Skip to main content
. 2017 Apr 26;12(4):e0176223. doi: 10.1371/journal.pone.0176223

Table 3. Concept extraction.

Model Concept Total
Developing Process for Mobile Device Forensics [43]
Procedure, Chain of Custody, Information, Incident, Identification, Legal Authority, Search Warrant, Removable Data Storage, Mobile Device, Source, Potential Evidence, Forensic Tool, Documentation, Preparation, Drivers, Isolation, Faraday Bag, Radio Frequency Shielding, Extraction, Physical Memory Dump, logical Acquisition, Manual Extraction, Flash Memory Chip, Examination Data, Analyst, Examiner, File System, Verification, Hash Value, Integrity, Presentation, Prosecutor, Court, Investigator, Audience, Evidence, Jury, Archiving, Finding, Experience, Photographing, Backup, Equipment, Physical Acquisition, Unlocking Bootloader, Airplane Mode, Network Provider 47
Symbian smartphones forensic process model [44]
Preparation, Identification, Initial Information, Mobile Device, Forensic Tool, Policy, Analysis Data, Integrity, Pattern matching, Examination Data, Interpretation, Presentation, Review, Result, Evidence, Removable Media 16
Windows Mobile Forensic Process Model [45]
Preparation, Recording, Photographing, Sketching, Crime, Crime Scene, Investigator, Evidence Source, Assessment Crime, Authorization, Search Warrant, Experience, Mobile Device, PackagingAndSealing, Transportation and Storage, Jurisdictional Law, Chain of Custody, Integrity, People, External Storage Media, Survey, Recognition, Potential Evidence, Search Plan, Securing Scene, Environmental Circumstance, Shock, Humidity, Temperature, Victims, Suspect, Witness, Forensic Specialist, KeywordSearch, Documentation, Communication Shielding, Evidence Collection, Volatile Evidence, Non-Volatile Evidence, Forensic Tool, Instigation Procedure, Examination Data, Data Filtering, Validation, Pattern Matching, Tampering, Hashing Technique, Recovering Data, Analysis Data, Investigative Team, Reconstructing Event, Timeframe Analysis, Hidden Data Analysis, Application and File Analysis, Interpretation, Presentation, Results, Audience, Law Enforcement, Technical Expert, Legal Expert, Corporate Management, Court of Law, Conclusion, Evidence, Jury, Police Investigation, Review, Legal Constraint, Investigation strategy, Backup, Equipment, Source, Unlocking Bootloader 76
Smartphone Forensic Investigation Process Model [46]
Tool, Crime Scene, Search Warrant, Knowledge, Mobile Device, PackagingAndSealing, Transportation and Storage, Investigation Procedure, Legal Constraint, Legal Jurisdictional, Suspect, Authorization, Integrity, Investigator, Chain of Custody, Recording, Photographing, KeywordSearch, Crime-scene Mapping, Documentation, Tampering, Victim, Witness, Communication Shielding, Environmental Effect, Shock, Humidity, Temperature, Volatile Evidence, Non-volatile Evidence, External Storage, Cell Site Analysis, Law Enforcement, Examination Data, Data Filtering, Validation, Pattern Matching, Recovering Data, Forensic Specialist, Hashing Technique, Analysis Data, Reconstructing Event, Timeframe Analysis, Hidden Data Analysis, Application and File Analysis, Interpretation, Presentation, Audience, Technical Expert, Legal Expert, Jury, Corporate Management, Court of Law, Police Investigation, Conclusion, Review, Result, Systematic Strategy, Forensic Laboratory, Securing Scene, Airplane Mode, Cell Site Analysis, Local Service Provider 66
Smart-Phone DEFSOP [47]
Legislation, Documentation, Crime, People, Preparation, Mobile Device, Investigator, Searching Place, Forensic Tool, Integrity, Collecting information, Detaining Evidence, Analysis Data, Mobile Calendar, Call History, Message, Voicemail, Memory Card, Acquired Data, Crime Scene, Court, Result, Copy of Evidence, Judge, Equipment Identification, Presentation, Laboratory 27
Enhanced Mobile Forensic Process Model [48]
