MoLIFE: mDT Forensics

Arxiv pdf 2026-07-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

Nowadays, mobile forensics is less explored in Digital Forensics case analysis due to the increase<br>in data protection mechanisms implemented by tech companies (i.e. Google for Android and Apple<br>for iOS). For example, the physical acquisition or analysis of specf c directories under super-<br>user protection would corrupt the evidence; access to such data is protected, and bypassing this<br>protection requires either privilege escalation or custom ROM installation, leading to the modif cation<br>of the device state. At the same time, the demand for mobile technologies and their respective<br>communication systems is increasing exponentially, exposing numerous security threats and risks. For<br>that reason, this paper presents a Mobile Live Intelligent Forensics Examination (MoLIFE), a novel<br>Digital Forensics (DF) methodology for data acquisition and analysis of mobile devices. The proposed<br>methodology is based on NIST SP800-101 for the DF process. MoLIFE can be integrated with new and<br>emerging technologies by exploiting their power (e.g. AI, blockchain, quantum computing). MoLIFE<br>can also be used to prevent cyber threats and incidents, as well as DF post-mortem analysis, ofering<br>examples of applying the MoLIFE methodology and good practices for the future. To prove the<br>technical feasibility of the methodology, a small case study on Android devices data acquisition via<br>the mDT will be presented. As the methodology is based on new and emerging technologies, it depends<br>on their limitations that would be overcome in a few years.

Loading executive summary...

LINK COPIED TO CLIPBOARD