SlideShare a Scribd company logo
1 of 32
GPS forensic analysis

     Damir Delija
     Insig2 2012
What we will talk about
• GPS
  – how to acquire evidence
  – where we can find GPS (device or just functionality)
• What we can find on a GPS
  – What tools and procedures to use ?
• Examples in EnCase: Magellan, TomTom, Exif
  data ..
  – examples slides are here as help/idea for practitioners
                                                        Page 2
Sources
• Materials are compilation of various sources
  – Celebrite “Portable GPS Forensic”
     http://www.cellebrite.com/gps.html
  – “GPS Device Acquisition and Examination”, CEIC
    2012 by Nathen Langfeldt, Guidance Software, Inc
  – “Forenzika GPS uređaja”, Filip
    Baričevid, DATAFOCUS 2012

                   GPS Device Acquisition and Examination   Page 3
GPS
• GPS -Global Positioning System
• http://en.wikipedia.org/wiki/Global_Positioni
  ng_System
• Not only GPS, but other systems
  Russia, China, India, EU ..

                                             Page 4
GPS embedded in another device
•   Mobiles / smartphones
•   Tablets – PC’s
•   car, robots (?)
•   Usually direct connection to Internet and live
    map access

                                                 Page 5
GPS standalone devices
•   Garmin
•   Magellan
•   MIO
•   TomTom

• Maps are prepared and sold by vendor
• Maybe small vendors will go extinct
Forensic tools and GPS
• Today all commercial tool have support GPS data
  extraction, level can vary, depends on model,
  encryption...
• Idea is to get out geolocation data and put in on the
  map, also and all other available data from device
   – location data can be obtained from other sources too
• There is a BIG difference among mobile device forensic
  tools and general purpose forensic tools
                                                            Page 7
Forensic Tool Examples
• EnCase - general purpose forensic tool
    – support for geolocation data extracted from evidence as part of smartphone support
      module
    – support for standalone device as disk image and enscripts to extract data
• UFED ultimate / UFED physical analyzer - mobile device forensic tool
    – support only for geolocation data extracted from evidence as part of smartphone
      support (some magic can be done too)
    – support for standalone device but in a way as mobile phones or smartphones
    – support for encrypted logs and data on some standalone devices (tom-tom)
    – python scripts for additional processing
• It is almost impossible to mix results of both tools ....
    – it takes a lot of effort
    – there is no standardization (like E01 format in traditional digital forensic)

                                                                                        Page 8
GPS information
1.   travel path
2.   trackpoints (coordinates)
3.   waypoints (coordinates and names)
4.   route (list of waypoint)
5.   saved locations
6.   video, pictures
7.   all other available data from device related to
     locations / positions

                                                       Page 9
Example Tom-Tom data
  • *.cfg – locations.
  • ttgo.bif, ttnavigator.bif –
    general info on
    device, S/N, model ...
  • password (encrypted)
  • settings.dat – IDs, user data
    ...
  • triplog files – encrypted files
    – user route data
                                      Page 10
GPS seizure
•   Device seizure is the first step and can be difficult

•   These devices send and receive signals when
    powered on – precautions need to be taken

•   How do you stop a GPS from updating its location?

     −   If possible, a Faraday bag

•   What if a Faraday bag is not available???

•   Once the device is protected, what next?

                                                            •   Page 11
                                                                          Page 11
What is needed for acquisition
• Once the device has been seized, the next
  logical step is to acquire the device.
• The following is a list of tools that could be
  important:

     • USB cable to connect the device to an
       acquisition machine/tool
     • Faraday bag (as mentioned previously)
     • write blocker (either software or hardware
       will be acceptable)
     • Card reader (optional)

                                                    Page 12
                                                         Page 12
Examples
• ENCase details in CEIC 2012 “GPS Device
  Acquisition and Examination”
  – EnCase and Garmin
  – EnCase and TomTom
  – Encase and Magellan
  – Encase and Exif data
                      Master Title          Page 13
                                                 Page 13
EnCase and TomTom/Garmin
•   Encase can acquire Garmin and TomTom GPS devices
    trough the use of a write-block device


Note:
• If a media card is in use by the
    GPS device, the card must be
    removed and imaged separately.
    If it is not removed, the media
    card may be the only thing that
    shows up during a preview
                                                       Page 14
                                                            Page 14
EnCase and Magellan
• Similarly to Garmin or TomTom, acquisition of a
  Magellan GPS device can be accomplished by
  using a write-block device and a forensic
  acquisition tool (EnCase)
• Some Magellan's may not be imaged in this
  fashion
• The only solution may be to use a backup of the
  device on a media card supported by the device

• Or to use another tool like UFED .


                                                    Page 15
                                                         Page 15
Garmin device examination through EnCase
     More can be done for Garmin .gpx...
•   Aside from viewing the .gpx file within EnCase or an XML
    browser, the file can be viewed in Google Earth.
•   This can be accomplished one of two ways:
      − Bring the .gpx file out of EnCase
        and use a website to convert the
        file to KML
      − This site is used for the
        conversion:
         http://www.gpsvisualizer.com/map_input?form=googleearth




                                                                   Page 16
                                                                        Page 16
EnCase Garmin examination

•   Once at this
    site, the settings
    can be observed.




                            Page 17
                                 Page 17
EnCase Garmin examination
• Click the “create KML”
  button
• A new page will be loaded
• The KML file can then be
  downloaded




                              Page 18
                                   Page 18
EnCase Garmin examination
•   With the KML file
    brought into Google
    Earth, we can begin
    the examination.

