Suppr超能文献

Windows即时通讯应用取证:以Facebook和Skype为例

Windows Instant Messaging App Forensics: Facebook and Skype as Case Studies.

作者信息

Yang Teing Yee, Dehghantanha Ali, Choo Kim-Kwang Raymond, Muda Zaiton

机构信息

Department of Computer Science, Faculty of Computer Science and Information Technology, Universiti Putra Malaysia, UPM Serdang, Selangor, Malaysia.

The School of Computing, Science & Engineering, Newton Building, University of Salford, Salford, Greater Manchester, United Kingdom.

出版信息

PLoS One. 2016 Mar 16;11(3):e0150300. doi: 10.1371/journal.pone.0150300. eCollection 2016.

Abstract

Instant messaging (IM) has changed the way people communicate with each other. However, the interactive and instant nature of these applications (apps) made them an attractive choice for malicious cyber activities such as phishing. The forensic examination of IM apps for modern Windows 8.1 (or later) has been largely unexplored, as the platform is relatively new. In this paper, we seek to determine the data remnants from the use of two popular Windows Store application software for instant messaging, namely Facebook and Skype on a Windows 8.1 client machine. This research contributes to an in-depth understanding of the types of terrestrial artefacts that are likely to remain after the use of instant messaging services and application software on a contemporary Windows operating system. Potential artefacts detected during the research include data relating to the installation or uninstallation of the instant messaging application software, log-in and log-off information, contact lists, conversations, and transferred files.

摘要

即时通讯(IM)改变了人们相互交流的方式。然而,这些应用程序(应用)的交互性和即时性使其成为网络钓鱼等恶意网络活动的诱人选择。由于Windows 8.1(或更高版本)这个平台相对较新,对其进行即时通讯应用程序的法医检查在很大程度上尚未得到探索。在本文中,我们试图确定在一台Windows 8.1客户端机器上使用两款流行的Windows应用商店即时通讯应用软件(即Facebook和Skype)后留下的数据残余。这项研究有助于深入了解在当代Windows操作系统上使用即时通讯服务和应用软件后可能残留的各类痕迹。研究过程中检测到的潜在痕迹包括与即时通讯应用软件安装或卸载相关的数据、登录和注销信息、联系人列表、对话以及传输的文件。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8c84/4794233/6da63998714b/pone.0150300.g001.jpg

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验