6711 initial commit for more general data model refactor

This commit is contained in:
William Schaefer
2020-08-20 13:21:49 -04:00
parent 4811cf49fe
commit 98e790c4e6
30 changed files with 696 additions and 883 deletions
@@ -59,10 +59,10 @@ public abstract class AbstractFilter {
* @return The list of results that match this filter (and any that came
* before it)
*
* @throws FileSearchException
* @throws DiscoveryException
*/
public List<ResultFile> applyAlternateFilter(List<ResultFile> currentResults, SleuthkitCase caseDb,
CentralRepository centralRepoDb) throws FileSearchException {
CentralRepository centralRepoDb) throws DiscoveryException {
return new ArrayList<>();
}
@@ -1,96 +0,0 @@
/*
* Autopsy
*
* Copyright 2020 Basis Technology Corp.
* Contact: carrier <at> sleuthkit <dot> org
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.sleuthkit.autopsy.discovery.search;
import java.util.Collection;
import java.util.Collections;
import java.util.EnumSet;
import java.util.HashSet;
import java.util.Set;
import org.openide.util.NbBundle;
import org.sleuthkit.datamodel.BlackboardArtifact;
/**
* Utility enums for searches made for attributes with Discovery.
*/
public class AttributeSearchData implements SearchData {
private static final Set<BlackboardArtifact.ARTIFACT_TYPE> DOMAIN_ARTIFACT_TYPES = EnumSet.of(BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_BOOKMARK, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_CACHE, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_COOKIE, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_DOWNLOAD, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_HISTORY, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_SEARCH_QUERY, BlackboardArtifact.ARTIFACT_TYPE.TSK_EMAIL_MSG);
@Override
public ResultType getResultType() {
return ResultType.ATTRIBUTE;
}
/**
* Enum representing the attribute type.
*/
@NbBundle.Messages({
"AttributeSearchData.AttributeType.Domain.displayName=Domain",
"AttributeSearchData.AttributeType.Other.displayName=Other"})
public enum AttributeType {
DOMAIN(0, Bundle.AttributeSearchData_AttributeType_Domain_displayName(), DOMAIN_ARTIFACT_TYPES),
OTHER(1, Bundle.AttributeSearchData_AttributeType_Other_displayName(), new HashSet<>());
private final int ranking; // For ordering in the UI
private final String displayName;
private final Set<BlackboardArtifact.ARTIFACT_TYPE> artifactTypes = new HashSet<>();
AttributeType(int value, String displayName, Set<BlackboardArtifact.ARTIFACT_TYPE> types) {
this.ranking = value;
this.displayName = displayName;
this.artifactTypes.addAll(types);
}
/**
* Get the BlackboardArtifact types matching this category.
*
* @return Collection of BlackboardArtifact types.
*/
public Collection<BlackboardArtifact.ARTIFACT_TYPE> getBlackboardTypes() {
return Collections.unmodifiableCollection(artifactTypes);
}
@Override
public String toString() {
return displayName;
}
/**
* Get the rank for sorting.
*
* @return the rank (lower should be displayed first)
*/
public int getRanking() {
return ranking;
}
public static AttributeType fromBlackboardArtifact(final BlackboardArtifact.ARTIFACT_TYPE type) {
switch (type) {
case TSK_WEB_BOOKMARK:
return DOMAIN;
default:
return OTHER;
}
}
}
}
@@ -22,10 +22,8 @@ import com.google.common.eventbus.EventBus;
import java.util.Collections;
import java.util.List;
import java.util.Map;
import org.sleuthkit.autopsy.discovery.search.AttributeSearchData.AttributeType;
import org.sleuthkit.autopsy.discovery.search.DiscoveryKeyUtils.GroupKey;
import org.sleuthkit.autopsy.discovery.search.FileSearchData.FileType;
import org.sleuthkit.autopsy.discovery.search.SearchData.ResultType;
import org.sleuthkit.autopsy.discovery.search.SearchData.Type;
import org.sleuthkit.datamodel.AbstractFile;
/**
@@ -56,47 +54,27 @@ public final class DiscoveryEventUtils {
*/
public static final class SearchStartedEvent {
private final ResultType resultType;
private final FileType fileType;
private final AttributeType attributeType;
private final Type type;
/**
* Construct a new SearchStartedEvent
*
* @param type The type of file the search event is for.
*/
public SearchStartedEvent(ResultType resultType, FileType fileType, AttributeType attributeType) {
this.resultType = resultType;
this.fileType = fileType;
this.attributeType = attributeType;
public SearchStartedEvent(Type type) {
this.type = type;
}
/**
* Get the broad search type.
*
* @return The result type, either FILES, or ATTRIBUTES.
*/
public ResultType getResultType() {
return resultType;
}
/**
* Get the type of file the search is being performed for.
*
* @return The type of files being searched for.
*/
public FileType getFileType() {
return fileType;
public Type getType() {
return type;
}
/**
* Get the type of attribute the search is being performed for.
*
* @return The type of attribute being searched for.
*/
public AttributeType getAttributeType() {
return attributeType;
}
}
/**
@@ -142,7 +120,7 @@ public final class DiscoveryEventUtils {
private final Map<GroupKey, Integer> groupMap;
private final List<AbstractFilter> searchFilters;
private final FileSearch.AttributeType groupingAttribute;
private final FileGroup.GroupSortingAlgorithm groupSort;
private final Group.GroupSortingAlgorithm groupSort;
private final FileSorter.SortingMethod fileSortMethod;
/**
@@ -157,7 +135,7 @@ public final class DiscoveryEventUtils {
* @param fileSortMethod The sorting method used for files.
*/
public SearchCompleteEvent(Map<GroupKey, Integer> groupMap, List<AbstractFilter> searchfilters,
FileSearch.AttributeType groupingAttribute, FileGroup.GroupSortingAlgorithm groupSort,
FileSearch.AttributeType groupingAttribute, Group.GroupSortingAlgorithm groupSort,
FileSorter.SortingMethod fileSortMethod) {
this.groupMap = groupMap;
this.searchFilters = searchfilters;
@@ -198,7 +176,7 @@ public final class DiscoveryEventUtils {
*
* @return The sorting algorithm used for groups.
*/
public FileGroup.GroupSortingAlgorithm getGroupSort() {
public Group.GroupSortingAlgorithm getGroupSort() {
return groupSort;
}
@@ -221,7 +199,7 @@ public final class DiscoveryEventUtils {
private final List<ResultFile> results;
private final int page;
private final FileType resultType;
private final Type resultType;
/**
* Construct a new PageRetrievedEvent.
@@ -230,7 +208,7 @@ public final class DiscoveryEventUtils {
* @param page The number of the page which was retrieved.
* @param results The list of files in the page retrieved.
*/
public PageRetrievedEvent(FileType resultType, int page, List<ResultFile> results) {
public PageRetrievedEvent(Type resultType, int page, List<ResultFile> results) {
this.results = results;
this.page = page;
this.resultType = resultType;
@@ -259,7 +237,7 @@ public final class DiscoveryEventUtils {
*
* @return The type of files which exist in the page.
*/
public FileType getType() {
public Type getType() {
return resultType;
}
}
@@ -296,12 +274,12 @@ public final class DiscoveryEventUtils {
*/
public static final class GroupSelectedEvent {
private final FileType resultType;
private final Type resultType;
private final GroupKey groupKey;
private final int groupSize;
private final List<AbstractFilter> searchfilters;
private final FileSearch.AttributeType groupingAttribute;
private final FileGroup.GroupSortingAlgorithm groupSort;
private final Group.GroupSortingAlgorithm groupSort;
private final FileSorter.SortingMethod fileSortMethod;
/**
@@ -319,8 +297,8 @@ public final class DiscoveryEventUtils {
* @param resultType The type of files which exist in the group.
*/
public GroupSelectedEvent(List<AbstractFilter> searchfilters,
FileSearch.AttributeType groupingAttribute, FileGroup.GroupSortingAlgorithm groupSort,
FileSorter.SortingMethod fileSortMethod, GroupKey groupKey, int groupSize, FileType resultType) {
FileSearch.AttributeType groupingAttribute, Group.GroupSortingAlgorithm groupSort,
FileSorter.SortingMethod fileSortMethod, GroupKey groupKey, int groupSize, Type resultType) {
this.searchfilters = searchfilters;
this.groupingAttribute = groupingAttribute;
this.groupSort = groupSort;
@@ -335,7 +313,7 @@ public final class DiscoveryEventUtils {
*
* @return The type of files which exist in the group.
*/
public FileType getResultType() {
public Type getResultType() {
return resultType;
}
@@ -364,7 +342,7 @@ public final class DiscoveryEventUtils {
*
* @return The sorting algorithm used for groups.
*/
public FileGroup.GroupSortingAlgorithm getGroupSort() {
public Group.GroupSortingAlgorithm getGroupSort() {
return groupSort;
}
@@ -21,7 +21,7 @@ package org.sleuthkit.autopsy.discovery.search;
/**
* Exception type used for FileSearch.
*/
final public class FileSearchException extends Exception {
final public class DiscoveryException extends Exception {
private static final long serialVersionUID = 1L;
@@ -30,7 +30,7 @@ final public class FileSearchException extends Exception {
*
* @param message The message to associate with this exception.
*/
FileSearchException(String message) {
DiscoveryException(String message) {
super(message);
}
@@ -40,7 +40,7 @@ final public class FileSearchException extends Exception {
* @param message The message to associate with this exception.
* @param cause The Throwable cause of the exception.
*/
FileSearchException(String message, Throwable cause) {
DiscoveryException(String message, Throwable cause) {
super(message, cause);
}
}
@@ -53,7 +53,7 @@ public class DiscoveryKeyUtils {
*/
SearchKey(String userName, List<AbstractFilter> filters,
FileSearch.AttributeType groupAttributeType,
FileGroup.GroupSortingAlgorithm groupSortingType,
Group.GroupSortingAlgorithm groupSortingType,
FileSorter.SortingMethod fileSortingMethod) {
StringBuilder searchStringBuilder = new StringBuilder();
searchStringBuilder.append(userName);
@@ -153,13 +153,13 @@ public class DiscoveryKeyUtils {
*/
static class FileSizeGroupKey extends GroupKey {
private final FileSearchData.FileSize fileSize;
private final SearchData.FileSize fileSize;
FileSizeGroupKey(ResultFile file) {
if (file.getFileType() == FileSearchData.FileType.VIDEO) {
fileSize = FileSearchData.FileSize.fromVideoSize(file.getFirstInstance().getSize());
if (file.getFileType() == SearchData.Type.VIDEO) {
fileSize = SearchData.FileSize.fromVideoSize(file.getFirstInstance().getSize());
} else {
fileSize = FileSearchData.FileSize.fromImageSize(file.getFirstInstance().getSize());
fileSize = SearchData.FileSize.fromImageSize(file.getFirstInstance().getSize());
}
}
@@ -200,7 +200,7 @@ public class DiscoveryKeyUtils {
/**
* @return the fileSize
*/
FileSearchData.FileSize getFileSize() {
SearchData.FileSize getFileSize() {
return fileSize;
}
}
@@ -210,7 +210,7 @@ public class DiscoveryKeyUtils {
*/
static class FileTypeGroupKey extends GroupKey {
private final FileSearchData.FileType fileType;
private final SearchData.Type fileType;
FileTypeGroupKey(ResultFile file) {
fileType = file.getFileType();
@@ -253,7 +253,7 @@ public class DiscoveryKeyUtils {
/**
* @return the fileType
*/
FileSearchData.FileType getFileType() {
SearchData.Type getFileType() {
return fileType;
}
}
@@ -644,7 +644,7 @@ public class DiscoveryKeyUtils {
*/
static class FrequencyGroupKey extends GroupKey {
private final FileSearchData.Frequency frequency;
private final SearchData.Frequency frequency;
FrequencyGroupKey(ResultFile file) {
frequency = file.getFrequency();
@@ -687,7 +687,7 @@ public class DiscoveryKeyUtils {
/**
* @return the frequency
*/
FileSearchData.Frequency getFrequency() {
SearchData.Frequency getFrequency() {
return frequency;
}
}
@@ -0,0 +1,30 @@
/*
* Autopsy
*
* Copyright 2020 Basis Technology Corp.
* Contact: carrier <at> sleuthkit <dot> org
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.sleuthkit.autopsy.discovery.search;
/**
* Main class to perform the domain search.