•   When it is brought
    in, the data will show
    up under Temporary
    Places.




                             Page 19
                                  Page 19
EnCase Garmin examination
             • The data is broken down into two main pieces:

                 − Waypoints
                 − Tracks
             • Waypoints contains data like address book entries

             • Tracks can contain data from recent routes that were
               traveled



                                                               Page 20
                                                                    Page 20
EnCase Garmin examination
•   An example of a Waypoint




                               Page 21
                                    Page 21
EnCase Garmin examination
•   The other option is to bring the KML
    file straight into Google Earth

•   If this option is used, you will be
    presented with three options.

•   “Create KML LineStrings” is
    unchecked by default

      − It is recommended
        that this be
        checked


                                           Page 22
                                                Page 22
EnCase Garmin examination
•   In summary, Garmin GPS devices are
    super easy to examine and can be the
    most fruitful
•   The data is easy to access and should
    not be overlooked

•   Some upcoming challenges:
      − Who uses a portable GPS device?
      − Garmin now has multiple apps
        available for download


                                            Page 23
                                                 Page 23
EnCase TomTom examination
•   TomTom GPS devices have been
    around for some time and are
    widely used

•   The examination of these devices
    is a bit different

•   TomTom GPS devices can in some
    ways store more info than Garmin




                                       Page 24
                                            Page 24
EnCase TomTom examination
•   With TomTom GPS devices, a few
    files will be of interest to us

•   To start, we can look at the
    CurrentMap.dat

•   In this example the file is sitting
    at the root of the device

•   This will give the name of the
    map that is currently in use

•   As you can see in the
    example, “North_America_2GB”
    is the name of the map being
    used                                  Page 25
                                               Page 25
EnCase TomTom examination
•   In summary, TomTom GPS can be examined
    through the use of an EnScript module or
    third-party tools
•   If trip logs are present, a request could be
    made to TomTom in an attempt to get the
    logs decrypted (or trough UFED tools)
•   Some upcoming challenges:
      − Who uses a portable
        GPS device?
      − TomTom now has
        multiple apps available
        for download

                                                   Page 26
                                                        Page 26
EnCase Magellan examination
• Magellan devices can be more difficult in
  part because of the the acquisition
  process

• Some Magellan devices may not be able
  to be acquired at the physical level

• In those cases it might be possible to
  create a backup through the device
  directly to an SD card

• The SD card containing the backup can
  then be acquired


                                              Page 27
                                                   Page 27
EnCase Magellan examination
•   In summary, Magellan GPS devices are
    the most difficult to examine due to the
    limited information available
•   Though third-party tools are
    available, their ability to parse data may
    be limited by the actual models
    supported
•   Some upcoming challenges:
      − Who uses a portable
        GPS device?
      − Magellan now has
        multiple apps
        available for
        download
                                                 Page 28
                                                      Page 28
Examination of EXIF GPS Data
• The examination of EXIF GPS
  can be made simple
• This data can be extracted
  and made invaluable through
  the use of various third-party
  tools or an EnScript program
• The “Exif GPS Information
  Reader” EnScript module will
  be used here

                                   The images used here were taken with a BlackBerry

                                                                             Page 29
                                                                                  Page 29
Examination of EXIF GPS Data



•   The exported KML file can
    be viewed in Google Earth




                                Page 30
                                     Page 30
Conclusion ?
• It is wild area
• in developement, new models, new features,
  encryption, applications od devices
• legal issuses
• a lot to learn
                    Master Title         Page 31
                                               Page 31
Questions ?


damir.delija@insig2.hr




        Master Title     Page 32
                              Page 32

More Related Content

What's hot

Global positioning system (gps)
Global positioning system (gps)Global positioning system (gps)
Global positioning system (gps)Gokul Saud
 
Architecting the ArcGIS Platform
Architecting the ArcGIS PlatformArchitecting the ArcGIS Platform
Architecting the ArcGIS PlatformEsri UK
 
Antropological Comparision Between Human and Non-human Skeleton Remains
Antropological Comparision Between Human and Non-human Skeleton RemainsAntropological Comparision Between Human and Non-human Skeleton Remains
Antropological Comparision Between Human and Non-human Skeleton RemainsG.S Shaktawat
 
SKULL RECONSTRUCTION
SKULL RECONSTRUCTIONSKULL RECONSTRUCTION
SKULL RECONSTRUCTIONpragati241997
 
Spot 7 satellite
Spot 7 satelliteSpot 7 satellite
Spot 7 satelliteNimra Butt
 
Signature verification in biometrics
Signature verification in biometricsSignature verification in biometrics
Signature verification in biometricsSwapnil Bangera
 

What's hot (20)

Ambis latest
Ambis latestAmbis latest
Ambis latest
 
Global positioning system (gps)
Global positioning system (gps)Global positioning system (gps)
Global positioning system (gps)
 
Geographic information system
Geographic information systemGeographic information system
Geographic information system
 
Introduction to gis
Introduction to gisIntroduction to gis
Introduction to gis
 
Gps and its application
Gps and its applicationGps and its application
Gps and its application
 
NIBIN
NIBINNIBIN
NIBIN
 
Architecting the ArcGIS Platform
Architecting the ArcGIS PlatformArchitecting the ArcGIS Platform
Architecting the ArcGIS Platform
 
Antropological Comparision Between Human and Non-human Skeleton Remains
Antropological Comparision Between Human and Non-human Skeleton RemainsAntropological Comparision Between Human and Non-human Skeleton Remains
Antropological Comparision Between Human and Non-human Skeleton Remains
 