Preparation, Authorization, Search Warrant, Recording, Photographing, Sketching, Planning, Tool, Securing Scene, Survey, Recognition, Forensic Specialist, Device Mode, PackagingAndSealing, Transportation and Storage, Signal Isolation, Acquired Data, Hand-held device, Evidence, Laboratory Evidence, Volatile Evidence, Investigative Team, Examination Data, Analysis Data, Evidence, Backup, Hidden Data, Reconstructing Event, Presentation, Chain of Custody, Review, Audience, Result, Law Enforcement, Corporate Management, Legal Expert, Court Ruling, Crime, Seizure, Forensic Examiner 41
Framework for iPhone Forensic [49]
Tool, Forensic Investigator, Data Integrity, Logical Acquisition, Physical Acquisition, Suspect Device, Data Analysis, Text Evidence, Network Evidence, Audio-Visual Evidence, Online Activity Evidence, User Activity Evidence, Software, Backup, Retrieved Evidence, Evidence, Authority, Crime Scene, Cellular Provider 19
Mobile Forensics using the Harmonised Digital Forensic Investigation Process [50]
Investigation Procedures, Incident, Identification, First Responder, Investigator, Planning, Techniques, Preparation Equipment, Documentation, Incident Scene, Chain of Custody, Extraction, Evidence, Authorization, Investigative Team, Photographing, Recording Scene, Potential Evidence, Integrity, Transportation and Storage, Shock, Acquired Data, Logical Acquisition, Physical Acquisition, Analysis Data, Reconstructing Scene, Recovery, Evidence, Interpretation, Expert witness’s testimony, Presentation, Timestamp, Stakeholders, jury, Accused, Lawyers, Prosecutor, Validity, Investigation Conclusion, Decision, Laboratory, Retrieved Data, Internal Memory 45
A quantitative approach to Triaging in Mobile Forensics [51] Device Identification, Crime Scene, Extraction, Data Triaging, Technique, Analysis Data, Evidence, Forensics Lab, Extracted Data, Investigator, Mobile Content, Mobile Phone 13
A Theoretical Process Model for Smartphones [52]
Transportation and Storage, Device, Isolation, Investigator, Faraday Bag, Documentation, Classification, Case, Forensic Tool, Suspect, Victim, Collecting Facts, Information Device, Forensic Examiner, Potential Evidence, Backup, Examination Data, Investigation Procedures, Analysis Data, Extracting Data, Evidence, Hashing Method, Verification, Internal Components, Removable Component, Interpretation, Presentation, Result, Stakeholder, Law Enforcement, Source 31
Mobile Smart Device Investigation Process [53]
Incident Detection, Crime Scene, Preparation, Sketching, Photographing, Recording, Chain of Custody, Target Device, First Responder, Assessment Incident, Investigation Plan, Potential Evidence, People, Forensic Personnel, Investigation Strategy, Identification, Isolating, Pattern Matching, Search Warrant, Documentation, Device Power, Recovering Data, Acquisition Method, Manual Acquisition, Logical Acquisition, Physical Acquisition, Integrity, Duplicate Evidence, Examination Data, Search, Filtering, Hidden Data, Visibility, Traceability, Validating, Evidence, Tool, External Evidence, Analysis Data, Reconstructing Event, Conclusion, Legal Expert, Investigator, Presentation, Summarizing, Court, Physical Evidence, Response Strategy, Acquired Data, Source, Rooting 53
Conceptual Evidence Collection and Analysis Methodology for Android Devices [54]
Procedure, Practitioner, Device, Faraday Bag, Photographing, Seizure, Practice, Disable Device Radio, Internal Memory, Physical Evidence, Filtering, Physical Collection, Device State, Potential Evidence, Forensic Procedure, Extraction, Suspect, Non-volatile Evidence, Integrity, Flash Memory, Forensic Tool, Organization, Hashing Algorithm, External Storage, Analysis Technique, Examination Data, Analysis Data, Evidence, KeywordSearch, Verification, Presentation, Finding, Court, Backup, Unlocking Bootloader, Airplane Mode, Rooting 39
Mobile Forensic Investigation Life Cycle Process [55]
Seizure, Identification, Planning, Preparation, Disable Network, Acquiring Mobile, Faraday Bag, Internal Memory, External Memory, Transportation and Storage, Laboratory, Crime, Storage Media, Chain of Custody, Data Analysis, Examination Forensic, Presentation, Legal Authority, Capturing, KeywordSearch, Source 21
