Back to results

AUT University

Mobile Devices: iPhone Risks and Forensic Tool Capability

Abstract

The research evaluates the capability of software based tools that extract data stored on an Apple iPhone. A literature review is performed covering material on: mobile devices, iPhone, hard disks, networking connectivity, usage environments, data integrity, evidence volatility, data extraction methods and operating systems. Literature shows that iPhone data extraction is complex due to hardware and software limitations. Understanding the capability of the tool used to retrieve data is important in ensuring a sound investigation. Based on literature a research methodology is defined. A descriptive approach is selected. The research process is split into three phases: test iPhone capability, evaluate extraction tools and compare extraction tools. At each phase data is collected, processed and analysed. At the first stage a “catalog” of known data stored on the iPhone is collected. At the second phase an audit “journal” of procedure and “extraction log” of extracted data is collected. At the last phase a sample set of weighted scenarios are used to analyse tool capability. Research findings indicate 12,963 files were extracted from an iPhone and classified in the catalog. Operating system limitations restrict user access to the iPhone file system. A method of opening access, known as jailbreaking, can be used to bypass such restrictions. Of the files in the catalog the highest result obtained by an extraction tool is 797 from Oxygen Forensics Suite 2010 and the lowest result is 178 from Device Seizure. Scenario analysis indicates Oxygen Forensics Suite 2010 works better in case scenarios whereas non-forensic tools have more limitations. Discussion of findings indicates that SQLite and Property List files are common sources of data storage on the iPhone. Analysis into the iPhone operating system shows that Apple has put multiple controls to limit access to the stored data. There is potential for further research in expanding research into extraction tool capability.

Author and committee

dc:creator, dc:contributor.*
Author
  • Knight, Benjamin Andrew

Subjects

dc:subject × 6

Identifiers

dc:identifier.*
Identifier
hdl:10292/1196
OAI identifier oai:identifier
oai:openrepository.aut.ac.nz:10292/1196

Chain of custody

source
Harvested from
AUT University
Base URL
openrepository.aut.ac.nz/server/oai/request
Last updated
2026-07-27
Source record
OAI-PMH GetRecord
citation

Knight, Benjamin Andrew. Mobile Devices: iPhone Risks and Forensic Tool Capability. 2010.