iOS forensics is defined as the discipline concerning the systematic retrieval, examination, and preservation of digital evidence from Apple devices that run on iOS, primarily iPhones. While iPads now run a separate but closely related OS called iPadOS, many forensic principles overlap, given their shared architecture. Slight differences may appear at the file system level in behavior and supported features, thus potentially affecting the forensic process. iOS and iPadOS are highly secure and give a hard time to investigators. The enforcement of advanced security considerations thus places them under certain operational constraints that forbid unauthorized access. In a nutshell, these operating systems have an XNU kernel basis and layered architecture that separates system services, user interfaces, and application frameworks to provide strict security boundaries. This chapter discusses acquisition methods, device security models, categories of obtainable data in forensic investigations, and available tools for iOS and iPadOS analysis. Data on iOS devices may include user data, such as contacts, messages, and photos, as well as system data, which include logs and settings; app data comprises preferences and internal databases. Forensic investigators use acquisition methods to gain access to this data; they can acquire it logically, where the contents are accessible to extract files, or physically, which provides a bit-for-bit copy of the device's storage. Several commercial forensic tools are in use, such as Cellebrite UFED, Belkasoft, Magnet AXIOM , oxygen forensics and elcomsoft and open-source options like Libimobiledevice, in an attempt to find ways through the iOS security scheme to find critical evidence without compromising data integrity at any stage of the forensic process.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

iOS Forensics Fundamentals

  • Ravi Sheth,
  • Keshav Kaushik,
  • Chandresh Parekha,
  • Narendrakumar Chayal

摘要

iOS forensics is defined as the discipline concerning the systematic retrieval, examination, and preservation of digital evidence from Apple devices that run on iOS, primarily iPhones. While iPads now run a separate but closely related OS called iPadOS, many forensic principles overlap, given their shared architecture. Slight differences may appear at the file system level in behavior and supported features, thus potentially affecting the forensic process. iOS and iPadOS are highly secure and give a hard time to investigators. The enforcement of advanced security considerations thus places them under certain operational constraints that forbid unauthorized access. In a nutshell, these operating systems have an XNU kernel basis and layered architecture that separates system services, user interfaces, and application frameworks to provide strict security boundaries. This chapter discusses acquisition methods, device security models, categories of obtainable data in forensic investigations, and available tools for iOS and iPadOS analysis. Data on iOS devices may include user data, such as contacts, messages, and photos, as well as system data, which include logs and settings; app data comprises preferences and internal databases. Forensic investigators use acquisition methods to gain access to this data; they can acquire it logically, where the contents are accessible to extract files, or physically, which provides a bit-for-bit copy of the device's storage. Several commercial forensic tools are in use, such as Cellebrite UFED, Belkasoft, Magnet AXIOM , oxygen forensics and elcomsoft and open-source options like Libimobiledevice, in an attempt to find ways through the iOS security scheme to find critical evidence without compromising data integrity at any stage of the forensic process.