mirror of
https://github.com/elisspace/autopsy.git
synced 2026-10-06 01:06:20 +00:00
6711 initial commit for more general data model refactor
This commit is contained in:
@@ -59,10 +59,10 @@ public abstract class AbstractFilter {
|
||||
* @return The list of results that match this filter (and any that came
|
||||
* before it)
|
||||
*
|
||||
* @throws FileSearchException
|
||||
* @throws DiscoveryException
|
||||
*/
|
||||
public List<ResultFile> applyAlternateFilter(List<ResultFile> currentResults, SleuthkitCase caseDb,
|
||||
CentralRepository centralRepoDb) throws FileSearchException {
|
||||
CentralRepository centralRepoDb) throws DiscoveryException {
|
||||
return new ArrayList<>();
|
||||
}
|
||||
|
||||
|
||||
@@ -1,96 +0,0 @@
|
||||
/*
|
||||
* Autopsy
|
||||
*
|
||||
* Copyright 2020 Basis Technology Corp.
|
||||
* Contact: carrier <at> sleuthkit <dot> org
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
package org.sleuthkit.autopsy.discovery.search;
|
||||
|
||||
import java.util.Collection;
|
||||
import java.util.Collections;
|
||||
import java.util.EnumSet;
|
||||
import java.util.HashSet;
|
||||
import java.util.Set;
|
||||
import org.openide.util.NbBundle;
|
||||
import org.sleuthkit.datamodel.BlackboardArtifact;
|
||||
|
||||
/**
|
||||
* Utility enums for searches made for attributes with Discovery.
|
||||
*/
|
||||
public class AttributeSearchData implements SearchData {
|
||||
|
||||
private static final Set<BlackboardArtifact.ARTIFACT_TYPE> DOMAIN_ARTIFACT_TYPES = EnumSet.of(BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_BOOKMARK, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_CACHE, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_COOKIE, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_DOWNLOAD, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_HISTORY, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_SEARCH_QUERY, BlackboardArtifact.ARTIFACT_TYPE.TSK_EMAIL_MSG);
|
||||
|
||||
@Override
|
||||
public ResultType getResultType() {
|
||||
return ResultType.ATTRIBUTE;
|
||||
}
|
||||
|
||||
/**
|
||||
* Enum representing the attribute type.
|
||||
*/
|
||||
@NbBundle.Messages({
|
||||
"AttributeSearchData.AttributeType.Domain.displayName=Domain",
|
||||
"AttributeSearchData.AttributeType.Other.displayName=Other"})
|
||||
public enum AttributeType {
|
||||
|
||||
DOMAIN(0, Bundle.AttributeSearchData_AttributeType_Domain_displayName(), DOMAIN_ARTIFACT_TYPES),
|
||||
OTHER(1, Bundle.AttributeSearchData_AttributeType_Other_displayName(), new HashSet<>());
|
||||
|
||||
private final int ranking; // For ordering in the UI
|
||||
private final String displayName;
|
||||
private final Set<BlackboardArtifact.ARTIFACT_TYPE> artifactTypes = new HashSet<>();
|
||||
|
||||
AttributeType(int value, String displayName, Set<BlackboardArtifact.ARTIFACT_TYPE> types) {
|
||||
this.ranking = value;
|
||||
this.displayName = displayName;
|
||||
this.artifactTypes.addAll(types);
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the BlackboardArtifact types matching this category.
|
||||
*
|
||||
* @return Collection of BlackboardArtifact types.
|
||||
*/
|
||||
public Collection<BlackboardArtifact.ARTIFACT_TYPE> getBlackboardTypes() {
|
||||
return Collections.unmodifiableCollection(artifactTypes);
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return displayName;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the rank for sorting.
|
||||
*
|
||||
* @return the rank (lower should be displayed first)
|
||||
*/
|
||||
public int getRanking() {
|
||||
return ranking;
|
||||
}
|
||||
|
||||
public static AttributeType fromBlackboardArtifact(final BlackboardArtifact.ARTIFACT_TYPE type) {
|
||||
switch (type) {
|
||||
case TSK_WEB_BOOKMARK:
|
||||
return DOMAIN;
|
||||
default:
|
||||
return OTHER;
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
}
|
||||
@@ -22,10 +22,8 @@ import com.google.common.eventbus.EventBus;
|
||||
import java.util.Collections;
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
import org.sleuthkit.autopsy.discovery.search.AttributeSearchData.AttributeType;
|
||||
import org.sleuthkit.autopsy.discovery.search.DiscoveryKeyUtils.GroupKey;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData.FileType;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData.ResultType;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData.Type;
|
||||
import org.sleuthkit.datamodel.AbstractFile;
|
||||
|
||||
/**
|
||||
@@ -56,47 +54,27 @@ public final class DiscoveryEventUtils {
|
||||
*/
|
||||
public static final class SearchStartedEvent {
|
||||
|
||||
private final ResultType resultType;
|
||||
private final FileType fileType;
|
||||
private final AttributeType attributeType;
|
||||
private final Type type;
|
||||
|
||||
/**
|
||||
* Construct a new SearchStartedEvent
|
||||
*
|
||||
* @param type The type of file the search event is for.
|
||||
*/
|
||||
public SearchStartedEvent(ResultType resultType, FileType fileType, AttributeType attributeType) {
|
||||
this.resultType = resultType;
|
||||
this.fileType = fileType;
|
||||
this.attributeType = attributeType;
|
||||
public SearchStartedEvent(Type type) {
|
||||
this.type = type;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the broad search type.
|
||||
*
|
||||
* @return The result type, either FILES, or ATTRIBUTES.
|
||||
*/
|
||||
public ResultType getResultType() {
|
||||
return resultType;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the type of file the search is being performed for.
|
||||
*
|
||||
* @return The type of files being searched for.
|
||||
*/
|
||||
public FileType getFileType() {
|
||||
return fileType;
|
||||
public Type getType() {
|
||||
return type;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the type of attribute the search is being performed for.
|
||||
*
|
||||
* @return The type of attribute being searched for.
|
||||
*/
|
||||
public AttributeType getAttributeType() {
|
||||
return attributeType;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -142,7 +120,7 @@ public final class DiscoveryEventUtils {
|
||||
private final Map<GroupKey, Integer> groupMap;
|
||||
private final List<AbstractFilter> searchFilters;
|
||||
private final FileSearch.AttributeType groupingAttribute;
|
||||
private final FileGroup.GroupSortingAlgorithm groupSort;
|
||||
private final Group.GroupSortingAlgorithm groupSort;
|
||||
private final FileSorter.SortingMethod fileSortMethod;
|
||||
|
||||
/**
|
||||
@@ -157,7 +135,7 @@ public final class DiscoveryEventUtils {
|
||||
* @param fileSortMethod The sorting method used for files.
|
||||
*/
|
||||
public SearchCompleteEvent(Map<GroupKey, Integer> groupMap, List<AbstractFilter> searchfilters,
|
||||
FileSearch.AttributeType groupingAttribute, FileGroup.GroupSortingAlgorithm groupSort,
|
||||
FileSearch.AttributeType groupingAttribute, Group.GroupSortingAlgorithm groupSort,
|
||||
FileSorter.SortingMethod fileSortMethod) {
|
||||
this.groupMap = groupMap;
|
||||
this.searchFilters = searchfilters;
|
||||
@@ -198,7 +176,7 @@ public final class DiscoveryEventUtils {
|
||||
*
|
||||
* @return The sorting algorithm used for groups.
|
||||
*/
|
||||
public FileGroup.GroupSortingAlgorithm getGroupSort() {
|
||||
public Group.GroupSortingAlgorithm getGroupSort() {
|
||||
return groupSort;
|
||||
}
|
||||
|
||||
@@ -221,7 +199,7 @@ public final class DiscoveryEventUtils {
|
||||
|
||||
private final List<ResultFile> results;
|
||||
private final int page;
|
||||
private final FileType resultType;
|
||||
private final Type resultType;
|
||||
|
||||
/**
|
||||
* Construct a new PageRetrievedEvent.
|
||||
@@ -230,7 +208,7 @@ public final class DiscoveryEventUtils {
|
||||
* @param page The number of the page which was retrieved.