*/
public class DomainSearch {
private DomainSearch() {
// Class should not be instantiated
}
}
@@ -40,7 +40,7 @@ import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepoException;
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepoDbUtil;
import org.sleuthkit.autopsy.centralrepository.datamodel.InstanceTableCallback;
import org.sleuthkit.autopsy.coreutils.Logger;
import org.sleuthkit.autopsy.discovery.search.FileSearchData.Frequency;
import org.sleuthkit.autopsy.discovery.search.SearchData.Frequency;
import org.sleuthkit.datamodel.AbstractFile;
import org.sleuthkit.datamodel.BlackboardArtifact;
import org.sleuthkit.datamodel.BlackboardAttribute;
@@ -82,14 +82,14 @@ public class FileSearch {
*
* @return The raw search results
*
* @throws FileSearchException
* @throws DiscoveryException
*/
static SearchResults runFileSearchDebug(String userName,
List<AbstractFilter> filters,
AttributeType groupAttributeType,
FileGroup.GroupSortingAlgorithm groupSortingType,
Group.GroupSortingAlgorithm groupSortingType,
FileSorter.SortingMethod fileSortingMethod,
SleuthkitCase caseDb, CentralRepository centralRepoDb) throws FileSearchException {
SleuthkitCase caseDb, CentralRepository centralRepoDb) throws DiscoveryException {
// Make a list of attributes that we want to add values for. This ensures the
// ResultFile objects will have all needed fields set when it's time to group
// and sort them. For example, if we're grouping by central repo frequency, we need
@@ -134,14 +134,14 @@ public class FileSearch {
*
* @return A LinkedHashMap grouped and sorted according to the parameters
*
* @throws FileSearchException
* @throws DiscoveryException
*/
public static Map<GroupKey, Integer> getGroupSizes(String userName,
List<AbstractFilter> filters,
AttributeType groupAttributeType,
FileGroup.GroupSortingAlgorithm groupSortingType,
Group.GroupSortingAlgorithm groupSortingType,
FileSorter.SortingMethod fileSortingMethod,
SleuthkitCase caseDb, CentralRepository centralRepoDb) throws FileSearchException {
SleuthkitCase caseDb, CentralRepository centralRepoDb) throws DiscoveryException {
Map<GroupKey, List<ResultFile>> searchResults = runFileSearch(userName, filters,
groupAttributeType, groupSortingType, fileSortingMethod, caseDb, centralRepoDb);
LinkedHashMap<GroupKey, Integer> groupSizes = new LinkedHashMap<>();
@@ -171,17 +171,17 @@ public class FileSearch {
*
* @return A LinkedHashMap grouped and sorted according to the parameters
*
* @throws FileSearchException
* @throws DiscoveryException
*/
public static List<ResultFile> getFilesInGroup(String userName,
List<AbstractFilter> filters,
AttributeType groupAttributeType,
FileGroup.GroupSortingAlgorithm groupSortingType,
Group.GroupSortingAlgorithm groupSortingType,
FileSorter.SortingMethod fileSortingMethod,
GroupKey groupKey,
int startingEntry,
int numberOfEntries,
SleuthkitCase caseDb, CentralRepository centralRepoDb) throws FileSearchException {
SleuthkitCase caseDb, CentralRepository centralRepoDb) throws DiscoveryException {
//the group should be in the cache at this point
List<ResultFile> filesInGroup = null;
SearchKey searchKey = new SearchKey(userName, filters, groupAttributeType, groupSortingType, fileSortingMethod);
@@ -267,14 +267,14 @@ public class FileSearch {
*
* @return A LinkedHashMap grouped and sorted according to the parameters
*
* @throws FileSearchException
* @throws DiscoveryException
*/
private static Map<GroupKey, List<ResultFile>> runFileSearch(String userName,
List<AbstractFilter> filters,
AttributeType groupAttributeType,
FileGroup.GroupSortingAlgorithm groupSortingType,
Group.GroupSortingAlgorithm groupSortingType,
FileSorter.SortingMethod fileSortingMethod,
SleuthkitCase caseDb, CentralRepository centralRepoDb) throws FileSearchException {
SleuthkitCase caseDb, CentralRepository centralRepoDb) throws DiscoveryException {
// Make a list of attributes that we want to add values for. This ensures the
// ResultFile objects will have all needed fields set when it's time to group
@@ -313,10 +313,10 @@ public class FileSearch {
* @param centralRepoDb The central repository database. Can be null if not
* needed.
*
* @throws FileSearchException
* @throws DiscoveryException
*/
private static void addAttributes(List<AttributeType> attrs, List<ResultFile> resultFiles, SleuthkitCase caseDb, CentralRepository centralRepoDb)
throws FileSearchException {
throws DiscoveryException {
for (AttributeType attr : attrs) {
attr.addAttributeToResultFiles(resultFiles, caseDb, centralRepoDb);
}
@@ -357,7 +357,7 @@ public class FileSearch {
}
private static String createSetNameClause(List<ResultFile> files,
int artifactTypeID, int setNameAttrID) throws FileSearchException {
int artifactTypeID, int setNameAttrID) throws DiscoveryException {
// Concatenate the object IDs in the list of files
String objIdList = ""; // NON-NLS
@@ -405,9 +405,9 @@ public class FileSearch {
* @param centralRepoDb The central repository database. Can be null if
* not needed.
*
* @throws FileSearchException
* @throws DiscoveryException
*/
public void addAttributeToResultFiles(List<ResultFile> files, SleuthkitCase caseDb, CentralRepository centralRepoDb) throws FileSearchException {
public void addAttributeToResultFiles(List<ResultFile> files, SleuthkitCase caseDb, CentralRepository centralRepoDb) throws DiscoveryException {
// Default is to do nothing
}
}
@@ -479,7 +479,7 @@ public class FileSearch {
@Override
public void addAttributeToResultFiles(List<ResultFile> files, SleuthkitCase caseDb,
CentralRepository centralRepoDb) throws FileSearchException {
CentralRepository centralRepoDb) throws DiscoveryException {
// Get pairs of (object ID, keyword list name) for all files in the list of files that have
// keyword list hits.
@@ -490,7 +490,7 @@ public class FileSearch {
try {
caseDb.getCaseDbAccessManager().select(selectQuery, callback);
} catch (TskCoreException ex) {
throw new FileSearchException("Error looking up keyword list attributes", ex); // NON-NLS
throw new DiscoveryException("Error looking up keyword list attributes", ex); // NON-NLS
}
}
@@ -553,7 +553,7 @@ public class FileSearch {
@Override
public void addAttributeToResultFiles(List<ResultFile> files, SleuthkitCase caseDb,
CentralRepository centralRepoDb) throws FileSearchException {
CentralRepository centralRepoDb) throws DiscoveryException {
if (centralRepoDb == null) {
for (ResultFile file : files) {
if (file.getFrequency() == Frequency.UNKNOWN && file.getFirstInstance().getKnown() == TskData.FileKnown.KNOWN) {
@@ -648,7 +648,7 @@ public class FileSearch {
@Override
public void addAttributeToResultFiles(List<ResultFile> files, SleuthkitCase caseDb,
CentralRepository centralRepoDb) throws FileSearchException {
CentralRepository centralRepoDb) throws DiscoveryException {
// Get pairs of (object ID, hash set name) for all files in the list of files that have
// hash set hits.
@@ -659,7 +659,7 @@ public class FileSearch {
try {
caseDb.getCaseDbAccessManager().select(selectQuery, callback);
} catch (TskCoreException ex) {
throw new FileSearchException("Error looking up hash set attributes", ex); // NON-NLS
throw new DiscoveryException("Error looking up hash set attributes", ex); // NON-NLS
}
}
@@ -719,7 +719,7 @@ public class FileSearch {
@Override
public void addAttributeToResultFiles(List<ResultFile> files, SleuthkitCase caseDb,
CentralRepository centralRepoDb) throws FileSearchException {
CentralRepository centralRepoDb) throws DiscoveryException {
// Get pairs of (object ID, interesting item set name) for all files in the list of files that have
// interesting file set hits.
@@ -730,7 +730,7 @@ public class FileSearch {
try {
caseDb.getCaseDbAccessManager().select(selectQuery, callback);
} catch (TskCoreException ex) {
throw new FileSearchException("Error looking up interesting file set attributes", ex); // NON-NLS
throw new DiscoveryException("Error looking up interesting file set attributes", ex); // NON-NLS
}
}
@@ -792,7 +792,7 @@ public class FileSearch {
@Override
public void addAttributeToResultFiles(List<ResultFile> files, SleuthkitCase caseDb,
CentralRepository centralRepoDb) throws FileSearchException {
CentralRepository centralRepoDb) throws DiscoveryException {
// Get pairs of (object ID, object type name) for all files in the list of files that have
// objects detected
@@ -803,7 +803,7 @@ public class FileSearch {
try {
caseDb.getCaseDbAccessManager().select(selectQuery, callback);
} catch (TskCoreException ex) {
throw new FileSearchException("Error looking up object detected attributes", ex); // NON-NLS
throw new DiscoveryException("Error looking up object detected attributes", ex); // NON-NLS
}
}
@@ -864,7 +864,7 @@ public class FileSearch {
@Override
public void addAttributeToResultFiles(List<ResultFile> files, SleuthkitCase caseDb,
CentralRepository centralRepoDb) throws FileSearchException {
CentralRepository centralRepoDb) throws DiscoveryException {
try {
for (ResultFile resultFile : files) {
@@ -875,7 +875,7 @@ public class FileSearch {
}
}
} catch (TskCoreException ex) {
throw new FileSearchException("Error looking up file tag attributes", ex); // NON-NLS
throw new DiscoveryException("Error looking up file tag attributes", ex); // NON-NLS
}
}
}
@@ -1,441 +0,0 @@
/*
* Autopsy Forensic Browser
*
* Copyright 2019 Basis Technology Corp.
* Contact: carrier <at> sleuthkit <dot> org
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.sleuthkit.autopsy.discovery.search;
import com.google.common.collect.ImmutableSet;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Collection;
import java.util.Collections;
import java.util.List;
import org.openide.util.NbBundle;
import org.sleuthkit.autopsy.coreutils.FileTypeUtils;
/**
* Utility enums for searches made for files with Discovery.
*/
public final class FileSearchData implements SearchData {
private final static long BYTES_PER_MB = 1000000;
@Override
public ResultType getResultType() {
return ResultType.FILE;
}
/**
* Enum representing how often the file occurs in the Central Repository.
*/
@NbBundle.Messages({
"FileSearchData.Frequency.unique.displayName=Unique (1)",
"FileSearchData.Frequency.rare.displayName=Rare (2-10)",
"FileSearchData.Frequency.common.displayName=Common (11 - 100)",
"FileSearchData.Frequency.verycommon.displayName=Very Common (100+)",
"FileSearchData.Frequency.known.displayName=Known (NSRL)",
"FileSearchData.Frequency.unknown.displayName=Unknown",})
public enum Frequency {
UNIQUE(0, 1, Bundle.FileSearchData_Frequency_unique_displayName()),
RARE(1, 10, Bundle.FileSearchData_Frequency_rare_displayName()),
COMMON(2, 100, Bundle.FileSearchData_Frequency_common_displayName()),
VERY_COMMON(3, 0, Bundle.FileSearchData_Frequency_verycommon_displayName()),
KNOWN(4, 0, Bundle.FileSearchData_Frequency_known_displayName()),
UNKNOWN(5, 0, Bundle.FileSearchData_Frequency_unknown_displayName());
private final int ranking;
private final String displayName;
private final int maxOccur;
Frequency(int ranking, int maxOccur, String displayName) {
this.ranking = ranking;
this.maxOccur = maxOccur;
this.displayName = displayName;
}
/**
* Get the rank for sorting.
*
* @return the rank (lower should be displayed first)
*/
public int getRanking() {
return ranking;
}
/**
* Get the enum matching the given occurrence count.
*
* @param count Number of times a file is in the Central Repository.
*
* @return the corresponding enum
*/
public static Frequency fromCount(long count) {
if (count <= UNIQUE.getMaxOccur()) {
return UNIQUE;
} else if (count <= RARE.getMaxOccur()) {
return RARE;
} else if (count <= COMMON.getMaxOccur()) {
return COMMON;
}
return VERY_COMMON;
}
/**
* Get the list of enums that are valid for filtering when a CR is
* enabled.
*
* @return enums that can be used to filter with a CR.
*/
public static List<Frequency> getOptionsForFilteringWithCr() {
return Arrays.asList(UNIQUE, RARE, COMMON, VERY_COMMON, KNOWN);
}
/**
* Get the list of enums that are valid for filtering when no CR is
* enabled.
*
* @return enums that can be used to filter without a CR.
