The advent of the Internet has significantly transformed the daily activities of millions of people, with one of them being the way people communicate where Instant Messaging (IM) and Voice over IP (VoIP) communications have become prevalent. Although IM applications are ubiquitous communication tools nowadays, it was observed that the relevant research on the topic of evidence collection from IM services was limited. The reason is an IM can serve as a very useful yet very dangerous platform for the victim and the suspect to communicate. Indeed, the increased use of Instant Messengers on smart phones has turned to be the goldmine for mobile and computer forensic experts. Traces and Evidence left by applications can be held on smart phones and retrieving those potential evidences with right forensic technique is strongly required. Recently, most research on IM forensics focus on applications such as WhatsApp, Viber and Skype. However, in the literature, there are very few forensic analysis and comparison related to IM applications such as WhatsApp, Viber and Skype and Tango on both iOS and Android platforms, even though the total users of this application already exceeded 1 billion. Therefore, in this paper we present forensic acquisition and analysis of these four IMs and VoIPs for both iOS and Android platforms. We try to answer on how evidence can be collected when IM communications are used. We also define taxonomy of target artefacts in order to guide and structure the subsequent forensic analysis. Finally, a review of the information that can become available via the IM vendor was conducted. The achieved results of this research provided elaborative answers on the types of artifacts that can be identified by these IM and VoIP applications. We compare moreover the forensics analysis of these popular applications: WhatApp, Skype, Viber and Tango.
翻译:互联网的出现极大地改变了数百万人的日常活动,其中之一是人们在即时通信和语音对IP(VoIP)通信的流行时,即时通信和语音对IP(VoIP)通信的交流方式。虽然目前IM应用程序是无处不在的通信工具,但人们注意到,关于IM服务收集证据的专题的相关研究有限,原因是IM可成为受害者和嫌疑人沟通的非常有用而又非常危险的平台。事实上,在智能电话上更多地使用Instalpp 公益信使的答案已成为移动和计算机法医专家的金矿。应用留下的痕迹和证据可以存放在智能电话上,用正确的法医技术检索这些潜在证据。最近,关于IM的多数法医研究侧重于“WhatsApp、Viber和Skype”等应用程序的应用。在文献中,很少有与IM通信应用有关的法医分析和比较,在iOS和android平台上,即使应用程序的用户总数已经超过10亿次的IPO(IP)数据库分析,我们也可以用这些解算取的IP(VOM)和(IP)数据库分析结果,我们也可以在本文上找到。