An Android Social App Forensics Adversary Model [56]
Logical Forensic, Physical Forensic, Forensic Analysis, Tool, Examination, Evidence, Investigator, Findings, Android Phone, Internal Device Memory, Personal Information, Rooting 12
Android cache taxonomy and forensic process [57]
Law Enforcement, Forensic Examination, Classification, Forensic Practitioner, Practice, Forensic Analysis, Internal Storage, Mobile Device, Presentation, Court, Extraction, External Storage, Rooting 13
Thumbnail forensic recovery process for Android devices [58]
Identification, Mobile Device, Potential Evidence, Flash Memory, Tampering, Evidence, Physical Acquisition, Logical Acquisition, Manual Acquisition, Data Recovery, Extraction, Analysis Data, Hashing, Integrity, Matching, Presentation, Source, Unlocking Bootloader 19
Integrated Digital Forensic Investigation Framework for smartphone [59]
Preparation, Notification, Authorization, Seized Device, Incident Response, Securing Scene, Documentation, Crime, Scene, Event Triggering, Transportation and Storage, Communication Shielding, Volatile Evidence, Non-Volatile Evidence, Examination Data, Analysis Data, Reconstruction, Hashing, Presentation, Conclusion, Dissemination, Decision, Investigator 24
Framework of Digital Forensics for the Samsung Star Series Phone [60]
Preparation, Authorization, Forensic Examination, Transportation and Storage, Practice, Search, Seizure, Warrant, Witness, Evidence, Authority, First Responder, Crime Scene, Investigator, Equipment, Investigation Procedure, Disable Signal, Phone State, Live Acquisition, Manual Acquisition, Logical Acquisition, Capturing, Analysis Data, Presentation, Collected Data 25
Guidelines on Mobile Device Forensics [42]
Mobile Device, Identification, Securing Scene, Evaluating Scene, Potential Digital Evidence, Procedure, Seizure Device, Integrity, Preparing, Search, Documentation, Recording, Photographing, Evidence Collection, Memory Volatility, PackagingAndSealing, Transporting and Storing Evidence, Isolation, Faraday Cage, Decision, Filtering, Law Enforcement, Validation, Hidden Data Analysis, Equipment, Removable Media, Verification, Interviewing, Internal Memory, Forensic Examiner, Capturing, Forensic Specialist, Forensic Laboratory, Acquisition Method, Logical Acquisition, Physical Acquisition, Manual Extraction, Extraction, Recovering, Search Warrant, Forensic Tool, Examination Data, Copy of Evidence, Forensic Analyst, Potential Evidence, Suspect, Analysis Data, Hash Value, Application and File Analysis, Timeframe Analysis, Court of Law, Results, Evidence, Jurisdiction, Scene, Conclusion, Acquired Data, KeywordSearch, Source, Airplane Mode, Cell Site Analysis, Network Provider 62
Mobile Forensics Model [61]
Preparation, People, Investigation Team, First Responder, Securing Scene, Crime scene, Systematic Strategy, Legal Constraint, Evidence, Chain of Custody, Integrity, Cut Network Communication, Acquisition Method, Manual Acquisition, Logical Acquisition, Physical Acquisition, Mobile Device, Internal Memory, Non-Volatile Evidence, Volatile Evidence, Documentation, Legal Authority, Photographing, Examiner, Investigation, Transportation and Storage, Procedure, Humidity, Temperature, Environmental Effect, Forensics Lab, Examination Data, Collected Evidence, Copy of Evidence, Data Filtering, Validation, Detecting, Recovering Data, Forensics Tool, Analysis Data, Time frame Analysis, Presentation, Court of Law, Decision, Crime, Culprit, Evidence, Review, investigator, Result 52
An Approach for Mobile Forensics Analysis [62]
Investigator, Seizure, Wireless Network Off, Faraday Cage, Suspect, Crime Scene, Documentation, Forensic Lab, Tool, Forensic Analyst, Analysis, Forensic Analysis, External Memory, Forensic Examiner, Hash Function, Integrity, Presentation, Result, Audience, Collected Data, Evidence, Internal Memory, Source, Airplane Mode 24