*/
public static List<Frequency> getOptionsForFilteringWithoutCr() {
return Arrays.asList(KNOWN, UNKNOWN);
}
@Override
public String toString() {
return displayName;
}
/**
* @return the maxOccur
*/
public int getMaxOccur() {
return maxOccur;
}
}
/**
* Enum representing the file size
*/
@NbBundle.Messages({
"FileSearchData.FileSize.XXLARGE.displayName=XXLarge",
"FileSearchData.FileSize.XLARGE.displayName=XLarge",
"FileSearchData.FileSize.LARGE.displayName=Large",
"FileSearchData.FileSize.MEDIUM.displayName=Medium",
"FileSearchData.FileSize.SMALL.displayName=Small",
"FileSearchData.FileSize.XSMALL.displayName=XSmall",
"FileSearchData.FileSize.10PlusGb=: 10GB+",
"FileSearchData.FileSize.5gbto10gb=: 5-10GB",
"FileSearchData.FileSize.1gbto5gb=: 1-5GB",
"FileSearchData.FileSize.100mbto1gb=: 100MB-1GB",
"FileSearchData.FileSize.200PlusMb=: 200MB+",
"FileSearchData.FileSize.50mbto200mb=: 50-200MB",
"FileSearchData.FileSize.500kbto100mb=: 500KB-100MB",
"FileSearchData.FileSize.1mbto50mb=: 1-50MB",
"FileSearchData.FileSize.100kbto1mb=: 100KB-1MB",
"FileSearchData.FileSize.16kbto100kb=: 16-100KB",
"FileSearchData.FileSize.upTo500kb=: 0-500KB",
"FileSearchData.FileSize.upTo16kb=: 0-16KB",})
public enum FileSize {
XXLARGE_VIDEO(0, 10000 * BYTES_PER_MB, -1, Bundle.FileSearchData_FileSize_XXLARGE_displayName(), Bundle.FileSearchData_FileSize_10PlusGb()),
XLARGE_VIDEO(1, 5000 * BYTES_PER_MB, 10000 * BYTES_PER_MB, Bundle.FileSearchData_FileSize_XLARGE_displayName(), Bundle.FileSearchData_FileSize_5gbto10gb()),
LARGE_VIDEO(2, 1000 * BYTES_PER_MB, 5000 * BYTES_PER_MB, Bundle.FileSearchData_FileSize_LARGE_displayName(), Bundle.FileSearchData_FileSize_1gbto5gb()),
MEDIUM_VIDEO(3, 100 * BYTES_PER_MB, 1000 * BYTES_PER_MB, Bundle.FileSearchData_FileSize_MEDIUM_displayName(), Bundle.FileSearchData_FileSize_100mbto1gb()),
SMALL_VIDEO(4, 500000, 100 * BYTES_PER_MB, Bundle.FileSearchData_FileSize_SMALL_displayName(), Bundle.FileSearchData_FileSize_500kbto100mb()),
XSMALL_VIDEO(5, 0, 500000, Bundle.FileSearchData_FileSize_XSMALL_displayName(), Bundle.FileSearchData_FileSize_upTo500kb()),
XXLARGE_IMAGE(6, 200 * BYTES_PER_MB, -1, Bundle.FileSearchData_FileSize_XXLARGE_displayName(), Bundle.FileSearchData_FileSize_200PlusMb()),
XLARGE_IMAGE(7, 50 * BYTES_PER_MB, 200 * BYTES_PER_MB, Bundle.FileSearchData_FileSize_XLARGE_displayName(), Bundle.FileSearchData_FileSize_50mbto200mb()),
LARGE_IMAGE(8, 1 * BYTES_PER_MB, 50 * BYTES_PER_MB, Bundle.FileSearchData_FileSize_LARGE_displayName(), Bundle.FileSearchData_FileSize_1mbto50mb()),
MEDIUM_IMAGE(9, 100000, 1 * BYTES_PER_MB, Bundle.FileSearchData_FileSize_MEDIUM_displayName(), Bundle.FileSearchData_FileSize_100kbto1mb()),
SMALL_IMAGE(10, 16000, 100000, Bundle.FileSearchData_FileSize_SMALL_displayName(), Bundle.FileSearchData_FileSize_16kbto100kb()),
XSMALL_IMAGE(11, 0, 16000, Bundle.FileSearchData_FileSize_XSMALL_displayName(), Bundle.FileSearchData_FileSize_upTo16kb());
private final int ranking; // Must be unique for each value
private final long minBytes; // Note that the size must be strictly greater than this to match
private final long maxBytes;
private final String sizeGroup;
private final String displaySize;
final static long NO_MAXIMUM = -1;
FileSize(int ranking, long minB, long maxB, String displayName, String displaySize) {
this.ranking = ranking;
this.minBytes = minB;
if (maxB >= 0) {
this.maxBytes = maxB;
} else {
this.maxBytes = NO_MAXIMUM;
}
this.sizeGroup = displayName;
this.displaySize = displaySize;
}
/**
* Get the enum corresponding to the given file size for image files.
* The file size must be strictly greater than minBytes.
*
* @param size the file size
*
* @return the enum whose range contains the file size
*/
public static FileSize fromImageSize(long size) {
if (size > XXLARGE_IMAGE.getMinBytes()) {
return XXLARGE_IMAGE;
} else if (size > XLARGE_IMAGE.getMinBytes()) {
return XLARGE_IMAGE;
} else if (size > LARGE_IMAGE.getMinBytes()) {
return LARGE_IMAGE;
} else if (size > MEDIUM_IMAGE.getMinBytes()) {
return MEDIUM_IMAGE;
} else if (size > SMALL_IMAGE.getMinBytes()) {
return SMALL_IMAGE;
} else {
return XSMALL_IMAGE;
}
}
/**
* Get the enum corresponding to the given file size for video files.
* The file size must be strictly greater than minBytes.
*
* @param size the file size
*
* @return the enum whose range contains the file size
*/
public static FileSize fromVideoSize(long size) {
if (size > XXLARGE_VIDEO.getMinBytes()) {
return XXLARGE_VIDEO;
} else if (size > XLARGE_VIDEO.getMinBytes()) {
return XLARGE_VIDEO;
} else if (size > LARGE_VIDEO.getMinBytes()) {
return LARGE_VIDEO;
} else if (size > MEDIUM_VIDEO.getMinBytes()) {
return MEDIUM_VIDEO;
} else if (size > SMALL_VIDEO.getMinBytes()) {
return SMALL_VIDEO;
} else {
return XSMALL_VIDEO;
}
}
/**
* Get the upper limit of the range.
*
* @return the maximum file size that will fit in this range.
*/
public long getMaxBytes() {
return maxBytes;
}
/**
* Get the lower limit of the range.
*
* @return the maximum file size that is not part of this range
*/
public long getMinBytes() {
return minBytes;
}
/**
* Get the rank for sorting.
*
* @return the rank (lower should be displayed first)
*/
public int getRanking() {
return ranking;
}
@Override
public String toString() {
return sizeGroup + displaySize;
}
public String getSizeGroup() {
return sizeGroup;
}
/**
* Get the list of enums that are valid for most file sizes.
*
* @return Enums that can be used to filter most file including images
* by size.
*/
public static List<FileSize> getDefaultSizeOptions() {
return Arrays.asList(XXLARGE_IMAGE, XLARGE_IMAGE, LARGE_IMAGE, MEDIUM_IMAGE, SMALL_IMAGE, XSMALL_IMAGE);
}
/**
* Get the list of enums that are valid for video sizes.
*
* @return enums that can be used to filter videos by size.
*/
public static List<FileSize> getOptionsForVideos() {
return Arrays.asList(XXLARGE_VIDEO, XLARGE_VIDEO, LARGE_VIDEO, MEDIUM_VIDEO, SMALL_VIDEO, XSMALL_VIDEO);
}
}
//Discovery uses a different list of document mime types than FileTypeUtils.FileTypeCategory.DOCUMENTS
private static final ImmutableSet<String> DOCUMENT_MIME_TYPES
= new ImmutableSet.Builder<String>()
.add("text/html", //NON-NLS
"text/csv", //NON-NLS
"application/rtf", //NON-NLS
"application/pdf", //NON-NLS
"application/xhtml+xml", //NON-NLS
"application/x-msoffice", //NON-NLS
"application/msword", //NON-NLS
"application/msword2", //NON-NLS
"application/vnd.wordperfect", //NON-NLS
"application/vnd.openxmlformats-officedocument.wordprocessingml.document", //NON-NLS
"application/vnd.ms-powerpoint", //NON-NLS
"application/vnd.openxmlformats-officedocument.presentationml.presentation", //NON-NLS
"application/vnd.ms-excel", //NON-NLS
"application/vnd.ms-excel.sheet.4", //NON-NLS
"application/vnd.openxmlformats-officedocument.spreadsheetml.sheet", //NON-NLS
"application/vnd.oasis.opendocument.presentation", //NON-NLS
"application/vnd.oasis.opendocument.spreadsheet", //NON-NLS
"application/vnd.oasis.opendocument.text" //NON-NLS
).build();
private static final ImmutableSet<String> IMAGE_UNSUPPORTED_DOC_TYPES
= new ImmutableSet.Builder<String>()
.add("application/pdf", //NON-NLS
"application/xhtml+xml").build(); //NON-NLS
public static Collection<String> getDocTypesWithoutImageExtraction() {
return Collections.unmodifiableCollection(IMAGE_UNSUPPORTED_DOC_TYPES);
}
/**
* Enum representing the file type. We don't simply use
* FileTypeUtils.FileTypeCategory because: - Some file types categories
* overlap - It is convenient to have the "OTHER" option for files that
* don't match the given types
*/
@NbBundle.Messages({
"FileSearchData.FileType.Audio.displayName=Audio",
"FileSearchData.FileType.Video.displayName=Video",
"FileSearchData.FileType.Image.displayName=Image",
"FileSearchData.FileType.Documents.displayName=Documents",
"FileSearchData.FileType.Executables.displayName=Executables",
"FileSearchData.FileType.Other.displayName=Other/Unknown"})
public enum FileType {
IMAGE(0, Bundle.FileSearchData_FileType_Image_displayName(), FileTypeUtils.FileTypeCategory.IMAGE.getMediaTypes()),
AUDIO(1, Bundle.FileSearchData_FileType_Audio_displayName(), FileTypeUtils.FileTypeCategory.AUDIO.getMediaTypes()),
VIDEO(2, Bundle.FileSearchData_FileType_Video_displayName(), FileTypeUtils.FileTypeCategory.VIDEO.getMediaTypes()),
EXECUTABLE(3, Bundle.FileSearchData_FileType_Executables_displayName(), FileTypeUtils.FileTypeCategory.EXECUTABLE.getMediaTypes()),
DOCUMENTS(4, Bundle.FileSearchData_FileType_Documents_displayName(), DOCUMENT_MIME_TYPES),
OTHER(5, Bundle.FileSearchData_FileType_Other_displayName(), new ArrayList<>());
private final int ranking; // For ordering in the UI
private final String displayName;
private final Collection<String> mediaTypes;
FileType(int value, String displayName, Collection<String> mediaTypes) {
this.ranking = value;
this.displayName = displayName;
this.mediaTypes = mediaTypes;
}
/**
* Get the MIME types matching this category.
*
* @return Collection of MIME type strings
*/
public Collection<String> getMediaTypes() {
return Collections.unmodifiableCollection(mediaTypes);
}
@Override
public String toString() {
return displayName;
}
/**
* Get the rank for sorting.
*
* @return the rank (lower should be displayed first)
*/
public int getRanking() {
return ranking;
}
/**
* Get the enum matching the given MIME type.
*
* @param mimeType The MIME type for the file
*
* @return the corresponding enum (will be OTHER if no types matched)
*/
public static FileType fromMIMEtype(String mimeType) {
for (FileType type : FileType.values()) {
if (type.getMediaTypes().contains(mimeType)) {
return type;
}
}
return OTHER;
}
}
/**
* Enum representing the score of the file.
*/
@NbBundle.Messages({
"FileSearchData.Score.notable.displayName=Notable",
"FileSearchData.Score.interesting.displayName=Interesting",
"FileSearchData.Score.unknown.displayName=Unknown",})
public enum Score {
NOTABLE(0, Bundle.FileSearchData_Score_notable_displayName()),
INTERESTING(1, Bundle.FileSearchData_Score_interesting_displayName()),
UNKNOWN(2, Bundle.FileSearchData_Score_unknown_displayName());
private final int ranking;
private final String displayName;
Score(int ranking, String displayName) {
this.ranking = ranking;
this.displayName = displayName;
}
/**
* Get the rank for sorting.
*
* @return the rank (lower should be displayed first)
*/
public int getRanking() {
return ranking;
}
/**
* Get the list of enums that are valid for filtering.
*
* @return enums that can be used to filter
*/
public static List<Score> getOptionsForFiltering() {
return Arrays.asList(NOTABLE, INTERESTING);
}
@Override
public String toString() {
return displayName;
}
}
private FileSearchData() {
// Class should not be instantiated
}
}
@@ -26,9 +26,9 @@ import org.openide.util.NbBundle.Messages;
/**
* Class for storing files that belong to a particular group.
*/
public class FileGroup implements Comparable<FileGroup> {
public class Group implements Comparable<Group> {
private final FileGroup.GroupSortingAlgorithm groupSortingType;
private final Group.GroupSortingAlgorithm groupSortingType;
private final DiscoveryKeyUtils.GroupKey groupKey;
private final List<ResultFile> files;
private final String displayName;
@@ -39,7 +39,7 @@ public class FileGroup implements Comparable<FileGroup> {
* @param groupSortingType The method for sorting the group
* @param groupKey The GroupKey for this group
*/
public FileGroup(FileGroup.GroupSortingAlgorithm groupSortingType, DiscoveryKeyUtils.GroupKey groupKey) {
public Group(Group.GroupSortingAlgorithm groupSortingType, DiscoveryKeyUtils.GroupKey groupKey) {
this.groupSortingType = groupSortingType;
this.groupKey = groupKey;
files = new ArrayList<>();
@@ -95,7 +95,7 @@ public class FileGroup implements Comparable<FileGroup> {
* otherwise
*/
@Override
public int compareTo(FileGroup otherGroup) {
public int compareTo(Group otherGroup) {
switch (groupSortingType) {
case BY_GROUP_SIZE:
@@ -114,7 +114,7 @@ public class FileGroup implements Comparable<FileGroup> {
*
* @return -1 if group1 should be displayed before group2, 1 otherwise
*/
private static int compareGroupsByGroupKey(FileGroup group1, FileGroup group2) {
private static int compareGroupsByGroupKey(Group group1, Group group2) {
return group1.getGroupKey().compareTo(group2.getGroupKey());
}
@@ -127,7 +127,7 @@ public class FileGroup implements Comparable<FileGroup> {
*
* @return -1 if group1 should be displayed before group2, 1 otherwise
*/
private static int compareGroupsBySize(FileGroup group1, FileGroup group2) {
private static int compareGroupsBySize(Group group1, Group group2) {
if (group1.getFiles().size() != group2.getFiles().size()) {
return -1 * Long.compare(group1.getFiles().size(), group2.getFiles().size()); // High to low
} else {
@@ -0,0 +1,26 @@
/*
* Autopsy
*
* Copyright 2020 Basis Technology Corp.
* Contact: carrier <at> sleuthkit <dot> org
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.sleuthkit.autopsy.discovery.search;
/**
* Interface implemented by all types of results.
*/
public interface Result {
}
@@ -0,0 +1,24 @@
/*
* Autopsy
*
* Copyright 2020 Basis Technology Corp.