|
||||
* @param results The list of files in the page retrieved.
|
||||
*/
|
||||
public PageRetrievedEvent(FileType resultType, int page, List<ResultFile> results) {
|
||||
public PageRetrievedEvent(Type resultType, int page, List<ResultFile> results) {
|
||||
this.results = results;
|
||||
this.page = page;
|
||||
this.resultType = resultType;
|
||||
@@ -259,7 +237,7 @@ public final class DiscoveryEventUtils {
|
||||
*
|
||||
* @return The type of files which exist in the page.
|
||||
*/
|
||||
public FileType getType() {
|
||||
public Type getType() {
|
||||
return resultType;
|
||||
}
|
||||
}
|
||||
@@ -296,12 +274,12 @@ public final class DiscoveryEventUtils {
|
||||
*/
|
||||
public static final class GroupSelectedEvent {
|
||||
|
||||
private final FileType resultType;
|
||||
private final Type resultType;
|
||||
private final GroupKey groupKey;
|
||||
private final int groupSize;
|
||||
private final List<AbstractFilter> searchfilters;
|
||||
private final FileSearch.AttributeType groupingAttribute;
|
||||
private final FileGroup.GroupSortingAlgorithm groupSort;
|
||||
private final Group.GroupSortingAlgorithm groupSort;
|
||||
private final FileSorter.SortingMethod fileSortMethod;
|
||||
|
||||
/**
|
||||
@@ -319,8 +297,8 @@ public final class DiscoveryEventUtils {
|
||||
* @param resultType The type of files which exist in the group.
|
||||
*/
|
||||
public GroupSelectedEvent(List<AbstractFilter> searchfilters,
|
||||
FileSearch.AttributeType groupingAttribute, FileGroup.GroupSortingAlgorithm groupSort,
|
||||
FileSorter.SortingMethod fileSortMethod, GroupKey groupKey, int groupSize, FileType resultType) {
|
||||
FileSearch.AttributeType groupingAttribute, Group.GroupSortingAlgorithm groupSort,
|
||||
FileSorter.SortingMethod fileSortMethod, GroupKey groupKey, int groupSize, Type resultType) {
|
||||
this.searchfilters = searchfilters;
|
||||
this.groupingAttribute = groupingAttribute;
|
||||
this.groupSort = groupSort;
|
||||
@@ -335,7 +313,7 @@ public final class DiscoveryEventUtils {
|
||||
*
|
||||
* @return The type of files which exist in the group.
|
||||
*/
|
||||
public FileType getResultType() {
|
||||
public Type getResultType() {
|
||||
return resultType;
|
||||
}
|
||||
|
||||
@@ -364,7 +342,7 @@ public final class DiscoveryEventUtils {
|
||||
*
|
||||
* @return The sorting algorithm used for groups.
|
||||
*/
|
||||
public FileGroup.GroupSortingAlgorithm getGroupSort() {
|
||||
public Group.GroupSortingAlgorithm getGroupSort() {
|
||||
return groupSort;
|
||||
}
|
||||
|
||||
|
||||
+3
-3
@@ -21,7 +21,7 @@ package org.sleuthkit.autopsy.discovery.search;
|
||||
/**
|
||||
* Exception type used for FileSearch.
|
||||
*/
|
||||
final public class FileSearchException extends Exception {
|
||||
final public class DiscoveryException extends Exception {
|
||||
|
||||
private static final long serialVersionUID = 1L;
|
||||
|
||||
@@ -30,7 +30,7 @@ final public class FileSearchException extends Exception {
|
||||
*
|
||||
* @param message The message to associate with this exception.
|
||||
*/
|
||||
FileSearchException(String message) {
|
||||
DiscoveryException(String message) {
|
||||
super(message);
|
||||
}
|
||||
|
||||
@@ -40,7 +40,7 @@ final public class FileSearchException extends Exception {
|
||||
* @param message The message to associate with this exception.
|
||||
* @param cause The Throwable cause of the exception.
|
||||
*/
|
||||
FileSearchException(String message, Throwable cause) {
|
||||
DiscoveryException(String message, Throwable cause) {
|
||||
super(message, cause);
|
||||
}
|
||||
}
|
||||
@@ -53,7 +53,7 @@ public class DiscoveryKeyUtils {
|
||||
*/
|
||||
SearchKey(String userName, List<AbstractFilter> filters,
|
||||
FileSearch.AttributeType groupAttributeType,
|
||||
FileGroup.GroupSortingAlgorithm groupSortingType,
|
||||
Group.GroupSortingAlgorithm groupSortingType,
|
||||
FileSorter.SortingMethod fileSortingMethod) {
|
||||
StringBuilder searchStringBuilder = new StringBuilder();
|
||||
searchStringBuilder.append(userName);
|
||||
@@ -153,13 +153,13 @@ public class DiscoveryKeyUtils {
|
||||
*/
|
||||
static class FileSizeGroupKey extends GroupKey {
|
||||
|
||||
private final FileSearchData.FileSize fileSize;
|
||||
private final SearchData.FileSize fileSize;
|
||||
|
||||
FileSizeGroupKey(ResultFile file) {
|
||||
if (file.getFileType() == FileSearchData.FileType.VIDEO) {
|
||||
fileSize = FileSearchData.FileSize.fromVideoSize(file.getFirstInstance().getSize());
|
||||
if (file.getFileType() == SearchData.Type.VIDEO) {
|
||||
fileSize = SearchData.FileSize.fromVideoSize(file.getFirstInstance().getSize());
|
||||
} else {
|
||||
fileSize = FileSearchData.FileSize.fromImageSize(file.getFirstInstance().getSize());
|
||||
fileSize = SearchData.FileSize.fromImageSize(file.getFirstInstance().getSize());
|
||||
}
|
||||
}
|
||||
|
||||
@@ -200,7 +200,7 @@ public class DiscoveryKeyUtils {
|
||||
/**
|
||||
* @return the fileSize
|
||||
*/
|
||||
FileSearchData.FileSize getFileSize() {
|
||||
SearchData.FileSize getFileSize() {
|
||||
return fileSize;
|
||||
}
|
||||
}
|
||||
@@ -210,7 +210,7 @@ public class DiscoveryKeyUtils {
|
||||
*/
|
||||
static class FileTypeGroupKey extends GroupKey {
|
||||
|
||||
private final FileSearchData.FileType fileType;
|
||||
private final SearchData.Type fileType;
|
||||
|
||||
FileTypeGroupKey(ResultFile file) {
|
||||
fileType = file.getFileType();
|
||||
@@ -253,7 +253,7 @@ public class DiscoveryKeyUtils {
|
||||
/**
|
||||
* @return the fileType
|
||||
*/
|
||||
FileSearchData.FileType getFileType() {
|
||||
SearchData.Type getFileType() {
|
||||
return fileType;
|
||||
}
|
||||
}
|
||||
@@ -644,7 +644,7 @@ public class DiscoveryKeyUtils {
|
||||
*/
|
||||
static class FrequencyGroupKey extends GroupKey {
|
||||
|
||||
private final FileSearchData.Frequency frequency;
|
||||
private final SearchData.Frequency frequency;
|
||||
|
||||
FrequencyGroupKey(ResultFile file) {
|
||||
frequency = file.getFrequency();
|
||||
@@ -687,7 +687,7 @@ public class DiscoveryKeyUtils {
|
||||
/**
|
||||
* @return the frequency
|
||||
*/
|
||||
FileSearchData.Frequency getFrequency() {
|
||||
SearchData.Frequency getFrequency() {
|
||||
return frequency;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,30 @@
|
||||
/*
|
||||
* Autopsy
|
||||
*
|
||||
* Copyright 2020 Basis Technology Corp.
|
||||
* Contact: carrier <at> sleuthkit <dot> org
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
package org.sleuthkit.autopsy.discovery.search;
|
||||
|
||||
/**
|
||||
* Main class to perform the domain search.
