Game consoles have been able to store personally identifiable information for years; what is less well known is what remains when they are bought or sold on the second-hand market. We share the results of two case studies on Nintendo devices: the Switch and the 3DS.
Computer and console-based video games are an important part of the entertainment industry. Such devices may be found in evidence lockers as part of investigations, or overlooked as their intrinsic value to an investigation may not be well-understood. Modern games consoles provide network connectivity and functionality that allows a significant degree of interaction via peer-to-peer connections and/or the Internet. These gaming consoles store settings, user preferences, user information, and can capture photos, audio and video, all of which potentially contain forensic artifacts about a person of interest. Games consoles have a fixed lifespan, eventually superseded by newer models with an expanded range of capabilities. As there are significant numbers of consoles available on the secondhand market, there is clear evidence that older consoles remain in circulation even after production has ceased. What is unclear, however, is the actual extent of forensic data available within these consoles. This paper shares the results of a digital forensic case-study undertaken to assess what artifacts are retrievable based on ‘real-world’ dataset, particularly the aging, but popular Nintendo 3DS series. A total of 47 Nintendo 3DS/2DS handheld systems were purchased secondhand. They were forensically imaged then examined to identify what artifacts are commonly found ‘in the wild’ on these often overlooked systems. Results presented in this paper provide guidance to digital forensic investigators of what may be realistically obtained from these non-traditional devices.
Investigators searching for digital evidence may encounter a variety of different IoT (Internet of Things) devices. Data in such devices and their environments can be both valuable, but also highly volatile. To meet best practices and to process these devices in an expeditious and forensically-sound manner, an investigator should have a predefined plan. Developing such plans requires prior knowledge developed through the exploration and experimentation of the “target” devices. The expanding variety, number, and pervasiveness of IoT devices means there is an increasing need for pre-incident analysis to ensure forensic tools and techniques acquire, preserve and document evidence appropriately. Many of these IoT devices have proprietary file- and operating-systems and may employ mechanisms to protect intellectual property by limiting or preventing access by researchers. Disassembly of the device and circumventing these mechanisms may be restricted by contract, end-user licence agreement (EULA) or legislation regarding intellectual-property rights. Legislative exclusions exist for security research, in some jurisdictions, permitting legitimate analyses. The pre-incident analyses of hardware to establish a forensic process bear some similarity to vulnerability and security research, however there are distinct differences in their end goals. This paper discusses the legal and ethical issues that may be encountered when conducting pre-incident forensics analyses focussing on IoT hardware. It highlights areas of particular concern, identifies best practice and subjects requiring future work as presented in the literature before providing a series of recommendations for forensics investigators processing these types of devices.
This chapter describes a suite of digital forensic examination tools for the Nintendo 3DS series of game consoles. The Nintendo 3DS is a handheld game console with capabilities that include video recording, photography, web browsing and network communications. Originally released in 2011, the consoles remain popular, with almost 76 million units sold. Since the consoles can enable illegal activities, they are potential containers of evidence in criminal investigations. Previous research has highlighted the artifacts found on Nintendo 3DS and other similar devices. However, this chapter expands the body of research focused on automating artifact extraction and validation. The extraction and validation efforts would be of interest to forensic practitioners as well as researchers focusing on small-scale embedded devices.
There is a body of current research on the technical analysis of computer games consoles to determine if information present might be of value in a criminal investigation. This research has highlighted the potential forensic value of the various consoles depending on the type of crime and the capabilities of the console. There is also anecdotal information, presented in the media, on various crimes that have been prosecuted using evidence obtained from games consoles. However, there appears to be no recent study examining the degree of involvement of games consoles in actual criminal activity, cases being investigated or their use in court cases. This paper presents the results of a Freedom of Information request using the UK Freedom of Information Act (2000) and the Freedom of Information (Scotland) Act 2002. The Freedom of Information Act request was aimed at obtaining an overview of the criminal misuse of game consoles during 2020. This request was sent to the 49 Police forces that cover England, Scotland, Wales and Northern Ireland, seeking details on games consoles included in cases that they have investigated. Current results provide limited information on the involvement of game consoles in cybercrime in the United Kingdom. In examining the prevalence of different types of games consoles in police investigations, the potential need for further work on game console forensics is discussed along with possible factors affecting both the data collection and the patterns observed in the study.
The growth of the Internet of Things (IoT) over the last five years has been sizeable. The scale of changes has ranged from connected domestic appliances to connected cities; the scope for IoT has expanded. Most of the major vendors; including Google, Amazon, and Microsoft, now offer various devices to control aspects of homes. The issues surrounding IoT devices include security, vendors have not considered security when creating the devices and most users do not consider security when connecting the devices to home networks. This research focuses on an example of malware that attacks Raspberry Pi devices on the internet. The paper discusses the severity of a large-scale attack performed on the Internet of Things (IoT). A honeypot set up to capture different forms of malware obtained multiple samples from several unrelated IP addresses without any regular pattern. This paper addresses an analysis of the malware and how it infects new devices across the internet. The results show that the misconfiguration of Pi based IoT devices can lead to exploitation very rapidly and that malware can spread easily across a network, to infect all devices on the network.