* Contact: carrier <at> sleuthkit <dot> org
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.sleuthkit.autopsy.discovery.search;
public class ResultDomain implements Result {
}
@@ -18,7 +18,7 @@
*/
package org.sleuthkit.autopsy.discovery.search;
import org.sleuthkit.autopsy.discovery.search.FileSearchData.FileType;
import org.sleuthkit.autopsy.discovery.search.SearchData.Type;
import org.sleuthkit.datamodel.AbstractFile;
import java.util.ArrayList;
import java.util.Collections;
@@ -29,6 +29,7 @@ import org.sleuthkit.autopsy.casemodule.Case;
import org.sleuthkit.autopsy.casemodule.NoCurrentCaseException;
import org.sleuthkit.autopsy.corecomponents.DataResultViewerTable;
import org.sleuthkit.autopsy.coreutils.Logger;
import static org.sleuthkit.autopsy.discovery.search.SearchData.Type.OTHER;
import org.sleuthkit.datamodel.BlackboardArtifact;
import org.sleuthkit.datamodel.ContentTag;
import org.sleuthkit.datamodel.HashUtility;
@@ -39,10 +40,10 @@ import org.sleuthkit.datamodel.TskData;
/**
* Container for files that holds all necessary data for grouping and sorting.
*/
public class ResultFile {
public class ResultFile implements Result{
private final static Logger logger = Logger.getLogger(ResultFile.class.getName());
private FileSearchData.Frequency frequency;
private SearchData.Frequency frequency;
private final List<String> keywordListNames;
private final List<String> hashSetNames;
private final List<String> tagNames;
@@ -52,7 +53,7 @@ public class ResultFile {
private DataResultViewerTable.Score currentScore = DataResultViewerTable.Score.NO_SCORE;
private String scoreDescription = null;
private boolean deleted = false;
private FileType fileType;
private Type fileType;
/**
* Create a ResultFile from an AbstractFile
@@ -72,13 +73,13 @@ public class ResultFile {
deleted = true;
}
updateScoreAndDescription(abstractFile);
this.frequency = FileSearchData.Frequency.UNKNOWN;
this.frequency = SearchData.Frequency.UNKNOWN;
keywordListNames = new ArrayList<>();
hashSetNames = new ArrayList<>();
tagNames = new ArrayList<>();
interestingSetNames = new ArrayList<>();
objectDetectedNames = new ArrayList<>();
fileType = FileType.fromMIMEtype(abstractFile.getMIMEType());
fileType = fromMIMEtype(abstractFile.getMIMEType());
}
/**
@@ -86,7 +87,7 @@ public class ResultFile {
*
* @return The Frequency enum
*/
public FileSearchData.Frequency getFrequency() {
public SearchData.Frequency getFrequency() {
return frequency;
}
@@ -95,7 +96,7 @@ public class ResultFile {
*
* @param frequency The frequency of the file as an enum
*/
public void setFrequency(FileSearchData.Frequency frequency) {
public void setFrequency(SearchData.Frequency frequency) {
this.frequency = frequency;
}
@@ -109,8 +110,8 @@ public class ResultFile {
if (deleted && !duplicate.isDirNameFlagSet(TskData.TSK_FS_NAME_FLAG_ENUM.UNALLOC)) {
deleted = false;
}
if (fileType == FileType.OTHER) {
fileType = FileType.fromMIMEtype(duplicate.getMIMEType());
if (fileType == Type.OTHER) {
fileType = fromMIMEtype(duplicate.getMIMEType());
}
updateScoreAndDescription(duplicate);
try {
@@ -167,7 +168,7 @@ public class ResultFile {
*
* @return The FileType enum.
*/
public FileType getFileType() {
public Type getFileType() {
return fileType;
}
@@ -380,4 +381,20 @@ public class ResultFile {
}
}
}
/**
* Get the enum matching the given MIME type.
*
* @param mimeType The MIME type for the file.
*
* @return the corresponding enum (will be OTHER if no types matched)
*/
public static Type fromMIMEtype(String mimeType) {
for (Type type : Type.values()) {
if (type.getMediaTypes().contains(mimeType)) {
return type;
}
}
return OTHER;
}
}
@@ -1,7 +1,7 @@
/*
* Autopsy
* Autopsy Forensic Browser
*
* Copyright 2020 Basis Technology Corp.
* Copyright 2019 Basis Technology Corp.
* Contact: carrier <at> sleuthkit <dot> org
*
* Licensed under the Apache License, Version 2.0 (the "License");
@@ -18,22 +18,413 @@
*/
package org.sleuthkit.autopsy.discovery.search;
import com.google.common.collect.ImmutableSet;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Collection;
import java.util.Collections;
import java.util.EnumSet;
import java.util.List;
import java.util.Set;
import org.openide.util.NbBundle;
import org.sleuthkit.autopsy.coreutils.FileTypeUtils;
import org.sleuthkit.datamodel.BlackboardArtifact;
/**
* Abstract class to contain data that is common to all result types.
* Utility enums for searches made for files with Discovery.
*/
public interface SearchData {
public final class SearchData {
private final static long BYTES_PER_MB = 1000000;
private static final Set<BlackboardArtifact.ARTIFACT_TYPE> DOMAIN_ARTIFACT_TYPES = EnumSet.of(BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_BOOKMARK, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_CACHE, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_COOKIE, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_DOWNLOAD, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_HISTORY, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_SEARCH_QUERY, BlackboardArtifact.ARTIFACT_TYPE.TSK_EMAIL_MSG);
/**
* Enum of the broad result type categories.
* Enum representing how often the file occurs in the Central Repository.
*/
public enum ResultType {
FILE,
ATTRIBUTE;
@NbBundle.Messages({
"SearchData.Frequency.unique.displayName=Unique (1)",
"SearchData.Frequency.rare.displayName=Rare (2-10)",
"SearchData.Frequency.common.displayName=Common (11 - 100)",
"SearchData.Frequency.verycommon.displayName=Very Common (100+)",
"SearchData.Frequency.known.displayName=Known (NSRL)",
"SearchData.Frequency.unknown.displayName=Unknown",})
public enum Frequency {
UNIQUE(0, 1, Bundle.SearchData_Frequency_unique_displayName()),
RARE(1, 10, Bundle.SearchData_Frequency_rare_displayName()),
COMMON(2, 100, Bundle.SearchData_Frequency_common_displayName()),
VERY_COMMON(3, 0, Bundle.SearchData_Frequency_verycommon_displayName()),
KNOWN(4, 0, Bundle.SearchData_Frequency_known_displayName()),
UNKNOWN(5, 0, Bundle.SearchData_Frequency_unknown_displayName());
private final int ranking;
private final String displayName;
private final int maxOccur;
Frequency(int ranking, int maxOccur, String displayName) {
this.ranking = ranking;
this.maxOccur = maxOccur;
this.displayName = displayName;
}
/**
* Get the rank for sorting.
*
* @return the rank (lower should be displayed first)
*/
public int getRanking() {
return ranking;
}
/**
* Get the enum matching the given occurrence count.
*
* @param count Number of times a file is in the Central Repository.
*
* @return the corresponding enum
*/
public static Frequency fromCount(long count) {
if (count <= UNIQUE.getMaxOccur()) {
return UNIQUE;
} else if (count <= RARE.getMaxOccur()) {
return RARE;
} else if (count <= COMMON.getMaxOccur()) {
return COMMON;
}
return VERY_COMMON;
}
/**
* Get the list of enums that are valid for filtering when a CR is
* enabled.
*
* @return enums that can be used to filter with a CR.
*/
public static List<Frequency> getOptionsForFilteringWithCr() {
return Arrays.asList(UNIQUE, RARE, COMMON, VERY_COMMON, KNOWN);
}
/**
* Get the list of enums that are valid for filtering when no CR is
* enabled.
*
* @return enums that can be used to filter without a CR.
*/
public static List<Frequency> getOptionsForFilteringWithoutCr() {
return Arrays.asList(KNOWN, UNKNOWN);
}
@Override
public String toString() {
return displayName;
}
/**
* @return the maxOccur
*/
public int getMaxOccur() {
return maxOccur;
}
}
/**
* Get the broad result type.
* Enum representing the file size
*/
public abstract ResultType getResultType();
@NbBundle.Messages({
"SearchData.FileSize.XXLARGE.displayName=XXLarge",
"SearchData.FileSize.XLARGE.displayName=XLarge",
"SearchData.FileSize.LARGE.displayName=Large",
"SearchData.FileSize.MEDIUM.displayName=Medium",
"SearchData.FileSize.SMALL.displayName=Small",
"SearchData.FileSize.XSMALL.displayName=XSmall",
"SearchData.FileSize.10PlusGb=: 10GB+",
"SearchData.FileSize.5gbto10gb=: 5-10GB",
"SearchData.FileSize.1gbto5gb=: 1-5GB",
"SearchData.FileSize.100mbto1gb=: 100MB-1GB",
"SearchData.FileSize.200PlusMb=: 200MB+",
"SearchData.FileSize.50mbto200mb=: 50-200MB",
"SearchData.FileSize.500kbto100mb=: 500KB-100MB",
"SearchData.FileSize.1mbto50mb=: 1-50MB",
"SearchData.FileSize.100kbto1mb=: 100KB-1MB",
"SearchData.FileSize.16kbto100kb=: 16-100KB",
"SearchData.FileSize.upTo500kb=: 0-500KB",
"SearchData.FileSize.upTo16kb=: 0-16KB",})
public enum FileSize {
XXLARGE_VIDEO(0, 10000 * BYTES_PER_MB, -1, Bundle.SearchData_FileSize_XXLARGE_displayName(), Bundle.SearchData_FileSize_10PlusGb()),
XLARGE_VIDEO(1, 5000 * BYTES_PER_MB, 10000 * BYTES_PER_MB, Bundle.SearchData_FileSize_XLARGE_displayName(), Bundle.SearchData_FileSize_5gbto10gb()),
LARGE_VIDEO(2, 1000 * BYTES_PER_MB, 5000 * BYTES_PER_MB, Bundle.SearchData_FileSize_LARGE_displayName(), Bundle.SearchData_FileSize_1gbto5gb()),
MEDIUM_VIDEO(3, 100 * BYTES_PER_MB, 1000 * BYTES_PER_MB, Bundle.SearchData_FileSize_MEDIUM_displayName(), Bundle.SearchData_FileSize_100mbto1gb()),
SMALL_VIDEO(4, 500000, 100 * BYTES_PER_MB, Bundle.SearchData_FileSize_SMALL_displayName(), Bundle.SearchData_FileSize_500kbto100mb()),
XSMALL_VIDEO(5, 0, 500000, Bundle.SearchData_FileSize_XSMALL_displayName(), Bundle.SearchData_FileSize_upTo500kb()),
XXLARGE_IMAGE(6, 200 * BYTES_PER_MB, -1, Bundle.SearchData_FileSize_XXLARGE_displayName(), Bundle.SearchData_FileSize_200PlusMb()),
XLARGE_IMAGE(7, 50 * BYTES_PER_MB, 200 * BYTES_PER_MB, Bundle.SearchData_FileSize_XLARGE_displayName(), Bundle.SearchData_FileSize_50mbto200mb()),
LARGE_IMAGE(8, 1 * BYTES_PER_MB, 50 * BYTES_PER_MB, Bundle.SearchData_FileSize_LARGE_displayName(), Bundle.SearchData_FileSize_1mbto50mb()),
MEDIUM_IMAGE(9, 100000, 1 * BYTES_PER_MB, Bundle.SearchData_FileSize_MEDIUM_displayName(), Bundle.SearchData_FileSize_100kbto1mb()),
SMALL_IMAGE(10, 16000, 100000, Bundle.SearchData_FileSize_SMALL_displayName(), Bundle.SearchData_FileSize_16kbto100kb()),
XSMALL_IMAGE(11, 0, 16000, Bundle.SearchData_FileSize_XSMALL_displayName(), Bundle.SearchData_FileSize_upTo16kb());
private final int ranking; // Must be unique for each value
private final long minBytes; // Note that the size must be strictly greater than this to match
private final long maxBytes;
private final String sizeGroup;
private final String displaySize;
final static long NO_MAXIMUM = -1;
FileSize(int ranking, long minB, long maxB, String displayName, String displaySize) {
this.ranking = ranking;
this.minBytes = minB;
if (maxB >= 0) {
this.maxBytes = maxB;
} else {
this.maxBytes = NO_MAXIMUM;
}
this.sizeGroup = displayName;
this.displaySize = displaySize;
}
/**
* Get the enum corresponding to the given file size for image files.
* The file size must be strictly greater than minBytes.
*
* @param size the file size
*
* @return the enum whose range contains the file size
*/
public static FileSize fromImageSize(long size) {
if (size > XXLARGE_IMAGE.getMinBytes()) {
return XXLARGE_IMAGE;
} else if (size > XLARGE_IMAGE.getMinBytes()) {
return XLARGE_IMAGE;
} else if (size > LARGE_IMAGE.getMinBytes()) {
return LARGE_IMAGE;
} else if (size > MEDIUM_IMAGE.getMinBytes()) {
return MEDIUM_IMAGE;
} else if (size > SMALL_IMAGE.getMinBytes()) {
return SMALL_IMAGE;
} else {
return XSMALL_IMAGE;
}
}
/**
* Get the enum corresponding to the given file size for video files.
* The file size must be strictly greater than minBytes.
*
* @param size the file size
*
* @return the enum whose range contains the file size
*/
public static FileSize fromVideoSize(long size) {
if (size > XXLARGE_VIDEO.getMinBytes()) {
return XXLARGE_VIDEO;
} else if (size > XLARGE_VIDEO.getMinBytes()) {
return XLARGE_VIDEO;
} else if (size > LARGE_VIDEO.getMinBytes()) {
return LARGE_VIDEO;
} else if (size > MEDIUM_VIDEO.getMinBytes()) {
return MEDIUM_VIDEO;
} else if (size > SMALL_VIDEO.getMinBytes()) {
return SMALL_VIDEO;
} else {
return XSMALL_VIDEO;
}
}
/**
* Get the upper limit of the range.
*
* @return the maximum file size that will fit in this range.