|
||||
*/
|
||||
public class DomainSearch {
|
||||
|
||||
private DomainSearch() {
|
||||
// Class should not be instantiated
|
||||
}
|
||||
|
||||
}
|
||||
@@ -40,7 +40,7 @@ import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepoException;
|
||||
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepoDbUtil;
|
||||
import org.sleuthkit.autopsy.centralrepository.datamodel.InstanceTableCallback;
|
||||
import org.sleuthkit.autopsy.coreutils.Logger;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData.Frequency;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData.Frequency;
|
||||
import org.sleuthkit.datamodel.AbstractFile;
|
||||
import org.sleuthkit.datamodel.BlackboardArtifact;
|
||||
import org.sleuthkit.datamodel.BlackboardAttribute;
|
||||
@@ -82,14 +82,14 @@ public class FileSearch {
|
||||
*
|
||||
* @return The raw search results
|
||||
*
|
||||
* @throws FileSearchException
|
||||
* @throws DiscoveryException
|
||||
*/
|
||||
static SearchResults runFileSearchDebug(String userName,
|
||||
List<AbstractFilter> filters,
|
||||
AttributeType groupAttributeType,
|
||||
FileGroup.GroupSortingAlgorithm groupSortingType,
|
||||
Group.GroupSortingAlgorithm groupSortingType,
|
||||
FileSorter.SortingMethod fileSortingMethod,
|
||||
SleuthkitCase caseDb, CentralRepository centralRepoDb) throws FileSearchException {
|
||||
SleuthkitCase caseDb, CentralRepository centralRepoDb) throws DiscoveryException {
|
||||
// Make a list of attributes that we want to add values for. This ensures the
|
||||
// ResultFile objects will have all needed fields set when it's time to group
|
||||
// and sort them. For example, if we're grouping by central repo frequency, we need
|
||||
@@ -134,14 +134,14 @@ public class FileSearch {
|
||||
*
|
||||
* @return A LinkedHashMap grouped and sorted according to the parameters
|
||||
*
|
||||
* @throws FileSearchException
|
||||
* @throws DiscoveryException
|
||||
*/
|
||||
public static Map<GroupKey, Integer> getGroupSizes(String userName,
|
||||
List<AbstractFilter> filters,
|
||||
AttributeType groupAttributeType,
|
||||
FileGroup.GroupSortingAlgorithm groupSortingType,
|
||||
Group.GroupSortingAlgorithm groupSortingType,
|
||||
FileSorter.SortingMethod fileSortingMethod,
|
||||
SleuthkitCase caseDb, CentralRepository centralRepoDb) throws FileSearchException {
|
||||
SleuthkitCase caseDb, CentralRepository centralRepoDb) throws DiscoveryException {
|
||||
Map<GroupKey, List<ResultFile>> searchResults = runFileSearch(userName, filters,
|
||||
groupAttributeType, groupSortingType, fileSortingMethod, caseDb, centralRepoDb);
|
||||
LinkedHashMap<GroupKey, Integer> groupSizes = new LinkedHashMap<>();
|
||||
@@ -171,17 +171,17 @@ public class FileSearch {
|
||||
*
|
||||
* @return A LinkedHashMap grouped and sorted according to the parameters
|
||||
*
|
||||
* @throws FileSearchException
|
||||
* @throws DiscoveryException
|
||||
*/
|
||||
public static List<ResultFile> getFilesInGroup(String userName,
|
||||
List<AbstractFilter> filters,
|
||||
AttributeType groupAttributeType,
|
||||
FileGroup.GroupSortingAlgorithm groupSortingType,
|
||||
Group.GroupSortingAlgorithm groupSortingType,
|
||||
FileSorter.SortingMethod fileSortingMethod,
|
||||
GroupKey groupKey,
|
||||
int startingEntry,
|
||||
int numberOfEntries,
|
||||
SleuthkitCase caseDb, CentralRepository centralRepoDb) throws FileSearchException {
|
||||
SleuthkitCase caseDb, CentralRepository centralRepoDb) throws DiscoveryException {
|
||||
//the group should be in the cache at this point
|
||||
List<ResultFile> filesInGroup = null;
|
||||
SearchKey searchKey = new SearchKey(userName, filters, groupAttributeType, groupSortingType, fileSortingMethod);
|
||||
@@ -267,14 +267,14 @@ public class FileSearch {
|
||||
*
|
||||
* @return A LinkedHashMap grouped and sorted according to the parameters
|
||||
*
|
||||
* @throws FileSearchException
|
||||
* @throws DiscoveryException
|
||||
*/
|
||||
private static Map<GroupKey, List<ResultFile>> runFileSearch(String userName,
|
||||
List<AbstractFilter> filters,
|
||||
AttributeType groupAttributeType,
|
||||
FileGroup.GroupSortingAlgorithm groupSortingType,
|
||||
Group.GroupSortingAlgorithm groupSortingType,
|
||||
FileSorter.SortingMethod fileSortingMethod,
|
||||
SleuthkitCase caseDb, CentralRepository centralRepoDb) throws FileSearchException {
|
||||
SleuthkitCase caseDb, CentralRepository centralRepoDb) throws DiscoveryException {
|
||||
|
||||
// Make a list of attributes that we want to add values for. This ensures the
|
||||
// ResultFile objects will have all needed fields set when it's time to group
|
||||
@@ -313,10 +313,10 @@ public class FileSearch {
|
||||
* @param centralRepoDb The central repository database. Can be null if not
|
||||
* needed.
|
||||
*
|
||||
* @throws FileSearchException
|
||||
* @throws DiscoveryException
|
||||
*/
|
||||
private static void addAttributes(List<AttributeType> attrs, List<ResultFile> resultFiles, SleuthkitCase caseDb, CentralRepository centralRepoDb)
|
||||
throws FileSearchException {
|
||||
throws DiscoveryException {
|
||||
for (AttributeType attr : attrs) {
|
||||
attr.addAttributeToResultFiles(resultFiles, caseDb, centralRepoDb);
|
||||
}
|
||||
@@ -357,7 +357,7 @@ public class FileSearch {
|
||||
}
|
||||
|
||||
private static String createSetNameClause(List<ResultFile> files,
|
||||
int artifactTypeID, int setNameAttrID) throws FileSearchException {
|
||||
int artifactTypeID, int setNameAttrID) throws DiscoveryException {
|
||||
|
||||
// Concatenate the object IDs in the list of files
|
||||
String objIdList = ""; // NON-NLS
|
||||
@@ -405,9 +405,9 @@ public class FileSearch {
|
||||
* @param centralRepoDb The central repository database. Can be null if
|
||||
* not needed.
|
||||
*
|
||||
* @throws FileSearchException
|
||||
* @throws DiscoveryException
|
||||
*/
|
||||
public void addAttributeToResultFiles(List<ResultFile> files, SleuthkitCase caseDb, CentralRepository centralRepoDb) throws FileSearchException {
|
||||
public void addAttributeToResultFiles(List<ResultFile> files, SleuthkitCase caseDb, CentralRepository centralRepoDb) throws DiscoveryException {
|
||||
// Default is to do nothing
|
||||
}
|
||||
}
|
||||
@@ -479,7 +479,7 @@ public class FileSearch {
|
||||
|
||||
@Override
|
||||
public void addAttributeToResultFiles(List<ResultFile> files, SleuthkitCase caseDb,
|
||||
CentralRepository centralRepoDb) throws FileSearchException {
|
||||
CentralRepository centralRepoDb) throws DiscoveryException {
|
||||
|
||||
// Get pairs of (object ID, keyword list name) for all files in the list of files that have
|
||||
// keyword list hits.
|
||||
@@ -490,7 +490,7 @@ public class FileSearch {
|
||||
try {
|
||||
caseDb.getCaseDbAccessManager().select(selectQuery, callback);
|
||||
} catch (TskCoreException ex) {
|
||||
throw new FileSearchException("Error looking up keyword list attributes", ex); // NON-NLS
|
||||
throw new DiscoveryException("Error looking up keyword list attributes", ex); // NON-NLS
|
||||
}
|
||||
}
|
||||
|
||||
@@ -553,7 +553,7 @@ public class FileSearch {
|
||||
|
||||
@Override
|
||||
public void addAttributeToResultFiles(List<ResultFile> files, SleuthkitCase caseDb,
|
||||
CentralRepository centralRepoDb) throws FileSearchException {
|
||||
CentralRepository centralRepoDb) throws DiscoveryException {
|
||||
if (centralRepoDb == null) {
|
||||
for (ResultFile file : files) {
|
||||
if (file.getFrequency() == Frequency.UNKNOWN && file.getFirstInstance().getKnown() == TskData.FileKnown.KNOWN) {
|
||||
@@ -648,7 +648,7 @@ public class FileSearch {
|
||||
|
||||
@Override
|
||||
public void addAttributeToResultFiles(List<ResultFile> files, SleuthkitCase caseDb,
|
||||
CentralRepository centralRepoDb) throws FileSearchException {
|
||||
CentralRepository centralRepoDb) throws DiscoveryException {
|
||||
|
||||
// Get pairs of (object ID, hash set name) for all files in the list of files that have
|
||||
// hash set hits.