Microwave remote sensing
Microwave remote sensingMicrowave remote sensing
Microwave remote sensing
 
SKULL RECONSTRUCTION
SKULL RECONSTRUCTIONSKULL RECONSTRUCTION
SKULL RECONSTRUCTION
 
Spot 7 satellite
Spot 7 satelliteSpot 7 satellite
Spot 7 satellite
 
Gps surveying
Gps surveyingGps surveying
Gps surveying
 
Mobile mapping
Mobile mappingMobile mapping
Mobile mapping
 
My ppt on gis
My ppt on gisMy ppt on gis
My ppt on gis
 
What is web gis
What is web gisWhat is web gis
What is web gis
 
Introduction to GNSS (1)
Introduction to GNSS (1)Introduction to GNSS (1)
Introduction to GNSS (1)
 
Signature verification in biometrics
Signature verification in biometricsSignature verification in biometrics
Signature verification in biometrics
 
sexualoffences-
sexualoffences-sexualoffences-
sexualoffences-
 
Remote sensing
Remote sensing Remote sensing
Remote sensing
 
Global positioning system
Global positioning systemGlobal positioning system
Global positioning system
 

Similar to Gps

hiking_tuto.pdf
hiking_tuto.pdfhiking_tuto.pdf
hiking_tuto.pdfSaka32
 
Topo na9manual
Topo na9manualTopo na9manual
Topo na9manuallatium
 
Apps, Maps and Drones: Technology for the Forest Landowner and Manager
Apps, Maps and Drones: Technology for the Forest Landowner and ManagerApps, Maps and Drones: Technology for the Forest Landowner and Manager
Apps, Maps and Drones: Technology for the Forest Landowner and ManagerArkansas Forestry Association
 
Collector app mipn presentation
Collector app mipn presentationCollector app mipn presentation
Collector app mipn presentationslogankoby
 
International Shipping Finals/Group A /C.P.I
International Shipping Finals/Group A /C.P.IInternational Shipping Finals/Group A /C.P.I
International Shipping Finals/Group A /C.P.IJoshua Morisson
 
Maps and Apps
Maps and AppsMaps and Apps
Maps and AppsAddy Pope
 
2018 GIS in Education: Car Racing With Collector
2018 GIS in Education: Car Racing With Collector2018 GIS in Education: Car Racing With Collector
2018 GIS in Education: Car Racing With CollectorGIS in the Rockies
 
Geopaparazzi workshop on FOSS4G2015 Seoul
Geopaparazzi workshop on FOSS4G2015 SeoulGeopaparazzi workshop on FOSS4G2015 Seoul
Geopaparazzi workshop on FOSS4G2015 SeoulHirofumi Hayashi
 
Navigating on bikes using a smartphone
Navigating on bikes using a smartphoneNavigating on bikes using a smartphone
Navigating on bikes using a smartphoneHugh Davis
 
Londe mobile devices appropriate uses
Londe mobile devices appropriate usesLonde mobile devices appropriate uses
Londe mobile devices appropriate usesGeCo in the Rockies
 
Operating System for Undergraduates. level 200 course
Operating System for Undergraduates. level 200 courseOperating System for Undergraduates. level 200 course
Operating System for Undergraduates. level 200 courseReubenMawukoDordunu
 
Memory forensics.pptx
Memory forensics.pptxMemory forensics.pptx
Memory forensics.pptx9905234521
 
Network Implementation and Support Lesson 09 Group Policy - Eric Vanderburg
Network Implementation and Support Lesson 09   Group Policy - Eric VanderburgNetwork Implementation and Support Lesson 09   Group Policy - Eric Vanderburg
Network Implementation and Support Lesson 09 Group Policy - Eric VanderburgEric Vanderburg
 

Similar to Gps (20)

Introduction to Digimap's Ordnance Survey Collection
Introduction to Digimap's Ordnance Survey CollectionIntroduction to Digimap's Ordnance Survey Collection
Introduction to Digimap's Ordnance Survey Collection
 
hiking_tuto.pdf
hiking_tuto.pdfhiking_tuto.pdf
hiking_tuto.pdf
 
Topo na9manual
Topo na9manualTopo na9manual
Topo na9manual
 
Apps, Maps and Drones: Technology for the Forest Landowner and Manager
Apps, Maps and Drones: Technology for the Forest Landowner and ManagerApps, Maps and Drones: Technology for the Forest Landowner and Manager
Apps, Maps and Drones: Technology for the Forest Landowner and Manager
 
Collector app mipn presentation
Collector app mipn presentationCollector app mipn presentation
Collector app mipn presentation
 
International Shipping Finals/Group A /C.P.I
International Shipping Finals/Group A /C.P.IInternational Shipping Finals/Group A /C.P.I
International Shipping Finals/Group A /C.P.I
 
Maps and Apps
Maps and AppsMaps and Apps
Maps and Apps
 
Hardware
HardwareHardware
Hardware
 
2018 GIS in Education: Car Racing With Collector
2018 GIS in Education: Car Racing With Collector2018 GIS in Education: Car Racing With Collector
2018 GIS in Education: Car Racing With Collector
 
manual global mapper
manual global mappermanual global mapper
manual global mapper
 
Geopaparazzi workshop on FOSS4G2015 Seoul
Geopaparazzi workshop on FOSS4G2015 SeoulGeopaparazzi workshop on FOSS4G2015 Seoul
Geopaparazzi workshop on FOSS4G2015 Seoul
 
Navigating on bikes using a smartphone
Navigating on bikes using a smartphoneNavigating on bikes using a smartphone
Navigating on bikes using a smartphone
 
