• DocumentCode
    512353
  • Title

    Analysis of DB files based on compound document format

  • Author

    Liu, Jiajia ; Meng, Fanlin ; He, Jialong ; Wu, Shunxiang

  • Author_Institution
    Dept. of Autom., Xiamen Univ., Xiamen, China
  • Volume
    1
  • fYear
    2009
  • fDate
    28-29 Nov. 2009
  • Firstpage
    87
  • Lastpage
    90
  • Abstract
    In Internet era, instant messaging software are closely linked with Net users. However, with enormous growth of instant messaging software users, a lot of lawbreakers carry out criminal activities using them as a medium. Then, mining and analyzing the useful clues from raw data left on the computer has become a significant means and research area for investigation and forensics. In this paper, taking Tencent QQ2008, which is China´s most popular instant messaging software, as an example, we firstly deeply research into the information storage structures as well as the data encryption method of QQ Friends List file and QQ Chat Log file whose file suffix known as DB. Based on this, through parsing the DB files, we have obtained comprehensive analysis results of friends list and chat log. Most importantly, an analysis tool has been developed, which proves to be useful for computer investigation and forensics in practical use.
  • Keywords
    Internet; computer forensics; cryptography; data mining; document handling; information storage; program compilers; social networking (online); DB files; Internet; QQ Chat Log file; QQ Friends List file; Tencent QQ2008; compound document format; data encryption; data mining; forensics; information storage structures; instant messaging software; parsing; Application software; Computational intelligence; Computer industry; Cryptography; Data mining; Forensics; Helium; Information analysis; Internet; Text analysis; Chat Log; Compound Document Format; DB files; Data Analysis; Friends List;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Intelligence and Industrial Applications, 2009. PACIIA 2009. Asia-Pacific Conference on
  • Conference_Location
    Wuhan
  • Print_ISBN
    978-1-4244-4606-3
  • Type

    conf

  • DOI
    10.1109/PACIIA.2009.5406367
  • Filename
    5406367