<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>SIM Cards Forensic Capability and Evaluation of Extraction Tools</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Ismaila Idris</string-name>
          <email>1ismi.idris@futminna.edu.ng</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>John K. Alhassan</string-name>
          <email>2jkalhassan@futminna.edu.ng</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Victor O. Waziri</string-name>
          <email>3victor.waziri@futminna.edu.ng</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Muhammad Umar Majigi</string-name>
          <email>4majigiumar1@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Department of Cyber Security Science, Federal University of Technology</institution>
          ,
          <addr-line>Minna</addr-line>
          ,
          <country country="NG">Nigeria</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Extraction Tool” A thesis submitted in partial fulfillment of the requirement of Edinburgh Napier University for the Degree of Master of Science in Advanced Security &amp; Digital Forensics. April</institution>
          ,
          <addr-line>2012</addr-line>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Federal University of Technology</institution>
          ,
          <addr-line>Minna</addr-line>
          ,
          <country country="NG">Nigeria</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2016</year>
      </pub-date>
      <fpage>75</fpage>
      <lpage>81</lpage>
      <abstract>
        <p>-Mobile phones have turned into a very essential tool for personal communication. Thus, it is of immense importance that forensic investigators have possibilities to extract proof items from mobile phones. The Modern mobile phones store facts items on inner memories as well as SIM cards. With the introduction of modern functionality, these accessories and their devices might be used as tools in a crime. Appropriate forensic examination of such memories, including recovery of deleted items has not been possible until now. This research paper presents two mobile SIM cards to assess a chosen set of six existing mobile forensic software tools that where developed mainly for mobile Subscriber Identification Module (SIM) forensics which is aimed to find out their capability and efficiency when compared with other software. This would help a forensic investigator decision making in choosing a tool unique for acquiring specific evidence from a SIM card, and hopefully bring about a save in time and resources.</p>
      </abstract>
      <kwd-group>
        <kwd>-forensic</kwd>
        <kwd>mobile phone SIM card</kwd>
        <kwd>Tecno android phone</kwd>
        <kwd>software</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>INTRODUCTION</p>
      <p>Communication technology is the major integral part of
everyday human life. The invention of telecommunication
technology, especially smart phones which are one of the
most commonly used and dominant technology derived from
the advent of Information and Communication Technology
(ICT) over the past few decade, have brought about changes
and re-defined the world’s order and the way most things
are done.</p>
      <p>
        Mobile cellular phone usage is seen to have really
increased tremendously over the past decade, with an
estimated average global mobile subscription of 7.2 Billion
in 1st Quarter of the year 2015 and 99 percent Global mobile
penetration by 1st Quarter of 2015. Smartphones especially
accounted for about 75 percent of all mobile phones that
were sold in the 1st Quarter of 2015, compared to around 65
percent during 1st Quarter of 2014 [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. While the estimated
number of smartphones in particular is set to double by year
2020 [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Such portable communication devices which are
now very advanced with great computing power have taken
over the dominant role of personal computers. With a mobile
phone, a person can make calls, send SMS messages and
also browse the internet and store large amounts of digital
data. Mobile phones are now much more popular than
personal computers due to portability and can be used in
most cases since it has the same content and has capability
for the same computing tasks as that of personal computer
[
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
Williamson et al. studied the performance of mobile forensic
tools TULP 2G, Cell seizure and Oxygen Phone Manager etc
peculiar to Nokia phones [
        <xref ref-type="bibr" rid="ref7">8</xref>
        ]. In 2007, Jansen and Ayers
again compared existing tools on contemporary mobile
phones and collected their work into a NIST report [9].
Later, [
        <xref ref-type="bibr" rid="ref9">10</xref>
        ] Yates notes the diversity of the mobile device
market and the associated complexity presented to a
practitioner attempting to select the appropriate digital
forensics tool. Just the comparison papers mentioned here
cover: Cell Seizure, GSM.XRY, MOBILedit! Forensic,
TULP 2G, Forensic Card Reader, ForensicSIM, SIMCon,
SIMIS and Oxygen Phone Manager.