3.1 storage devices_and_media (1)
3.1 storage devices_and_media (1)3.1 storage devices_and_media (1)
3.1 storage devices_and_media (1)
 
Londe mobile devices appropriate uses
Londe mobile devices appropriate usesLonde mobile devices appropriate uses
Londe mobile devices appropriate uses
 
Storage Technologies
Storage TechnologiesStorage Technologies
Storage Technologies
 
Operating System for Undergraduates. level 200 course
Operating System for Undergraduates. level 200 courseOperating System for Undergraduates. level 200 course
Operating System for Undergraduates. level 200 course
 
COMPUTER STORAGE
COMPUTER STORAGECOMPUTER STORAGE
COMPUTER STORAGE
 
Memory forensics.pptx
Memory forensics.pptxMemory forensics.pptx
Memory forensics.pptx
 
Research skills
Research skillsResearch skills
Research skills
 
Network Implementation and Support Lesson 09 Group Policy - Eric Vanderburg
Network Implementation and Support Lesson 09   Group Policy - Eric VanderburgNetwork Implementation and Support Lesson 09   Group Policy - Eric Vanderburg
Network Implementation and Support Lesson 09 Group Policy - Eric Vanderburg
 

More from Damir Delija

6414 preparation and planning of the development of a proficiency test in the...
6414 preparation and planning of the development of a proficiency test in the...6414 preparation and planning of the development of a proficiency test in the...
6414 preparation and planning of the development of a proficiency test in the...Damir Delija
 
6528 opensource intelligence as the new introduction in the graduate cybersec...
6528 opensource intelligence as the new introduction in the graduate cybersec...6528 opensource intelligence as the new introduction in the graduate cybersec...
6528 opensource intelligence as the new introduction in the graduate cybersec...Damir Delija
 
Uvođenje novih sadržaja u nastavu digitalne forenzike i kibernetičke sigurnos...
Uvođenje novih sadržaja u nastavu digitalne forenzike i kibernetičke sigurnos...Uvođenje novih sadržaja u nastavu digitalne forenzike i kibernetičke sigurnos...
Uvođenje novih sadržaja u nastavu digitalne forenzike i kibernetičke sigurnos...Damir Delija
 
Remote forensics fsec2016 delija draft
Remote forensics fsec2016 delija draftRemote forensics fsec2016 delija draft
Remote forensics fsec2016 delija draftDamir Delija
 
Ecase direct servlet acess v1
Ecase direct servlet acess  v1Ecase direct servlet acess  v1
Ecase direct servlet acess v1Damir Delija
 
Cis 2016 moč forenzičikih alata 1.1
Cis 2016 moč forenzičikih alata 1.1Cis 2016 moč forenzičikih alata 1.1
Cis 2016 moč forenzičikih alata 1.1Damir Delija
 
Draft current state of digital forensic and data science
Draft current state of digital forensic and data science Draft current state of digital forensic and data science
Draft current state of digital forensic and data science Damir Delija
 
Why i hate digital forensics - draft
Why i hate digital forensics  -  draftWhy i hate digital forensics  -  draft
Why i hate digital forensics - draftDamir Delija
 
Concepts and Methodology in Mobile Devices Digital Forensics Education and Tr...
Concepts and Methodology in Mobile Devices Digital Forensics Education and Tr...Concepts and Methodology in Mobile Devices Digital Forensics Education and Tr...
Concepts and Methodology in Mobile Devices Digital Forensics Education and Tr...Damir Delija
 
Deep Web and Digital Investigations
Deep Web and Digital Investigations Deep Web and Digital Investigations
Deep Web and Digital Investigations Damir Delija
 
Datafoucs 2014 on line digital forensic investigations damir delija 2
Datafoucs 2014 on line digital forensic investigations damir delija 2Datafoucs 2014 on line digital forensic investigations damir delija 2
Datafoucs 2014 on line digital forensic investigations damir delija 2Damir Delija
 
EnCase Enterprise Basic File Collection
EnCase Enterprise Basic File Collection EnCase Enterprise Basic File Collection
EnCase Enterprise Basic File Collection Damir Delija
 
Olaf extension td3 inisg2 2
Olaf extension td3 inisg2 2Olaf extension td3 inisg2 2
Olaf extension td3 inisg2 2Damir Delija
 
LTEC 2013 - EnCase v7.08.01 presentation
LTEC 2013 - EnCase v7.08.01 presentation LTEC 2013 - EnCase v7.08.01 presentation
LTEC 2013 - EnCase v7.08.01 presentation Damir Delija
 
Moguće tehnike pristupa forenzckim podacima 09.2013
Moguće tehnike pristupa forenzckim podacima 09.2013 Moguće tehnike pristupa forenzckim podacima 09.2013
Moguće tehnike pristupa forenzckim podacima 09.2013 Damir Delija
 
Usage aspects techniques for enterprise forensics data analytics tools
Usage aspects techniques for enterprise forensics data analytics toolsUsage aspects techniques for enterprise forensics data analytics tools
Usage aspects techniques for enterprise forensics data analytics toolsDamir Delija
 
Cis 2013 digitalna forenzika osvrt
Cis 2013 digitalna forenzika osvrt  Cis 2013 digitalna forenzika osvrt
Cis 2013 digitalna forenzika osvrt Damir Delija
 
Aix workload manager
Aix workload managerAix workload manager
Aix workload managerDamir Delija
 

More from Damir Delija (20)

6414 preparation and planning of the development of a proficiency test in the...
6414 preparation and planning of the development of a proficiency test in the...6414 preparation and planning of the development of a proficiency test in the...
6414 preparation and planning of the development of a proficiency test in the...
 