|
||||
@@ -659,7 +659,7 @@ public class FileSearch {
|
||||
try {
|
||||
caseDb.getCaseDbAccessManager().select(selectQuery, callback);
|
||||
} catch (TskCoreException ex) {
|
||||
throw new FileSearchException("Error looking up hash set attributes", ex); // NON-NLS
|
||||
throw new DiscoveryException("Error looking up hash set attributes", ex); // NON-NLS
|
||||
}
|
||||
}
|
||||
|
||||
@@ -719,7 +719,7 @@ public class FileSearch {
|
||||
|
||||
@Override
|
||||
public void addAttributeToResultFiles(List<ResultFile> files, SleuthkitCase caseDb,
|
||||
CentralRepository centralRepoDb) throws FileSearchException {
|
||||
CentralRepository centralRepoDb) throws DiscoveryException {
|
||||
|
||||
// Get pairs of (object ID, interesting item set name) for all files in the list of files that have
|
||||
// interesting file set hits.
|
||||
@@ -730,7 +730,7 @@ public class FileSearch {
|
||||
try {
|
||||
caseDb.getCaseDbAccessManager().select(selectQuery, callback);
|
||||
} catch (TskCoreException ex) {
|
||||
throw new FileSearchException("Error looking up interesting file set attributes", ex); // NON-NLS
|
||||
throw new DiscoveryException("Error looking up interesting file set attributes", ex); // NON-NLS
|
||||
}
|
||||
}
|
||||
|
||||
@@ -792,7 +792,7 @@ public class FileSearch {
|
||||
|
||||
@Override
|
||||
public void addAttributeToResultFiles(List<ResultFile> files, SleuthkitCase caseDb,
|
||||
CentralRepository centralRepoDb) throws FileSearchException {
|
||||
CentralRepository centralRepoDb) throws DiscoveryException {
|
||||
|
||||
// Get pairs of (object ID, object type name) for all files in the list of files that have
|
||||
// objects detected
|
||||
@@ -803,7 +803,7 @@ public class FileSearch {
|
||||
try {
|
||||
caseDb.getCaseDbAccessManager().select(selectQuery, callback);
|
||||
} catch (TskCoreException ex) {
|
||||
throw new FileSearchException("Error looking up object detected attributes", ex); // NON-NLS
|
||||
throw new DiscoveryException("Error looking up object detected attributes", ex); // NON-NLS
|
||||
}
|
||||
}
|
||||
|
||||
@@ -864,7 +864,7 @@ public class FileSearch {
|
||||
|
||||
@Override
|
||||
public void addAttributeToResultFiles(List<ResultFile> files, SleuthkitCase caseDb,
|
||||
CentralRepository centralRepoDb) throws FileSearchException {
|
||||
CentralRepository centralRepoDb) throws DiscoveryException {
|
||||
|
||||
try {
|
||||
for (ResultFile resultFile : files) {
|
||||
@@ -875,7 +875,7 @@ public class FileSearch {
|
||||
}
|
||||
}
|
||||
} catch (TskCoreException ex) {
|
||||
throw new FileSearchException("Error looking up file tag attributes", ex); // NON-NLS
|
||||
throw new DiscoveryException("Error looking up file tag attributes", ex); // NON-NLS
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,441 +0,0 @@
|
||||
/*
|
||||
* Autopsy Forensic Browser
|
||||
*
|
||||
* Copyright 2019 Basis Technology Corp.
|
||||
* Contact: carrier <at> sleuthkit <dot> org
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
package org.sleuthkit.autopsy.discovery.search;
|
||||
|
||||
import com.google.common.collect.ImmutableSet;
|
||||
import java.util.ArrayList;
|
||||
import java.util.Arrays;
|
||||
import java.util.Collection;
|
||||
import java.util.Collections;
|
||||
import java.util.List;
|
||||
import org.openide.util.NbBundle;
|
||||
import org.sleuthkit.autopsy.coreutils.FileTypeUtils;
|
||||
|
||||
/**
|
||||
* Utility enums for searches made for files with Discovery.
|
||||
*/
|
||||
public final class FileSearchData implements SearchData {
|
||||
|
||||
private final static long BYTES_PER_MB = 1000000;
|
||||
|
||||
@Override
|
||||
public ResultType getResultType() {
|
||||
return ResultType.FILE;
|
||||
}
|
||||
|
||||
/**
|
||||
* Enum representing how often the file occurs in the Central Repository.
|
||||
*/
|
||||
@NbBundle.Messages({
|
||||
"FileSearchData.Frequency.unique.displayName=Unique (1)",
|
||||
"FileSearchData.Frequency.rare.displayName=Rare (2-10)",
|
||||
"FileSearchData.Frequency.common.displayName=Common (11 - 100)",
|
||||
"FileSearchData.Frequency.verycommon.displayName=Very Common (100+)",
|
||||
"FileSearchData.Frequency.known.displayName=Known (NSRL)",
|
||||
"FileSearchData.Frequency.unknown.displayName=Unknown",})
|
||||
public enum Frequency {
|
||||
UNIQUE(0, 1, Bundle.FileSearchData_Frequency_unique_displayName()),
|
||||
RARE(1, 10, Bundle.FileSearchData_Frequency_rare_displayName()),
|
||||
COMMON(2, 100, Bundle.FileSearchData_Frequency_common_displayName()),
|
||||
VERY_COMMON(3, 0, Bundle.FileSearchData_Frequency_verycommon_displayName()),
|
||||
KNOWN(4, 0, Bundle.FileSearchData_Frequency_known_displayName()),
|
||||
UNKNOWN(5, 0, Bundle.FileSearchData_Frequency_unknown_displayName());
|
||||
|
||||
private final int ranking;
|
||||
private final String displayName;
|
||||
private final int maxOccur;
|
||||
|
||||
Frequency(int ranking, int maxOccur, String displayName) {
|
||||
this.ranking = ranking;
|
||||
this.maxOccur = maxOccur;
|
||||
this.displayName = displayName;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the rank for sorting.
|
||||
*
|
||||
* @return the rank (lower should be displayed first)
|
||||
*/
|
||||
public int getRanking() {
|
||||
return ranking;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the enum matching the given occurrence count.
|
||||
*
|
||||
* @param count Number of times a file is in the Central Repository.
|
||||
*
|
||||
* @return the corresponding enum
|
||||
*/
|
||||
public static Frequency fromCount(long count) {
|
||||
if (count <= UNIQUE.getMaxOccur()) {
|
||||
return UNIQUE;
|
||||
} else if (count <= RARE.getMaxOccur()) {
|
||||
return RARE;
|
||||
} else if (count <= COMMON.getMaxOccur()) {
|
||||
return COMMON;
|
||||
}
|
||||
return VERY_COMMON;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the list of enums that are valid for filtering when a CR is
|
||||
* enabled.
|
||||
*
|
||||
* @return enums that can be used to filter with a CR.
|
||||
*/
|
||||
public static List<Frequency> getOptionsForFilteringWithCr() {
|
||||
return Arrays.asList(UNIQUE, RARE, COMMON, VERY_COMMON, KNOWN);
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the list of enums that are valid for filtering when no CR is
|
||||
* enabled.
|
||||
*
|
||||
* @return enums that can be used to filter without a CR.
