Digital Forensics Analysis of Ubuntu Touch on PinePhone

New smartphones made by small companies enter the technology market everyday. These new devices introduce new challenges for mobile forensic investigators as these devices end up becoming pertinent evidence during an investigation. One such device is the PinePhone from Pine Microsystems (Pine64). Th...

Full description

Bibliographic Details
Main Authors: Yansi Keim, Yung Han Yoon, Umit Karabiyik
Format: Article
Language:English
Published: MDPI AG 2021-02-01
Series:Electronics
Subjects:
Online Access:https://www.mdpi.com/2079-9292/10/3/343
_version_ 1797416889357434880
author Yansi Keim
Yung Han Yoon
Umit Karabiyik
author_facet Yansi Keim
Yung Han Yoon
Umit Karabiyik
author_sort Yansi Keim
collection DOAJ
description New smartphones made by small companies enter the technology market everyday. These new devices introduce new challenges for mobile forensic investigators as these devices end up becoming pertinent evidence during an investigation. One such device is the PinePhone from Pine Microsystems (Pine64). These new devices are sometimes also shipped with OSes that are developed by open source communities and are otherwise never seen by investigators. Ubuntu Touch is one of these OSes and is currently being developed for deployment on the PinePhone. There is little research behind both the device and OS on what methodology an investigator should follow to reliably and accurately extract data. This results in potentially flawed methodologies being used before any testing can occur and contributes to the backlog of devices that need to be processed. Therefore, in this paper, the first forensic analysis of the PinePhone device with Ubuntu Touch OS is performed using Autopsy, an open source tool, to establish a framework that can be used to examine and analyze devices running the Ubuntu Touch OS. The findings include analysis of artifacts that could impact user privacy and data security, organization structure of file storage, app storage, OS, etc. Moreover, locations within the device that stores call logs, SMS messages, images, and videos are reported. Interesting findings include forensic artifacts, which could be useful to investigators in understanding user activity and attribution. This research will provide a roadmap to the digital forensic investigators to efficiently and effectively conduct their investigations where they have Ubuntu Touch OS and/or PinePhone as the evidence source.
first_indexed 2024-03-09T06:10:49Z
format Article
id doaj.art-bb071ac0068f4ab4ac232dc81224217d
institution Directory Open Access Journal
issn 2079-9292
language English
last_indexed 2024-03-09T06:10:49Z
publishDate 2021-02-01
publisher MDPI AG
record_format Article
series Electronics
spelling doaj.art-bb071ac0068f4ab4ac232dc81224217d2023-12-03T11:59:14ZengMDPI AGElectronics2079-92922021-02-0110334310.3390/electronics10030343Digital Forensics Analysis of Ubuntu Touch on PinePhoneYansi Keim0Yung Han Yoon1Umit Karabiyik2Department of Computer and Information Technology, Purdue University, West Lafayette, IN 47907, USADepartment of Computer and Information Technology, Purdue University, West Lafayette, IN 47907, USADepartment of Computer and Information Technology, Purdue University, West Lafayette, IN 47907, USANew smartphones made by small companies enter the technology market everyday. These new devices introduce new challenges for mobile forensic investigators as these devices end up becoming pertinent evidence during an investigation. One such device is the PinePhone from Pine Microsystems (Pine64). These new devices are sometimes also shipped with OSes that are developed by open source communities and are otherwise never seen by investigators. Ubuntu Touch is one of these OSes and is currently being developed for deployment on the PinePhone. There is little research behind both the device and OS on what methodology an investigator should follow to reliably and accurately extract data. This results in potentially flawed methodologies being used before any testing can occur and contributes to the backlog of devices that need to be processed. Therefore, in this paper, the first forensic analysis of the PinePhone device with Ubuntu Touch OS is performed using Autopsy, an open source tool, to establish a framework that can be used to examine and analyze devices running the Ubuntu Touch OS. The findings include analysis of artifacts that could impact user privacy and data security, organization structure of file storage, app storage, OS, etc. Moreover, locations within the device that stores call logs, SMS messages, images, and videos are reported. Interesting findings include forensic artifacts, which could be useful to investigators in understanding user activity and attribution. This research will provide a roadmap to the digital forensic investigators to efficiently and effectively conduct their investigations where they have Ubuntu Touch OS and/or PinePhone as the evidence source.https://www.mdpi.com/2079-9292/10/3/343Ubuntu Touch OSdigital forensicsmobile forensicssecurityprivacyoperating system
spellingShingle Yansi Keim
Yung Han Yoon
Umit Karabiyik
Digital Forensics Analysis of Ubuntu Touch on PinePhone
Electronics
Ubuntu Touch OS
digital forensics
mobile forensics
security
privacy
operating system
title Digital Forensics Analysis of Ubuntu Touch on PinePhone
title_full Digital Forensics Analysis of Ubuntu Touch on PinePhone
title_fullStr Digital Forensics Analysis of Ubuntu Touch on PinePhone
title_full_unstemmed Digital Forensics Analysis of Ubuntu Touch on PinePhone
title_short Digital Forensics Analysis of Ubuntu Touch on PinePhone
title_sort digital forensics analysis of ubuntu touch on pinephone
topic Ubuntu Touch OS
digital forensics
mobile forensics
security
privacy
operating system
url https://www.mdpi.com/2079-9292/10/3/343
work_keys_str_mv AT yansikeim digitalforensicsanalysisofubuntutouchonpinephone
AT yunghanyoon digitalforensicsanalysisofubuntutouchonpinephone
AT umitkarabiyik digitalforensicsanalysisofubuntutouchonpinephone