ASTM E3046-2015 Standard Guide for Core Competencies for Mobile Phone Forensics《手机取证用核心能力的标准指南》.pdf
《ASTM E3046-2015 Standard Guide for Core Competencies for Mobile Phone Forensics《手机取证用核心能力的标准指南》.pdf》由会员分享,可在线阅读,更多相关《ASTM E3046-2015 Standard Guide for Core Competencies for Mobile Phone Forensics《手机取证用核心能力的标准指南》.pdf(4页珍藏版)》请在麦多课文档分享上搜索。
1、Designation: E3046 15Standard Guide forCore Competencies for Mobile Phone Forensics1This standard is issued under the fixed designation E3046; the number immediately following the designation indicates the year oforiginal adoption or, in the case of revision, the year of last revision. A number in p
2、arentheses indicates the year of last reapproval. Asuperscript epsilon () indicates an editorial change since the last revision or reapproval.1. Scope1.1 This guide identifies the core competencies necessaryfor the handling and forensic processing of mobile cellular(cell) telephones (phones). It app
3、lies to both first respondersand laboratory personnel.1.2 Different levels of cell phone analysis are discussed aswell as the basic skills required at each of these levels.1.3 This guide does not address core competencies forchip-off or MicroRead extraction methods.1.4 Refer to the Scientific Workin
4、g Group on Digital Evi-dence (SWGDE) Guidelines and Recommendations for Train-ing in Digital and Multimedia Evidence for general trainingrequirements of forensic practitioners.1.5 This standard does not purport to address all of thesafety concerns, if any, associated with its use. It is theresponsib
5、ility of the user of this standard to establish appro-priate safety and health practices and determine the applica-bility of regulatory limitations prior to use.2. Referenced Documents2.1 2.1 SWGDE Documents:2SWGDE Guidelines and Recommendations for Training inDigital and Multimedia EvidenceSWGDE Mi
6、nimum Requirements for Quality Assurance inthe Processing of Digital and Multimedia EvidenceSWGDEs Best Practices for Mobile Phone ForensicsSWGDE Best Practices for Examining Mobile Phones UsingJTAG2.2 NIST Documents:3NIST Special Publication 800-101 Revision 1Guidelineson Mobile Device Forensics3.
7、Significance and Use3.1 This guide provides an outline of the knowledge, skills,and abilities all practitioners of mobile phone forensics shouldpossess. The core competencies provide a basis for training andtesting programs. This basis is suitable for certification,competency, and proficiency testin
8、g.4. Core Competencies Overview4.1 First responders are defined as individuals that might beresponsible for the collection and minimal examination of amobile phone. There are two levels of first responders. Level 1first responders are individuals that collect or manually exam-ine mobile phones or bo
9、th. Level 2 first responders areindividuals that use a tool or software to extract data from themobile phone. Laboratory personnel are defined as individualsthat might be responsible for the collection and extensiveexamination of a mobile phone in a laboratory environmentand their competencies are o
10、utlined in Section 7 below. The useof any tool to download/extract data from a mobile phonenecessitates that proper training be completed by the individualusing that tool.4.2 The mobile phone forensics field continues to be dy-namic and shares some aspects of traditional computer foren-sics. A pract
11、itioner should have an overall understanding ofmobile forensics analysis and can remain current by readingtrade journals, taking classes, participating in professionalorganizations, taking continuing education, on-the-job training,and hands-on experience.4.3 An examiner shall adhere to:4.3.1 All app
12、ropriate standard operating procedures, andpolicies and4.3.2 A code of ethics including neutrality in the scientificprocesses.4.4 An examiner should apply all principles as defined inthe SWGDE Minimum Requirements for Quality Assurance inthe Processing of Digital and Multimedia Evidence.4.5 An exami
13、ner might be assigned casework that fallswithin one or more of the following levels and should,therefore, have the appropriate level of training to perform theexamination.4.6 The concept of levels of extraction for mobile devices isnot new to the mobile forensics field, but, it is important that1Thi
14、s guide is under the jurisdiction of ASTM Committee E30 on ForensicSciences and is the direct responsibility of Subcommittee E30.12 on Digital andMultimedia Evidence.Current edition approved Dec. 1, 2015. Published February 2016. DOI: 10.1520/E3046-15.2Available from the Scientific Working Group on
15、Digital Evidence (SWGDE),https:/www.swgde.org.3Available from National Institute of Standards and Technology (NIST), 100Bureau Dr., Stop 1070, Gaithersburg, MD 20899-1070, http:/www.nist.gov.Copyright ASTM International, 100 Barr Harbor Drive, PO Box C700, West Conshohocken, PA 19428-2959. United St
16、ates1the reader have a basic understanding of this concept to bestcomprehend the technical aspects of this document.4The levelof extraction technique used will be dependent on the requestand the specifics of the investigation. Higher levels of analysisrequire a more comprehensive examination, additi
17、onal skills,and might not be applicable nor possible for every device orsituation. The levels are:4.6.1 ManualA process that involves the manual manipu-lation of the keypad and handset display to document datapresent in the mobile phones internal memory.4.6.2 LogicalA process that provides access to
18、 the useraccessible files. This process will not generally provide accessto deleted data. This includes file system extractions.4.6.3 Hex Dumping/Joint Test Action Group (JTAG)Aprocess that provides the forensic examiner more direct accessto the raw information stored in flash memory of a mobilephon
19、es data. This might provide access to deleted data that hasnot been overwritten.4.6.4 Chip-OffA process that involves the direct readingand extraction of data as contained within a memory chip(generally requiring removal) to then conduct analysis on thedata extracted. This includes In-System Program
20、ming (ISP).4.6.5 MicroReadA process that involves the use of ahigh-power microscope to provide a physical view of theelectronic circuitry of memory. This would typically be usedwhen acquiring data from physically damaged memory chips.5. Core Competencies for First Responders (Level 1)5.1 The compete
21、ncies listed below outline the minimumrequirements for a first responder manually analyzing a mobilephone in the field without the use of an examination tool. Anexample of a Level 1 first responder would be a patrolofficer/case agent who encounters a mobile phone during thecourse of an investigation
22、.5.2 Three examples of manual examinations include: (1)browsing through a mobile phones handset to view the datastored in the phone, (2) photographing or videotaping the datafound on the screen, or (3) manually transcribing the data asviewed on the screen of a device.5.3 The Level 1 first responder
23、shall understand:5.3.1 Proper evidence handling, labeling, preservation, andseizure (for example, obtain the personal identification number(PIN) or pattern lock codes before seizure);5.3.2 Possible damage that can be caused to mobile devicesby exposure to fluids (bodily or other) as well as the prop
24、erevidence preservation and decontamination procedures basedon the substance(s) involved;5.3.3 Consequences and risks associated with manipulatingthe mobile phone to be examined;5.3.4 Placing a foreign subscriber identification module(SIM) or memory cards in different computers or mobilephones might
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
5000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ASTME30462015STANDARDGUIDEFORCORECOMPETENCIESFORMOBILEPHONEFORENSICS 手机 取证 核心 能力 标准 指南 PDF

链接地址:http://www.mydoc123.com/p-532284.html