Analysis of autopsy mobile forensic tools against unsent messages on whatsapp messaging application

Fahdiaz Alief, Yohan Suryanto, Linda Rosselina, Tofan Hermawan

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

This paper discusses the new feature implemented in most social media messaging applications: the unsent feature, where the sender can delete the message he sent both in the sender and the recipient devices. This new feature poses a new challenge in mobile forensic, as it could potentially delete sent messages that can be used as evidence without the means to retrieve it. This paper aims to analyze how well Autopsy open-source mobile forensics tools in extracting and identifying the deleted messages, both that are sent or received. The device used in this paper is a Redmi Xiaomi Note 4, which has its userdata block extracted using linux command, and the application we’re using is WhatsApp. Autopsy will analyze the extracted image and see what information can be extracted from the unsent messages. From the result of our experiment, Autopsy is capable of obtaining substantial information, but due to how each vendor and mobile OS store files and databases differently, only WhatsApp data can be extracted from the device. And based on the WhatsApp data analysis, Autopsy is not capable of retrieving the deleted messages. However it can detect the traces of deleted data that is sent from the device. And using sqlite3 database browser, the author can find remnants of received deleted messages from the extracted files by Autopsy.

Original languageEnglish
Title of host publicationProceedings - 2020 7th International Conference on Electrical Engineering, Computer Science and Informatics, EECSI 2020
PublisherInstitute of Advanced Engineering and Science
Pages26-30
Number of pages5
ISBN (Electronic)9786020737614
DOIs
Publication statusPublished - 1 Oct 2020
Event7th International Conference on Electrical Engineering, Computer Science and Informatics, EECSI 2020 - Yogyakarta, Indonesia
Duration: 1 Oct 20202 Oct 2020

Publication series

NameInternational Conference on Electrical Engineering, Computer Science and Informatics (EECSI)
Volume2020-October
ISSN (Print)2407-439X

Conference

Conference7th International Conference on Electrical Engineering, Computer Science and Informatics, EECSI 2020
Country/TerritoryIndonesia
CityYogyakarta
Period1/10/202/10/20

Keywords

  • Autopsy
  • Mobile forensic
  • Social media messaging
  • Sqlite3
  • Unsent feature
  • Whatsapp

Fingerprint

Dive into the research topics of 'Analysis of autopsy mobile forensic tools against unsent messages on whatsapp messaging application'. Together they form a unique fingerprint.

Cite this