19 package org.sleuthkit.autopsy.modules.android;
22 import java.io.IOException;
23 import java.sql.Connection;
24 import java.sql.DriverManager;
25 import java.sql.ResultSet;
26 import java.sql.SQLException;
27 import java.sql.Statement;
28 import java.util.Arrays;
29 import java.util.List;
30 import java.util.logging.Level;
31 import org.openide.util.NbBundle;
41 import org.
sleuthkit.datamodel.BlackboardAttribute.ATTRIBUTE_TYPE;
49 class CallLogAnalyzer {
51 private static final String moduleName = AndroidModuleFactory.getModuleName();
52 private static final Logger logger = Logger.getLogger(CallLogAnalyzer.class.getName());
53 private static Blackboard blackboard;
58 private static final Iterable<String> tableNames = Arrays.asList(
"calls",
"logs");
60 public static void findCallLogs(Content dataSource, FileManager fileManager) {
61 blackboard = Case.getCurrentCase().getServices().getBlackboard();
63 List<AbstractFile> absFiles = fileManager.findFiles(dataSource,
"logs.db");
64 absFiles.addAll(fileManager.findFiles(dataSource,
"contacts.db"));
65 absFiles.addAll(fileManager.findFiles(dataSource,
"contacts2.db"));
66 for (AbstractFile abstractFile : absFiles) {
68 File file =
new File(Case.getCurrentCase().getTempDirectory(), abstractFile.getName());
69 ContentUtils.writeToFile(abstractFile, file);
70 findCallLogsInDB(file.toString(), abstractFile);
71 }
catch (IOException e) {
72 logger.log(Level.SEVERE,
"Error writing temporary call log db to disk", e);
75 }
catch (TskCoreException e) {
76 logger.log(Level.SEVERE,
"Error finding call logs", e);
80 private static void findCallLogsInDB(String DatabasePath, AbstractFile f) {
82 if (DatabasePath == null || DatabasePath.isEmpty()) {
85 try (Connection connection = DriverManager.getConnection(
"jdbc:sqlite:" + DatabasePath);
86 Statement statement = connection.createStatement();) {
88 for (String tableName : tableNames) {
89 try (ResultSet resultSet = statement.executeQuery(
90 "SELECT number,date,duration,type, name FROM " + tableName +
" ORDER BY date DESC;");) {
91 logger.log(Level.INFO,
"Reading call log from table {0} in db {1}",
new Object[]{tableName, DatabasePath});
92 while (resultSet.next()) {
93 Long date = resultSet.getLong(
"date") / 1000;
94 final CallDirection direction = CallDirection.fromType(resultSet.getInt(
"type"));
95 String directionString = direction != null ? direction.getDisplayName() :
"";
96 final String number = resultSet.getString(
"number");
97 final long duration = resultSet.getLong(
"duration");
98 final String name = resultSet.getString(
"name");
101 BlackboardArtifact bba = f.newArtifact(BlackboardArtifact.ARTIFACT_TYPE.TSK_CALLLOG);
102 if (direction == CallDirection.OUTGOING) {
103 bba.addAttribute(
new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PHONE_NUMBER_TO, moduleName, number));
105 bba.addAttribute(
new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PHONE_NUMBER_FROM, moduleName, number));
107 bba.addAttribute(
new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME_START, moduleName, date));
108 bba.addAttribute(
new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME_END, moduleName, duration + date));
109 bba.addAttribute(
new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DIRECTION, moduleName, directionString));
110 bba.addAttribute(
new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_NAME, moduleName, name));
114 blackboard.indexArtifact(bba);
115 }
catch (Blackboard.BlackboardException ex) {
116 logger.log(Level.SEVERE, NbBundle.getMessage(Blackboard.class,
"Blackboard.unableToIndexArtifact.error.msg", bba.getDisplayName()), ex);
117 MessageNotifyUtil.Notify.error(
118 NbBundle.getMessage(Blackboard.class,
"Blackboard.unableToIndexArtifact.exception.msg"), bba.getDisplayName());
120 }
catch (TskCoreException ex) {
121 logger.log(Level.SEVERE,
"Error posting call log record to the Blackboard", ex);
124 }
catch (SQLException e) {
125 logger.log(Level.WARNING,
"Could not read table {0} in db {1}",
new Object[]{tableName, DatabasePath});
128 }
catch (SQLException e) {
129 logger.log(Level.SEVERE,
"Could not parse call log; error connecting to db " + DatabasePath, e);
135 INCOMING(1,
"Incoming"),
OUTGOING(2,
"Outgoing"), MISSED(3,
"Missed");
147 this.displayName = displayName;
CallDirection(int type, String displayName)
static CallDirection fromType(int t)