Guide to SIMfill Use and Devlopment (NIST IR-7658)
暫譯: SIMfill 使用與開發指南 (NIST IR-7658)

Wayne Jansen, Aurelien Delaitre

  • 出版商: CreateSpace Independ
  • 出版日期: 2012-06-30
  • 售價: $890
  • 貴賓價: 9.5$846
  • 語言: 英文
  • 頁數: 60
  • 裝訂: Paperback
  • ISBN: 1478168706
  • ISBN-13: 9781478168706
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

The National Institute of Standards and Technology IR-7658, Guide to SIMfill Use and Development discusses SIMFull which is a proof-of-concept, open source, application developed by NIST to populate identity modules with test data, as a way to assess the recovery capability of mobile forensic tools. An initial set of test data is also provided with SIMfill as a baseline for creating other test cases. This report describes the design and organization of SIMfill in sufficient detail to allow informed use and experimentation with the software and test data provided, including the option to modify and extend the program and data provided to meet specific needs. Reference materials are vital in forensic laboratories and similar settings, where quality assurance is a major issue. Reference material refers to material, sufficiently homogeneous and stable with respect to one or more specified properties, which has been established to be fit for its intended use in a measurement process. One area of application is in the validation of forensic tools to identify inaccuracies that might exist and establish overall suitability for use. New versions of forensic software tools are issued regularly by a tool manufacturer to broaden the range of existing functions, provide new features, and correct identified problems. After the laboratory successfully validates a tool, it can be safely put into use for its intended purpose. Reference materials, such as handsets and identity modules containing populated data, are typically used to validate forensic tools targeting mobile handheld devices. However, populating such devices with data that exhibit the needed properties, including a broad range of character sets, data structures, and file content, is difficult. Populating a device with a representative data to create suitable reference material can be done in various ways: Manually – Using manual means to populate a group of individual items onto devices is typically a time-consuming and error-prone process, since it is normally done through the user interface of a handset; Semi-automated – Using a semi-automated process typically preserves manually populated data for reuse by copying or transferring the data to another device with the same or very similar characteristics; Automated – Using an automated means to populate devices through a well-defined interface can greatly expedite validation, once the initial effort to construct the test data is completed. SIMfill is a proof-of-concept application developed to expedite validation by populating certain devices automatically with test data, to create reference material for tool assessment. SIMfill works with Subscriber Identity Modules (SIMs) found in many present-day mobile phones. Universal Mobile Telecommunications System (UMTS) SIMs (USIMs) being deployed in 3G networks are often backwards-compatible with SIMs and able to be populated by SIMfill as well [3GPP09c]. (U)SIMs are highly standardized devices with well-defined interfaces. The vast majority of forensic tools for cell phones provides the functionality to recover (U)SIM-resident data, making SIMfill a potentially useful means for use in assessing their capabilities. This report describes the design and organization of SIMfill in sufficient detail to allow informed use and experimentation with the software distribution, including the option to modify the program and test dataset provided to meet specific needs.~

商品描述(中文翻譯)

《國家標準與技術研究所 IR-7658,SIMfill 使用與開發指南》討論了 SIMFull,這是一個由 NIST 開發的概念驗證開源應用程式,用於填充身份模組(Identity Modules)以測試數據,作為評估行動取證工具恢復能力的一種方式。SIMfill 還提供了一組初始測試數據,作為創建其他測試案例的基準。本報告詳細描述了 SIMfill 的設計和組織,以便用戶能夠充分了解如何使用和實驗所提供的軟體和測試數據,包括修改和擴展所提供的程式和數據以滿足特定需求的選項。

參考材料在取證實驗室及類似環境中至關重要,因為質量保證是一個主要問題。參考材料是指在一個或多個指定屬性方面足夠均勻和穩定的材料,已被確定適合其在測量過程中的預期用途。其應用的一個領域是驗證取證工具,以識別可能存在的不準確性並確定其整體適用性。取證軟體工具的新版本由工具製造商定期發佈,以擴大現有功能的範圍,提供新特性,並修正已識別的問題。在實驗室成功驗證工具後,可以安全地將其用於預期的目的。

參考材料,例如包含填充數據的手機和身份模組,通常用於驗證針對行動手持設備的取證工具。然而,填充這些設備所需的數據,包括廣泛的字符集、數據結構和文件內容,是一項挑戰。用代表性數據填充設備以創建合適的參考材料可以通過多種方式進行:

手動 – 通常通過手機的用戶界面手動將一組個別項目填充到設備上是一個耗時且容易出錯的過程;半自動 – 使用半自動過程通常保留手動填充的數據,以便通過複製或轉移數據到具有相同或非常相似特徵的另一設備進行重用;自動 – 通過明確定義的介面使用自動方式填充設備可以大大加快驗證速度,一旦完成初始的測試數據構建工作。

SIMfill 是一個概念驗證應用程式,旨在通過自動填充某些設備的測試數據來加快驗證,以創建工具評估的參考材料。SIMfill 與許多現代手機中的用戶身份模組(Subscriber Identity Modules, SIMs)一起使用。部署在 3G 網絡中的通用行動通信系統(Universal Mobile Telecommunications System, UMTS)SIM(USIM)通常向後兼容 SIM,並且也能夠被 SIMfill 填充。(U)SIM 是高度標準化的設備,具有明確定義的介面。絕大多數針對手機的取證工具提供恢復(U)SIM 居住數據的功能,使得 SIMfill 成為評估其能力的潛在有用工具。

本報告詳細描述了 SIMfill 的設計和組織,以便用戶能夠充分了解如何使用和實驗所提供的軟體發行版,包括修改所提供的程式和測試數據集以滿足特定需求的選項。