|
||||
*/
|
||||
public static List<Frequency> getOptionsForFilteringWithoutCr() {
|
||||
return Arrays.asList(KNOWN, UNKNOWN);
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return displayName;
|
||||
}
|
||||
|
||||
/**
|
||||
* @return the maxOccur
|
||||
*/
|
||||
public int getMaxOccur() {
|
||||
return maxOccur;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Enum representing the file size
|
||||
*/
|
||||
@NbBundle.Messages({
|
||||
"FileSearchData.FileSize.XXLARGE.displayName=XXLarge",
|
||||
"FileSearchData.FileSize.XLARGE.displayName=XLarge",
|
||||
"FileSearchData.FileSize.LARGE.displayName=Large",
|
||||
"FileSearchData.FileSize.MEDIUM.displayName=Medium",
|
||||
"FileSearchData.FileSize.SMALL.displayName=Small",
|
||||
"FileSearchData.FileSize.XSMALL.displayName=XSmall",
|
||||
"FileSearchData.FileSize.10PlusGb=: 10GB+",
|
||||
"FileSearchData.FileSize.5gbto10gb=: 5-10GB",
|
||||
"FileSearchData.FileSize.1gbto5gb=: 1-5GB",
|
||||
"FileSearchData.FileSize.100mbto1gb=: 100MB-1GB",
|
||||
"FileSearchData.FileSize.200PlusMb=: 200MB+",
|
||||
"FileSearchData.FileSize.50mbto200mb=: 50-200MB",
|
||||
"FileSearchData.FileSize.500kbto100mb=: 500KB-100MB",
|
||||
"FileSearchData.FileSize.1mbto50mb=: 1-50MB",
|
||||
"FileSearchData.FileSize.100kbto1mb=: 100KB-1MB",
|
||||
"FileSearchData.FileSize.16kbto100kb=: 16-100KB",
|
||||
"FileSearchData.FileSize.upTo500kb=: 0-500KB",
|
||||
"FileSearchData.FileSize.upTo16kb=: 0-16KB",})
|
||||
public enum FileSize {
|
||||
XXLARGE_VIDEO(0, 10000 * BYTES_PER_MB, -1, Bundle.FileSearchData_FileSize_XXLARGE_displayName(), Bundle.FileSearchData_FileSize_10PlusGb()),
|
||||
XLARGE_VIDEO(1, 5000 * BYTES_PER_MB, 10000 * BYTES_PER_MB, Bundle.FileSearchData_FileSize_XLARGE_displayName(), Bundle.FileSearchData_FileSize_5gbto10gb()),
|
||||
LARGE_VIDEO(2, 1000 * BYTES_PER_MB, 5000 * BYTES_PER_MB, Bundle.FileSearchData_FileSize_LARGE_displayName(), Bundle.FileSearchData_FileSize_1gbto5gb()),
|
||||
MEDIUM_VIDEO(3, 100 * BYTES_PER_MB, 1000 * BYTES_PER_MB, Bundle.FileSearchData_FileSize_MEDIUM_displayName(), Bundle.FileSearchData_FileSize_100mbto1gb()),
|
||||
SMALL_VIDEO(4, 500000, 100 * BYTES_PER_MB, Bundle.FileSearchData_FileSize_SMALL_displayName(), Bundle.FileSearchData_FileSize_500kbto100mb()),
|
||||
XSMALL_VIDEO(5, 0, 500000, Bundle.FileSearchData_FileSize_XSMALL_displayName(), Bundle.FileSearchData_FileSize_upTo500kb()),
|
||||
XXLARGE_IMAGE(6, 200 * BYTES_PER_MB, -1, Bundle.FileSearchData_FileSize_XXLARGE_displayName(), Bundle.FileSearchData_FileSize_200PlusMb()),
|
||||
XLARGE_IMAGE(7, 50 * BYTES_PER_MB, 200 * BYTES_PER_MB, Bundle.FileSearchData_FileSize_XLARGE_displayName(), Bundle.FileSearchData_FileSize_50mbto200mb()),
|
||||
LARGE_IMAGE(8, 1 * BYTES_PER_MB, 50 * BYTES_PER_MB, Bundle.FileSearchData_FileSize_LARGE_displayName(), Bundle.FileSearchData_FileSize_1mbto50mb()),
|
||||
MEDIUM_IMAGE(9, 100000, 1 * BYTES_PER_MB, Bundle.FileSearchData_FileSize_MEDIUM_displayName(), Bundle.FileSearchData_FileSize_100kbto1mb()),
|
||||
SMALL_IMAGE(10, 16000, 100000, Bundle.FileSearchData_FileSize_SMALL_displayName(), Bundle.FileSearchData_FileSize_16kbto100kb()),
|
||||
XSMALL_IMAGE(11, 0, 16000, Bundle.FileSearchData_FileSize_XSMALL_displayName(), Bundle.FileSearchData_FileSize_upTo16kb());
|
||||
|
||||
private final int ranking; // Must be unique for each value
|
||||
private final long minBytes; // Note that the size must be strictly greater than this to match
|
||||
private final long maxBytes;
|
||||
private final String sizeGroup;
|
||||
private final String displaySize;
|
||||
final static long NO_MAXIMUM = -1;
|
||||
|
||||
FileSize(int ranking, long minB, long maxB, String displayName, String displaySize) {
|
||||
this.ranking = ranking;
|
||||
this.minBytes = minB;
|
||||
if (maxB >= 0) {
|
||||
this.maxBytes = maxB;
|
||||
} else {
|
||||
this.maxBytes = NO_MAXIMUM;
|
||||
}
|
||||
this.sizeGroup = displayName;
|
||||
this.displaySize = displaySize;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the enum corresponding to the given file size for image files.
|
||||
* The file size must be strictly greater than minBytes.
|
||||
*
|
||||
* @param size the file size
|
||||
*
|
||||
* @return the enum whose range contains the file size
|
||||
*/
|
||||
public static FileSize fromImageSize(long size) {
|
||||
if (size > XXLARGE_IMAGE.getMinBytes()) {
|
||||
return XXLARGE_IMAGE;
|
||||
} else if (size > XLARGE_IMAGE.getMinBytes()) {
|
||||
return XLARGE_IMAGE;
|
||||
} else if (size > LARGE_IMAGE.getMinBytes()) {
|
||||
return LARGE_IMAGE;
|
||||
} else if (size > MEDIUM_IMAGE.getMinBytes()) {
|
||||
return MEDIUM_IMAGE;
|
||||
} else if (size > SMALL_IMAGE.getMinBytes()) {
|
||||
return SMALL_IMAGE;
|
||||
} else {
|
||||
return XSMALL_IMAGE;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the enum corresponding to the given file size for video files.
|
||||
* The file size must be strictly greater than minBytes.
|
||||
*
|
||||
* @param size the file size
|
||||
*
|
||||
* @return the enum whose range contains the file size
|
||||
*/
|
||||
public static FileSize fromVideoSize(long size) {
|
||||
if (size > XXLARGE_VIDEO.getMinBytes()) {
|
||||
return XXLARGE_VIDEO;
|
||||
} else if (size > XLARGE_VIDEO.getMinBytes()) {
|
||||
return XLARGE_VIDEO;
|
||||
} else if (size > LARGE_VIDEO.getMinBytes()) {
|
||||
return LARGE_VIDEO;
|
||||
} else if (size > MEDIUM_VIDEO.getMinBytes()) {
|
||||
return MEDIUM_VIDEO;
|
||||
} else if (size > SMALL_VIDEO.getMinBytes()) {
|
||||
return SMALL_VIDEO;
|
||||
} else {
|
||||
return XSMALL_VIDEO;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the upper limit of the range.
|
||||
*
|
||||
* @return the maximum file size that will fit in this range.
|
||||
*/
|
||||
public long getMaxBytes() {
|
||||
return maxBytes;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the lower limit of the range.
|
||||
*
|
||||
* @return the maximum file size that is not part of this range
|
||||
*/
|
||||
public long getMinBytes() {
|
||||
return minBytes;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the rank for sorting.
|
||||
*
|
||||
* @return the rank (lower should be displayed first)
|
||||
*/
|
||||
public int getRanking() {
|
||||
return ranking;
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return sizeGroup + displaySize;
|
||||
}
|
||||
|
||||
public String getSizeGroup() {
|
||||
return sizeGroup;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the list of enums that are valid for most file sizes.
|
||||
*
|
||||
* @return Enums that can be used to filter most file including images
|
||||
* by size.