6528 opensource intelligence as the new introduction in the graduate cybersec...
6528 opensource intelligence as the new introduction in the graduate cybersec...6528 opensource intelligence as the new introduction in the graduate cybersec...
6528 opensource intelligence as the new introduction in the graduate cybersec...
 
Uvođenje novih sadržaja u nastavu digitalne forenzike i kibernetičke sigurnos...
Uvođenje novih sadržaja u nastavu digitalne forenzike i kibernetičke sigurnos...Uvođenje novih sadržaja u nastavu digitalne forenzike i kibernetičke sigurnos...
Uvođenje novih sadržaja u nastavu digitalne forenzike i kibernetičke sigurnos...
 
Remote forensics fsec2016 delija draft
Remote forensics fsec2016 delija draftRemote forensics fsec2016 delija draft
Remote forensics fsec2016 delija draft
 
Ecase direct servlet acess v1
Ecase direct servlet acess  v1Ecase direct servlet acess  v1
Ecase direct servlet acess v1
 
Cis 2016 moč forenzičikih alata 1.1
Cis 2016 moč forenzičikih alata 1.1Cis 2016 moč forenzičikih alata 1.1
Cis 2016 moč forenzičikih alata 1.1
 
Draft current state of digital forensic and data science
Draft current state of digital forensic and data science Draft current state of digital forensic and data science
Draft current state of digital forensic and data science
 
Why i hate digital forensics - draft
Why i hate digital forensics  -  draftWhy i hate digital forensics  -  draft
Why i hate digital forensics - draft
 
Concepts and Methodology in Mobile Devices Digital Forensics Education and Tr...
Concepts and Methodology in Mobile Devices Digital Forensics Education and Tr...Concepts and Methodology in Mobile Devices Digital Forensics Education and Tr...
Concepts and Methodology in Mobile Devices Digital Forensics Education and Tr...
 
Deep Web and Digital Investigations
Deep Web and Digital Investigations Deep Web and Digital Investigations
Deep Web and Digital Investigations
 
Datafoucs 2014 on line digital forensic investigations damir delija 2
Datafoucs 2014 on line digital forensic investigations damir delija 2Datafoucs 2014 on line digital forensic investigations damir delija 2
Datafoucs 2014 on line digital forensic investigations damir delija 2
 
EnCase Enterprise Basic File Collection
EnCase Enterprise Basic File Collection EnCase Enterprise Basic File Collection
EnCase Enterprise Basic File Collection
 
Ocr and EnCase
Ocr and EnCaseOcr and EnCase
Ocr and EnCase
 
Olaf extension td3 inisg2 2
Olaf extension td3 inisg2 2Olaf extension td3 inisg2 2
Olaf extension td3 inisg2 2
 
LTEC 2013 - EnCase v7.08.01 presentation
LTEC 2013 - EnCase v7.08.01 presentation LTEC 2013 - EnCase v7.08.01 presentation
LTEC 2013 - EnCase v7.08.01 presentation
 
Moguće tehnike pristupa forenzckim podacima 09.2013
Moguće tehnike pristupa forenzckim podacima 09.2013 Moguće tehnike pristupa forenzckim podacima 09.2013
Moguće tehnike pristupa forenzckim podacima 09.2013
 
Usage aspects techniques for enterprise forensics data analytics tools
Usage aspects techniques for enterprise forensics data analytics toolsUsage aspects techniques for enterprise forensics data analytics tools
Usage aspects techniques for enterprise forensics data analytics tools
 
Cis 2013 digitalna forenzika osvrt
Cis 2013 digitalna forenzika osvrt  Cis 2013 digitalna forenzika osvrt
Cis 2013 digitalna forenzika osvrt
 
Ibm aix wlm idea
Ibm aix wlm ideaIbm aix wlm idea
Ibm aix wlm idea
 
Aix workload manager
Aix workload managerAix workload manager
Aix workload manager
 

Recently uploaded

24 ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH SỞ GIÁO DỤC HẢI DƯ...
24 ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH SỞ GIÁO DỤC HẢI DƯ...24 ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH SỞ GIÁO DỤC HẢI DƯ...
24 ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH SỞ GIÁO DỤC HẢI DƯ...Nguyen Thanh Tu Collection
 
Major project report on Tata Motors and its marketing strategies
Major project report on Tata Motors and its marketing strategiesMajor project report on Tata Motors and its marketing strategies
Major project report on Tata Motors and its marketing strategiesAmanpreetKaur157993
 
ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH FORM 50 CÂU TRẮC NGHI...
ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH FORM 50 CÂU TRẮC NGHI...ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH FORM 50 CÂU TRẮC NGHI...
ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH FORM 50 CÂU TRẮC NGHI...Nguyen Thanh Tu Collection
 
SURVEY I created for uni project research
SURVEY I created for uni project researchSURVEY I created for uni project research
SURVEY I created for uni project researchCaitlinCummins3
 
The Liver & Gallbladder (Anatomy & Physiology).pptx
The Liver &  Gallbladder (Anatomy & Physiology).pptxThe Liver &  Gallbladder (Anatomy & Physiology).pptx
The Liver & Gallbladder (Anatomy & Physiology).pptxVishal Singh
 
male presentation...pdf.................
male presentation...pdf.................male presentation...pdf.................
male presentation...pdf.................MirzaAbrarBaig5
 
