mobile devices used for testing PadAppleiPad MiniAppleiPad MiniSamsungGalaxy S3SamsungGalaxy S4SamsungGalaxy S5HTC OneHTC OneSamsungGalaxyNote 3Nexus 4SamsungRugby 3Model55siPad 2 MD065LL/AiPad Air ME999LL/AiPad Mini ME030LL/AiPad Mini MF075LL/ASGH-1747SGH-M919SM-G900VHTCC6525LVWHTC OneSM-N900VNexus 4SGH-A997OSiOS 6.1.4(10B350)iOS 7.1(11D167)iOS 6.1.3(10B329)iOS 7.1(11D167)iOS 6.1.3(10B329)iOS Android4.2.2Android4.1.2Android 4.3Android .3250.20 ble 1: Mobile DevicesSeptember 2014Page 4 of 16XRY/XACT v6.10.1

3 Testing EnvironmentThe tests were run in the NIST CFTT lab. This section describes the selected testexecution environment, and the data objects populated onto the internal memory ofmobile devices and UICCs.3.1 Execution EnvironmentMicro Systemation XRY/XACT version 6.10.1 was installed on Windows 7 v6.1.7601.3.2 Internal Memory Data ObjectsMicro Systemation’s XRY/XACT was measured by analyzing acquired data from theinternal memory of pre-populated mobile devices. Table 2 defines the data objects andelements used for populating mobile devices provided the mobile device supports thedata element.Data ObjectsAddress Book EntriesData ElementsRegular LengthMaximum LengthSpecial CharacterBlank NameRegular Length, emailRegular Length, graphicRegular Length, AddressDeleted EntryNon-ASCII EntryPIM DataDatebook/CalendarMemosRegular LengthMaximum LengthDeleted EntrySpecial CharacterBlank EntryCall LogsIncomingOutgoingMissedIncoming - DeletedOutgoing - DeletedMissed - DeletedText MessagesIncoming SMS - ReadIncoming SMS - UnreadOutgoing SMSIncoming EMS - ReadIncoming EMS - UnreadOutgoing EMSSeptember 2014Page 5 of 16XRY/XACT v6.10.1

Data ObjectsData ElementsIncoming SMS - DeletedOutgoing SMS - DeletedIncoming EMS - DeletedOutgoing EMS - DeletedNon-ASCII SMS/EMSMMS MessagesIncoming AudioIncoming GraphicIncoming VideoOutgoing AudioOutgoing GraphicOutgoing VideoApplication DataDevice Specific App DataStand-alone data filesAudioGraphicVideoAudio - DeletedGraphic - DeletedVideo - DeletedInternet DataVisited SitesBookmarksLocation DataGPS CoordinatesSocial Media DataFacebookTwitterLinkedInTable 2: Internal Memory Data ObjectsSeptember 2014Page 6 of 16XRY/XACT v6.10.1

3.3 UICC Data ObjectsThe table below (Table 3) provides an overview of the data elements populated onUniversal Integrated Circuit Cards (UICCs).Data ObjectsAbbreviated Dialing Numbers (ADN)Data ElementsMaximum LengthSpecial CharacterBlank NameNon-ASCII EntryRegular Length - Deleted NumberCall LogsLast Numbers Dialed (LND)Text MessagesIncoming SMS - ReadIncoming SMS - UnreadNon-ASCII SMSIncoming SMS - DeletedNon-ASCII EMSIncoming EMS - DeletedTable 3: UICC Data ObjectsSeptember 2014Page 7 of 16XRY/XACT v6.10.1

4 Test ResultsThis section provides the test cases results reported by the tool. Sections 4.1 – 4.3identify the mobile device operating system type (e.g., Android, iOS) and the make andmodel of mobile devices used for testing Micro Systemation’s XRY/XACT v6.10.1.Section 4.4 covers Universal Integrated Circuit Cards (UICCs).The Test Cases column (internal memory acquisition/UICC) in sections 4.1 - 4.4 arecomprised of two sub-columns that define a particular test category and individual sub categories that are verified when acquiring the internal memory for supported mobiledevices and UICCs within each test case. Each individual sub-category row results foreach mobile device/UICC tested. The results are as follows:As Expected: the mobile forensic application returned expected test results – the toolacquired and reported data from the mobile device/UICC successfully.Partial: the mobile forensic application returned some of data from the mobiledevice/UICC.Not As Expected: the mobile forensic application failed to return expected test results –the tool did not acquire or report supported data from the mobile device/UICCsuccessfully.NA: Not Applicable – the mobile forensic application is unable to perform the test or thetool does not provide support for the acquisition for a particular data element.September 2014Page 8 of 16XRY/XACT v6.10.1