|
||||
*/
|
||||
public static List<FileSize> getDefaultSizeOptions() {
|
||||
return Arrays.asList(XXLARGE_IMAGE, XLARGE_IMAGE, LARGE_IMAGE, MEDIUM_IMAGE, SMALL_IMAGE, XSMALL_IMAGE);
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the list of enums that are valid for video sizes.
|
||||
*
|
||||
* @return enums that can be used to filter videos by size.
|
||||
*/
|
||||
public static List<FileSize> getOptionsForVideos() {
|
||||
return Arrays.asList(XXLARGE_VIDEO, XLARGE_VIDEO, LARGE_VIDEO, MEDIUM_VIDEO, SMALL_VIDEO, XSMALL_VIDEO);
|
||||
}
|
||||
}
|
||||
|
||||
//Discovery uses a different list of document mime types than FileTypeUtils.FileTypeCategory.DOCUMENTS
|
||||
private static final ImmutableSet<String> DOCUMENT_MIME_TYPES
|
||||
= new ImmutableSet.Builder<String>()
|
||||
.add("text/html", //NON-NLS
|
||||
"text/csv", //NON-NLS
|
||||
"application/rtf", //NON-NLS
|
||||
"application/pdf", //NON-NLS
|
||||
"application/xhtml+xml", //NON-NLS
|
||||
"application/x-msoffice", //NON-NLS
|
||||
"application/msword", //NON-NLS
|
||||
"application/msword2", //NON-NLS
|
||||
"application/vnd.wordperfect", //NON-NLS
|
||||
"application/vnd.openxmlformats-officedocument.wordprocessingml.document", //NON-NLS
|
||||
"application/vnd.ms-powerpoint", //NON-NLS
|
||||
"application/vnd.openxmlformats-officedocument.presentationml.presentation", //NON-NLS
|
||||
"application/vnd.ms-excel", //NON-NLS
|
||||
"application/vnd.ms-excel.sheet.4", //NON-NLS
|
||||
"application/vnd.openxmlformats-officedocument.spreadsheetml.sheet", //NON-NLS
|
||||
"application/vnd.oasis.opendocument.presentation", //NON-NLS
|
||||
"application/vnd.oasis.opendocument.spreadsheet", //NON-NLS
|
||||
"application/vnd.oasis.opendocument.text" //NON-NLS
|
||||
).build();
|
||||
|
||||
private static final ImmutableSet<String> IMAGE_UNSUPPORTED_DOC_TYPES
|
||||
= new ImmutableSet.Builder<String>()
|
||||
.add("application/pdf", //NON-NLS
|
||||
"application/xhtml+xml").build(); //NON-NLS
|
||||
|
||||
public static Collection<String> getDocTypesWithoutImageExtraction() {
|
||||
return Collections.unmodifiableCollection(IMAGE_UNSUPPORTED_DOC_TYPES);
|
||||
}
|
||||
|
||||
/**
|
||||
* Enum representing the file type. We don't simply use
|
||||
* FileTypeUtils.FileTypeCategory because: - Some file types categories
|
||||
* overlap - It is convenient to have the "OTHER" option for files that
|
||||
* don't match the given types
|
||||
*/
|
||||
@NbBundle.Messages({
|
||||
"FileSearchData.FileType.Audio.displayName=Audio",
|
||||
"FileSearchData.FileType.Video.displayName=Video",
|
||||
"FileSearchData.FileType.Image.displayName=Image",
|
||||
"FileSearchData.FileType.Documents.displayName=Documents",
|
||||
"FileSearchData.FileType.Executables.displayName=Executables",
|
||||
"FileSearchData.FileType.Other.displayName=Other/Unknown"})
|
||||
public enum FileType {
|
||||
|
||||
IMAGE(0, Bundle.FileSearchData_FileType_Image_displayName(), FileTypeUtils.FileTypeCategory.IMAGE.getMediaTypes()),
|
||||
AUDIO(1, Bundle.FileSearchData_FileType_Audio_displayName(), FileTypeUtils.FileTypeCategory.AUDIO.getMediaTypes()),
|
||||
VIDEO(2, Bundle.FileSearchData_FileType_Video_displayName(), FileTypeUtils.FileTypeCategory.VIDEO.getMediaTypes()),
|
||||
EXECUTABLE(3, Bundle.FileSearchData_FileType_Executables_displayName(), FileTypeUtils.FileTypeCategory.EXECUTABLE.getMediaTypes()),
|
||||
DOCUMENTS(4, Bundle.FileSearchData_FileType_Documents_displayName(), DOCUMENT_MIME_TYPES),
|
||||
OTHER(5, Bundle.FileSearchData_FileType_Other_displayName(), new ArrayList<>());
|
||||
|
||||
private final int ranking; // For ordering in the UI
|
||||
private final String displayName;
|
||||
private final Collection<String> mediaTypes;
|
||||
|
||||
FileType(int value, String displayName, Collection<String> mediaTypes) {
|
||||
this.ranking = value;
|
||||
this.displayName = displayName;
|
||||
this.mediaTypes = mediaTypes;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the MIME types matching this category.
|
||||
*
|
||||
* @return Collection of MIME type strings
|
||||
*/
|
||||
public Collection<String> getMediaTypes() {
|
||||
return Collections.unmodifiableCollection(mediaTypes);
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return displayName;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the rank for sorting.
|
||||
*
|
||||
* @return the rank (lower should be displayed first)
|
||||
*/
|
||||
public int getRanking() {
|
||||
return ranking;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the enum matching the given MIME type.
|
||||
*
|
||||
* @param mimeType The MIME type for the file
|
||||
*
|
||||
* @return the corresponding enum (will be OTHER if no types matched)
|
||||
*/
|
||||
public static FileType fromMIMEtype(String mimeType) {
|
||||
for (FileType type : FileType.values()) {
|
||||
if (type.getMediaTypes().contains(mimeType)) {
|
||||
return type;
|
||||
}
|
||||
}
|
||||
return OTHER;
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
/**
|
||||
* Enum representing the score of the file.
|
||||
*/
|
||||
@NbBundle.Messages({
|
||||
"FileSearchData.Score.notable.displayName=Notable",
|
||||
"FileSearchData.Score.interesting.displayName=Interesting",
|
||||
"FileSearchData.Score.unknown.displayName=Unknown",})
|
||||
public enum Score {
|
||||
NOTABLE(0, Bundle.FileSearchData_Score_notable_displayName()),
|
||||
INTERESTING(1, Bundle.FileSearchData_Score_interesting_displayName()),
|
||||
UNKNOWN(2, Bundle.FileSearchData_Score_unknown_displayName());
|
||||
|
||||
private final int ranking;
|
||||
private final String displayName;
|
||||
|
||||
Score(int ranking, String displayName) {
|
||||
this.ranking = ranking;
|
||||
this.displayName = displayName;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the rank for sorting.
|
||||
*
|
||||
* @return the rank (lower should be displayed first)
|
||||
*/
|
||||
public int getRanking() {
|
||||
return ranking;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the list of enums that are valid for filtering.
|
||||
*
|
||||
* @return enums that can be used to filter
|
||||
*/
|
||||
public static List<Score> getOptionsForFiltering() {
|
||||
return Arrays.asList(NOTABLE, INTERESTING);
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return displayName;
|
||||
}
|
||||
}
|
||||
|
||||
private FileSearchData() {
|
||||
// Class should not be instantiated
|
||||
}
|
||||
}
|
||||
+6
-6
@@ -26,9 +26,9 @@ import org.openide.util.NbBundle.Messages;
|
||||
/**
|
||||
* Class for storing files that belong to a particular group.
