Author:
Ong Wee Sern,Ab Rahman Nurul Hidayah
Abstract
In this study, we demonstrate the role of visualization to facilitate forensic analysis goal in interpreting metadata of evidence of interest to answer who, what, why, when, where, and how an incident occurred. Two mobile Instant Messaging (IM) applications (i.e. WhatsApp and Line) were deployed as a case study. Subsequently, a tool – W*W Visualizer – was designed and developed with the aims to analyze and visualize the connection of evidence metadata, text frequency and word count, and display report of analysis activities. The tool is developed by adopting Object-Oriented Software Development Model with Visual Studio platform and C# language were used to develop the system. Our findings show that W*W Visualizer could transform the data of the chat database into a visual form, for example graph, chart and word cloud. The tool also allows the user to perform search feature such as searching based on keyword and timestamp from the IM chat history. It is expected that outcomes from this study would significantly influence digital forensics practitioners in analyzing and interpreting evidence data, and judicial authorities in understanding the presentation of evidence.
Publisher
School of Computing, Telkom University
Reference31 articles.
1. Statista, “Number of smartphone users worldwide from 2014 to 2020 (in billions),” 2018. .
2. S. Alhidaifi, “Mobile Forensics : Android Platforms and WhatsApp Extraction Tools,” Int. J. Comput. Appl., vol. 179, no. 47, pp. 25–29, 2018.
3. K. Curran, A. Robinson, S. Peacocke, and S. Cassidy, “Mobile Phone Forensic Analysis,” in Crime Prevention Technologies and Applications for Advancing Criminal Investigation, 2016, pp. 250–262.
4. R. V. Dharaskar, “Mobile Forensics : An Overview , Tools , Future trends and Challenges from Law Enforcement Perspective,” in 6th international conference on e-governance, iceg, emerging technologies in e-government, m-government, 2008, pp. 312–323.
5. S. Lowman and I. Ferguson, “Web History Visualisation for Forensic Investigations,” pp. 1–15, 2011.