|
A
Forensic Log File Extraction Tool for ICQ Instant Messaging
Clients
Kim
Morfitt
Edith
Cowan University
Western Australia
Craig
Valli
Edith
Cowan University
Western Australia
ABSTRACT
Instant messenger programs such as ICQ
are often used by hackers and criminals for illicit purposes and
consequently the log files from such programs are of interest in
a forensic investigation. This paper outlines research that has
resulted in the development of a tool for the extraction of ICQ
log file entries. Detailed reconstruction of data from log files
was achieved with a number of different ICQ software. There are
several limitations with the current design including timestamp
information not adjusted for the time zone, data could be
altered, and conversations must be manually reconstructed.
Future research will aim to address these and other limitations
as pointed out in this paper.
Keywords: ICQ, instant
messaging, logfile, forensic, extraction
|