|
||||
*/
|
||||
public class FileGroup implements Comparable<FileGroup> {
|
||||
public class Group implements Comparable<Group> {
|
||||
|
||||
private final FileGroup.GroupSortingAlgorithm groupSortingType;
|
||||
private final Group.GroupSortingAlgorithm groupSortingType;
|
||||
private final DiscoveryKeyUtils.GroupKey groupKey;
|
||||
private final List<ResultFile> files;
|
||||
private final String displayName;
|
||||
@@ -39,7 +39,7 @@ public class FileGroup implements Comparable<FileGroup> {
|
||||
* @param groupSortingType The method for sorting the group
|
||||
* @param groupKey The GroupKey for this group
|
||||
*/
|
||||
public FileGroup(FileGroup.GroupSortingAlgorithm groupSortingType, DiscoveryKeyUtils.GroupKey groupKey) {
|
||||
public Group(Group.GroupSortingAlgorithm groupSortingType, DiscoveryKeyUtils.GroupKey groupKey) {
|
||||
this.groupSortingType = groupSortingType;
|
||||
this.groupKey = groupKey;
|
||||
files = new ArrayList<>();
|
||||
@@ -95,7 +95,7 @@ public class FileGroup implements Comparable<FileGroup> {
|
||||
* otherwise
|
||||
*/
|
||||
@Override
|
||||
public int compareTo(FileGroup otherGroup) {
|
||||
public int compareTo(Group otherGroup) {
|
||||
|
||||
switch (groupSortingType) {
|
||||
case BY_GROUP_SIZE:
|
||||
@@ -114,7 +114,7 @@ public class FileGroup implements Comparable<FileGroup> {
|
||||
*
|
||||
* @return -1 if group1 should be displayed before group2, 1 otherwise
|
||||
*/
|
||||
private static int compareGroupsByGroupKey(FileGroup group1, FileGroup group2) {
|
||||
private static int compareGroupsByGroupKey(Group group1, Group group2) {
|
||||
return group1.getGroupKey().compareTo(group2.getGroupKey());
|
||||
}
|
||||
|
||||
@@ -127,7 +127,7 @@ public class FileGroup implements Comparable<FileGroup> {
|
||||
*
|
||||
* @return -1 if group1 should be displayed before group2, 1 otherwise
|
||||
*/
|
||||
private static int compareGroupsBySize(FileGroup group1, FileGroup group2) {
|
||||
private static int compareGroupsBySize(Group group1, Group group2) {
|
||||
if (group1.getFiles().size() != group2.getFiles().size()) {
|
||||
return -1 * Long.compare(group1.getFiles().size(), group2.getFiles().size()); // High to low
|
||||
} else {
|
||||
@@ -0,0 +1,26 @@
|
||||
/*
|
||||
* Autopsy
|
||||
*
|
||||
* Copyright 2020 Basis Technology Corp.
|
||||
* Contact: carrier <at> sleuthkit <dot> org
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
package org.sleuthkit.autopsy.discovery.search;
|
||||
|
||||
/**
|
||||
* Interface implemented by all types of results.
|
||||
*/
|
||||
public interface Result {
|
||||
|
||||
}
|
||||
@@ -0,0 +1,24 @@
|
||||
/*
|
||||
* Autopsy
|
||||
*
|
||||
* Copyright 2020 Basis Technology Corp.
|
||||
* Contact: carrier <at> sleuthkit <dot> org
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
package org.sleuthkit.autopsy.discovery.search;
|
||||
|
||||
|
||||
public class ResultDomain implements Result {
|
||||
|
||||
}
|
||||
@@ -18,7 +18,7 @@
|
||||
*/
|
||||
package org.sleuthkit.autopsy.discovery.search;
|
||||
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData.FileType;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData.Type;
|
||||
import org.sleuthkit.datamodel.AbstractFile;
|
||||
import java.util.ArrayList;
|
||||
import java.util.Collections;
|
||||
@@ -29,6 +29,7 @@ import org.sleuthkit.autopsy.casemodule.Case;
|
||||
import org.sleuthkit.autopsy.casemodule.NoCurrentCaseException;
|
||||
import org.sleuthkit.autopsy.corecomponents.DataResultViewerTable;
|
||||
import org.sleuthkit.autopsy.coreutils.Logger;
|
||||
import static org.sleuthkit.autopsy.discovery.search.SearchData.Type.OTHER;
|
||||
import org.sleuthkit.datamodel.BlackboardArtifact;
|
||||
import org.sleuthkit.datamodel.ContentTag;
|
||||
import org.sleuthkit.datamodel.HashUtility;
|
||||
@@ -39,10 +40,10 @@ import org.sleuthkit.datamodel.TskData;
|
||||
/**
|
||||
* Container for files that holds all necessary data for grouping and sorting.
|
||||
*/
|
||||
public class ResultFile {
|
||||
public class ResultFile implements Result{
|
||||
|
||||
private final static Logger logger = Logger.getLogger(ResultFile.class.getName());
|
||||
private FileSearchData.Frequency frequency;
|
||||
private SearchData.Frequency frequency;
|
||||
private final List<String> keywordListNames;
|
||||
private final List<String> hashSetNames;
|
||||
private final List<String> tagNames;
|
||||
@@ -52,7 +53,7 @@ public class ResultFile {
|
||||
private DataResultViewerTable.Score currentScore = DataResultViewerTable.Score.NO_SCORE;
|
||||
private String scoreDescription = null;
|
||||
private boolean deleted = false;
|
||||
private FileType fileType;
|
||||
private Type fileType;
|
||||
|
||||
/**
|
||||
* Create a ResultFile from an AbstractFile
|
||||
@@ -72,13 +73,13 @@ public class ResultFile {
|
||||
deleted = true;
|
||||
}
|
||||
updateScoreAndDescription(abstractFile);
|
||||
this.frequency = FileSearchData.Frequency.UNKNOWN;
|
||||
this.frequency = SearchData.Frequency.UNKNOWN;
|
||||
keywordListNames = new ArrayList<>();
|
||||
hashSetNames = new ArrayList<>();
|
||||
tagNames = new ArrayList<>();
|
||||
interestingSetNames = new ArrayList<>();
|
||||
objectDetectedNames = new ArrayList<>();
|
||||
fileType = FileType.fromMIMEtype(abstractFile.getMIMEType());
|
||||
fileType = fromMIMEtype(abstractFile.getMIMEType());
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -86,7 +87,7 @@ public class ResultFile {
|
||||
*
|
||||
* @return The Frequency enum
|
||||
*/
|
||||
public FileSearchData.Frequency getFrequency() {
|
||||
public SearchData.Frequency getFrequency() {
|
||||
return frequency;
|
||||
}
|
||||
|
||||
@@ -95,7 +96,7 @@ public class ResultFile {
|
||||
*
|
||||
* @param frequency The frequency of the file as an enum
|
||||
*/
|
||||
public void setFrequency(FileSearchData.Frequency frequency) {
|
||||
public void setFrequency(SearchData.Frequency frequency) {
|
||||
this.frequency = frequency;
|
||||
}
|
||||
|
||||
@@ -109,8 +110,8 @@ public class ResultFile {
|
||||
if (deleted && !duplicate.isDirNameFlagSet(TskData.TSK_FS_NAME_FLAG_ENUM.UNALLOC)) {
|
||||
deleted = false;
|
||||
}
|
||||
if (fileType == FileType.OTHER) {
|
||||
fileType = FileType.fromMIMEtype(duplicate.getMIMEType());
|
||||
if (fileType == Type.OTHER) {
|
||||
fileType = fromMIMEtype(duplicate.getMIMEType());
|
||||
}
|
||||
updateScoreAndDescription(duplicate);
|
||||
try {
|
||||
@@ -167,7 +168,7 @@ public class ResultFile {
|
||||
*
|
||||
* @return The FileType enum.
|
||||
*/
|
||||
public FileType getFileType() {
|
||||
public Type getFileType() {
|
||||
return fileType;
|
||||
}
|
||||
|
||||
@@ -380,4 +381,20 @@ public class ResultFile {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the enum matching the given MIME type.
|
||||
*
|
||||
* @param mimeType The MIME type for the file.
|
||||
*
|
||||
* @return the corresponding enum (will be OTHER if no types matched)
|
||||
*/
|
||||
public static Type fromMIMEtype(String mimeType) {
|
||||
for (Type type : Type.values()) {
|
||||
if (type.getMediaTypes().contains(mimeType)) {
|
||||
return type;
|
||||
}
|
||||
}
|
||||
return OTHER;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
/*
|
||||
* Autopsy
|
||||
* Autopsy Forensic Browser
|
||||
*
|
||||
* Copyright 2020 Basis Technology Corp.
|
||||
* Copyright 2019 Basis Technology Corp.
