From 99053a002849283d5f72d47f1f96e47b17fd80f7 Mon Sep 17 00:00:00 2001 From: William Schaefer Date: Wed, 16 Jan 2019 12:19:21 -0500 Subject: [PATCH] 4629 prevent duplicate OS_INFO and DATA_SOURCE_USAGE from being generated --- .../DataSourceUsageAnalyzer.java | 37 +++++++++++++------ 1 file changed, 25 insertions(+), 12 deletions(-) diff --git a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/DataSourceUsageAnalyzer.java b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/DataSourceUsageAnalyzer.java index d5e13bd39d..57bdc55fcb 100644 --- a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/DataSourceUsageAnalyzer.java +++ b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/DataSourceUsageAnalyzer.java @@ -89,20 +89,33 @@ public class DataSourceUsageAnalyzer extends Extract { //if any files existed matching the specified file if (!files.isEmpty()) { if (!dataSourceUsageDescription.isEmpty()) { - //if the data source usage description is not empty create a data source usage artifact - Collection bbattributes = new ArrayList<>(); - bbattributes.add(new BlackboardAttribute(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DESCRIPTION, - Bundle.DataSourceUsageAnalyzer_parentModuleName(), - dataSourceUsageDescription)); //NON-NLS - addArtifact(BlackboardArtifact.ARTIFACT_TYPE.TSK_DATA_SOURCE_USAGE, dataSource, bbattributes); + //if the data source usage description is not empty create a data source usage artifact if an Usage artifact does not already exist with the same description + List artifacts = tskCase.getBlackboardArtifacts(BlackboardArtifact.ARTIFACT_TYPE.TSK_DATA_SOURCE_USAGE, dataSource.getId()); + boolean createNewUsageArtifact = true; + for (BlackboardArtifact artifact : artifacts) { + if (artifact.getAttribute(new BlackboardAttribute.Type(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DESCRIPTION)).getValueString().equals(dataSourceUsageDescription)) { + createNewUsageArtifact = false; + break; + } + } + if (createNewUsageArtifact) { + Collection bbattributes = new ArrayList<>(); + bbattributes.add(new BlackboardAttribute(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DESCRIPTION, + Bundle.DataSourceUsageAnalyzer_parentModuleName(), + dataSourceUsageDescription)); //NON-NLS + addArtifact(BlackboardArtifact.ARTIFACT_TYPE.TSK_DATA_SOURCE_USAGE, dataSource, bbattributes); + } } if (!osInfoProgramName.isEmpty()) { - //if the os info program name is not empty create an os info artifacts - Collection bbattributes = new ArrayList<>(); - bbattributes.add(new BlackboardAttribute(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_PROG_NAME, - Bundle.DataSourceUsageAnalyzer_parentModuleName(), - osInfoProgramName)); //NON-NLS - addArtifact(BlackboardArtifact.ARTIFACT_TYPE.TSK_OS_INFO, dataSource, bbattributes); + //check if OS INFO artifact already created on this file + if (tskCase.getBlackboardArtifacts(BlackboardArtifact.ARTIFACT_TYPE.TSK_OS_INFO, files.get(0).getId()).isEmpty()) { + //if the os info program name is not empty create an os info artifact on the first of the files found + Collection bbattributes = new ArrayList<>(); + bbattributes.add(new BlackboardAttribute(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_PROG_NAME, + Bundle.DataSourceUsageAnalyzer_parentModuleName(), + osInfoProgramName)); //NON-NLS + addArtifact(BlackboardArtifact.ARTIFACT_TYPE.TSK_OS_INFO, files.get(0), bbattributes); + } } } }