      </p>
    </sec>
    <sec id="sec-2">
      <title>A. The Subscriber Identification Module (SIM)</title>
      <p>
        Most modern mobile cellular mobile phones carry a
small removable smart card which is called a SIM card. The
SIM (Subscriber Identity Module) is a fundamental
component of mobile cellular phones that allows a phone
user to connect to the GSM telecommunication network,
own a cellular number and a subscriber account. It also has a
little memory space that can store valuable user information.
A SIM card has a tiny chip containing a file system, a
processor and an operating system that runs on top of it to
control all the actions and processes undertaking by the SIM
card [
        <xref ref-type="bibr" rid="ref10">11</xref>
        ]. Most SIM cards have a capacity range from 32 to
128 KB [
        <xref ref-type="bibr" rid="ref11">12</xref>
        ].
      </p>
      <p>II.</p>
      <p>LITERATURE REVIEW</p>
    </sec>
    <sec id="sec-3">
      <title>A. Introduction</title>
      <p>
        The skills of a forensic investigator is useful for the
detection and investigation of crime committed on mobile
devices, computers and computer networks, the internet and
other forms digital devices because such crimes have direct
and indirect effects on businesses, government, individual’s
privacy and corporate organizations functions due to
tremendous increased usage of internet and mobile services.
Also criminals can take advantage of this large number of
potential unsecured targets and ease of access to various
offensive tools in order to gain unauthorized access to
sensitive information. Therefore we have a need to
investigate the ways and processes through which these
crimes that are being committed [
        <xref ref-type="bibr" rid="ref12">13</xref>
        ]. Forensics based
research works by various authors are reviewed for the
purpose of this work.
      </p>
    </sec>
    <sec id="sec-4">
      <title>B. SIM Data of Forensic Value</title>
      <p>
        Depending on the type of mobile phone technology and
access control scheme, various types of data such as contact
list, SMS messages could be stored on the SIM, in the
mobile phone, or even on the memory card [
        <xref ref-type="bibr" rid="ref13">14</xref>
        ]. A typical
SIM card could contain a repository of data and information,
some of which are listed below as given by [
        <xref ref-type="bibr" rid="ref14">15</xref>
        ]:
 SMS Messages
 Contact Numbers
 Deleted SMS and Contact
 International Mobile Subscriber Identity (IMSI)
 Integrated Circuit Card Identifier (ICCID)
 Abbreviated Dialing Numbers (ADN)








      </p>
      <sec id="sec-4-1">
        <title>Service Provider Name (SPN)</title>
        <p>Mobile Network Code (MNC)
Mobile Subscriber Identification Number (MSIN)
Abbreviated Dialing Numbers (ADN)
Mobile Station International Subscriber Directory
Number (MSISDN)
Abbreviated Dialing Numbers (ADN)
Mobile Country Code (MCC)</p>
        <p>Last Dialed Numbers (LDN)</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>C. Review of Related Works</title>
      <p>This study aims at performing a comparative analysis of
mobile SIM forensic software tools. This section reviews
eight (8) literatures of related forensics based works. Below
are Meta table reviews of literatures of related research
background.
Authors (Date)
Focus
Methodology
Result
Limitation
AFLogical, Oxygen
Forensic, MobileEdit
Forensic, HTC
Sensation XE, HTC
Desire S
The test result showed
data produced from the
evaluation is huge and
was quite difficult to
table, graphical
representation of data
was used to ensure
readability and easier
analysis although of all
the tools tested, Oxygen
forensic gave a most
visible and standardized
results.</p>
      <p>He used two android
phones of the same
manufacturer HTC.</p>
      <p>FOUR
Smartphone Forensics:
A case study with Nokia
E5-00 Mobile phone.</p>
      <p>
        Seyedhossein, M., Ali,
D., &amp; Hoorange, G. B.