4.1 Android Mobile DevicesThe internal memory contents for Android devices were acquired and analyzed withMicro Systemation’s XRY/XACT v6.10.1.All test cases pertaining to the acquisition of supported Android devices were successfulwith the exception of the following. Readability and completeness of PIM Data i.e. graphic files associated withcontact entries are not reported in the html report for all Android devices.Readability and completeness of PIM Data i.e. non-Latin contact entries (i.e.,Chinese) were not reported in their native format in the pdf report for all Androiddevices.Subscriber related data (i.e., MSISDN) were not reported for all Android devices.Memo entries were not reported for all Android devices.Bookmarks for visited Internet URLs were not reported for the Samsung GalaxyNote 3.Incoming and outgoing audio and picture (MMS) messages were not reported forthe Samsung Galaxy Note 3.Deleted data remnants for graphic, audio and video files were not recovered whenperforming a physical acquisition for the Samsung Galaxy S3, Galaxy S4.See Table 4 below for more details.XRY/XACT v6.10.1GalaxyS3 GSMGalaxyS4 GSMGalaxyS5CDMAGalaxyNote 3CDMAHTC OneGSMHTC OneCDMANexus 4GSMMobile Device Platform: sExpectedNANot AsExpectedPartialNot AsExpectedPartialNot AsExpectedPartialNot AsExpectedPartialNot AsExpectedPartialNot AsExpectedPartialNot ATest Cases – InternalMemory ent/User DataGeneratedReportsIMEIMEID/ESNMSISDNContactsPIM DataCalendarTo-Do List/September 2014Page 9 of 16AsExpectedXRY/XACT v6.10.1

XRY/XACT v6.10.1GalaxyS3 GSMGalaxyS4 GSMGalaxyS5CDMAGalaxyNote 3CDMAHTC OneGSMHTC OneCDMANexus 4GSMMobile Device Platform: AndroidSpreadsheetsNot AsExpectedAsExpectedNot AsExpectedNANot AsExpectedAsExpectedNot AsExpectedNANot AsExpectedAsExpectedNot AsExpectedNANot AsExpectedNot AsExpectedNot Not AsExpectedNANot AsExpectedAsExpectedNot AsExpectedNANot AsExpectedAsExpectedNot AsExpectedNANot AsExpectedAsExpectedNot sExpectedAsExpectedAsExpectedNot AsExpectedNot st Cases – InternalMemory AcquisitionTasksMemosIncomingCall aHistoryFacebookSocial MediaDataTwitterLinkedInAcquire AllAcquisitionSelected AllSelectIndividualSeptember 2014Page 10 of 16XRY/XACT v6.10.1

XRY/XACT v6.10.1GalaxyS3 GSMGalaxyS4 GSMGalaxyS5CDMAGalaxyNote 3CDMAHTC OneGSMHTC OneCDMANexus 4GSMMobile Device Platform: AndroidModify edAsExpectedHashingHashesreported foracquired ctedAsExpectedNANANAGPS DataTest Cases – InternalMemory AcquisitionCase acterDeleted FileRecoveryReported innative formatTable 4: Android Mobile Devices4.2 iOS Mobile DevicesThe internal memory contents for iOS devices were acquired and analyzed with MicroSystemation’s XRY/XACT v6.10.1.All test cases pertaining to the acquisition of supported iOS devices were successful withthe exception of the following. MEID was not reported for the iPad Air (CDMA) and the iPadMini (CDMA).See Table 5 below for more details.September 2014Page 11 of 16XRY/XACT v6.10.1

XRY/XACT v6.10.1iPhone5GSMiPhone5SCDMAiPadGSMiPad AirCDMAiPADMiniGSMiPad MiniCDMAMobile Device Platform: NANANANot pectedAsExpectedAsExpectedAsExpectedNANANot ctedAsExpectedAsExpectedAsExpectedNot AsExpectedNot AsExpectedAsExpectedAsExpectedTest Cases – InternalMemory ent/User ndarPIM DataTo-Do List/TasksMemosIncomingCall oVideoSeptember 2014Page 12 of 16XRY/XACT v6.10.1

XRY/XACT v6.10.1iPhone5GSMiPhone5SCDMAiPadGSMiPad AirCDMAiPADMiniGSMiPad MiniCDMAMobile Device Platform: edAsExpectedAsExpectedAsExpectedNATest Cases – InternalMemory etDataHistoryFacebookSocial MediaDataTwitterLinkedInAcquire AllAcquisitionCase acterHashingGPS DataSelected AllSelectIndividualModify ANADeleted FileRecoveryNANANANANANAReported innative formatHashesreported foracquired edAsExpectedTable 5: iOS Mobile DevicesSeptember 2014Page 13 of 16XRY/XACT v6.10.1

4.3 Feature PhonesThe internal memory contents for the feature phone was acquired and analyzed withMicro Systemation’s XRY/XACT v6.10.1.All test cases pertaining to the acquisition of the Samsung Rugby III were successful withthe exception of the following. Non-Latin contact entries (i.e., Chinese) were not reported.EMS messages (messages over 160 characters) were not reported.See Table 6 below for more details.XRY/XACT v6.10.1Test Cases – InternalMemory AcquisitionMobile Device Platforms:Feature DevicesSamsung Rugy 3 GSMNon gGenerated ReportsIMEIEquipment/User rPIM DataTo-Do List/ TasksSMSMessagesMMSSeptember 2014AsExpectedNAAsExpectedMemosCall utgoingPartialGraphicAsExpectedPage 14 of 16XRY/XACT v6.10.1

