Forensic analysis of the backup database file in KakaoTalk messenger

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

10 Scopus citations

Abstract

Instant messaging services should be designed to securely protect their users' personal contents such as chat messages, photos and video clips against a wide range of attacks. In general, such contents are securely encrypted in storage. In this paper, however, we demonstrated that the backup database file for chat messages in KakaoTalk (the most popularly used instant messaging service in Republic of Korea, http://www.kakao.com/talk/en) can be leaked to unauthorized users. We carefully examined the backup procedure in KakaoTalk through reverse engineering the KakaoTalk application to analyze how the backup database file was encrypted and the encryption key can be generated. Our analysis showed that the encrypted database is susceptible to off-line password guessing attacks. Based on this finding, we recommend that a secure key generation technique should be designed to improve resistance against offline password guessing attacks by using a random secret number to generate the encryption key.

Original languageEnglish
Title of host publication2017 IEEE International Conference on Big Data and Smart Computing, BigComp 2017
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages156-161
Number of pages6
ISBN (Electronic)9781509030156
DOIs
StatePublished - 17 Mar 2017
Event2017 IEEE International Conference on Big Data and Smart Computing, BigComp 2017 - Jeju Island, Korea, Republic of
Duration: 13 Feb 201716 Feb 2017

Publication series

Name2017 IEEE International Conference on Big Data and Smart Computing, BigComp 2017

Conference

Conference2017 IEEE International Conference on Big Data and Smart Computing, BigComp 2017
Country/TerritoryKorea, Republic of
CityJeju Island
Period13/02/1716/02/17

Keywords

  • database encryption
  • KakaoTalk
  • key generation
  • off-line password guessing
  • reverse-engineering

Fingerprint

Dive into the research topics of 'Forensic analysis of the backup database file in KakaoTalk messenger'. Together they form a unique fingerprint.

Cite this