*/
public long getMaxBytes() {
return maxBytes;
}
/**
* Get the lower limit of the range.
*
* @return the maximum file size that is not part of this range
*/
public long getMinBytes() {
return minBytes;
}
/**
* Get the rank for sorting.
*
* @return the rank (lower should be displayed first)
*/
public int getRanking() {
return ranking;
}
@Override
public String toString() {
return sizeGroup + displaySize;
}
public String getSizeGroup() {
return sizeGroup;
}
/**
* Get the list of enums that are valid for most file sizes.
*
* @return Enums that can be used to filter most file including images
* by size.
*/
public static List<FileSize> getDefaultSizeOptions() {
return Arrays.asList(XXLARGE_IMAGE, XLARGE_IMAGE, LARGE_IMAGE, MEDIUM_IMAGE, SMALL_IMAGE, XSMALL_IMAGE);
}
/**
* Get the list of enums that are valid for video sizes.
*
* @return enums that can be used to filter videos by size.
*/
public static List<FileSize> getOptionsForVideos() {
return Arrays.asList(XXLARGE_VIDEO, XLARGE_VIDEO, LARGE_VIDEO, MEDIUM_VIDEO, SMALL_VIDEO, XSMALL_VIDEO);
}
}
//Discovery uses a different list of document mime types than FileTypeUtils.FileTypeCategory.DOCUMENTS
private static final ImmutableSet<String> DOCUMENT_MIME_TYPES
= new ImmutableSet.Builder<String>()
.add("text/html", //NON-NLS
"text/csv", //NON-NLS
"application/rtf", //NON-NLS
"application/pdf", //NON-NLS
"application/xhtml+xml", //NON-NLS
"application/x-msoffice", //NON-NLS
"application/msword", //NON-NLS
"application/msword2", //NON-NLS
"application/vnd.wordperfect", //NON-NLS
"application/vnd.openxmlformats-officedocument.wordprocessingml.document", //NON-NLS
"application/vnd.ms-powerpoint", //NON-NLS
"application/vnd.openxmlformats-officedocument.presentationml.presentation", //NON-NLS
"application/vnd.ms-excel", //NON-NLS
"application/vnd.ms-excel.sheet.4", //NON-NLS
"application/vnd.openxmlformats-officedocument.spreadsheetml.sheet", //NON-NLS
"application/vnd.oasis.opendocument.presentation", //NON-NLS
"application/vnd.oasis.opendocument.spreadsheet", //NON-NLS
"application/vnd.oasis.opendocument.text" //NON-NLS
).build();
private static final ImmutableSet<String> IMAGE_UNSUPPORTED_DOC_TYPES
= new ImmutableSet.Builder<String>()
.add("application/pdf", //NON-NLS
"application/xhtml+xml").build(); //NON-NLS
public static Collection<String> getDocTypesWithoutImageExtraction() {
return Collections.unmodifiableCollection(IMAGE_UNSUPPORTED_DOC_TYPES);
}
/**
* Enum representing the type.
*/
@NbBundle.Messages({
"SearchData.FileType.Audio.displayName=Audio",
"SearchData.FileType.Video.displayName=Video",
"SearchData.FileType.Image.displayName=Image",
"SearchData.FileType.Documents.displayName=Documents",
"SearchData.FileType.Executables.displayName=Executables",
"SearchData.AttributeType.Domain.displayName=Domains",
"SearchData.FileType.Other.displayName=Other/Unknown"})
public enum Type {
IMAGE(0, Bundle.SearchData_FileType_Image_displayName(), FileTypeUtils.FileTypeCategory.IMAGE.getMediaTypes(), new ArrayList<>()),
AUDIO(1, Bundle.SearchData_FileType_Audio_displayName(), FileTypeUtils.FileTypeCategory.AUDIO.getMediaTypes(), new ArrayList<>()),
VIDEO(2, Bundle.SearchData_FileType_Video_displayName(), FileTypeUtils.FileTypeCategory.VIDEO.getMediaTypes(), new ArrayList<>()),
EXECUTABLE(3, Bundle.SearchData_FileType_Executables_displayName(), FileTypeUtils.FileTypeCategory.EXECUTABLE.getMediaTypes(),new ArrayList<>()),
DOCUMENTS(4, Bundle.SearchData_FileType_Documents_displayName(), DOCUMENT_MIME_TYPES, new ArrayList<>()),
DOMAIN(6, Bundle.SearchData_AttributeType_Domain_displayName(), new ArrayList<>(), DOMAIN_ARTIFACT_TYPES),
OTHER(5, Bundle.SearchData_FileType_Other_displayName(), new ArrayList<>(), new ArrayList<>());
private final int ranking; // For ordering in the UI
private final String displayName;
private final Collection<String> mediaTypes;
private final Collection<BlackboardArtifact.ARTIFACT_TYPE> artifactTypes;
Type(int value, String displayName, Collection<String> mediaTypes, Collection<BlackboardArtifact.ARTIFACT_TYPE> artifactTypes) {
this.ranking = value;
this.displayName = displayName;
this.mediaTypes = mediaTypes;
this.artifactTypes = artifactTypes;
}
/**
* Get the MIME types matching this category.
*
* @return Collection of MIME type strings
*/
public Collection<String> getMediaTypes() {
return Collections.unmodifiableCollection(mediaTypes);
}
public Collection<BlackboardArtifact.ARTIFACT_TYPE> getArtifactTypes() {
return Collections.unmodifiableCollection(artifactTypes);
}
@Override
public String toString() {
return displayName;
}
/**
* Get the rank for sorting.
*
* @return the rank (lower should be displayed first)
*/
public int getRanking() {
return ranking;
}
}
/**
* Enum representing the score of the item.
*/
@NbBundle.Messages({
"SearchData.Score.notable.displayName=Notable",
"SearchData.Score.interesting.displayName=Interesting",
"SearchData.Score.unknown.displayName=Unknown",})
public enum Score {
NOTABLE(0, Bundle.SearchData_Score_notable_displayName()),
INTERESTING(1, Bundle.SearchData_Score_interesting_displayName()),
UNKNOWN(2, Bundle.SearchData_Score_unknown_displayName());
private final int ranking;
private final String displayName;
Score(int ranking, String displayName) {
this.ranking = ranking;
this.displayName = displayName;
}
/**
* Get the rank for sorting.
*
* @return the rank (lower should be displayed first)
*/
public int getRanking() {
return ranking;
}
/**
* Get the list of enums that are valid for filtering.
*
* @return enums that can be used to filter
*/
public static List<Score> getOptionsForFiltering() {
return Arrays.asList(NOTABLE, INTERESTING);
}
@Override
public String toString() {
return displayName;
}
}
private SearchData() {
// Class should not be instantiated
}
}
@@ -21,10 +21,10 @@ package org.sleuthkit.autopsy.discovery.search;
import org.sleuthkit.autopsy.centralrepository.datamodel.CorrelationAttributeInstance;
import org.sleuthkit.autopsy.centralrepository.datamodel.CorrelationAttributeNormalizationException;
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepoException;
import org.sleuthkit.autopsy.discovery.search.FileSearchData.FileSize;
import org.sleuthkit.autopsy.discovery.search.FileSearchData.FileType;
import org.sleuthkit.autopsy.discovery.search.FileSearchData.Frequency;
import org.sleuthkit.autopsy.discovery.search.FileSearchData.Score;
import org.sleuthkit.autopsy.discovery.search.SearchData.FileSize;
import org.sleuthkit.autopsy.discovery.search.SearchData.Type;
import org.sleuthkit.autopsy.discovery.search.SearchData.Frequency;
import org.sleuthkit.autopsy.discovery.search.SearchData.Score;
import org.sleuthkit.datamodel.AbstractFile;
import org.sleuthkit.datamodel.DataSource;
import org.sleuthkit.datamodel.SleuthkitCase;
@@ -54,9 +54,9 @@ public class SearchFiltering {
*
* @return
*/
static List<ResultFile> runQueries(List<AbstractFilter> filters, SleuthkitCase caseDb, CentralRepository centralRepoDb) throws FileSearchException {
static List<ResultFile> runQueries(List<AbstractFilter> filters, SleuthkitCase caseDb, CentralRepository centralRepoDb) throws DiscoveryException {
if (caseDb == null) {
throw new FileSearchException("Case DB parameter is null"); // NON-NLS
throw new DiscoveryException("Case DB parameter is null"); // NON-NLS
}
// Combine all the SQL queries from the filters into one query
String combinedQuery = "";
@@ -71,12 +71,12 @@ public class SearchFiltering {
if (combinedQuery.isEmpty()) {
// The file search filter is required, so this should never be empty.
throw new FileSearchException("Selected filters do not include a case database query");
throw new DiscoveryException("Selected filters do not include a case database query");
}
try {
return getResultList(filters, combinedQuery, caseDb, centralRepoDb);
} catch (TskCoreException ex) {
throw new FileSearchException("Error querying case database", ex); // NON-NLS
throw new DiscoveryException("Error querying case database", ex); // NON-NLS
}
}
@@ -92,9 +92,9 @@ public class SearchFiltering {
* @return An ArrayList of ResultFiles returned by the query.
*
* @throws TskCoreException
* @throws FileSearchException
* @throws DiscoveryException
*/
private static List<ResultFile> getResultList(List<AbstractFilter> filters, String combinedQuery, SleuthkitCase caseDb, CentralRepository centralRepoDb) throws TskCoreException, FileSearchException {
private static List<ResultFile> getResultList(List<AbstractFilter> filters, String combinedQuery, SleuthkitCase caseDb, CentralRepository centralRepoDb) throws TskCoreException, DiscoveryException {
// Get all matching abstract files
List<ResultFile> resultList = new ArrayList<>();
List<AbstractFile> sqlResults = caseDb.findAllFilesWhere(combinedQuery);
@@ -431,14 +431,14 @@ public class SearchFiltering {
*/
public static class FileTypeFilter extends AbstractFilter {
private final List<FileType> categories;
private final List<Type> categories;
/**
* Create the FileTypeFilter
*
* @param categories List of file types to filter on
*/
public FileTypeFilter(List<FileType> categories) {
public FileTypeFilter(List<Type> categories) {
this.categories = categories;
}
@@ -447,7 +447,7 @@ public class SearchFiltering {
*
* @param category the file type to filter on
*/
public FileTypeFilter(FileType category) {
public FileTypeFilter(Type category) {
this.categories = new ArrayList<>();
this.categories.add(category);
}
@@ -455,7 +455,7 @@ public class SearchFiltering {
@Override
public String getWhereClause() {
String queryStr = ""; // NON-NLS
for (FileType cat : categories) {
for (Type cat : categories) {
for (String type : cat.getMediaTypes()) {
if (!queryStr.isEmpty()) {
queryStr += ","; // NON-NLS
@@ -474,7 +474,7 @@ public class SearchFiltering {
@Override
public String getDesc() {
String desc = "";
for (FileType cat : categories) {
for (Type cat : categories) {
if (!desc.isEmpty()) {
desc += Bundle.SearchFiltering_FileTypeFilter_or();
}
@@ -515,12 +515,12 @@ public class SearchFiltering {
@Override
public List<ResultFile> applyAlternateFilter(List<ResultFile> currentResults, SleuthkitCase caseDb,
CentralRepository centralRepoDb) throws FileSearchException {
CentralRepository centralRepoDb) throws DiscoveryException {
// We have to have run some kind of SQL filter before getting to this point,
// and should have checked afterward to see if the results were empty.
if (currentResults.isEmpty()) {
throw new FileSearchException("Can not run on empty list"); // NON-NLS
throw new DiscoveryException("Can not run on empty list"); // NON-NLS
}
// Set the frequency for each file
@@ -835,16 +835,16 @@ public class SearchFiltering {
@Override
public List<ResultFile> applyAlternateFilter(List<ResultFile> currentResults, SleuthkitCase caseDb,
CentralRepository centralRepoDb) throws FileSearchException {
CentralRepository centralRepoDb) throws DiscoveryException {
if (centralRepoDb == null) {
throw new FileSearchException("Can not run Previously Notable filter with null Central Repository DB"); // NON-NLS
throw new DiscoveryException("Can not run Previously Notable filter with null Central Repository DB"); // NON-NLS
}
// We have to have run some kind of SQL filter before getting to this point,
// and should have checked afterward to see if the results were empty.
if (currentResults.isEmpty()) {
throw new FileSearchException("Can not run on empty list"); // NON-NLS
throw new DiscoveryException("Can not run on empty list"); // NON-NLS
}
// The matching files
@@ -865,7 +865,7 @@ public class SearchFiltering {
}
return notableResults;
} catch (CentralRepoException | CorrelationAttributeNormalizationException ex) {
throw new FileSearchException("Error querying central repository", ex); // NON-NLS
throw new DiscoveryException("Error querying central repository", ex); // NON-NLS
}
}
@@ -32,12 +32,12 @@ import org.sleuthkit.autopsy.discovery.search.DiscoveryKeyUtils.GroupKey;
*/
class SearchResults {
private final FileGroup.GroupSortingAlgorithm groupSortingType;
private final Group.GroupSortingAlgorithm groupSortingType;
private final FileSearch.AttributeType attrType;
private final FileSorter fileSorter;
private final Map<GroupKey, FileGroup> groupMap = new HashMap<>();
private List<FileGroup> groupList = new ArrayList<>();
private final Map<GroupKey, Group> groupMap = new HashMap<>();
private List<Group> groupList = new ArrayList<>();
private static final long MAX_OUTPUT_FILES = 2000; // For debug UI - maximum number of lines to print
@@ -50,7 +50,7 @@ class SearchResults {
* @param fileSortingMethod The method that should be used to
* sortGroupsAndFiles the files in each group.