(2011) [
        <xref ref-type="bibr" rid="ref15">16</xref>
        ]
      </p>
      <p>METHODOLOGY</p>
      <p>This paper is aimed at carrying out comparative
evaluation of a set of six existing software tools using two
3G enabled GSM mobile SIM cards as a case study. In this
chapter all materials, methods, steps and processes
undertaking to achieve the project’s aim and objectives are
listed and explained. Including all software tools used, how
mobile evidence data was created, manipulated and sampling
techniques used for data recovery by various tools for the
purpose of evaluation. The various tools used are listed with
each capabilities as stated by their developers.</p>
      <p>Considering the large number of already existing mobile
forensic software tools for mobile forensics and the fact that
software vendors generally do not follow a common
methodology or established standard when developing these
tools or their capabilities it was paramount to source tools
from various different vendors. From an investigative
perspective it is generally required that all evidence be
acquired as quickly as possible and to examine the evidence
proper so as to ensure that law enforcement professionals can
defend their case in a court of law based on the strong
probative evidence.</p>
      <p>The simple fact is that forensic examiners looking to
create the forensically sound image in a quick manner, as
anything that forces them to delay the evidence will
substantially reduce their chances of producing the evidence
in the court of law. [21] Various mobile data and devices are
used in order to successfully carry out comparative
evaluation of the chosen forensic software set.</p>
      <p>The research framework involved in this paper is briefly
discussed by the Flow Chart below.</p>
      <p>Each mobile forensic tools method use against the mobile
SIM data evidence are equally explained for the purpose of
this research. Then the performance results of each mobile
forensic analysis report generated by using each tools
towards the acquisition of stored and deleted mobile SIM
card data are explained. The general comparative
performance and efficiency in retrieving such mobile SIM
card data evidence is presented tabular against results
produced by all the other tools.</p>
    </sec>
    <sec id="sec-6">
      <title>A. Data Analysis Procedure</title>
      <p>Data analysis is a process involving either qualitative or
quantitative inspection, modelling or transformation of any
data sample with an aim of discovering any useful
information, suggesting conclusion and supporting good
decision making.</p>
      <p>Different number of SIM contacts and SMS in form of
data evidence was created on both SIM cards with part of
these data deleted to analyze the capabilities of each mobile
forensic tools whether they could be used in retrieval of both
stored and deleted SIM data. These various SIM forensic
tools used in this project are listed below, their reviews and
features as stated by manufacturers explained.</p>
      <p>The SIM data evidence used were created gradually over
a period of 2 days. Half the contacts and SMS data were
created on each day. While calls were made on the second
day. Also half the SIM data evidence created including
Contacts and SMS were then manually deleted from the SIM
memory gradually one after the other on both SIM cards.</p>
      <p>The mobile SIMs are then removed from the Phantom
phone and then connected to the laptop via the SIM card
reader. After which each software is used to try and recover
various data on the both SIM cards.</p>
      <p>Tools assessment and testing criteria is based on whether
these tools support
 Basic SIM Data recovery
 Location Information recovery
 Deleted data recovery
 Foreign language Data support
 Examine SIM and produce forensic standard results
Usually all the forensic tools will prompt you to connect
the SIM card reader to the system and choose if to create a
case file or directly carry out any data retrieval from a
connected SIM card, which would allow for further analysis
of the mobile forensic tools based on individual results being
produced by each recovery tool.</p>
      <p>To ensure that all tools do not change any data on the
various SIM cards a write block is implemented for USB
port by changing registry setting on the computer. Through
/Run/HKEY_LOCAL_MACHINE\SYSTEM\CurrentContol
Set\Control (right click and creating a new key
StorageDevicePolicies with a new Dword WriteProtect
double click and value set to 1).</p>
      <p>Each forensic software tool is used for data acquisition
on the two different SIM cards generating twelve different
forensic results which are presented in a tabular format
showing each tool’s capability compared to others.</p>
    </sec>
    <sec id="sec-7">
      <title>B. Research Instruments</title>
      <p>Several tools and software were used in this research
work including various sampling mobile data in order to
successfully carry out the comparative analysis all these are
listed and explained below.</p>
    </sec>
    <sec id="sec-8">
      <title>1) Mobile 3G enabled SIM cards: The two SIM cards</title>
      <p>have 3G capability and only varying in their individual
memory capacity SIM 1 of MTN network has 64kb of
memory while SIM 2 of the Etisalat Network has 128kb of
memory.
