[Paper Review] Forensics Acquisition and Analysis of instant messaging and VoIP applications
This paper presents a comprehensive forensic acquisition and analysis framework for four major instant messaging and VoIP applications—WhatsApp, Skype, Viber, and Tango—on iOS and Android platforms. It identifies, classifies, and compares digital artifacts across these platforms, offering a taxonomy of target artefacts and evaluating evidence recovery potential, with key findings highlighting platform-specific data retention and forensic accessibility differences.
The advent of the Internet has significantly transformed the daily activities of millions of people, with one of them being the way people communicate where Instant Messaging (IM) and Voice over IP (VoIP) communications have become prevalent. Although IM applications are ubiquitous communication tools nowadays, it was observed that the relevant research on the topic of evidence collection from IM services was limited. The reason is an IM can serve as a very useful yet very dangerous platform for the victim and the suspect to communicate. Indeed, the increased use of Instant Messengers on smart phones has turned to be the goldmine for mobile and computer forensic experts. Traces and Evidence left by applications can be held on smart phones and retrieving those potential evidences with right forensic technique is strongly required. Recently, most research on IM forensics focus on applications such as WhatsApp, Viber and Skype. However, in the literature, there are very few forensic analysis and comparison related to IM applications such as WhatsApp, Viber and Skype and Tango on both iOS and Android platforms, even though the total users of this application already exceeded 1 billion. Therefore, in this paper we present forensic acquisition and analysis of these four IMs and VoIPs for both iOS and Android platforms. We try to answer on how evidence can be collected when IM communications are used. We also define taxonomy of target artefacts in order to guide and structure the subsequent forensic analysis. Finally, a review of the information that can become available via the IM vendor was conducted. The achieved results of this research provided elaborative answers on the types of artifacts that can be identified by these IM and VoIP applications. We compare moreover the forensics analysis of these popular applications: WhatApp, Skype, Viber and Tango.
Motivation & Objective
- To address the gap in forensic research on popular IM and VoIP applications like WhatsApp, Viber, Skype, and Tango despite their widespread use.
- To develop a systematic taxonomy of digital artefacts generated by these applications for structured forensic analysis.
- To compare forensic acquisition techniques and evidence availability across iOS and Android platforms.
- To evaluate the potential for evidence extraction from these applications using both device-level and vendor-provided data sources.
- To provide practical guidance for digital forensic investigators on collecting and analyzing IM/ VoIP communications.
Proposed method
- Conducted device-level forensic acquisition on iOS and Android devices running WhatsApp, Skype, Viber, and Tango.
- Identified and categorized digital artefacts such as message logs, contact lists, media files, and metadata across platforms.
- Developed a standardized taxonomy of target artefacts to guide systematic forensic analysis.
- Performed comparative analysis of evidence types and accessibility across the four applications on both operating systems.
- Evaluated the availability and reliability of evidence through direct device extraction and vendor data requests.
- Used reverse engineering and file system analysis to locate and extract volatile and persistent data.
Experimental results
Research questions
- RQ1What types of digital artefacts are generated by WhatsApp, Skype, Viber, and Tango on iOS and Android platforms?
- RQ2How do the forensic acquisition techniques and evidence availability differ between iOS and Android for these IM/ VoIP applications?
- RQ3What is the comparative forensic value of these four applications in terms of recoverable evidence?
- RQ4How can a standardized taxonomy of artefacts improve the efficiency and consistency of IM/ VoIP forensics?
- RQ5To what extent can evidence be obtained from vendor-provided data sources in addition to device-level acquisition?
Key findings
- WhatsApp on iOS retains more recoverable message data compared to Android, particularly in SQLite databases and cached files.
- Skype on Android stores message logs in a less structured format, reducing evidence reliability compared to iOS.
- Viber on iOS exhibits stronger data persistence, with messages stored in encrypted but accessible database files.
- Tango on both platforms shows limited evidence retention, with most data stored in volatile or obfuscated formats.
- The proposed taxonomy effectively categorizes artefacts into message logs, media, metadata, and configuration files, enabling systematic analysis.
- Vendor-provided data was found to be supplementary but not always available, especially for end-to-end encrypted services.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.