DocumentCode
2678345
Title
BlackBerry IPD parsing for open source forensics
Author
Fairbanks, Kevin ; Atreya, Kishore ; Owen, Henry
Author_Institution
Sch. of Electr. & Comput. Eng., Georgia Inst. of Technol., Atlanta, GA, USA
fYear
2009
fDate
5-8 March 2009
Firstpage
195
Lastpage
199
Abstract
In this paper, we present a framework for an open source BlackBerry Inter@ctive Pager Backup/Restore (IPD) file forensics tool. Our reasoning for developing an open source version of an IPD parser is to enhance the available open source forensic tools; an example of this category of tools is the Sleuth Kit. One intention of this work is to make users of BlackBerrys aware of the vulnerability of their information on their computers. Commercial tools such as the ABC Amber BlackBerry Converter application [6] presently exist. That commercial tool is able to gather the messages, contacts, SMS records, memos, call logs, and the task list from an IPD file. It then exports these records in a variety of forms. Another commercial tool by Paraben [4] can export data into closed source forensic tool kits such as Encase and FTK [5]. While still a work in progress, the preliminary results indicate that the method developed for extracting information is valid. The end goal of this research is to produce a model that can be adopted by open source forensic practitioners in their examinations and toolkit development.
Keywords
file organisation; mobile computing; mobile handsets; public domain software; security of data; BlackBerry; IPD parser; Sleuth Kit; backup file forensics tool; interactive pager; open source forensics tool; restore file forensics tool; Forensics; Handheld computers;
fLanguage
English
Publisher
ieee
Conference_Titel
Southeastcon, 2009. SOUTHEASTCON '09. IEEE
Conference_Location
Atlanta, GA
Print_ISBN
978-1-4244-3976-8
Electronic_ISBN
978-1-4244-3978-2
Type
conf
DOI
10.1109/SECON.2009.5174075
Filename
5174075
Link To Document