Uncovering Signal : Simplifying Forensic Investigations of the Signal Application

The increasing availability of easy-to-use end-to-end encrypted messaging applications has made it possible for more people to conduct their conversations privately. This is something that criminals have taken advantage of and it has proven to make digital forensic investigations more difficult as m...

Full description

Bibliographic Details
Main Authors: Liljekvist, Erika, Hedlund, Oscar
Format: Others
Language:English
Published: Högskolan i Halmstad, Akademin för informationsteknologi 2021
Subjects:
Online Access:http://urn.kb.se/resolve?urn=urn:nbn:se:hh:diva-44835
id ndltd-UPSALLA1-oai-DiVA.org-hh-44835
record_format oai_dc
spelling ndltd-UPSALLA1-oai-DiVA.org-hh-448352021-06-19T05:28:15ZUncovering Signal : Simplifying Forensic Investigations of the Signal ApplicationengSignals Svaghet : Underlättande av forensiska undersökningar av chatapplikationen SignalLiljekvist, ErikaHedlund, OscarHögskolan i Halmstad, Akademin för informationsteknologiHögskolan i Halmstad, Akademin för informationsteknologi2021SignalEncryptionDigital forensicsDatabase analysisDecryptionSQLCipherJailbreakObjectionFRIDAOpen-sourceDigital forensic toolComputer SystemsDatorsystemThe increasing availability of easy-to-use end-to-end encrypted messaging applications has made it possible for more people to conduct their conversations privately. This is something that criminals have taken advantage of and it has proven to make digital forensic investigations more difficult as methods of decrypting the data are needed. In this thesis, data from iOS and Windows devices is extracted and analysed, with focus on the application Signal. Even though other operating systems are compatible with the Signal application, such as Android, it is outside the scope of this thesis. The results of this thesis provide access to data stored in the encrypted application Signalwithout the need for expensive analysis tools. This is done by developing and publishing the first open-source script for decryption and parsing of the Signal database. The script is available for anyone at https://github.com/decryptSignal/decryptSignal. Student thesisinfo:eu-repo/semantics/bachelorThesistexthttp://urn.kb.se/resolve?urn=urn:nbn:se:hh:diva-44835application/pdfinfo:eu-repo/semantics/openAccess
collection NDLTD
language English
format Others
sources NDLTD
topic Signal
Encryption
Digital forensics
Database analysis
Decryption
SQLCipher
Jailbreak
Objection
FRIDA
Open-source
Digital forensic tool
Computer Systems
Datorsystem
spellingShingle Signal
Encryption
Digital forensics
Database analysis
Decryption
SQLCipher
Jailbreak
Objection
FRIDA
Open-source
Digital forensic tool
Computer Systems
Datorsystem
Liljekvist, Erika
Hedlund, Oscar
Uncovering Signal : Simplifying Forensic Investigations of the Signal Application
description The increasing availability of easy-to-use end-to-end encrypted messaging applications has made it possible for more people to conduct their conversations privately. This is something that criminals have taken advantage of and it has proven to make digital forensic investigations more difficult as methods of decrypting the data are needed. In this thesis, data from iOS and Windows devices is extracted and analysed, with focus on the application Signal. Even though other operating systems are compatible with the Signal application, such as Android, it is outside the scope of this thesis. The results of this thesis provide access to data stored in the encrypted application Signalwithout the need for expensive analysis tools. This is done by developing and publishing the first open-source script for decryption and parsing of the Signal database. The script is available for anyone at https://github.com/decryptSignal/decryptSignal.
author Liljekvist, Erika
Hedlund, Oscar
author_facet Liljekvist, Erika
Hedlund, Oscar
author_sort Liljekvist, Erika
title Uncovering Signal : Simplifying Forensic Investigations of the Signal Application
title_short Uncovering Signal : Simplifying Forensic Investigations of the Signal Application
title_full Uncovering Signal : Simplifying Forensic Investigations of the Signal Application
title_fullStr Uncovering Signal : Simplifying Forensic Investigations of the Signal Application
title_full_unstemmed Uncovering Signal : Simplifying Forensic Investigations of the Signal Application
title_sort uncovering signal : simplifying forensic investigations of the signal application
publisher Högskolan i Halmstad, Akademin för informationsteknologi
publishDate 2021
url http://urn.kb.se/resolve?urn=urn:nbn:se:hh:diva-44835
work_keys_str_mv AT liljekvisterika uncoveringsignalsimplifyingforensicinvestigationsofthesignalapplication
AT hedlundoscar uncoveringsignalsimplifyingforensicinvestigationsofthesignalapplication
AT liljekvisterika signalssvaghetunderlattandeavforensiskaundersokningaravchatapplikationensignal
AT hedlundoscar signalssvaghetunderlattandeavforensiskaundersokningaravchatapplikationensignal
_version_ 1719411247293661184