DocumentCode :
2678345
Title :
BlackBerry IPD parsing for open source forensics
Author :
Fairbanks, Kevin ; Atreya, Kishore ; Owen, Henry
Author_Institution :
Sch. of Electr. & Comput. Eng., Georgia Inst. of Technol., Atlanta, GA, USA
fYear :
2009
fDate :
5-8 March 2009
Firstpage :
195
Lastpage :
199
Abstract :
In this paper, we present a framework for an open source BlackBerry Inter@ctive Pager Backup/Restore (IPD) file forensics tool. Our reasoning for developing an open source version of an IPD parser is to enhance the available open source forensic tools; an example of this category of tools is the Sleuth Kit. One intention of this work is to make users of BlackBerrys aware of the vulnerability of their information on their computers. Commercial tools such as the ABC Amber BlackBerry Converter application [6] presently exist. That commercial tool is able to gather the messages, contacts, SMS records, memos, call logs, and the task list from an IPD file. It then exports these records in a variety of forms. Another commercial tool by Paraben [4] can export data into closed source forensic tool kits such as Encase and FTK [5]. While still a work in progress, the preliminary results indicate that the method developed for extracting information is valid. The end goal of this research is to produce a model that can be adopted by open source forensic practitioners in their examinations and toolkit development.
Keywords :
file organisation; mobile computing; mobile handsets; public domain software; security of data; BlackBerry; IPD parser; Sleuth Kit; backup file forensics tool; interactive pager; open source forensics tool; restore file forensics tool; Forensics; Handheld computers;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Southeastcon, 2009. SOUTHEASTCON '09. IEEE
Conference_Location :
Atlanta, GA
Print_ISBN :
978-1-4244-3976-8
Electronic_ISBN :
978-1-4244-3978-2
Type :
conf
DOI :
10.1109/SECON.2009.5174075
Filename :
5174075
Link To Document :
بازگشت