Firmansyah Firmansyah
Universitas Ahmad Dahlan

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Metadata Analysis and Encryption in Decentralized Messaging Applications using NIST SP 800-86 Firmansyah Firmansyah; Firmansyah Firmansyah; Imam Riadi; Sunardi Sunardi
Insect (Informatics and Security): Jurnal Teknik Informatika Vol. 12 No. 2 (2026): Oktober 2026
Publisher : Universitas Muhammadiyah Sorong

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.33506/insect.v12i2.5702

Abstract

This study conducted a digital forensic analysis of metadata on two decentralized messaging applications: Session, based on Oxen onion routing with E2EE Libsodium, and BitChat, based on an ephemeral Bluetooth mesh network. The main objective was to compare the metadata leakage resilience of both applications and the effectiveness of the NIST SP 800-86 framework in the investigation process. The study used a forensic simulation approach on a rooted Android device in a controlled environment. The process was carried out according to the four phases of NIST SP 800-86: Collection, Examination, Analysis, and Reporting. The analyzed data included volatile data RAM dumps, BLE packets, persistent storage database SQLCipher, network artifacts, and system logs. The results showed significant differences. In Session, 47 message metadata were successfully extracted from the signal.db file along with attachment paths and onion routing hops with a 65% recovery rate. Meanwhile, BitChat only generated 12 hop events along with RSSI proximity data with a 25% recovery rate, mostly from volatile memory due to its panic wipe feature and ephemeral nature. Session is more vulnerable to timeline reconstruction, while BitChat excels in resistance to local forensics. This study concludes that no privacy-by-design application is completely immune to digital forensics. Session is better suited for conventional investigations, while BitChat provides better protection in high-risk offline scenarios. Recommendations are provided for users, investigators, and application developers to improve anti-forensic mechanisms.