Browse > Article
http://dx.doi.org/10.13089/JKIISC.2019.29.3.541

Study on The Decryption Method and Analysis of MalangMalang Talkcafe Application Database  

Kim, Giyoon (Dept. of Financial Information Security, Kookmin University)
Lee, Jonghyeok (Dept. of Information Security, Cryptology and Mathematics, Kookmin University)
Shin, Sumin (Dept. of Information Security, Cryptology and Mathematics, Kookmin University)
Kim, Jongsung (Dept. of Financial Information Security, Kookmin University)
Abstract
As leakage cases of personal information increase, the concern of personal information protection is also increasing. As a result, most applications encrypt and store sensitive information such as personal information. Especially, in case of instant messengers, it is more difficult to find database where is not encrypted and stored. However, this kind of database encryption acts as anti-forensic from the point of view of digital forensic investigation. In this paper, we analyze database encryption process of MalangMalang Talkcafe application which is one of instant messenger. Based on our analysis, we propose a decryption method and explain the meaningful information collected in the database.
Keywords
Instant Messenger; SQLCipher; Decrypt; Database;
Citations & Related Records
연도 인용수 순위
  • Reference
1 Pew Research Center, "Mobile", http://www.pewresearch.org/topic/mobile/
2 ANGLANO, Cosimo; CANONICO, Massimo; GUAZZONE, Marco. Forensic analysis of the chatsecure instant messaging application on android smartphones. Digital investigation, vol. 19, pp 4-59, Mar. 2016.
3 SUDOZAI, M. A. K., et al. Forensics study of IMO call and chat app. Digital Investigation, vol. 25, pp. 5-23, Dec. 2018.   DOI
4 WU, Songyang, et al. Forensic analysis of WeChat on Android smartphones. Digital investigation, vol. 21, pp. 3-10, Jun. 2017.   DOI
5 Zentic "SQLCipher API", https://www.zetetic.net/sqlcipher/sqlcipher-api/#key
6 Android Developers, "Provider Android_id", https://developer.android.com/reference/android/provider/Settings.Secure?hl=ko#ANDROID_ID