</p>
      <p>The software were all installed on an Hp system
running Microsoft windows 7 64 bit. Also .NET
frameworks was installed to support operations of
some of the tools.</p>
    </sec>
    <sec id="sec-9">
      <title>2) PC/SC Smart SIM card reader:A SIYOTEAM SY</title>
      <p>386 PC/SC mobile SIM card reader is used to connect SIM
cards directly to the computer system. It comes with a driver
software disk which also holds a SIM data management
software.</p>
    </sec>
    <sec id="sec-10">
      <title>3) TECNO Android Mobile Phone: The TECNO</title>
      <p>Phantom A+ Andriod 4.2 Jelly Bean mobile phone was used
to create new contacts, SMS messages and make calls with
the two SIM cards. The phantom A+ has capacity for dual
SIM support, with a 5.0 inch touch screen, 1.0 Ghz
processor, 3G, Bluetooth 3.0 and Wi-Fi connectivity.</p>
    </sec>
    <sec id="sec-11">
      <title>4) Forensic Software Tools: The choice of forensic</title>
      <p>software tools used in this work and all the components
necessary to install them and carry out the digital forensic
process are listed below:
 A set of SIX different mobile forensic tools were
used for this paper these include Dekart SIM
Explorer version 2.5, Paraben SIM Seizure version
4.04954, MOBILedit SIM clone version 3.1,
001Micon Data recovery SIM Card version 5.4.1.2
and Forensic Card Reader version 2.2 are used in
this research. The Paraben SIM seizure and Dekart
SIM explorer were obtained by registering with the
developers using a secure internet connection, demo
version of the softwares were download from the
links.</p>
      <p>RESULTS AND DISCUSSION</p>
      <p>The results generated by use of each forensic tools are
then comparatively evaluated based on the capabilities of
each tool for collecting data evidence from the two sample
SIM cards.</p>
      <p>The SIM data being used for sampling was deliberately
generated and partially deleted to test the retrieval capability
of the chosen set of forensics tools. All the tools were able to
connect to the SIM card reader and were able to access and
retrieve at least some stored information from both SIM
cards.</p>
      <p>The forensic evidence data that these software tools were
tested upon was contact phone numbers, SMS messages, and
foreign language SMS messages and deleted SMS and
Contacts.</p>
    </sec>
    <sec id="sec-12">
      <title>A. Evaluation of Results</title>
      <p>The evaluation of the results produced by all the chosen
set of forensics tools when used for mobile evidence
collection, against the mobile data evidence that was
generated for the sole purpose of this project. For the results
analysis two comparative table of results was created
although all the tools produced the same results when the
same tool is being used to analyze both SIM cards. The
results produced by each forensic tool being tested for each
specific criteria are analyzed below:</p>
      <p>The two tables above showed that using Dekart SIM
Explorer we can recover basic evidence on both SIM cards
and saved such data with a hash value for integrity before
exporting in a forensic report format, with the only limitation
of not supporting foreign languages such as Arabic SMS.</p>
      <p>From the analysis results forensic card reader could not
recover deleted SMS and contact information but was able to
recover basic SIM identification numbers and stored SMS
and Contacts, it also has the capability to export such
information to a Forensic report format.</p>
      <p>While 001Micron Data Recovery was able to recover all
basic SIM data including the deleted SMS and Contact
details it did not allow the administration of PIN and PUK
numbers, although the demo version was not able to save the
recovered data evidence or export such as forensic report
format.</p>
      <p>On the other hand Paraben SIM seizure was able to
recover all basic SIM identification data all stored and
deleted SMS and Contacts and stored such with a hash value
which could be exported in a forensic report format.</p>
      <p>From the analysis results we see that Dekart Sim
Manager was only able to recover stored SMS and Contacts
from both SIM cards with very little SIM identification
information, although it allowed PIN administration. It was
able to store such data in file but could not export such in a
forensic report format.</p>
      <p>All the tools were unable to recover any call records
because they were stored on the mobile phone. From the
performance results of these chosen set of forensic tools we
see that to some extent Paraben SIM Seizure is one of the
best mobile forensic tools to be considered when trying to
investigate any case relating to mobile SIM cards with the
capability to recover much information and produce a