Games consoles present a particular challenge to the forensics investigator due to the nature of the hardware and the inaccessibility of the file system. Many protection measures are put in place to make it deliberately difficult to access raw data in order to protect intellectual property, enhance digital rights management of software and, ultimately, to protect against piracy. History has shown that many such protections on game consoles are circumvented with exploits leading to jailbreaking/rooting and allowing unauthorized software to be launched on the games system. This paper details methods that enable the investigator to extract system activity, deleted images, Internet history items, relevant friends list information, the console's serial number and plaintext WiFi access point passwords. This is all possible with the use of publicly available, open-source security circumvention techniques that perform a non-invasive physical dump of the internal NAND storage of the Nintendo 3DS handheld device. It will also be shown that forensic integrity is maintained and a detailed analysis is possible without altering original evidence.
Many home interactive sensors and networked devices are being branded as “Internet of Things” or IoT devices. Such disparate gadgets often have little in common other than that they all communicate using similar protocols. The emergence of devices known as “smart home hubs” allow for such hardware to be controlled by non-technical users providing inexpensive home security and other home automation functions. To the cyber analyst, these smart environments can be a boon to digital forensics; information such as interactions with the devices, sensors registering motion, temperature or moisture levels in different rooms, all tend to be collected in one central location rather than separate ones. This paper presents the research work conducted on one such smart home hub environment, the Securifi Almond+, and provides guidance for forensic data acquisition and analysis of artefacts pertaining to user interaction across the hub, the iPhone/Android companion applications and the local & cloud-based web interfaces.
Cyber Security degree programs vary in scope; from those that are constructed around traditional computer science degrees with some additional security content, to those that are strongly focused on the need to develop a dedicated cyber security professional. The latter programs typically include a grounding in computer science concepts such as programming, operating systems and networks to specialised security content covering such disparate areas as digital forensics, information assurance, penetration testing and cryptography. The cyber security discipline as a whole faces new challenges as technology continues to evolve, and therefore significant changes are being faced by educators trying to incorporate the latest technological concepts into courses. This presents cybersecurity educators with a number of related challenges to ensure that changes to degree programs reflect not only the educational needs of students, but of the needs of industry and government. The evolving use of technology therefore presents both opportunities and problems, in how these changes are demonstrated in the curriculum. This paper highlights the accreditation, standards and guidelines (from three of the countries where the authors of this paper have sought accreditation) that shape the way educators are encouraged to develop and structure degree courses and considers these in lieu of factors relating to incorporating new technology in cybersecurity curriculum, particularly in the presentation of technical exercises to students.
This chapter presents the results of a forensic acquisition and analysis of an Amazon Fire TV Stick, a popular streaming media device. Although the primary functions of the Fire TV Stick are streaming videos and playing non-intensive video games, it is a reasonably powerful device that runs an Android operating system. This chapter explores the additional capabilities being developed for Fire TV Sticks in the hacker/enthusiast community and considers the implications that alterations to the devices could have with regard to digital forensics. An empirical assessment is conducted to identify the potential for misuse of Fire TV Sticks and to provide guidance to forensic investigators who analyze these devices.
Lifelong learning is said to encompass “lifelong”, “lifewide” and “voluntary and self-motivated” learning (Department of Education and Science, 2000) and it has been increasingly important to provide a foundation for this as part of higher education (Bologna Process European Higher Education Area, 2014)(Leuven/Louvain-laNeuve Communiqué, 2009). Marjan Laal (2011) also states “LLL will not only develop individuals to become responsible to themselves and their communities, but understand and involve actively at all levels of their societies”. Research has shown that students need to have a metacognitive awareness to be able to learn, unlearn and relearn. Metacognition refers to the your knowledge concerning your own process of learning and the strategies you use to reach a goal. Self-reflection is one way of achieving this knowledge. Noroff University College (NUC) has been using the integrated blogs in Moodle as reflective journal tool for a Bachelor program in Digital Forensics (DF). However, some issues have surfaced such as the lack of interaction between the students on these blogs and the assessment of the blogs. In an attempt to mitigate these issues, two of the courses offered in the DF program have included the Wiki activity in Moodle to be used as a reflective journal in addition to the blogs. Six students have participated in these courses and they were instructed to use both their blogs and the Wiki, and the information in one should not differ from the other. Two lecturers were involved in both delivering the two courses and assessing the reflective journals. This paper will compare the use of the two tools, with a specific focus on the ease of use, the level of interaction encouraged by the tools, and the benefits and drawbacks of the two. We have also conducted an interview with the students involved regarding the use of the tools and the level of interaction. The authors of this paper have also included a summary from the lecturers involved. Based on this summary and the interviews with the students, we have provided a table showing the benefits and drawbacks of using these tools as a reflective journal and concluded on a recommendation.