*/
SearchResults(FileGroup.GroupSortingAlgorithm groupSortingType, FileSearch.AttributeType attrType,
SearchResults(Group.GroupSortingAlgorithm groupSortingType, FileSearch.AttributeType attrType,
FileSorter.SortingMethod fileSortingMethod) {
this.groupSortingType = groupSortingType;
this.attrType = attrType;
@@ -62,7 +62,7 @@ class SearchResults {
* the search is finished.
*/
SearchResults() {
this.groupSortingType = FileGroup.GroupSortingAlgorithm.BY_GROUP_NAME;
this.groupSortingType = Group.GroupSortingAlgorithm.BY_GROUP_NAME;
this.attrType = new FileSearch.FileSizeAttribute();
this.fileSorter = new FileSorter(FileSorter.SortingMethod.BY_FILE_NAME);
}
@@ -78,7 +78,7 @@ class SearchResults {
GroupKey groupKey = attrType.getGroupKey(file);
if (!groupMap.containsKey(groupKey)) {
groupMap.put(groupKey, new FileGroup(groupSortingType, groupKey));
groupMap.put(groupKey, new Group(groupSortingType, groupKey));
}
groupMap.get(groupKey).addFile(file);
}
@@ -91,7 +91,7 @@ class SearchResults {
void sortGroupsAndFiles() {
// First sortGroupsAndFiles the files
for (FileGroup group : groupMap.values()) {
for (Group group : groupMap.values()) {
group.sortFiles(fileSorter);
}
@@ -108,7 +108,7 @@ class SearchResults {
}
long count = 0;
for (FileGroup group : groupList) {
for (Group group : groupList) {
result += group.getDisplayName() + "\n";
for (ResultFile file : group.getFiles()) {
@@ -143,7 +143,7 @@ class SearchResults {
if (groupName != null) {
final String modifiedGroupName = groupName.replaceAll(" \\([0-9]+\\)$", "");
java.util.Optional<FileGroup> fileGroup = groupList.stream().filter(p -> p.getDisplayName().equals(modifiedGroupName)).findFirst();
java.util.Optional<Group> fileGroup = groupList.stream().filter(p -> p.getDisplayName().equals(modifiedGroupName)).findFirst();
if (fileGroup.isPresent()) {
return fileGroup.get().getFiles();
}
@@ -156,14 +156,14 @@ class SearchResults {
*
* @return The grouped and sorted results.
*/
Map<GroupKey, List<ResultFile>> toLinkedHashMap() throws FileSearchException {
Map<GroupKey, List<ResultFile>> toLinkedHashMap() throws DiscoveryException {
Map<GroupKey, List<ResultFile>> map = new LinkedHashMap<>();
// Sort the groups and files
sortGroupsAndFiles();
// groupList is sorted and a LinkedHashMap will preserve that order.
for (FileGroup group : groupList) {
for (Group group : groupList) {
map.put(group.getGroupKey(), group.getFiles());
}
@@ -32,8 +32,6 @@ import javax.swing.JSplitPane;
import javax.swing.event.ListSelectionEvent;
import javax.swing.event.ListSelectionListener;
import org.apache.commons.lang3.StringUtils;
import org.sleuthkit.autopsy.discovery.search.AttributeSearchData;
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
import org.sleuthkit.autopsy.discovery.search.SearchData;
import org.sleuthkit.autopsy.discovery.search.SearchFiltering;
@@ -67,25 +65,11 @@ abstract class AbstractFiltersPanel extends JPanel implements ActionListener, Li
}
/**
* Get the broad ResultType, such as files or attributes.
* Get the type of results this filters panel is for.
*
* @return
* @return The type of results this panel filters.
*/
abstract SearchData.ResultType getResultType();
/**
* Get the file type of results this filters panel is for.
*
* @return The file type of results this panel filters.
*/
abstract FileSearchData.FileType getFileType();
/**
* Get the attribute type of results this filters panel is for.
*
* @return The attribute type of results this panel filters.
*/
abstract AttributeSearchData.AttributeType getArtifactType();
abstract SearchData.Type getType();
/**
* Add a DiscoveryFilterPanel to the specified column with the specified
@@ -264,10 +248,10 @@ abstract class AbstractFiltersPanel extends JPanel implements ActionListener, Li
synchronized List<AbstractFilter> getFilters() {
List<AbstractFilter> filtersToUse = new ArrayList<>();
if (getResultType().equals(SearchData.ResultType.FILE)) {
filtersToUse.add(new SearchFiltering.FileTypeFilter(getFileType()));
} else if (getResultType().equals(SearchData.ResultType.ATTRIBUTE)) {
if (getType().equals(SearchData.Type.DOMAIN)) {
} else {
filtersToUse.add(new SearchFiltering.FileTypeFilter(getType()));
}
for (AbstractDiscoveryFilterPanel filterPanel : filters) {
@@ -23,7 +23,7 @@ import javax.swing.DefaultListModel;
import javax.swing.JCheckBox;
import javax.swing.JLabel;
import javax.swing.JList;
import org.sleuthkit.autopsy.discovery.search.AttributeSearchData;
import org.sleuthkit.autopsy.discovery.search.SearchData;
import org.sleuthkit.datamodel.BlackboardArtifact;
/**
@@ -49,7 +49,7 @@ class ArtifactTypeFilterPanel extends AbstractDiscoveryFilterPanel {
int count = 0;
DefaultListModel<ArtifactTypeItem> artifactTypeModel = (DefaultListModel<ArtifactTypeItem>) jList1.getModel();
artifactTypeModel.removeAllElements();
for (BlackboardArtifact.ARTIFACT_TYPE artifactType : AttributeSearchData.AttributeType.DOMAIN.getBlackboardTypes()) {
for (BlackboardArtifact.ARTIFACT_TYPE artifactType : SearchData.Type.DOMAIN.getArtifactTypes()) {
artifactTypeModel.add(count, new ArtifactTypeItem(artifactType));
count++;
}
@@ -37,15 +37,13 @@ import org.sleuthkit.autopsy.casemodule.NoCurrentCaseException;
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepoException;
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
import org.sleuthkit.autopsy.coreutils.Logger;
import org.sleuthkit.autopsy.discovery.search.AttributeSearchData;
import org.sleuthkit.autopsy.discovery.search.DiscoveryEventUtils;
import org.sleuthkit.autopsy.discovery.search.FileGroup;
import org.sleuthkit.autopsy.discovery.search.FileGroup.GroupSortingAlgorithm;
import static org.sleuthkit.autopsy.discovery.search.FileGroup.GroupSortingAlgorithm.BY_GROUP_SIZE;
import org.sleuthkit.autopsy.discovery.search.Group;
import org.sleuthkit.autopsy.discovery.search.Group.GroupSortingAlgorithm;
import static org.sleuthkit.autopsy.discovery.search.Group.GroupSortingAlgorithm.BY_GROUP_SIZE;
import org.sleuthkit.autopsy.discovery.search.FileSearch;
import org.sleuthkit.autopsy.discovery.search.FileSearch.GroupingAttributeType;
import static org.sleuthkit.autopsy.discovery.search.FileSearch.GroupingAttributeType.PARENT_PATH;
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
import org.sleuthkit.autopsy.discovery.search.FileSorter;
import org.sleuthkit.autopsy.discovery.search.FileSorter.SortingMethod;
import static org.sleuthkit.autopsy.discovery.search.FileSorter.SortingMethod.BY_FILE_NAME;
@@ -76,9 +74,7 @@ final class DiscoveryDialog extends javax.swing.JDialog {
private SearchWorker searchWorker = null;
private static DiscoveryDialog discDialog;
private static volatile boolean shouldUpdate = false;
private SearchData.ResultType resultType = SearchData.ResultType.FILE;
private FileSearchData.FileType fileType = FileSearchData.FileType.IMAGE;
private AttributeSearchData.AttributeType artifactType = null;
private SearchData.Type type = SearchData.Type.IMAGE;
private final PropertyChangeListener listener;
private final Set<BlackboardAttribute> objectsDetected = new HashSet<>();
private final Set<BlackboardAttribute> interestingItems = new HashSet<>();
@@ -140,9 +136,7 @@ final class DiscoveryDialog extends javax.swing.JDialog {
imagesButton.setEnabled(false);
imagesButton.setBackground(SELECTED_COLOR);
imagesButton.setForeground(Color.BLACK);
resultType = SearchData.ResultType.FILE;
fileType = FileSearchData.FileType.IMAGE;
artifactType = null;
type = SearchData.Type.IMAGE;
add(imageFilterPanel, CENTER);
imageFilterPanel.addPropertyChangeListener(listener);
updateComboBoxes();
@@ -175,8 +169,8 @@ final class DiscoveryDialog extends javax.swing.JDialog {
private void updateComboBoxes() {
groupByCombobox.removeAllItems();
// Set up the grouping attributes
for (FileSearch.GroupingAttributeType type : FileSearch.GroupingAttributeType.getOptionsForGrouping()) {
addTypeToGroupByComboBox(type);
for (FileSearch.GroupingAttributeType groupingType : FileSearch.GroupingAttributeType.getOptionsForGrouping()) {
addTypeToGroupByComboBox(groupingType);
}
groupByCombobox.setSelectedItem(PARENT_PATH);
orderByCombobox.removeAllItems();
@@ -223,25 +217,11 @@ final class DiscoveryDialog extends javax.swing.JDialog {
groupByCombobox.addItem(type);
}
/**
* Validate the current filter settings of the selected type.
*/
synchronized void validateDialog() {
switch (resultType) {
case FILE:
validateFileDialog();
break;
case ATTRIBUTE:
validateArtifactDialog();
break;
}
}
/**
* Validate the filter settings for File type filters.
*/
private synchronized void validateFileDialog() {
switch (fileType) {
synchronized void validateDialog() {
switch (type) {
case IMAGE:
if (imageFilterPanel != null) {
imageFilterPanel.validateFields();
@@ -257,16 +237,6 @@ final class DiscoveryDialog extends javax.swing.JDialog {
documentFilterPanel.validateFields();
}
break;
default:
break;
}
}
/**
* Validate the filter settings for Artifact type filters.
*/
private synchronized void validateArtifactDialog() {
switch (artifactType) {
case DOMAIN:
if (domainFilterPanel != null) {
domainFilterPanel.validateFields();
@@ -497,9 +467,7 @@ final class DiscoveryDialog extends javax.swing.JDialog {
imagesButton.setEnabled(false);
imagesButton.setBackground(SELECTED_COLOR);
imagesButton.setForeground(Color.BLACK);
resultType = SearchData.ResultType.FILE;
artifactType = null;
fileType = FileSearchData.FileType.IMAGE;
type = SearchData.Type.IMAGE;
imageFilterPanel.addPropertyChangeListener(listener);
validateDialog();
pack();
@@ -515,9 +483,7 @@ final class DiscoveryDialog extends javax.swing.JDialog {
videosButton.setBackground(SELECTED_COLOR);
videosButton.setForeground(Color.BLACK);
videoFilterPanel.addPropertyChangeListener(listener);
resultType = SearchData.ResultType.FILE;
artifactType = null;
fileType = FileSearchData.FileType.VIDEO;
type = SearchData.Type.VIDEO;
validateDialog();
pack();
repaint();
@@ -531,9 +497,7 @@ final class DiscoveryDialog extends javax.swing.JDialog {
documentsButton.setEnabled(false);
documentsButton.setBackground(SELECTED_COLOR);
documentsButton.setForeground(Color.BLACK);
resultType = SearchData.ResultType.FILE;
artifactType = null;
fileType = FileSearchData.FileType.DOCUMENTS;
type = SearchData.Type.DOCUMENTS;
documentFilterPanel.addPropertyChangeListener(listener);
validateDialog();
pack();
@@ -587,11 +551,11 @@ final class DiscoveryDialog extends javax.swing.JDialog {
filters = new ArrayList<>();
}
DiscoveryEventUtils.getDiscoveryEventBus().post(new DiscoveryEventUtils.SearchStartedEvent(resultType, fileType, artifactType));
DiscoveryEventUtils.getDiscoveryEventBus().post(new DiscoveryEventUtils.SearchStartedEvent(type));
// Get the grouping attribute and group sorting method
FileSearch.AttributeType groupingAttr = groupByCombobox.getItemAt(groupByCombobox.getSelectedIndex()).getAttributeType();
FileGroup.GroupSortingAlgorithm groupSortAlgorithm = groupSortingComboBox.getItemAt(groupSortingComboBox.getSelectedIndex());
Group.GroupSortingAlgorithm groupSortAlgorithm = groupSortingComboBox.getItemAt(groupSortingComboBox.getSelectedIndex());
// Get the file sorting method
FileSorter.SortingMethod fileSort = (FileSorter.SortingMethod) orderByCombobox.getSelectedItem();
@@ -619,9 +583,7 @@ final class DiscoveryDialog extends javax.swing.JDialog {
domainsButton.setEnabled(false);
domainsButton.setBackground(SELECTED_COLOR);
domainsButton.setForeground(Color.BLACK);
resultType = SearchData.ResultType.ATTRIBUTE;
artifactType = AttributeSearchData.AttributeType.DOMAIN;
fileType = null;
type = SearchData.Type.DOMAIN;
documentFilterPanel.addPropertyChangeListener(listener);
validateDialog();
pack();
@@ -38,7 +38,6 @@ import org.openide.windows.TopComponent;
import org.openide.windows.WindowManager;
import org.sleuthkit.autopsy.coreutils.ThreadConfined;
import org.sleuthkit.autopsy.discovery.search.DiscoveryEventUtils;
import org.sleuthkit.autopsy.discovery.search.SearchData.ResultType;
/**
* Create a dialog for displaying the Discovery results.