standard forensic report on such investigation. Also Dekart
SIM Explorer is an extensively capable forensic tool for use
in the forensic analysis of mobile SIM cards.</p>
      <p>SUMMARY</p>
      <p>With the constant advancement of technology, the uses,
and importance of mobile devices in our everyday way of
life cannot be over emphasized. The process of properly and
legally acquiring any form of mobile evidence data from any
mobile devices or accessories must be carefully undertaken,
in all stages of the forensic process. Proper care must be
taken in selection of which set of tools to be used because
some of these mobile forensic tools developed may not be
compatible or well suitable to acquire evidence from a
specific mobile phone and its SIM card. Great forensic
importance is attached to a mobile SIM card considering it as
the heart of a mobile phone and is very easily transferable
cross devices. Therefore, the efficiency of any mobile
forensic tool should be considered before for acquiring of
evidence from any kind of mobile device and accessories. In
order to carry out this forensic analysis mobile data evidence
was gradually generated on two different memory capacity
SIM card of 64kb and 128kb over a period of 2 days and
then partially deleted using the same mobile phone. The
chosen set of SIM forensic tools were installed on a HP
laptop running window 7, 64 bit operating system. Then a
Siyoteam PC/SC SIM card reader was used to connect the
mobile SIM cards to the computer directly. The mobile SIM
forensic tools used are Dekart SIM Explorer, Paraben SIM
Seizure, Forensic Card reader V2, 001Micron Data Recovery
Sim card, Dekart SIM Manager, MOBILedit SIM Clone. A
Tecno Phanto A+ phone was used for data creation on the
SIM cards. The result of this research shows Paraben SIM
Seizure was able to recover most SIM identification
information and stored data, and also produce a forensic
standard report. Dekart SIM explorer was able to recover all
stored and even deleted data it was also able to produce a
forensic standard report. 001Micron was able to recover
basic SIM identification but could not administer SIM pins
and could not produce a forensic standard report. Forensic
card Reader was able to recover basic SIM identification
information and stored SMS and contacts but was unable to
retrieve any deleted mobile data evidence, MOBILedit SIM
clone was able to recover basic SIM identification
Information and stored SMS and contacts and save such as a
file but could not produce the results in a forensic standard
report.</p>
      <p>VI.</p>
      <p>CONCLUSION</p>
      <p>All the chosen SIM forensic tools were tested on both
SIM cards by extracting the data. The results of these
evaluations shows that it is not easy to retrieve all data
especially deleted mobile data evidence from a SIM card by
using only one type of mobile forensic tool because the
capability of each tool may be developed just for use in
acquiring some specific kind of mobile data evidence. Also
the limitations of some of the tools in terms of foreign
language support and generation of a forensic standard report
was gotten The main contribution of this research is to test
for the capability of each forensic tool as advertised and to
check the compatibility of this specific tool for use in the
forensic analysis of either a MTN 65kb Or Etisalat 128kb
SIM for retrieval of any stored, deleted mobile data evidence
in form of SIM identification and user generated data of
SMS and contacts.</p>
      <p>Modern mobile phones SIM are now ubiquitous in this
world and have progress into full-fledge computing
platforms. Thus, they are becoming more crucial as
evidentiary devices in criminal and civil investigations.
SIM Cards can yield an abundance of information such as
saved contacts, call logs and text messages etc. Conversely,
no single tool can be used by investigators to retrieve
evidence from these devices that it can aid in investigations.</p>
      <p>The possible deterrents to a vendor of forensic tools
from creating single solution is: the number of hardware
manufacturers and carriers the unique data formats used
by vendors for storing relevant information and the security
mechanisms put in place.</p>
      <p>VII.</p>
      <p>RECOMMENDATION</p>
      <p>Having used all the chosen mobile forensic tools and
comparing each result with the manufacturer’s advertised
capabilities, it shows that some tools are limited and cannot
be used singly to successfully acquire all the mobile data
evidence needed for investigation. Therefore any individual
or mobile forensic investigator working to legally acquire
data from mobile SIM should read the software descriptions
and capabilities by developer before proceeding purchase of
that specific software tool for use in forensic acquisition.