Spellings Wk 4 and Wk 5 for Grade 4 at CAPS
Spellings Wk 4 and Wk 5 for Grade 4 at CAPSSpellings Wk 4 and Wk 5 for Grade 4 at CAPS
Spellings Wk 4 and Wk 5 for Grade 4 at CAPSAnaAcapella
 
MuleSoft Integration with AWS Textract | Calling AWS Textract API |AWS - Clou...
MuleSoft Integration with AWS Textract | Calling AWS Textract API |AWS - Clou...MuleSoft Integration with AWS Textract | Calling AWS Textract API |AWS - Clou...
MuleSoft Integration with AWS Textract | Calling AWS Textract API |AWS - Clou...MysoreMuleSoftMeetup
 
Trauma-Informed Leadership - Five Practical Principles
Trauma-Informed Leadership - Five Practical PrinciplesTrauma-Informed Leadership - Five Practical Principles
Trauma-Informed Leadership - Five Practical PrinciplesPooky Knightsmith
 
e-Sealing at EADTU by Kamakshi Rajagopal
e-Sealing at EADTU by Kamakshi Rajagopale-Sealing at EADTU by Kamakshi Rajagopal
e-Sealing at EADTU by Kamakshi RajagopalEADTU
 
會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽
會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽
會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽中 央社
 
TỔNG HỢP HƠN 100 ĐỀ THI THỬ TỐT NGHIỆP THPT TOÁN 2024 - TỪ CÁC TRƯỜNG, TRƯỜNG...
TỔNG HỢP HƠN 100 ĐỀ THI THỬ TỐT NGHIỆP THPT TOÁN 2024 - TỪ CÁC TRƯỜNG, TRƯỜNG...TỔNG HỢP HƠN 100 ĐỀ THI THỬ TỐT NGHIỆP THPT TOÁN 2024 - TỪ CÁC TRƯỜNG, TRƯỜNG...
TỔNG HỢP HƠN 100 ĐỀ THI THỬ TỐT NGHIỆP THPT TOÁN 2024 - TỪ CÁC TRƯỜNG, TRƯỜNG...Nguyen Thanh Tu Collection
 
AIM of Education-Teachers Training-2024.ppt
AIM of Education-Teachers Training-2024.pptAIM of Education-Teachers Training-2024.ppt
AIM of Education-Teachers Training-2024.pptNishitharanjan Rout
 
8 Tips for Effective Working Capital Management
8 Tips for Effective Working Capital Management8 Tips for Effective Working Capital Management
8 Tips for Effective Working Capital ManagementMBA Assignment Experts
 
Transparency, Recognition and the role of eSealing - Ildiko Mazar and Koen No...
Transparency, Recognition and the role of eSealing - Ildiko Mazar and Koen No...Transparency, Recognition and the role of eSealing - Ildiko Mazar and Koen No...
Transparency, Recognition and the role of eSealing - Ildiko Mazar and Koen No...EADTU
 
How To Create Editable Tree View in Odoo 17
How To Create Editable Tree View in Odoo 17How To Create Editable Tree View in Odoo 17
How To Create Editable Tree View in Odoo 17Celine George
 
Stl Algorithms in C++ jjjjjjjjjjjjjjjjjj
Stl Algorithms in C++ jjjjjjjjjjjjjjjjjjStl Algorithms in C++ jjjjjjjjjjjjjjjjjj
Stl Algorithms in C++ jjjjjjjjjjjjjjjjjjMohammed Sikander
 

Recently uploaded (20)

24 ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH SỞ GIÁO DỤC HẢI DƯ...
24 ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH SỞ GIÁO DỤC HẢI DƯ...24 ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH SỞ GIÁO DỤC HẢI DƯ...
24 ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH SỞ GIÁO DỤC HẢI DƯ...
 
Major project report on Tata Motors and its marketing strategies
Major project report on Tata Motors and its marketing strategiesMajor project report on Tata Motors and its marketing strategies
Major project report on Tata Motors and its marketing strategies
 
Mattingly "AI & Prompt Design: Named Entity Recognition"
Mattingly "AI & Prompt Design: Named Entity Recognition"Mattingly "AI & Prompt Design: Named Entity Recognition"
Mattingly "AI & Prompt Design: Named Entity Recognition"
 
ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH FORM 50 CÂU TRẮC NGHI...
ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH FORM 50 CÂU TRẮC NGHI...ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH FORM 50 CÂU TRẮC NGHI...
ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH FORM 50 CÂU TRẮC NGHI...
 
SURVEY I created for uni project research
SURVEY I created for uni project researchSURVEY I created for uni project research
SURVEY I created for uni project research
 
The Liver & Gallbladder (Anatomy & Physiology).pptx
The Liver &  Gallbladder (Anatomy & Physiology).pptxThe Liver &  Gallbladder (Anatomy & Physiology).pptx
The Liver & Gallbladder (Anatomy & Physiology).pptx
 
male presentation...pdf.................
male presentation...pdf.................male presentation...pdf.................
male presentation...pdf.................
 
Spellings Wk 4 and Wk 5 for Grade 4 at CAPS
Spellings Wk 4 and Wk 5 for Grade 4 at CAPSSpellings Wk 4 and Wk 5 for Grade 4 at CAPS
Spellings Wk 4 and Wk 5 for Grade 4 at CAPS
 
MuleSoft Integration with AWS Textract | Calling AWS Textract API |AWS - Clou...
MuleSoft Integration with AWS Textract | Calling AWS Textract API |AWS - Clou...MuleSoft Integration with AWS Textract | Calling AWS Textract API |AWS - Clou...
MuleSoft Integration with AWS Textract | Calling AWS Textract API |AWS - Clou...
 
