In allowing real-time chats across many platforms with shocking ease, the emergence of web-based messaging apps like WhatsApp and Telegram has transformed communication. Even if they provide unrivaled simplicity, these technologies present different opportunities and difficulties for forensic investigations. Emphasizing their fundamental technologies, data storage approaches, and forensic data extraction methodologies, this article provides a complete forensic study of the web versions of WhatsApp and Telegram. Emphasizing the need for the QR token mechanism utilized for authentication and chat synchronization, we first look at the technical underpinnings of Web WhatsApp and Web Telegram. By use of a safe token exchange using QR codes, this mechanism guarantees that only confirmed users may access their chat history on web clients, therefore preserving the integrity and confidentiality of user interactions. Investigated in this study is the architecture of online portals employing JavaScript, WebSocket protocol, and Indexed Database for dynamic content loading, real-time message delivery, and efficient data storage. The section on forensic analysis specifies a strict method for gaining access to stored information from many websites. This entails locating cache and indexed database files comprising necessary forensic artifacts: metadata, session data, and chat history. One explains the preservation of chat messages, timestamps, sender/receiver IDs, and extra contextual data by means of an in-depth analysis of ldb files in the Indexed Database, thereby enabling a chance to extract and assess this data for forensic uses. Much of this work is on the analysis of RAM memory dumps, in which case volatile data from live Web WhatsApp and Web Telegram sessions is collected and examined. This study reveals chat messages, session tokens, and other transient data not permanently kept on disk, therefore offering a more whole picture of user activity over a session. The discovery of a consistent method for collecting phone numbers from the RAM dump indicates the feasibility of automated forensic extraction, hence improving the relevance of these investigations.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Advanced Forensic Analysis of Web-Based Social Messaging Platforms

  • Shubham Gupta,
  • Deepa Parasar,
  • Swetta Kukreja,
  • Nikhil Prajapat,
  • Preeti Narooka

摘要

In allowing real-time chats across many platforms with shocking ease, the emergence of web-based messaging apps like WhatsApp and Telegram has transformed communication. Even if they provide unrivaled simplicity, these technologies present different opportunities and difficulties for forensic investigations. Emphasizing their fundamental technologies, data storage approaches, and forensic data extraction methodologies, this article provides a complete forensic study of the web versions of WhatsApp and Telegram. Emphasizing the need for the QR token mechanism utilized for authentication and chat synchronization, we first look at the technical underpinnings of Web WhatsApp and Web Telegram. By use of a safe token exchange using QR codes, this mechanism guarantees that only confirmed users may access their chat history on web clients, therefore preserving the integrity and confidentiality of user interactions. Investigated in this study is the architecture of online portals employing JavaScript, WebSocket protocol, and Indexed Database for dynamic content loading, real-time message delivery, and efficient data storage. The section on forensic analysis specifies a strict method for gaining access to stored information from many websites. This entails locating cache and indexed database files comprising necessary forensic artifacts: metadata, session data, and chat history. One explains the preservation of chat messages, timestamps, sender/receiver IDs, and extra contextual data by means of an in-depth analysis of ldb files in the Indexed Database, thereby enabling a chance to extract and assess this data for forensic uses. Much of this work is on the analysis of RAM memory dumps, in which case volatile data from live Web WhatsApp and Web Telegram sessions is collected and examined. This study reveals chat messages, session tokens, and other transient data not permanently kept on disk, therefore offering a more whole picture of user activity over a session. The discovery of a consistent method for collecting phone numbers from the RAM dump indicates the feasibility of automated forensic extraction, hence improving the relevance of these investigations.