Considering the fact that some of the forensic tools used in
this research were trial and demo versions some of their
features could not be utilized, therefore a forensic
investigator should ensure that they purchase full versions of
these tools when there to be used recovering deleted mobile
SIM card data evidence.</p>
      <sec id="sec-12-1">
        <title>VIII. SUGGESTION FOR FURTHER WORK</title>
        <p>With the wide spread use of social media and their
applications on mobile phones, such applications are rich
repository for potential forensics evidence data. The
Compatibility of existing forensics tools for recovery of
these data can be researched.</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Ericsson</surname>
          </string-name>
          , “
          <article-title>On the pulse of the networked society”</article-title>
          <source>Ericsson News CenterRetrieved July20</source>
          ,
          <year>2015</year>
          from http://www.ericsson.com/res/docs/2015/tmd_report_feb_web.pdf.
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Ericsson</surname>
          </string-name>
          ,
          <article-title>"</article-title>
          <source>Ericsson Mobility Report" Retieved June</source>
          ,
          <year>2015</year>
          from www.ericsson.com/res/docs/2015/ericsson-mobility
          <source>-report-june2015.pdf</source>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>Dan</given-names>
            <surname>Lohrmann</surname>
          </string-name>
          ,
          <article-title>"</article-title>
          <source>Lohrmann on Cybersecurity &amp; Infrastructure" Will a Smartphone Replace Your PC? April</source>
          <volume>24</volume>
          ,
          <year>2016</year>
          . Retrieved from http://www.govtech.com/blogs/lohrmann-on
          <article-title>-cybersecurity/will-asmartphone-replace-your-pc.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>O.</given-names>
            <surname>Osho</surname>
          </string-name>
          and
          <string-name>
            <given-names>S. O.</given-names>
            <surname>Ohida</surname>
          </string-name>
          ,
          <article-title>"</article-title>
          <source>Comparative Evaluation of Mobile Forensic Tools" I.J. Information Technology and Computer Science</source>
          ,
          <year>2016</year>
          ,
          <volume>01</volume>
          ,
          <fpage>74</fpage>
          -
          <lpage>83</lpage>
          , doi: 10.5815/ijitcs.
          <year>2016</year>
          .
          <volume>01</volume>
          .09
          <string-name>
            <given-names>W.</given-names>
            <surname>Jansen</surname>
          </string-name>
          &amp; R. Ayers, “
          <article-title>Guidelines on cell phone forensics” NIST Special Publication</article-title>
          ,
          <volume>800</volume>
          ,
          <fpage>101</fpage>
          . Retrieved June 30,
          <year>2015</year>
          , from http://csrc.nist.gov/publications/nistpubs/800-101/
          <fpage>SP800</fpage>
          -101.pdf
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Kyle</surname>
            <given-names>D.</given-names>
          </string-name>
          <string-name>
            <surname>Lute</surname>
          </string-name>
          and Richard P. Mislan, “Challenges in Mobile Phone Forensics” International Institute of Informatics and Systemics, p.
          <volume>1</volume>
          ,
          <issue>2008fromwww</issue>
          .iiis.org/cds2008/cd2008sci/citsa2008/paperspdf/i649o k.pdf
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Timothy</surname>
            <given-names>V</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chengye</surname>
            <given-names>Z</given-names>
          </string-name>
          and
          <string-name>
            <surname>Nicolas</surname>
            <given-names>C</given-names>
          </string-name>
          ,
          <article-title>"Towards a General Collection Methodology for Android Devices"</article-title>
          pp.
          <fpage>1</fpage>
          -
          <lpage>2</lpage>
          2016
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>B.</given-names>
            <surname>Williamson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Apeldoorn</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Cheam</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M.</given-names>
            <surname>McDonald</surname>
          </string-name>
          , “
          <article-title>Forensic analysis of the contents of nokia mobile phones</article-title>
          ”
          <source>page 36</source>
          ,
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          <string-name>
            <given-names>W.</given-names>
            <surname>Jansen</surname>
          </string-name>
          and
          <string-name>
            <given-names>R.</given-names>
            <surname>Ayers</surname>
          </string-name>
          , “
          <article-title>Guidelines on cell phone forensics” NIST Special Publication</article-title>
          ,
          <volume>800</volume>
          :
          <fpage>101</fpage>
          ,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [10]
          <string-name>
            <surname>I. Yates</surname>
          </string-name>
          , “
          <article-title>Practical investigations of digital forensics tools for mobile devices</article-title>
          ” pages
          <fpage>156</fpage>
          -
          <lpage>162</lpage>
          . ACM,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Infosec</surname>
          </string-name>
          , “
          <source>Computer Forensics Investigation case study” Retrieved July 20</source>
          ,
          <year>2015</year>
          from http://resources.infosecinstitute.com/computerforensics-investigation
          <string-name>
            <surname>-</surname>
          </string-name>
          case-study/
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>Joel</given-names>
            <surname>Lee</surname>
          </string-name>
          , “
          <article-title>Why do cellphones need a SIM Card”</article-title>
          .
