Cellebrite UFED Analytics Enterprise Platform
October 03, 2016
Depends on configuration.
- Ease of Use:
- Value for Money:
- Overall Rating:
- Strengths: Very comprehensive feature set, solid analytics and well-thought-out user interface. Plenty of room for feature expansion to keep pace with cyber-investigation requirements.
- Weaknesses: None that we found.
- Verdict: This is for larger organisations, but if you have a reasonably heavy digital case load - especially if you already are a Cellebrite shop - this is for you. We have made various Cellebrite products SC Lab Approved in the past and for its innovative approach, solid analytics and forward-looking implementation, we add UFED Analytics to our SC Lab Approved list. Stay tuned for our report in 12 months on how we applied it to our research and testing in the SC Labs.
Over the years Cellebrite has been a pioneer in mobile device forensics. However, their long-term roadmap always has included the concept of end-to-end digital investigation. This is investigation that begins with the slightest digital breadcrumb and fans out to include all relevant evidence and it inter-relationships. In a small investigation that's pretty straightforward to accomplish. The company has developed a suite of products such as the cloud analyser and their link analysis tool that, taken individually, are very strong. From the UFED Ultimate to the Cloud Analyser and the other UFED products, for Cellebrite it's all about collecting the data - without which there is no analysis - and which they do more comprehensively than any other product suite we've seen.
But there have remained some stumbling blocks to successfully concluding today's cyber investigations. First, the amount of data in a typical investigation is massive. We have conducted trivial investigations on phones used by students that contained over 100,000 images, for example.
Additionally, there is the challenge of unification of workflow and data. When you have a large investigation with lots of data and multiple investigators, analysts and attorneys - as might be the case in a federal drug investigation - matching workflows appropriately while preserving privacy restrictions when necessary - a victim device, for example - can be a serious issue.
Finally, how do you maximise your technology investment. It has become axiomatic that a well-equipped lab will have multiple examples of tools from different vendors. How do you take advantage of those tools in ways that actually make sense and get you the most coverage for your investment?
All of these issues suggest some sort of unified analysis platform that can consume data and help the investigator make the necessary connections. This is especially important for larger organisations. The Cellebrite UFED Analytics Enterprise Platform does exactly that. It consumes digital forensic data collected - at the moment - by Cellebrite devices and ties the pieces together in a wide variety of ways. Obvious is the usual tabular listing. Like any digital forensic tool, Analytics allows for listing the data in a variety of formats - by caller, device, time, etc.
However, it also includes link analysis and the ability to extract social media data from the cloud. Given data on the device and data in the cloud, coupled with similar data on other devices - that may or may not be related - the link analyser automatically makes the connections starting with the big picture and drilling down to the relationships between a single actor and others with whom he or she has been in contact. All of that can be geolocated.
Searches by owner, locale, sources, entities and several others allow focusing in on the useful information. You can set watch lists so that as you comb through piles of data only those things with which you are concerned directly come up in your search. More important, perhaps, is the ability to search for unknown unknowns. For example, you may have no idea where your bad guys are located so you do a location view that shows anomalous activity in London. You are in Manchester, so London really wasn't in your scope, but your search shows a conversation between a suspect in Manchester and a person - unknown at the moment - in Birmingham. Your suspect asks, "What about our guy in London?" You just uncovered a lead that you might have otherwise missed or, at least, missed for a long time.
Cellebrite has had a top-notch support system and website for as long as we've been watching it. Currently the site and support are no exception to that longstanding rule. The product is in a constant state of growth, so expect to see frequent enhancements and upgrades as users present new use cases to the company. The UI is slick and simple to navigate and pricing is variable depending on what implementation you settle on.
SC Webcasts UK
Information Security Manager
Infosec People - Hammersmith, West London
Information Security Risk Manager, £45-55k + bens
Infosec People - West Midlands, England, Coventry
SOC Analyst, Aldershot, £55-63k + benefits
Infosec People - England, Aldershot, Hampshire
Security Architect, Cardiff - to £70k Basic
Infosec People - Cardiff, Wales
Interim CISO (Chief Information Security Officer) - Cyber Security Director
CYBER EXECS - London (Central), London (Greater)
Sign up to our newsletters
SC Magazine UK Articles
- Gooligan ad fraud malware infects 1.3M Android users, installs over 2M unwanted apps
- Met Police grab suspect with phone unlocked to get hold of data
- Cyber-security must reflect risk not just regulation
- Data centres are on the move - where will they end up?
- The information security implications of M&A deals
- SC Awards Europe 2016 winners announcements!
- ISIS radicalises 'lone wolves' through strong social media presence
- Updated: How will Brexit affect the cyber-security industry in UK and Europe?
- 9.2 million medical records for sale on darkweb
- Microsoft Office 365 hit with massive Cerber ransomware attack, report
- Over 400,000 phishing sites have been detected each month in 2016
- TalkTalk customers urged to get routers swapped over hacker fears
- Report: Mirai 'is just the tip of the iceberg'
- Avalanche takedown involved searches in 40 countries
- India Supreme Court calls on tech giants to curb sexual assault, cyber-crime