XRY/XACT v6.10.1Test Cases – InternalMemory AcquisitionMessagesMobile Device Platforms:Feature DevicesSamsung Rugy 3 cumentsApplicationDataInternetDataSocial istoryNAFacebookNATwitterNALinkedInNAAcquire AllAcquisitionCase FileDataProtectionSelected AllAsExpectedNASelect IndividualNAModify Case eted FileRecoveryReported in nativeformatHashingHashes reported foracquired data objectsGPS DataCoordinates(Long/Lat)PhysicalAcquisitionNotAs ExpectedAsExpectedNATable 6: Feature PhonesSeptember 2014Page 15 of 16XRY/XACT v6.10.1

4.4 Universal Integrated Circuit Cards (UICCs)The internal memory contents for Universal Integrated Circuit Cards (UICCs) wereacquired and analyzed with Micro Systemation’s XRY/XACT v6.10.1.All test cases pertaining to the acquisition of UICCs were successful.See Table 7 below for more details.XRY/XACT v6.10.1Test Cases – UICC AcquisitionUniversalIntegratedCircuitCardNon DisruptedAs ExpectedDisruptedAs ExpectedService Provider Name(SPN)ICCIDAs ExpectedIMSIAs ExpectedMSISDNAs ExpectedAbbreviated DialingNumbers (ADNs)Last Numbers Dialed(LNDs)As ExpectedSMS MessagesAs ExpectedEMS MessagesAs ExpectedLOCIAs ExpectedGPRSLOCIAs ExpectedAcquire AllAs ExpectedSelected AllAs ExpectedSelect IndividualAs ExpectedModify Case DataAs ExpectedAcquisition ofProtected SIMAs ExpectedPIN attempts reportedAs ExpectedPUK attempts reportedAs ExpectedNon-ASCIICharacterNon-ASCII charactersAs ExpectedHashingHashes reported foracquired data objectsAs ExpectedConnectivityEquipment/User DataPIM DataLocation RelatedDataAcquisitionCase File DataProtectionPasswordProtected SIMAcquirePIN/PUKAttemptsAs ExpectedAs ExpectedTable 7: Universal Integrated Circuit CardsSeptember 2014Page 16 of 16XRY/XACT v6.10.1

Samsung Galaxy S3 SGH-1747 Android 4.1.2 1747UCDMG2 GSM Samsung Galaxy S4 SGH-M919 Android 4.2.2 M919UVUAMDL GSM Samsung Galaxy S5 SM-G900V Android 4.2.2 G900V.05 CDMA HTC One HTCC6525LV W Android 4.2.2 0.89.20.0222 GSM HTC One HTC One Android 4.1.2 4A.17.3250.20_10.40.1150.0 4L CDMA Samsung Galaxy Note 3

Related Documents:

Bruksanvisning för bilstereo . Bruksanvisning for bilstereo . Instrukcja obsługi samochodowego odtwarzacza stereo . Operating Instructions for Car Stereo . 610-104 . SV . Bruksanvisning i original

10 tips och tricks för att lyckas med ert sap-projekt 20 SAPSANYTT 2/2015 De flesta projektledare känner säkert till Cobb’s paradox. Martin Cobb verkade som CIO för sekretariatet för Treasury Board of Canada 1995 då han ställde frågan

service i Norge och Finland drivs inom ramen för ett enskilt företag (NRK. 1 och Yleisradio), fin ns det i Sverige tre: Ett för tv (Sveriges Television , SVT ), ett för radio (Sveriges Radio , SR ) och ett för utbildnings program (Sveriges Utbildningsradio, UR, vilket till följd av sin begränsade storlek inte återfinns bland de 25 största

Hotell För hotell anges de tre klasserna A/B, C och D. Det betyder att den "normala" standarden C är acceptabel men att motiven för en högre standard är starka. Ljudklass C motsvarar de tidigare normkraven för hotell, ljudklass A/B motsvarar kraven för moderna hotell med hög standard och ljudklass D kan användas vid

LÄS NOGGRANT FÖLJANDE VILLKOR FÖR APPLE DEVELOPER PROGRAM LICENCE . Apple Developer Program License Agreement Syfte Du vill använda Apple-mjukvara (enligt definitionen nedan) för att utveckla en eller flera Applikationer (enligt definitionen nedan) för Apple-märkta produkter. . Applikationer som utvecklas för iOS-produkter, Apple .

device on your compatible mobile device or computer. Select an option: Set up the device on your mobile device (Mobile Setup). Set up the device on your computer (Computer Setup). Mobile Setup Before you can pair your vívosmart device with your mobile device, your mobile

Strategy 6: Mobile Workload Mobile devices are increasingly driving mainframe workloads April 2014: Mobile Workload Pricing – 60% reduction in mobile workload CPU to R4HA peak MUST be from mobile device MUST show connection to mobile device – Mobile Safari good – Desktop Safari not good Mobile to mainframe is .

4 MOBILE DEVICE DEFINITION In order to ensure alignment with the DOD Mobile Device Strategy, this document will use the same mobile device definition. A mobile device is a handheld computing device with a display screen that allows for user input (e.g., touch screen, keyboard). When connected to a network, it enables the