19 package org.sleuthkit.autopsy.modules.android;
22 import java.io.IOException;
23 import java.sql.Connection;
24 import java.sql.DriverManager;
25 import java.sql.ResultSet;
26 import java.sql.SQLException;
27 import java.sql.Statement;
28 import java.util.Arrays;
29 import java.util.List;
30 import java.util.logging.Level;
31 import java.util.stream.Collectors;
32 import java.util.stream.Stream;
48 class CallLogAnalyzer {
50 private static final String moduleName = AndroidModuleFactory.getModuleName();
51 private static final Logger logger = Logger.getLogger(CallLogAnalyzer.class.getName());
55 private static final Iterable<String> tableNames = Arrays.asList(
"calls",
"logs");
57 public static void findCallLogs(Content dataSource, FileManager fileManager) {
59 List<AbstractFile> absFiles = fileManager.findFiles(dataSource,
"logs.db");
60 absFiles.addAll(fileManager.findFiles(dataSource,
"contacts.db"));
61 absFiles.addAll(fileManager.findFiles(dataSource,
"contacts2.db"));
62 for (AbstractFile abstractFile : absFiles) {
64 File file =
new File(Case.getCurrentCase().getTempDirectory(), abstractFile.getName());
65 ContentUtils.writeToFile(abstractFile, file);
66 findCallLogsInDB(file.toString(), abstractFile);
67 }
catch (IOException e) {
68 logger.log(Level.SEVERE,
"Error writing temporary call log db to disk", e);
71 }
catch (TskCoreException e) {
72 logger.log(Level.SEVERE,
"Error finding call logs", e);
76 private static void findCallLogsInDB(String DatabasePath, AbstractFile f) {
78 if (DatabasePath == null || DatabasePath.isEmpty()) {
81 try (Connection connection = DriverManager.getConnection(
"jdbc:sqlite:" + DatabasePath);
82 Statement statement = connection.createStatement();) {
84 for (String tableName : tableNames) {
85 try (ResultSet resultSet = statement.executeQuery(
86 "SELECT number,date,duration,type, name FROM " + tableName +
" ORDER BY date DESC;");) {
87 logger.log(Level.INFO,
"Reading call log from table {0} in db {1}",
new Object[]{tableName, DatabasePath});
88 while (resultSet.next()) {
89 Long date = resultSet.getLong(
"date") / 1000;
90 final CallDirection direction = CallDirection.fromType(resultSet.getInt(
"type"));
91 String directionString = direction != null ? direction.getDisplayName() :
"";
92 final String number = resultSet.getString(
"number");
93 final long duration = resultSet.getLong(
"duration");
94 final String name = resultSet.getString(
"name");
97 BlackboardArtifact bba = f.newArtifact(BlackboardArtifact.ARTIFACT_TYPE.TSK_CALLLOG);
98 if(direction == CallDirection.OUTGOING) {
99 bba.addAttribute(
new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PHONE_NUMBER_TO.getTypeID(), moduleName, number));
102 bba.addAttribute(
new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_PHONE_NUMBER_FROM.getTypeID(), moduleName, number));
104 bba.addAttribute(
new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME_START.getTypeID(), moduleName, date));
105 bba.addAttribute(
new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DATETIME_END.getTypeID(), moduleName, duration + date));
106 bba.addAttribute(
new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_DIRECTION.getTypeID(), moduleName, directionString));
107 bba.addAttribute(
new BlackboardAttribute(ATTRIBUTE_TYPE.TSK_NAME.getTypeID(), moduleName, name));
108 }
catch (TskCoreException ex) {
109 logger.log(Level.SEVERE,
"Error posting call log record to the Blackboard", ex);
112 }
catch (SQLException e) {
113 logger.log(Level.WARNING,
"Could not read table {0} in db {1}",
new Object[]{tableName, DatabasePath});
116 }
catch (SQLException e) {
117 logger.log(Level.SEVERE,
"Could not parse call log; error connecting to db " + DatabasePath, e);
123 INCOMING(1,
"Incoming"),
OUTGOING(2,
"Outgoing"), MISSED(3,
"Missed");
135 this.displayName = displayName;
CallDirection(int type, String displayName)
static CallDirection fromType(int t)