Trauma-Informed Leadership - Five Practical Principles
Trauma-Informed Leadership - Five Practical PrinciplesTrauma-Informed Leadership - Five Practical Principles
Trauma-Informed Leadership - Five Practical Principles
 
VAMOS CUIDAR DO NOSSO PLANETA! .
VAMOS CUIDAR DO NOSSO PLANETA!                    .VAMOS CUIDAR DO NOSSO PLANETA!                    .
VAMOS CUIDAR DO NOSSO PLANETA! .
 
e-Sealing at EADTU by Kamakshi Rajagopal
e-Sealing at EADTU by Kamakshi Rajagopale-Sealing at EADTU by Kamakshi Rajagopal
e-Sealing at EADTU by Kamakshi Rajagopal
 
會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽
會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽
會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽會考英聽
 
TỔNG HỢP HƠN 100 ĐỀ THI THỬ TỐT NGHIỆP THPT TOÁN 2024 - TỪ CÁC TRƯỜNG, TRƯỜNG...
TỔNG HỢP HƠN 100 ĐỀ THI THỬ TỐT NGHIỆP THPT TOÁN 2024 - TỪ CÁC TRƯỜNG, TRƯỜNG...TỔNG HỢP HƠN 100 ĐỀ THI THỬ TỐT NGHIỆP THPT TOÁN 2024 - TỪ CÁC TRƯỜNG, TRƯỜNG...
TỔNG HỢP HƠN 100 ĐỀ THI THỬ TỐT NGHIỆP THPT TOÁN 2024 - TỪ CÁC TRƯỜNG, TRƯỜNG...
 
ESSENTIAL of (CS/IT/IS) class 07 (Networks)
ESSENTIAL of (CS/IT/IS) class 07 (Networks)ESSENTIAL of (CS/IT/IS) class 07 (Networks)
ESSENTIAL of (CS/IT/IS) class 07 (Networks)
 
AIM of Education-Teachers Training-2024.ppt
AIM of Education-Teachers Training-2024.pptAIM of Education-Teachers Training-2024.ppt
AIM of Education-Teachers Training-2024.ppt
 
8 Tips for Effective Working Capital Management
8 Tips for Effective Working Capital Management8 Tips for Effective Working Capital Management
8 Tips for Effective Working Capital Management
 
Transparency, Recognition and the role of eSealing - Ildiko Mazar and Koen No...
Transparency, Recognition and the role of eSealing - Ildiko Mazar and Koen No...Transparency, Recognition and the role of eSealing - Ildiko Mazar and Koen No...
Transparency, Recognition and the role of eSealing - Ildiko Mazar and Koen No...
 
How To Create Editable Tree View in Odoo 17
How To Create Editable Tree View in Odoo 17How To Create Editable Tree View in Odoo 17
How To Create Editable Tree View in Odoo 17
 
Stl Algorithms in C++ jjjjjjjjjjjjjjjjjj
Stl Algorithms in C++ jjjjjjjjjjjjjjjjjjStl Algorithms in C++ jjjjjjjjjjjjjjjjjj
Stl Algorithms in C++ jjjjjjjjjjjjjjjjjj
 