Handheld video game consoles have evolved much like their desktop counterparts over the years. The most recent eighth generation of game consoles are now defined not by their ability to interact online using a web browser, but by the social media facilities they now provide. This chapter describes a forensic methodology for analyzing Nintendo 3DS handheld video game consoles, demonstrating their potential for misuse and highlighting areas where evidence may reside. Empirical research has led to the formulation of a detailed methodology that can assist forensic examiners in maximizing evidence extraction while minimizing, if not preventing, the destruction of information.
Embedded devices are becoming ubiquitous in both domestic and commercial environments. Although smartphones, tablets, and video game consoles are all labeled by their primary function, most of these devices offer additional features and are capable of additional interactivity. Given the proprietary nature of such devices in terms of hardware and software and the protection mechanisms incorporated into these systems, it is and will continue to be extremely difficult to use “traditional digital forensics” methodologies to access storage media and acquire data for analysis. This paper examines how consumer law may be stifling research that the forensic community could ultimately depend upon to examine devices.
Considerable scholarly effort has been invested in interpreting the existing international legal instruments and diplomatic conventions that apply to kinetic warfare in relation to the field of cyber-warfare. The Tallinn Manual and other documents argue that current humanitarian laws are applicable in cyber-conflict. This includes the concept that particular religious and medical entities should be granted special, protected status along with sites of cultural and religious significance and those containing dangerous forces'. In a kinetic-warfare environment, these sites and non-combatants are identifiable by the use of international symbols such as the Red Cross, Red Crystal and Red Crescent emblems, or other specific signs. Here, Sutherland, Xynos, Jones and Blyth suggest that a simple digital marker could ensure that systems and traffic can be identified as protected in cyber-conflict under the Geneva Conventions.
Visualising data is an important part of the forensic analysis process. Many cell phone forensic tools have specialised visualisation components, but are as of yet able to tackle questions concerning the broad spectrum of social media communication sources. Visualisation tools tend to be stove-piped, it is difficult to take information seen in one visualisation tool and obtain a different perspective in another tool. If an interesting relationship is observed, needing to be explored in more depth, the process has to be reiterated by manually generating a subset of the data, converting it into the correct format, and invoking the new application. This paper describes a cloud-based data storage architecture and a set of interactive visualisation tools developed to allow for a more straightforward exploratory analysis. This approach developed in this tool suite is demonstrated using a case study consisting of social media data extracted from two mobile devices.
Organisations rely on business processes to define their day-to-day commercial activities. Any disruption of these business processes will have a direct impact on the organisation’s ability to perform its functions. In this paper we review the DEViSE Workbench, developed for network security visualisation, and demonstrate how business processes can be augmented with network security audit information to provide a precise understanding of how attacks impact the higher-level business roles. The paper outlines a prototype tool called BPEvents that can be used to highlight the severity of computer network attacks (CNA) in terms of the impact on business functions using the standard XPDL notation.
The increasing variety of Internet enabled hardware devices is creating a world of semi-autonomous, interconnected systems capable of control, automation and monitoring of a built environment. Many building automation and control systems that have previously been limited in connectivity, or due to cost only used in commercial environments, are now seeing increased uptake in domestic environments. Such systems may lack the management controls that are in place in commercial environments. The risk to these systems is further increased when they are connected to the Internet to allow control via a web browser or smartphone application. This paper explores the application of traditional digital forensics practices by applying established good practice guidelines to the field of building automation. In particular, we examine the application of the UK Association of Chief Police Officers guidelines for Digital Evidence, identifying the challenges and the gaps that arise in processes, procedures and available tools.
The primary function of a games console is that of an entertainment system. However the latest iteration of these consoles has added a number of new interactive features that may prove of value to the digital investigator. This paper highlights the value of these consoles, in particular Sony's latest version of their PlayStation. This console provides a number of features including web browsing, downloading of material and chat functionality; all communication features that will be of interest to forensic investigators. In this paper we undertake an initial investigation of the PlayStation 4 games console. This paper identifies potential information sources of forensic value with the PlayStation 4 and provides a method for acquiring information in a forensically sound manner. In particular issues with the online and offline investigative process are also identified.
Andrew C. Jones合作论文数School of Computer Science at University of Wales, Cardiff5
Suzanne M. Embury合作论文数Manchester University;Department of Computer Science1