@@ -286,13 +285,7 @@ public final class DiscoveryTopComponent extends TopComponent {
void handleSearchStartedEvent(DiscoveryEventUtils.SearchStartedEvent searchStartedEvent) {
newSearchButton.setText(Bundle.DiscoveryTopComponent_cancelButton_text());
progressMessageTextArea.setForeground(Color.red);
String text = Bundle.DiscoveryTopComponent_searchError_text();
if (searchStartedEvent.getResultType() == ResultType.FILE) {
text = Bundle.DiscoveryTopComponent_searchInProgress_text(searchStartedEvent.getFileType().name());
} else if (searchStartedEvent.getResultType() == ResultType.ATTRIBUTE) {
text = Bundle.DiscoveryTopComponent_searchInProgress_text(searchStartedEvent.getAttributeType().name());
}
progressMessageTextArea.setText(text);
progressMessageTextArea.setText(Bundle.DiscoveryTopComponent_searchInProgress_text(searchStartedEvent.getType().name()));
}
/**
@@ -19,8 +19,6 @@
package org.sleuthkit.autopsy.discovery.ui;
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
import org.sleuthkit.autopsy.discovery.search.AttributeSearchData;
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
import org.sleuthkit.autopsy.discovery.search.SearchData;
/**
@@ -29,7 +27,7 @@ import org.sleuthkit.autopsy.discovery.search.SearchData;
final class DocumentFilterPanel extends AbstractFiltersPanel {
private static final long serialVersionUID = 1L;
private static final FileSearchData.FileType FILE_TYPE = FileSearchData.FileType.DOCUMENTS;
private static final SearchData.Type TYPE = SearchData.Type.DOCUMENTS;
/**
* Constructs a new DocumentFilterPanel.
@@ -37,7 +35,7 @@ final class DocumentFilterPanel extends AbstractFiltersPanel {
DocumentFilterPanel() {
super();
initComponents();
SizeFilterPanel sizeFilterPanel = new SizeFilterPanel(FILE_TYPE);
SizeFilterPanel sizeFilterPanel = new SizeFilterPanel(TYPE);
int[] sizeIndicesSelected = {3, 4, 5};
addFilter(sizeFilterPanel, true, sizeIndicesSelected, 0);
addFilter(new DataSourceFilterPanel(), false, null, 0);
@@ -47,7 +45,7 @@ final class DocumentFilterPanel extends AbstractFiltersPanel {
} else {
pastOccurrencesIndices = new int[]{2, 3, 4};
}
addFilter(new PastOccurrencesFilterPanel(), true, pastOccurrencesIndices, 0);
addFilter(new PastOccurrencesFilterPanel(TYPE), true, pastOccurrencesIndices, 0);
addFilter(new HashSetFilterPanel(), false, null, 1);
addFilter(new InterestingItemsFilterPanel(), false, null, 1);
addFilter(new ParentFolderFilterPanel(), false, null, 1);
@@ -94,21 +92,11 @@ final class DocumentFilterPanel extends AbstractFiltersPanel {
add(documentFiltersScrollPane, java.awt.BorderLayout.CENTER);
}// </editor-fold>//GEN-END:initComponents
@Override
FileSearchData.FileType getFileType() {
return FILE_TYPE;
SearchData.Type getType() {
return TYPE;
}
// Variables declaration - do not modify//GEN-BEGIN:variables
private javax.swing.JSplitPane documentsFiltersSplitPane;
// End of variables declaration//GEN-END:variables
@Override
SearchData.ResultType getResultType() {
return SearchData.ResultType.FILE;
}
@Override
AttributeSearchData.AttributeType getArtifactType() {
throw new UnsupportedOperationException("Not supported yet."); //To change body of generated methods, choose Tools | Templates.
}
}
@@ -29,7 +29,7 @@ import javax.swing.JList;
import javax.swing.ListCellRenderer;
import org.openide.util.NbBundle.Messages;
import org.sleuthkit.autopsy.corecomponents.AutoWrappingJTextPane;
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
import org.sleuthkit.autopsy.discovery.search.SearchData;
/**
* Class which displays a preview and details about a document.
@@ -164,7 +164,7 @@ class DocumentPanel extends javax.swing.JPanel implements ListCellRenderer<Docum
if (value.getSummary().getNumberOfImages() > 0) {
numberOfImagesLabel.setText(Bundle.DocumentPanel_numberOfImages_text(value.getSummary().getNumberOfImages()));
sampleImageLabel.setIcon(new ImageIcon(value.getSummary().getSampleImage()));
} else if (FileSearchData.getDocTypesWithoutImageExtraction().contains(value.getResultFile().getFirstInstance().getMIMEType())) {
} else if (SearchData.getDocTypesWithoutImageExtraction().contains(value.getResultFile().getFirstInstance().getMIMEType())) {
numberOfImagesLabel.setText(Bundle.DocumentPanel_noImageExtraction_text());
sampleImageLabel.setIcon(DiscoveryUiUtils.getUnsupportedImageThumbnail());
} else {
@@ -19,8 +19,6 @@
package org.sleuthkit.autopsy.discovery.ui;
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
import org.sleuthkit.autopsy.discovery.search.AttributeSearchData;
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
import org.sleuthkit.autopsy.discovery.search.SearchData;
/**
@@ -29,7 +27,7 @@ import org.sleuthkit.autopsy.discovery.search.SearchData;
public class DomainFilterPanel extends AbstractFiltersPanel {
private static final long serialVersionUID = 1L;
private static final AttributeSearchData.AttributeType ARTIFACT_TYPE = AttributeSearchData.AttributeType.DOMAIN;
private static final SearchData.Type TYPE = SearchData.Type.DOMAIN;
/**
* Creates new form DomainFilterPanel.
@@ -44,7 +42,7 @@ public class DomainFilterPanel extends AbstractFiltersPanel {
if (CentralRepository.isEnabled()) {
pastOccurrencesIndices = new int[]{2, 3, 4};
}
addFilter(new PastOccurrencesFilterPanel(SearchData.ResultType.ATTRIBUTE), true, pastOccurrencesIndices, 0);
addFilter(new PastOccurrencesFilterPanel(TYPE), true, pastOccurrencesIndices, 0);
addPanelsToScrollPane(domainFiltersSplitPane);
}
@@ -91,19 +89,10 @@ public class DomainFilterPanel extends AbstractFiltersPanel {
}// </editor-fold>//GEN-END:initComponents
@Override
FileSearchData.FileType getFileType() {
throw new UnsupportedOperationException("Not supported yet."); //To change body of generated methods, choose Tools | Templates.
SearchData.Type getType() {
return TYPE;
}
@Override
SearchData.ResultType getResultType() {
return SearchData.ResultType.ATTRIBUTE;
}
@Override
AttributeSearchData.AttributeType getArtifactType() {
return ARTIFACT_TYPE;
}
// Variables declaration - do not modify//GEN-BEGIN:variables
@@ -31,9 +31,9 @@ import javax.swing.SwingUtilities;
import org.openide.util.NbBundle.Messages;
import org.sleuthkit.autopsy.discovery.search.DiscoveryEventUtils;
import org.sleuthkit.autopsy.discovery.search.DiscoveryKeyUtils.GroupKey;
import org.sleuthkit.autopsy.discovery.search.FileGroup;
import org.sleuthkit.autopsy.discovery.search.Group;
import org.sleuthkit.autopsy.discovery.search.FileSearch;
import org.sleuthkit.autopsy.discovery.search.FileSearchData.FileType;
import org.sleuthkit.autopsy.discovery.search.SearchData.Type;
import org.sleuthkit.autopsy.discovery.search.FileSorter;
/**
@@ -42,11 +42,11 @@ import org.sleuthkit.autopsy.discovery.search.FileSorter;
final class GroupListPanel extends javax.swing.JPanel {
private static final long serialVersionUID = 1L;
private FileType fileType = null;
private Type type = null;
private Map<GroupKey, Integer> groupMap = null;
private List<AbstractFilter> searchfilters;
private FileSearch.AttributeType groupingAttribute;
private FileGroup.GroupSortingAlgorithm groupSort;
private Group.GroupSortingAlgorithm groupSort;
private FileSorter.SortingMethod fileSortMethod;
private GroupKey selectedGroupKey;
@@ -64,7 +64,7 @@ final class GroupListPanel extends javax.swing.JPanel {
*/
@Subscribe
void handleSearchStartedEvent(DiscoveryEventUtils.SearchStartedEvent searchStartedEvent) {
fileType = searchStartedEvent.getFileType();
type = searchStartedEvent.getType();
groupKeyList.setListData(new GroupKey[0]);
}
@@ -175,7 +175,7 @@ final class GroupListPanel extends javax.swing.JPanel {
if (selectedGroup.equals(groupKey)) {
selectedGroupKey = groupKey;
DiscoveryEventUtils.getDiscoveryEventBus().post(new DiscoveryEventUtils.GroupSelectedEvent(
searchfilters, groupingAttribute, groupSort, fileSortMethod, selectedGroupKey, groupMap.get(selectedGroupKey), fileType));
searchfilters, groupingAttribute, groupSort, fileSortMethod, selectedGroupKey, groupMap.get(selectedGroupKey), type));
break;
}
}
@@ -19,8 +19,6 @@
package org.sleuthkit.autopsy.discovery.ui;
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
import org.sleuthkit.autopsy.discovery.search.AttributeSearchData;
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
import org.sleuthkit.autopsy.discovery.search.SearchData;
/**
@@ -29,7 +27,7 @@ import org.sleuthkit.autopsy.discovery.search.SearchData;
final class ImageFilterPanel extends AbstractFiltersPanel {
private static final long serialVersionUID = 1L;
private static final FileSearchData.FileType FILE_TYPE = FileSearchData.FileType.IMAGE;
private static final SearchData.Type TYPE = SearchData.Type.IMAGE;
/**
* Creates new form ImageFilterPanel.
@@ -37,7 +35,7 @@ final class ImageFilterPanel extends AbstractFiltersPanel {
ImageFilterPanel() {
super();
initComponents();
SizeFilterPanel sizeFilterPanel = new SizeFilterPanel(FILE_TYPE);
SizeFilterPanel sizeFilterPanel = new SizeFilterPanel(TYPE);
int[] sizeIndicesSelected = {3, 4, 5};
addFilter(sizeFilterPanel, true, sizeIndicesSelected, 0);
addFilter(new DataSourceFilterPanel(), false, null, 0);
@@ -47,7 +45,7 @@ final class ImageFilterPanel extends AbstractFiltersPanel {
} else {
pastOccurrencesIndices = new int[]{2, 3, 4};
}
addFilter(new PastOccurrencesFilterPanel(), true, pastOccurrencesIndices, 0);
addFilter(new PastOccurrencesFilterPanel(TYPE), true, pastOccurrencesIndices, 0);
addFilter(new UserCreatedFilterPanel(), false, null, 1);
addFilter(new HashSetFilterPanel(), false, null, 1);
addFilter(new InterestingItemsFilterPanel(), false, null, 1);
@@ -99,21 +97,12 @@ final class ImageFilterPanel extends AbstractFiltersPanel {
}// </editor-fold>//GEN-END:initComponents
@Override
FileSearchData.FileType getFileType() {
return FILE_TYPE;
SearchData.Type getType() {
return TYPE;
}
// Variables declaration - do not modify//GEN-BEGIN:variables
private javax.swing.JSplitPane imageFiltersSplitPane;
// End of variables declaration//GEN-END:variables
@Override
SearchData.ResultType getResultType() {
return SearchData.ResultType.FILE;
}
@Override
AttributeSearchData.AttributeType getArtifactType() {
throw new UnsupportedOperationException("Not supported yet."); //To change body of generated methods, choose Tools | Templates.
}
}
@@ -28,10 +28,10 @@ import org.sleuthkit.autopsy.coreutils.Logger;
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
import org.sleuthkit.autopsy.discovery.search.DiscoveryEventUtils;
import org.sleuthkit.autopsy.discovery.search.DiscoveryKeyUtils.GroupKey;
import org.sleuthkit.autopsy.discovery.search.FileGroup;
import org.sleuthkit.autopsy.discovery.search.Group;
import org.sleuthkit.autopsy.discovery.search.FileSearch;
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
import org.sleuthkit.autopsy.discovery.search.FileSearchException;
import org.sleuthkit.autopsy.discovery.search.SearchData;
import org.sleuthkit.autopsy.discovery.search.DiscoveryException;
import org.sleuthkit.autopsy.discovery.search.FileSorter;
import org.sleuthkit.autopsy.discovery.search.ResultFile;
@@ -44,12 +44,12 @@ final class PageWorker extends SwingWorker<Void, Void> {
private static final String USER_NAME_PROPERTY = "user.name"; //NON-NLS
private final List<AbstractFilter> searchfilters;
private final FileSearch.AttributeType groupingAttribute;
private final FileGroup.GroupSortingAlgorithm groupSort;
private final Group.GroupSortingAlgorithm groupSort;
private final FileSorter.SortingMethod fileSortMethod;
private final GroupKey groupKey;
private final int startingEntry;
private final int pageSize;
private final FileSearchData.FileType resultType;
private final SearchData.Type resultType;
private final CentralRepository centralRepo;
private final List<ResultFile> results = new ArrayList<>();
@@ -70,8 +70,8 @@ final class PageWorker extends SwingWorker<Void, Void> {
* @param centralRepo The central repository to be used.
