Using Instant Messaging (IM) such as Telegram, WhatsApp, etc. has become part of people’s daily activities. IM facilitates users’ communication with family, friends, social groups, and business-related activities. However, there are downsides associated with the use of this technology including online crime, fraud, malware, exploitation of minors, etc. In addition, many users may accidentally expose personal and intimate details about themselves, their friends, and their relationships online. This can be done by posting photos, participating in group activities, polling, and providing personally identifiable information such as their home addresses, phone numbers, etc. Forensic analysis of IMs can help investigators solve the crimes or misuse of IMs. This experimental research aims to investigate traces of WhatsApp user’s activities via computer forensics. The activities may include personal information or any type of exploitation information. Several open-source forensics tools will be used in the experiment. The platform for the experiment is Virtual Machines. This research demonstrates that memory forensics is more effective than regular forensics in retrieving IM-related artifacts.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Forensics Analysis of WhatsApp Using Virtual Machines

  • Ahmad Ghafarian,
  • Alfredo Madrigal

摘要

Using Instant Messaging (IM) such as Telegram, WhatsApp, etc. has become part of people’s daily activities. IM facilitates users’ communication with family, friends, social groups, and business-related activities. However, there are downsides associated with the use of this technology including online crime, fraud, malware, exploitation of minors, etc. In addition, many users may accidentally expose personal and intimate details about themselves, their friends, and their relationships online. This can be done by posting photos, participating in group activities, polling, and providing personally identifiable information such as their home addresses, phone numbers, etc. Forensic analysis of IMs can help investigators solve the crimes or misuse of IMs. This experimental research aims to investigate traces of WhatsApp user’s activities via computer forensics. The activities may include personal information or any type of exploitation information. Several open-source forensics tools will be used in the experiment. The platform for the experiment is Virtual Machines. This research demonstrates that memory forensics is more effective than regular forensics in retrieving IM-related artifacts.