MoLIFE: mDT Forensics
Abstract
Nowadays, mobile forensics is less explored in Digital Forensics case analysis due to the increase<br>in data protection mechanisms implemented by tech companies (i.e. Google for Android and Apple<br>for iOS). For example, the physical acquisition or analysis of specf c directories under super-<br>user protection would corrupt the evidence; access to such data is protected, and bypassing this<br>protection requires either privilege escalation or custom ROM installation, leading to the modif cation<br>of the device state. At the same time, the demand for mobile technologies and their respective<br>communication systems is increasing exponentially, exposing numerous security threats and risks. For<br>that reason, this paper presents a Mobile Live Intelligent Forensics Examination (MoLIFE), a novel<br>Digital Forensics (DF) methodology for data acquisition and analysis of mobile devices. The proposed<br>methodology is based on NIST SP800-101 for the DF process. MoLIFE can be integrated with new and<br>emerging technologies by exploiting their power (e.g. AI, blockchain, quantum computing). MoLIFE<br>can also be used to prevent cyber threats and incidents, as well as DF post-mortem analysis, ofering<br>examples of applying the MoLIFE methodology and good practices for the future. To prove the<br>technical feasibility of the methodology, a small case study on Android devices data acquisition via<br>the mDT will be presented. As the methodology is based on new and emerging technologies, it depends<br>on their limitations that would be overcome in a few years.