Guidelines on PDA Forensics
Table of Contents
TABLE OF CONTENTS ............................................................................................................. V
LIST OF FIGURES ....................................................................................................................VII
LIST OF TABLES.................................................................................................................... VIII
EXECUTIVE SUMMARY........................................................................................................... 1
1. INTRODUCTION.................................................................................................................. 2
1.1 A
UTHORITY ...................................................................................................................... 2
1.2 P
URPOSE AND SCOPE ........................................................................................................ 2
1.3 A
UDIENCE AND ASSUMPTIONS......................................................................................... 3
1.4 D
OCUMENT STRUCTURE .................................................................................................. 3
2. BACKGROUND.................................................................................................................... 4
2.1 D
EVICE CHARACTERISTICS .............................................................................................. 4
2.2 P
ALM OS........................................................................................................................... 6
2.3 P
OCKET PC ....................................................................................................................... 9
2.4 L
INUX.............................................................................................................................. 12
2.5 G
ENERIC STATES ............................................................................................................ 14
3. FORENSIC TOOLS............................................................................................................. 16
3.1 P
ALM DD (PDD) ............................................................................................................... 17
3.2 P
ILOT-LINK..................................................................................................................... 17
3.3 POSE .............................................................................................................................. 17
3.4 PDA S
EIZURE ................................................................................................................. 18
3.5 ENCASE .......................................................................................................................... 18
3.6 D
UPLICATE DISK (DD) .................................................................................................... 19
3.7 M
ISCELLANEOUS TOOLS ................................................................................................ 19
3.8 C
USTOM TOOLS .............................................................................................................. 20
4. PROCEDURES AND PRINCIPLES.................................................................................. 21
4.1 ROLES AND RESPONSIBILITIES ....................................................................................... 21
4.2 E
VIDENTIAL PRINCIPLES ................................................................................................ 22
4.3 P
ROCEDURAL MODELS................................................................................................... 23
5. PRESERVATION ................................................................................................................ 26
5.1 S
EARCH ........................................................................................................................... 28
5.2 R
ECOGNITION ................................................................................................................. 28
5.3 DOCUMENTATION........................................................................................................... 29
5.4 C
OLLECTION ................................................................................................................... 30
v