*/
PageWorker(List<AbstractFilter> searchfilters, FileSearch.AttributeType groupingAttribute,
FileGroup.GroupSortingAlgorithm groupSort, FileSorter.SortingMethod fileSortMethod, GroupKey groupKey,
int startingEntry, int pageSize, FileSearchData.FileType resultType, CentralRepository centralRepo) {
Group.GroupSortingAlgorithm groupSort, FileSorter.SortingMethod fileSortMethod, GroupKey groupKey,
int startingEntry, int pageSize, SearchData.Type resultType, CentralRepository centralRepo) {
this.searchfilters = searchfilters;
this.groupingAttribute = groupingAttribute;
this.groupSort = groupSort;
@@ -93,7 +93,7 @@ final class PageWorker extends SwingWorker<Void, Void> {
groupSort,
fileSortMethod, groupKey, startingEntry, pageSize,
Case.getCurrentCase().getSleuthkitCase(), centralRepo));
} catch (FileSearchException ex) {
} catch (DiscoveryException ex) {
logger.log(Level.SEVERE, "Error running file search test", ex);
cancel(true);
}
@@ -24,9 +24,9 @@ import javax.swing.JLabel;
import javax.swing.JList;
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
import org.sleuthkit.autopsy.discovery.search.AbstractFilter;
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
import org.sleuthkit.autopsy.discovery.search.FileSearchData.Frequency;
import org.sleuthkit.autopsy.discovery.search.SearchData.ResultType;
import org.sleuthkit.autopsy.discovery.search.SearchData;
import org.sleuthkit.autopsy.discovery.search.SearchData.Frequency;
import org.sleuthkit.autopsy.discovery.search.SearchData.Type;
import org.sleuthkit.autopsy.discovery.search.SearchFiltering;
/**
@@ -35,21 +35,12 @@ import org.sleuthkit.autopsy.discovery.search.SearchFiltering;
final class PastOccurrencesFilterPanel extends AbstractDiscoveryFilterPanel {
private static final long serialVersionUID = 1L;
private final ResultType type;
private final Type type;
/**
* Creates new form PastOccurrencesFilterPanel.
*/
PastOccurrencesFilterPanel() {
initComponents();
type = ResultType.FILE;
setUpFrequencyFilter();
}
/**
* Creates new form PastOccurrencesFilterPanel.
*/
PastOccurrencesFilterPanel(ResultType type) {
PastOccurrencesFilterPanel(Type type) {
initComponents();
this.type = type;
setUpFrequencyFilter();
@@ -111,17 +102,17 @@ final class PastOccurrencesFilterPanel extends AbstractDiscoveryFilterPanel {
*/
private void setUpFrequencyFilter() {
int count = 0;
DefaultListModel<FileSearchData.Frequency> frequencyListModel = (DefaultListModel<FileSearchData.Frequency>) crFrequencyList.getModel();
DefaultListModel<SearchData.Frequency> frequencyListModel = (DefaultListModel<SearchData.Frequency>) crFrequencyList.getModel();
frequencyListModel.removeAllElements();
if (!CentralRepository.isEnabled()) {
if (type != ResultType.ATTRIBUTE) {
for (FileSearchData.Frequency freq : FileSearchData.Frequency.getOptionsForFilteringWithoutCr()) {
if (type != Type.DOMAIN) {
for (SearchData.Frequency freq : SearchData.Frequency.getOptionsForFilteringWithoutCr()) {
frequencyListModel.add(count, freq);
}
}
} else {
for (FileSearchData.Frequency freq : FileSearchData.Frequency.getOptionsForFilteringWithCr()) {
if (type == ResultType.FILE || freq != FileSearchData.Frequency.KNOWN) {
for (SearchData.Frequency freq : SearchData.Frequency.getOptionsForFilteringWithCr()) {
if (type != Type.DOMAIN || freq != SearchData.Frequency.KNOWN) {
frequencyListModel.add(count, freq);
}
}
@@ -136,7 +127,7 @@ final class PastOccurrencesFilterPanel extends AbstractDiscoveryFilterPanel {
@Override
void configurePanel(boolean selected, int[] indicesSelected) {
boolean canBeFilteredOn = type == ResultType.FILE || CentralRepository.isEnabled();
boolean canBeFilteredOn = type != Type.DOMAIN || CentralRepository.isEnabled();
pastOccurrencesCheckbox.setEnabled(canBeFilteredOn);
pastOccurrencesCheckbox.setSelected(selected && canBeFilteredOn);
@@ -40,9 +40,9 @@ import org.sleuthkit.datamodel.AbstractFile;
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
import org.sleuthkit.autopsy.discovery.search.DiscoveryEventUtils;
import org.sleuthkit.autopsy.discovery.search.DiscoveryKeyUtils.GroupKey;
import org.sleuthkit.autopsy.discovery.search.FileGroup;
import org.sleuthkit.autopsy.discovery.search.Group;
import org.sleuthkit.autopsy.discovery.search.FileSearch;
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
import org.sleuthkit.autopsy.discovery.search.SearchData;
import org.sleuthkit.autopsy.discovery.search.FileSorter;
import org.sleuthkit.autopsy.discovery.search.ResultFile;
import org.sleuthkit.autopsy.textsummarizer.TextSummary;
@@ -60,12 +60,12 @@ final class ResultsPanel extends javax.swing.JPanel {
private final DocumentPreviewViewer documentPreviewViewer;
private List<AbstractFilter> searchFilters;
private FileSearch.AttributeType groupingAttribute;
private FileGroup.GroupSortingAlgorithm groupSort;
private Group.GroupSortingAlgorithm groupSort;
private FileSorter.SortingMethod fileSortMethod;
private GroupKey selectedGroupKey;
private int currentPage = 0;
private int previousPageSize = 10;
private FileSearchData.FileType resultType;
private SearchData.Type resultType;
private int groupSize = 0;
private PageWorker pageWorker;
private final List<SwingWorker<Void, Void>> resultContentWorkers = new ArrayList<>();
@@ -81,7 +81,7 @@ final class ResultsPanel extends javax.swing.JPanel {
videoThumbnailViewer = new VideoThumbnailViewer();
documentPreviewViewer = new DocumentPreviewViewer();
videoThumbnailViewer.addListSelectionListener((e) -> {
if (resultType == FileSearchData.FileType.VIDEO) {
if (resultType == SearchData.Type.VIDEO) {
if (!e.getValueIsAdjusting()) {
//send populateMesage
DiscoveryEventUtils.getDiscoveryEventBus().post(new DiscoveryEventUtils.PopulateInstancesListEvent(getInstancesForSelected()));
@@ -92,7 +92,7 @@ final class ResultsPanel extends javax.swing.JPanel {
}
});
imageThumbnailViewer.addListSelectionListener((e) -> {
if (resultType == FileSearchData.FileType.IMAGE) {
if (resultType == SearchData.Type.IMAGE) {
if (!e.getValueIsAdjusting()) {
//send populateMesage
DiscoveryEventUtils.getDiscoveryEventBus().post(new DiscoveryEventUtils.PopulateInstancesListEvent(getInstancesForSelected()));
@@ -104,7 +104,7 @@ final class ResultsPanel extends javax.swing.JPanel {
}
});
documentPreviewViewer.addListSelectionListener((e) -> {
if (resultType == FileSearchData.FileType.DOCUMENTS) {
if (resultType == SearchData.Type.DOCUMENTS) {
if (!e.getValueIsAdjusting()) {
//send populateMesage
DiscoveryEventUtils.getDiscoveryEventBus().post(new DiscoveryEventUtils.PopulateInstancesListEvent(getInstancesForSelected()));
@@ -29,9 +29,9 @@ import org.sleuthkit.autopsy.coreutils.Logger;
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
import org.sleuthkit.autopsy.discovery.search.DiscoveryEventUtils;
import org.sleuthkit.autopsy.discovery.search.DiscoveryKeyUtils.GroupKey;
import org.sleuthkit.autopsy.discovery.search.FileGroup;
import org.sleuthkit.autopsy.discovery.search.Group;
import org.sleuthkit.autopsy.discovery.search.FileSearch;
import org.sleuthkit.autopsy.discovery.search.FileSearchException;
import org.sleuthkit.autopsy.discovery.search.DiscoveryException;
import org.sleuthkit.autopsy.discovery.search.FileSorter;
/**
@@ -44,7 +44,7 @@ final class SearchWorker extends SwingWorker<Void, Void> {
private final List<AbstractFilter> filters;
private final FileSearch.AttributeType groupingAttr;
private final FileSorter.SortingMethod fileSort;
private final FileGroup.GroupSortingAlgorithm groupSortAlgorithm;
private final Group.GroupSortingAlgorithm groupSortAlgorithm;
private final CentralRepository centralRepoDb;
private final Map<GroupKey, Integer> results = new LinkedHashMap<>();
@@ -58,7 +58,7 @@ final class SearchWorker extends SwingWorker<Void, Void> {
* @param groupSort The Algorithm to sort groups by.
* @param fileSortMethod The SortingMethod to use for files.
*/
SearchWorker(CentralRepository centralRepo, List<AbstractFilter> searchfilters, FileSearch.AttributeType groupingAttribute, FileGroup.GroupSortingAlgorithm groupSort, FileSorter.SortingMethod fileSortMethod) {
SearchWorker(CentralRepository centralRepo, List<AbstractFilter> searchfilters, FileSearch.AttributeType groupingAttribute, Group.GroupSortingAlgorithm groupSort, FileSorter.SortingMethod fileSortMethod) {
centralRepoDb = centralRepo;
filters = searchfilters;
groupingAttr = groupingAttribute;
@@ -75,7 +75,7 @@ final class SearchWorker extends SwingWorker<Void, Void> {
groupSortAlgorithm,
fileSort,
Case.getCurrentCase().getSleuthkitCase(), centralRepoDb));
} catch (FileSearchException ex) {
} catch (DiscoveryException ex) {
logger.log(Level.SEVERE, "Error running file search test", ex);
cancel(true);
}
@@ -25,8 +25,8 @@ import javax.swing.DefaultListModel;
import javax.swing.JCheckBox;
import javax.swing.JLabel;
import javax.swing.JList;
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
import org.sleuthkit.autopsy.discovery.search.FileSearchData.FileSize;
import org.sleuthkit.autopsy.discovery.search.SearchData;
import org.sleuthkit.autopsy.discovery.search.SearchData.FileSize;
import org.sleuthkit.autopsy.discovery.search.SearchFiltering;
/**
@@ -41,7 +41,7 @@ final class SizeFilterPanel extends AbstractDiscoveryFilterPanel {
*
* @param type The type of result being searched for.
*/
SizeFilterPanel(FileSearchData.FileType type) {
SizeFilterPanel(SearchData.Type type) {
initComponents();
setUpSizeFilter(type);
}
@@ -136,7 +136,7 @@ final class SizeFilterPanel extends AbstractDiscoveryFilterPanel {
/**
* Initialize the file size filter.
*/
private void setUpSizeFilter(FileSearchData.FileType fileType) {
private void setUpSizeFilter(SearchData.Type fileType) {
int count = 0;
DefaultListModel<FileSize> sizeListModel = (DefaultListModel<FileSize>) sizeList.getModel();
sizeListModel.removeAllElements();
@@ -145,7 +145,7 @@ final class SizeFilterPanel extends AbstractDiscoveryFilterPanel {
sizeListModel.add(count, size);
}
} else {
List<FileSearchData.FileSize> sizes;
List<SearchData.FileSize> sizes;
switch (fileType) {
case VIDEO:
sizes = FileSize.getOptionsForVideos();
@@ -19,8 +19,6 @@
package org.sleuthkit.autopsy.discovery.ui;
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
import org.sleuthkit.autopsy.discovery.search.AttributeSearchData;
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
import org.sleuthkit.autopsy.discovery.search.SearchData;
/**
@@ -29,7 +27,7 @@ import org.sleuthkit.autopsy.discovery.search.SearchData;
final class VideoFilterPanel extends AbstractFiltersPanel {
private static final long serialVersionUID = 1L;
private static final FileSearchData.FileType FILE_TYPE = FileSearchData.FileType.VIDEO;
private static final SearchData.Type TYPE = SearchData.Type.VIDEO;
/**
* Creates new form VideoFilterPanel.
@@ -37,7 +35,7 @@ final class VideoFilterPanel extends AbstractFiltersPanel {
VideoFilterPanel() {
super();
initComponents();
SizeFilterPanel sizeFilterPanel = new SizeFilterPanel(FILE_TYPE);
SizeFilterPanel sizeFilterPanel = new SizeFilterPanel(TYPE);
int[] sizeIndicesSelected = {3, 4, 5};
addFilter(sizeFilterPanel, true, sizeIndicesSelected, 0);
addFilter(new DataSourceFilterPanel(), false, null, 0);
@@ -47,7 +45,7 @@ final class VideoFilterPanel extends AbstractFiltersPanel {
} else {
pastOccurrencesIndices = new int[]{2, 3, 4};
}
addFilter(new PastOccurrencesFilterPanel(), true, pastOccurrencesIndices, 0);
addFilter(new PastOccurrencesFilterPanel(TYPE), true, pastOccurrencesIndices, 0);
addFilter(new UserCreatedFilterPanel(), false, null, 1);
addFilter(new HashSetFilterPanel(), false, null, 1);
addFilter(new InterestingItemsFilterPanel(), false, null, 1);
@@ -100,22 +98,12 @@ final class VideoFilterPanel extends AbstractFiltersPanel {
add(videoFiltersScrollPane, java.awt.BorderLayout.CENTER);
}// </editor-fold>//GEN-END:initComponents
@Override
FileSearchData.FileType getFileType() {
return FILE_TYPE;
SearchData.Type getType() {
return TYPE;
}
// Variables declaration - do not modify//GEN-BEGIN:variables
private javax.swing.JSplitPane videoFiltersSplitPane;
// End of variables declaration//GEN-END:variables
@Override
SearchData.ResultType getResultType() {
return SearchData.ResultType.FILE;
}
@Override
AttributeSearchData.AttributeType getArtifactType() {
throw new UnsupportedOperationException("Not supported yet."); //To change body of generated methods, choose Tools | Templates.
}
}