Journal of the Faculty of Engineering and Architecture of Gazi University, cilt.39, sa.3, ss.1637-1647, 2024 (SCI-Expanded)
In forensic content examination, it is important to support electronic devices such as personal computers and mobile phones with the detection of MAC addresses. However, as a result of the examinations made with forensic examine software, it has been observed that the MAC address records that have fallen into the operating system cannot always be detected completely. In this study, suggestions for examination have been made. The Table A below shows an example of this situation. (Table Presented) Purpose: The aim of this study is to analyze the MAC address records of the phones connected to a computer with MacOS, to identify the problems encountered during the analysis and to offer solutions to these problems. Theory and Methods: This article suggests a methodology consisting of the preparation of the working environment, the collection of data, the analysis of the data and the evaluation of the results. In accordance with this methodology, a total of ten different applications were used by phones with iOS and ANDORID operating systems. Results: Obtained results showed that the MAC address records falling to the operating system did not work correctly every time, the connection type affects the results, and there are multiple MAC address records for one phone. These results may mislead the court conclusion. Conclusion: When iOS devices make a network connection with macOS computer over Wi-Fi, the MAC address records that fall on the operating system are completely different, how to find the correct MAC address record that falls on the operating system when USB connection is established, and in which case more than one MAC address in the operating system records for ANDROID devices record has been shown.