Gps

  • 1. GPS forensic analysis Damir Delija Insig2 2012
  • 2. What we will talk about • GPS – how to acquire evidence – where we can find GPS (device or just functionality) • What we can find on a GPS – What tools and procedures to use ? • Examples in EnCase: Magellan, TomTom, Exif data .. – examples slides are here as help/idea for practitioners Page 2
  • 3. Sources • Materials are compilation of various sources – Celebrite “Portable GPS Forensic” http://www.cellebrite.com/gps.html – “GPS Device Acquisition and Examination”, CEIC 2012 by Nathen Langfeldt, Guidance Software, Inc – “Forenzika GPS uređaja”, Filip Baričevid, DATAFOCUS 2012 GPS Device Acquisition and Examination Page 3
  • 4. GPS • GPS -Global Positioning System • http://en.wikipedia.org/wiki/Global_Positioni ng_System • Not only GPS, but other systems Russia, China, India, EU .. Page 4
  • 5. GPS embedded in another device • Mobiles / smartphones • Tablets – PC’s • car, robots (?) • Usually direct connection to Internet and live map access Page 5
  • 6. GPS standalone devices • Garmin • Magellan • MIO • TomTom • Maps are prepared and sold by vendor • Maybe small vendors will go extinct
  • 7. Forensic tools and GPS • Today all commercial tool have support GPS data extraction, level can vary, depends on model, encryption... • Idea is to get out geolocation data and put in on the map, also and all other available data from device – location data can be obtained from other sources too • There is a BIG difference among mobile device forensic tools and general purpose forensic tools Page 7
  • 8. Forensic Tool Examples • EnCase - general purpose forensic tool – support for geolocation data extracted from evidence as part of smartphone support module – support for standalone device as disk image and enscripts to extract data • UFED ultimate / UFED physical analyzer - mobile device forensic tool – support only for geolocation data extracted from evidence as part of smartphone support (some magic can be done too) – support for standalone device but in a way as mobile phones or smartphones – support for encrypted logs and data on some standalone devices (tom-tom) – python scripts for additional processing • It is almost impossible to mix results of both tools .... – it takes a lot of effort – there is no standardization (like E01 format in traditional digital forensic) Page 8
  • 9. GPS information 1. travel path 2. trackpoints (coordinates) 3. waypoints (coordinates and names) 4. route (list of waypoint) 5. saved locations 6. video, pictures 7. all other available data from device related to locations / positions Page 9
  • 10. Example Tom-Tom data • *.cfg – locations. • ttgo.bif, ttnavigator.bif – general info on device, S/N, model ... • password (encrypted) • settings.dat – IDs, user data ... • triplog files – encrypted files – user route data Page 10
  • 11. GPS seizure • Device seizure is the first step and can be difficult • These devices send and receive signals when powered on – precautions need to be taken • How do you stop a GPS from updating its location? − If possible, a Faraday bag • What if a Faraday bag is not available??? • Once the device is protected, what next? • Page 11 Page 11
  • 12. What is needed for acquisition • Once the device has been seized, the next logical step is to acquire the device. • The following is a list of tools that could be important: • USB cable to connect the device to an acquisition machine/tool • Faraday bag (as mentioned previously) • write blocker (either software or hardware will be acceptable) • Card reader (optional) Page 12 Page 12
  • 13. Examples • ENCase details in CEIC 2012 “GPS Device Acquisition and Examination” – EnCase and Garmin – EnCase and TomTom – Encase and Magellan – Encase and Exif data Master Title Page 13 Page 13
  • 14. EnCase and TomTom/Garmin • Encase can acquire Garmin and TomTom GPS devices trough the use of a write-block device Note: • If a media card is in use by the GPS device, the card must be removed and imaged separately. If it is not removed, the media card may be the only thing that shows up during a preview Page 14 Page 14
  • 15. EnCase and Magellan • Similarly to Garmin or TomTom, acquisition of a Magellan GPS device can be accomplished by using a write-block device and a forensic acquisition tool (EnCase) • Some Magellan's may not be imaged in this fashion • The only solution may be to use a backup of the device on a media card supported by the device • Or to use another tool like UFED . Page 15 Page 15
  • 16. Garmin device examination through EnCase More can be done for Garmin .gpx... • Aside from viewing the .gpx file within EnCase or an XML browser, the file can be viewed in Google Earth. • This can be accomplished one of two ways: − Bring the .gpx file out of EnCase and use a website to convert the file to KML − This site is used for the conversion: http://www.gpsvisualizer.com/map_input?form=googleearth Page 16 Page 16
  • 17. EnCase Garmin examination • Once at this site, the settings can be observed. Page 17 Page 17
  • 18. EnCase Garmin examination • Click the “create KML” button • A new page will be loaded • The KML file can then be downloaded Page 18 Page 18
  • 19. EnCase Garmin examination • With the KML file brought into Google Earth, we can begin the examination. • When it is brought in, the data will show up under Temporary Places. Page 19 Page 19
  • 20. EnCase Garmin examination • The data is broken down into two main pieces: − Waypoints − Tracks • Waypoints contains data like address book entries • Tracks can contain data from recent routes that were traveled Page 20 Page 20
  • 21. EnCase Garmin examination • An example of a Waypoint Page 21 Page 21
  • 22. EnCase Garmin examination • The other option is to bring the KML file straight into Google Earth • If this option is used, you will be presented with three options. • “Create KML LineStrings” is unchecked by default − It is recommended that this be checked Page 22 Page 22
  • 23. EnCase Garmin examination • In summary, Garmin GPS devices are super easy to examine and can be the most fruitful • The data is easy to access and should not be overlooked • Some upcoming challenges: − Who uses a portable GPS device? − Garmin now has multiple apps available for download Page 23 Page 23
  • 24. EnCase TomTom examination • TomTom GPS devices have been around for some time and are widely used • The examination of these devices is a bit different • TomTom GPS devices can in some ways store more info than Garmin Page 24 Page 24
  • 25. EnCase TomTom examination • With TomTom GPS devices, a few files will be of interest to us • To start, we can look at the CurrentMap.dat • In this example the file is sitting at the root of the device • This will give the name of the map that is currently in use • As you can see in the example, “North_America_2GB” is the name of the map being used Page 25 Page 25
  • 26. EnCase TomTom examination • In summary, TomTom GPS can be examined through the use of an EnScript module or third-party tools • If trip logs are present, a request could be made to TomTom in an attempt to get the logs decrypted (or trough UFED tools) • Some upcoming challenges: − Who uses a portable GPS device? − TomTom now has multiple apps available for download Page 26 Page 26
  • 27. EnCase Magellan examination • Magellan devices can be more difficult in part because of the the acquisition process • Some Magellan devices may not be able to be acquired at the physical level • In those cases it might be possible to create a backup through the device directly to an SD card • The SD card containing the backup can then be acquired Page 27 Page 27
  • 28. EnCase Magellan examination • In summary, Magellan GPS devices are the most difficult to examine due to the limited information available • Though third-party tools are available, their ability to parse data may be limited by the actual models supported • Some upcoming challenges: − Who uses a portable GPS device? − Magellan now has multiple apps available for download Page 28 Page 28
  • 29. Examination of EXIF GPS Data • The examination of EXIF GPS can be made simple • This data can be extracted and made invaluable through the use of various third-party tools or an EnScript program • The “Exif GPS Information Reader” EnScript module will be used here The images used here were taken with a BlackBerry Page 29 Page 29
  • 30. Examination of EXIF GPS Data • The exported KML file can be viewed in Google Earth Page 30 Page 30
  • 31. Conclusion ? • It is wild area • in developement, new models, new features, encryption, applications od devices • legal issuses • a lot to learn Master Title Page 31 Page 31
  • 32. Questions ? damir.delija@insig2.hr Master Title Page 32 Page 32