分析Web和UWP版本的WhatsApp进行数字取证

IF 2 4区 医学 Q3 COMPUTER SCIENCE, INFORMATION SYSTEMS
Giyoon Kim , Uk Hur , Soojin Kang , Jongsung Kim
{"title":"分析Web和UWP版本的WhatsApp进行数字取证","authors":"Giyoon Kim ,&nbsp;Uk Hur ,&nbsp;Soojin Kang ,&nbsp;Jongsung Kim","doi":"10.1016/j.fsidi.2024.301861","DOIUrl":null,"url":null,"abstract":"<div><div>WhatsApp is a global secure instant messenger with approximately two billion users. Secure instant messengers use various cryptographic techniques to ensure secure communication. WhatsApp utilizes end-to-end encryption, so even the server owner cannot view internal data. Although this provides strong privacy protection, it can act as a barrier to data collection during digital forensics investigations. We analyze in detail the Web and Universal Windows Platform (UWP) versions of WhatsApp to overcome the collection obstacles that hinder digital forensic investigations. Our analysis showed that for the Web version of WhatsApp, most of the elements needed to decrypt messages are stored in the browser's storage, except for Salt, which is exchanged through communication with the server. We propose a method to obtain Salt by revealing the communication process and the data exchanged, based on which we successfully decrypt the message. For the UWP version of WhatsApp, the database where messages are stored is protected using the identifier value of the application. The identifier value, a unique value assigned to the UWP application, cannot be accessed outside the application. Following a detailed analysis of the UWP API, we developed a method for reproducing the identifier value without calling the API. We also propose a way to decrypt encrypted messages of the UWP version of WhatsApp. Our findings provide a practical solution for forensic investigators analyzing encrypted WhatsApp messages and also provide insights that can be extended to other secure instant messengers.</div></div>","PeriodicalId":48481,"journal":{"name":"Forensic Science International-Digital Investigation","volume":"52 ","pages":"Article 301861"},"PeriodicalIF":2.0000,"publicationDate":"2025-01-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Analyzing the Web and UWP versions of WhatsApp for digital forensics\",\"authors\":\"Giyoon Kim ,&nbsp;Uk Hur ,&nbsp;Soojin Kang ,&nbsp;Jongsung Kim\",\"doi\":\"10.1016/j.fsidi.2024.301861\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><div>WhatsApp is a global secure instant messenger with approximately two billion users. Secure instant messengers use various cryptographic techniques to ensure secure communication. WhatsApp utilizes end-to-end encryption, so even the server owner cannot view internal data. Although this provides strong privacy protection, it can act as a barrier to data collection during digital forensics investigations. We analyze in detail the Web and Universal Windows Platform (UWP) versions of WhatsApp to overcome the collection obstacles that hinder digital forensic investigations. Our analysis showed that for the Web version of WhatsApp, most of the elements needed to decrypt messages are stored in the browser's storage, except for Salt, which is exchanged through communication with the server. We propose a method to obtain Salt by revealing the communication process and the data exchanged, based on which we successfully decrypt the message. For the UWP version of WhatsApp, the database where messages are stored is protected using the identifier value of the application. The identifier value, a unique value assigned to the UWP application, cannot be accessed outside the application. Following a detailed analysis of the UWP API, we developed a method for reproducing the identifier value without calling the API. We also propose a way to decrypt encrypted messages of the UWP version of WhatsApp. Our findings provide a practical solution for forensic investigators analyzing encrypted WhatsApp messages and also provide insights that can be extended to other secure instant messengers.</div></div>\",\"PeriodicalId\":48481,\"journal\":{\"name\":\"Forensic Science International-Digital Investigation\",\"volume\":\"52 \",\"pages\":\"Article 301861\"},\"PeriodicalIF\":2.0000,\"publicationDate\":\"2025-01-08\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Forensic Science International-Digital Investigation\",\"FirstCategoryId\":\"3\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S2666281724001884\",\"RegionNum\":4,\"RegionCategory\":\"医学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q3\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Forensic Science International-Digital Investigation","FirstCategoryId":"3","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2666281724001884","RegionNum":4,"RegionCategory":"医学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

摘要

WhatsApp是一个全球安全的即时通讯工具,拥有大约20亿用户。安全的即时通讯工具使用各种加密技术来确保通信的安全。WhatsApp采用端到端加密,因此即使是服务器所有者也无法查看内部数据。虽然这提供了强大的隐私保护,但在数字取证调查期间,它可能成为数据收集的障碍。我们详细分析了WhatsApp的Web和通用Windows平台(UWP)版本,以克服阻碍数字取证调查的收集障碍。我们的分析显示,对于Web版本的WhatsApp,解密消息所需的大部分元素都存储在浏览器的存储中,除了Salt,它通过与服务器的通信进行交换。我们提出了一种通过揭示通信过程和交换数据来获取Salt的方法,并在此基础上成功地对消息进行了解密。对于UWP版本的WhatsApp,存储消息的数据库使用应用程序的标识符值进行保护。标识符值是分配给UWP应用程序的唯一值,不能在应用程序外部访问。在详细分析了UWP API之后,我们开发了一种无需调用API即可再现标识符值的方法。我们还提出了一种解密UWP版本WhatsApp加密消息的方法。我们的发现为法医调查人员分析加密的WhatsApp消息提供了一个实用的解决方案,也提供了可以扩展到其他安全即时通讯工具的见解。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Analyzing the Web and UWP versions of WhatsApp for digital forensics
WhatsApp is a global secure instant messenger with approximately two billion users. Secure instant messengers use various cryptographic techniques to ensure secure communication. WhatsApp utilizes end-to-end encryption, so even the server owner cannot view internal data. Although this provides strong privacy protection, it can act as a barrier to data collection during digital forensics investigations. We analyze in detail the Web and Universal Windows Platform (UWP) versions of WhatsApp to overcome the collection obstacles that hinder digital forensic investigations. Our analysis showed that for the Web version of WhatsApp, most of the elements needed to decrypt messages are stored in the browser's storage, except for Salt, which is exchanged through communication with the server. We propose a method to obtain Salt by revealing the communication process and the data exchanged, based on which we successfully decrypt the message. For the UWP version of WhatsApp, the database where messages are stored is protected using the identifier value of the application. The identifier value, a unique value assigned to the UWP application, cannot be accessed outside the application. Following a detailed analysis of the UWP API, we developed a method for reproducing the identifier value without calling the API. We also propose a way to decrypt encrypted messages of the UWP version of WhatsApp. Our findings provide a practical solution for forensic investigators analyzing encrypted WhatsApp messages and also provide insights that can be extended to other secure instant messengers.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
5.90
自引率
15.00%
发文量
87
审稿时长
76 days
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信