论文标题
识别WhatsApp通信的拦截可能性
Identifying interception possibilities for WhatsApp communication
论文作者
论文摘要
执法人员每天都使用移动通信应用程序进行犯罪活动而挣扎。这些移动应用程序取代了SMS的信息,并在过去几年中从普通文本的数据传输和存储转变为加密版本。无论对所有遵守法律公民带来的好处如何,这都被认为是刑事调查的缺点。当可疑嫌疑人使用WhatsApp,Signal或Telegram等应用程序时,普通智能手机,计算机或网络调查不再提供实时的通信内容。其中,WhatsApp是犯罪和法律活动最常见的智能手机应用程序之一。 2016年初,WhatsApp为所有用户介绍了端到端的加密,立即使世界各地的执法人员在黑暗中。现有的恢复执法地位的研究仅限于一个调查领域,并且通常仅限于智能手机或计算机的验尸研究,而窃听仅限于元数据信息。因此,它仅提供历史数据或元数据,而执法人员则希望连续进行现场和实质性信息。本文确定了在可用方案进行执法调查的差距,并确定了用于法医获取和处理这些情况的方法的差距。在本文中,我们提出了一种法医方法,以在WhatsApp通信中创建实时见解。我们的方法基于窃听,解密WhatsApp数据库,开源智能和WhatsApp Web通信分析。我们还通过WhatsApp取证中的不同方案评估了我们的方法,以证明其可行性和效率。
On a daily basis, law enforcement officers struggle with suspects using mobile communication applications for criminal activities. These mobile applications replaced SMS-messaging and evolved the last few years from plain-text data transmission and storage to an encrypted version. Regardless of the benefits for all law abiding citizens, this is considered to be the downside for criminal investigations. Normal smartphone, computer or network investigations do no longer provide the contents of the communication in real-time when suspects are using apps like WhatsApp, Signal or Telegram. Among them, WhatsApp is one of the most common smartphone applications for communication, both criminal as well as legal activities. Early 2016 WhatsApp introduced end-to-end encryption for all users, immediately keeping law enforcement officers around the world in the dark. Existing research to recuperate the position of law enforcement is limited to a single field of investigation and often limited to post mortem research on smartphone or computer while wiretapping is limited to metadata information. Therefore, it provides only historical data or metadata while law enforcement officers want a continuous stream of live and substantive information. This paper identified that gap in available scenarios for law enforcement investigations and identified a gap in methods available for forensic acquiring and processing these scenarios. In this paper, we propose a forensic approach to create real-time insight in the WhatsApp communication. Our approach is based on the wiretapping, decrypting WhatsApp databases, open source intelligence and WhatsApp Web communication analysis. We also evaluate our method with different scenarios in WhatsApp forensics to prove its feasibility and efficiency.