首页> 外文会议>International Symposium on Networks, Computers and Communications >Asynchronous Forensic Investigative Approach to Recover Deleted Data from Instant Messaging Applications
【24h】

Asynchronous Forensic Investigative Approach to Recover Deleted Data from Instant Messaging Applications

机译:异步法医调查方法从即时消息应用程序中恢复已删除数据

获取原文

摘要

Proliferation of digital platforms specifically Instant Messaging Applications (IMAs), have introduced new challenges to digital forensic investigations. With the rapidly increased use of WhatsApp application, it is plausible to speculate that WhatsApp became a potential source of threat and/or cybercrime. Some newly added features on WhatsApp, such as ‘delete for everyone’, giving the users the ability to delete messages from both ends (sender and receiver), have resulted in complicating the cybercrime investigation process. Therefore, there is a need to revisit the investigation process and the structure of such updated features to be able to create a comprehensive digital forensic technique. This paper examines the forensic artifacts of the WhatsApp’s ‘delete for everyone’ feature. This feature is a great addition to the overall usability of IMAs, however, it is also crucial to update the digital forensic investigation techniques and test the capability of commercial forensic tools in recovering forensic evidence when a new technology has been introduced. During the course of this research, we tested and validated the digital forensic methodology and compared the investigation results with forensically sound commercial tools. During the data acquisition process, we conducted physical and logical forensic acquisitions of an Android device which led to a breakthrough discovery of a SQLite file called Write-Ahead-Log (WAL) which contains the application’s latest messages, including deleted (allegedly) messages.
机译:数字平台的扩散专门即时通讯应用程序(IMAS),对数字法医调查引起了新的挑战。随着WhatsApp应用的迅速增加,推测WhatsApp成为潜在的威胁和/或网络犯罪来源是合理的。 WhatsApp上的一些新增功能,例如“每个人的删除”,使用户能够删除来自两端(发件人和接收者)的消息,导致网络犯罪调查过程复杂化。因此,需要重新审视调查过程和这种更新功能的结构,以便能够创建全面的数字法医技术。本文介绍了WhatsApp的删除的法医文物的功能。此功能是IMAS整体可用性的一个很好的补充,但是,更新数字法医调查技术也至关重要,并在推出新技术时测试商业法医工具的能力。在这项研究过程中,我们测试并验证了数字法医方法,并将调查结果与额略良好的商业工具进行了比较。在数据采集过程中,我们进行了一个Android设备的物理和逻辑法医,导致了一个名为regly-feep-log(wal)的sqlite文件的突破性发现,其中包含应用程序的最新消息,包括删除(据称)消息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号