TY - JOUR
T1 - The advanced analysis of digital traces recoverability of WhatsApp program on MacBook
AU - Sun, Ai
AU - Huang, Yueh Min
AU - Chu, Hai Cheng
N1 - Funding Information:
This work was supported in part by National Taichung University of Education, Taiwan, under Grant NTCU-F105206.
PY - 2017
Y1 - 2017
N2 - Unquestionably, WhatsApp is one of the most pervasive instant message application programs in contemporary digital era. It could be utilized on mobile smart phones or desktop computing devices including Windows-based personal computers and MacBook with Mac OS X. On account of the tremendous amount of information security incidences occurring concerning the usage of WhatsApp program on a MacBook, this research work constructed several cases to validate the recoverability of digital evidences on the computing device. The recoverability of WhatsApp user ID, username, and the contents of instant message dialogues were discussed based on the physical memory acquisition of the MacBook from digital forensics point of view. In addition, by the inherent characteristics and the executing mechanism of the WhatsApp program, the manufacture and the mode of the smartphone was capable of being disclosed by the digital traces accordingly. All the aforementioned disclosed digital traces could be probative digital evidences in a court of law. Therefore, this research work could be substantively applied and extended to other mushrooming cybercrime investigations regarding instant message incidents in the public sector or the noncompliance of computing resource usages in the private sector. The procedures of physical memory acquisition should be scientifically premeditated and systematically conducted due to the volatility of the physical memory of a computing device with rigorous procedures.
AB - Unquestionably, WhatsApp is one of the most pervasive instant message application programs in contemporary digital era. It could be utilized on mobile smart phones or desktop computing devices including Windows-based personal computers and MacBook with Mac OS X. On account of the tremendous amount of information security incidences occurring concerning the usage of WhatsApp program on a MacBook, this research work constructed several cases to validate the recoverability of digital evidences on the computing device. The recoverability of WhatsApp user ID, username, and the contents of instant message dialogues were discussed based on the physical memory acquisition of the MacBook from digital forensics point of view. In addition, by the inherent characteristics and the executing mechanism of the WhatsApp program, the manufacture and the mode of the smartphone was capable of being disclosed by the digital traces accordingly. All the aforementioned disclosed digital traces could be probative digital evidences in a court of law. Therefore, this research work could be substantively applied and extended to other mushrooming cybercrime investigations regarding instant message incidents in the public sector or the noncompliance of computing resource usages in the private sector. The procedures of physical memory acquisition should be scientifically premeditated and systematically conducted due to the volatility of the physical memory of a computing device with rigorous procedures.
UR - http://www.scopus.com/inward/record.url?scp=85031679831&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=85031679831&partnerID=8YFLogxK
U2 - 10.6138/JIT.2017.18.5.20161216
DO - 10.6138/JIT.2017.18.5.20161216
M3 - Article
AN - SCOPUS:85031679831
SN - 1607-9264
VL - 18
SP - 953
EP - 961
JO - Journal of Internet Technology
JF - Journal of Internet Technology
IS - 5
ER -