          <source>Retrieved Dec. 6</source>
          , 2013 from http://www.makeuseof.com/tag/why
          <article-title>-do-cellphones-need-asim-card</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>D. R.</given-names>
            <surname>Matthews</surname>
          </string-name>
          , “
          <article-title>E-Discovery versus Computer Forensics</article-title>
          . Information
          <source>Security Journal”: A Global Perspective</source>
          , vol
          <volume>19</volume>
          iss.3, pp.
          <fpage>118</fpage>
          -
          <lpage>123</lpage>
          ,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>LGC</given-names>
            <surname>Forensics</surname>
          </string-name>
          ,
          <article-title>"Mobile handset examination" Retrieved 2010 from http</article-title>
          ://www.ifblgc.de/sites/default/files/assets/Files/Mobile%20handse t%20examination.pdf
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [15]
          <string-name>
            <surname>He</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Paar</surname>
            ,
            <given-names>I. C.</given-names>
          </string-name>
          “
          <article-title>SIM card security”</article-title>
          . Bochum: Ruhr-University.
          <year>2007</year>
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Seyedhossein</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ali</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Hoorange</surname>
          </string-name>
          , G. B.
          <article-title>"Smartphone Forensics: A Case Study with Nokia E5-00 Mobile Phone"</article-title>
          <source>International Journal of Digital Information and Wireless Communications (IJDIWC) 1</source>
          (
          <issue>3</issue>
          ):
          <fpage>651</fpage>
          -
          <lpage>655</lpage>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Stefan</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Knut</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Reiner</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          <article-title>"Overview of potential forensic analysis of an Android smartphone"</article-title>
          <source>Conference Paper in Proceedings of SPIE - The International Society for Optical Engineering · Retrieved February</source>
          ,
          <year>2012</year>
          fromhttps://www.researchgate.net/publication/258332974_Overview_
          <article-title>of_potential_forensic_analysis_of_an_</article-title>
          <source>Android_smartphone doi:10.1117/12</source>
          .909657
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Mubarak</surname>
            <given-names>A.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Ali</surname>
            <given-names>A.</given-names>
          </string-name>
          "
          <source>Smartphone Forensics Analysis: A Case Study" International Journal of Computer and Electrical Engineering</source>
          , Vol.
          <volume>5</volume>
          , No.
          <issue>6</issue>
          ,
          <string-name>
            <surname>December</surname>
            <given-names>2013</given-names>
          </string-name>
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>Al</given-names>
            <surname>Mutawa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            ,
            <surname>Baggili</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I.</given-names>
            , &amp;
            <surname>Marrington</surname>
          </string-name>
          ,
          <string-name>
            <surname>A.</surname>
          </string-name>
          “
          <article-title>Forensic analysis of social networking applications on mobile devices,” DigitalInvestigation</article-title>
          , vol.
          <volume>9</volume>
          , pp.
          <fpage>S24</fpage>
          -
          <lpage>S33</lpage>
          ,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Srivastava</surname>
            <given-names>A</given-names>
          </string-name>
          &amp;
          <string-name>
            <surname>Vatsal P "Forensic</surname>
          </string-name>
          <article-title>Importance of SIM Cards as a Digital Evidence"</article-title>
          .
          <source>J Forensic Res</source>
          <volume>7</volume>
          :
          <fpage>322</fpage>
          . doi:
          <volume>10</volume>
          .4172/
          <fpage>2157</fpage>
          -
          <lpage>7145</lpage>
          .1000322,
          <year>2016</year>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>