Windows平台微信数据恢复方法

WECHAT DATA RECOVERY ON WINDOWS PLATFORM

  • 摘要: 微信作为目前使用率极高的即时通信工具,存储了大量取证所需的重要数据。取证人员最关心的是对微信进行数据恢复与取证,恢复出来的微信数据可能会成为司法取证的关键证据,直接影响案件能否成功侦破。该文对Windows平台的微信数据恢复方法进行研究,提出基于SQLite数据库存储结构分析恢复方法。该方法在深入分析Windows平台微信数据库文件存储结构的基础上,融合多个数据库文件,基于数据库中存在的空闲页和自由块对微信删除数据进行恢复。通过实验验证了Windows平台数据恢复方法的可行性与有效性。

     

    Abstract: WeChat is currently a highly used communication tool that stores a large amount of important data required for forensics. Forensics personnel are most concerned about the data recovery and forensics of WeChat. The recovered WeChat data may become the key evidence of judicial forensics, which directly affects whether the case can be successfully solved. In this paper, we propose an analysis and recovery methods based on SQLite database storage structure. On the basis of in-depth analysis of the storage structure of WeChat database files on the Windows platform, multiple database files were integrated to recover deleted data from WeChat based on the existing idle pages and free blocks in the database. The feasibility and effectiveness of the Windows platform data recovery method was verified through experiments.

     

/

返回文章
返回