Digital Investigation and Forensics on MTK-based Pirated Phone

Li Cheng,Lin Jiang,Mengfei He
DOI: https://doi.org/10.3969/j.issn.1003-0972.2014.04.028
2014-01-01
Abstract:MTK-based pirated phone with NAND flash was analyzed and the related forensics techniques were studied. The physical storage format of two key digital evidences ( call record and web history) in pirated phone was analyzed and parsed using reverse engineering. Based on this, the storage mechanism and forensics techniques for the two digital evidences with complicated operations were studied. The results showed that purposely deleting operation could be detected by analyzing low-level binary image. Furthermore, some of the records could be successfully re-trieved.
What problem does this paper attempt to address?