iGEM: A Multi-Device Forensic Visualization Software for Geolocation and Digital Evidence Matching
Primary Investigator:
Umit Karabiyik
Akif Ozer, Xiao Hu, Umit Karabiyik, Marcus K. Rogers
Abstract
The rapid growth of mobile devices has changed the field of digital forensics and calls for new methods to analyze evidence comprehensively. Traditional forensic tools treat data sources separately, often missing important connections between spatial, temporal, and application usage information. This research, as detailed in the accompanying poster, introduces iGEM, a multi-device forensic visualization software that automates the extraction and integration of key artifacts from iOS devices. iGEM gathers information from sources such as Cache.Sqlite for GPS data, KnowledgeC.db for application logs, and KTX files for visual evidence. By merging these sources into a unified SQLite database and providing an interactive interface with timeline controls and map-based views, iGEM reveals hidden patterns in both time and space, thus enhancing investigative research and improving court presentations.