|
||||
* Contact: carrier <at> sleuthkit <dot> org
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
@@ -18,22 +18,413 @@
|
||||
*/
|
||||
package org.sleuthkit.autopsy.discovery.search;
|
||||
|
||||
import com.google.common.collect.ImmutableSet;
|
||||
import java.util.ArrayList;
|
||||
import java.util.Arrays;
|
||||
import java.util.Collection;
|
||||
import java.util.Collections;
|
||||
import java.util.EnumSet;
|
||||
import java.util.List;
|
||||
import java.util.Set;
|
||||
import org.openide.util.NbBundle;
|
||||
import org.sleuthkit.autopsy.coreutils.FileTypeUtils;
|
||||
import org.sleuthkit.datamodel.BlackboardArtifact;
|
||||
|
||||
/**
|
||||
* Abstract class to contain data that is common to all result types.
|
||||
* Utility enums for searches made for files with Discovery.
|
||||
*/
|
||||
public interface SearchData {
|
||||
public final class SearchData {
|
||||
|
||||
private final static long BYTES_PER_MB = 1000000;
|
||||
private static final Set<BlackboardArtifact.ARTIFACT_TYPE> DOMAIN_ARTIFACT_TYPES = EnumSet.of(BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_BOOKMARK, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_CACHE, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_COOKIE, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_DOWNLOAD, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_HISTORY, BlackboardArtifact.ARTIFACT_TYPE.TSK_WEB_SEARCH_QUERY, BlackboardArtifact.ARTIFACT_TYPE.TSK_EMAIL_MSG);
|
||||
|
||||
/**
|
||||
* Enum of the broad result type categories.
|
||||
* Enum representing how often the file occurs in the Central Repository.
|
||||
*/
|
||||
public enum ResultType {
|
||||
FILE,
|
||||
ATTRIBUTE;
|
||||
@NbBundle.Messages({
|
||||
"SearchData.Frequency.unique.displayName=Unique (1)",
|
||||
"SearchData.Frequency.rare.displayName=Rare (2-10)",
|
||||
"SearchData.Frequency.common.displayName=Common (11 - 100)",
|
||||
"SearchData.Frequency.verycommon.displayName=Very Common (100+)",
|
||||
"SearchData.Frequency.known.displayName=Known (NSRL)",
|
||||
"SearchData.Frequency.unknown.displayName=Unknown",})
|
||||
public enum Frequency {
|
||||
UNIQUE(0, 1, Bundle.SearchData_Frequency_unique_displayName()),
|
||||
RARE(1, 10, Bundle.SearchData_Frequency_rare_displayName()),
|
||||
COMMON(2, 100, Bundle.SearchData_Frequency_common_displayName()),
|
||||
VERY_COMMON(3, 0, Bundle.SearchData_Frequency_verycommon_displayName()),
|
||||
KNOWN(4, 0, Bundle.SearchData_Frequency_known_displayName()),
|
||||
UNKNOWN(5, 0, Bundle.SearchData_Frequency_unknown_displayName());
|
||||
|
||||
private final int ranking;
|
||||
private final String displayName;
|
||||
private final int maxOccur;
|
||||
|
||||
Frequency(int ranking, int maxOccur, String displayName) {
|
||||
this.ranking = ranking;
|
||||
this.maxOccur = maxOccur;
|
||||
this.displayName = displayName;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the rank for sorting.
|
||||
*
|
||||
* @return the rank (lower should be displayed first)
|
||||
*/
|
||||
public int getRanking() {
|
||||
return ranking;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the enum matching the given occurrence count.
|
||||
*
|
||||
* @param count Number of times a file is in the Central Repository.
|
||||
*
|
||||
* @return the corresponding enum
|
||||
*/
|
||||
public static Frequency fromCount(long count) {
|
||||
if (count <= UNIQUE.getMaxOccur()) {
|
||||
return UNIQUE;
|
||||
} else if (count <= RARE.getMaxOccur()) {
|
||||
return RARE;
|
||||
} else if (count <= COMMON.getMaxOccur()) {
|
||||
return COMMON;
|
||||
}
|
||||
return VERY_COMMON;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the list of enums that are valid for filtering when a CR is
|
||||
* enabled.
|
||||
*
|
||||
* @return enums that can be used to filter with a CR.
|
||||
*/
|
||||
public static List<Frequency> getOptionsForFilteringWithCr() {
|
||||
return Arrays.asList(UNIQUE, RARE, COMMON, VERY_COMMON, KNOWN);
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the list of enums that are valid for filtering when no CR is
|
||||
* enabled.
|
||||
*
|
||||
* @return enums that can be used to filter without a CR.
|
||||
*/
|
||||
public static List<Frequency> getOptionsForFilteringWithoutCr() {
|
||||
return Arrays.asList(KNOWN, UNKNOWN);
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return displayName;
|
||||
}
|
||||
|
||||
/**
|
||||
* @return the maxOccur
|
||||
*/
|
||||
public int getMaxOccur() {
|
||||
return maxOccur;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the broad result type.
|
||||
* Enum representing the file size
|
||||
*/
|
||||
public abstract ResultType getResultType();
|
||||
@NbBundle.Messages({
|
||||
"SearchData.FileSize.XXLARGE.displayName=XXLarge",
|
||||
"SearchData.FileSize.XLARGE.displayName=XLarge",
|
||||
"SearchData.FileSize.LARGE.displayName=Large",
|
||||
"SearchData.FileSize.MEDIUM.displayName=Medium",
|
||||
"SearchData.FileSize.SMALL.displayName=Small",
|
||||
"SearchData.FileSize.XSMALL.displayName=XSmall",
|
||||
"SearchData.FileSize.10PlusGb=: 10GB+",
|
||||
"SearchData.FileSize.5gbto10gb=: 5-10GB",
|
||||
"SearchData.FileSize.1gbto5gb=: 1-5GB",
|
||||
"SearchData.FileSize.100mbto1gb=: 100MB-1GB",
|
||||
"SearchData.FileSize.200PlusMb=: 200MB+",
|
||||
"SearchData.FileSize.50mbto200mb=: 50-200MB",
|
||||
"SearchData.FileSize.500kbto100mb=: 500KB-100MB",
|
||||
"SearchData.FileSize.1mbto50mb=: 1-50MB",
|
||||
"SearchData.FileSize.100kbto1mb=: 100KB-1MB",
|
||||
"SearchData.FileSize.16kbto100kb=: 16-100KB",
|
||||
"SearchData.FileSize.upTo500kb=: 0-500KB",
|
||||
"SearchData.FileSize.upTo16kb=: 0-16KB",})
|
||||
public enum FileSize {
|
||||
XXLARGE_VIDEO(0, 10000 * BYTES_PER_MB, -1, Bundle.SearchData_FileSize_XXLARGE_displayName(), Bundle.SearchData_FileSize_10PlusGb()),
|
||||
XLARGE_VIDEO(1, 5000 * BYTES_PER_MB, 10000 * BYTES_PER_MB, Bundle.SearchData_FileSize_XLARGE_displayName(), Bundle.SearchData_FileSize_5gbto10gb()),
|
||||
LARGE_VIDEO(2, 1000 * BYTES_PER_MB, 5000 * BYTES_PER_MB, Bundle.SearchData_FileSize_LARGE_displayName(), Bundle.SearchData_FileSize_1gbto5gb()),
|
||||
MEDIUM_VIDEO(3, 100 * BYTES_PER_MB, 1000 * BYTES_PER_MB, Bundle.SearchData_FileSize_MEDIUM_displayName(), Bundle.SearchData_FileSize_100mbto1gb()),
|
||||
SMALL_VIDEO(4, 500000, 100 * BYTES_PER_MB, Bundle.SearchData_FileSize_SMALL_displayName(), Bundle.SearchData_FileSize_500kbto100mb()),
|
||||
XSMALL_VIDEO(5, 0, 500000, Bundle.SearchData_FileSize_XSMALL_displayName(), Bundle.SearchData_FileSize_upTo500kb()),
|
||||
XXLARGE_IMAGE(6, 200 * BYTES_PER_MB, -1, Bundle.SearchData_FileSize_XXLARGE_displayName(), Bundle.SearchData_FileSize_200PlusMb()),
|
||||
XLARGE_IMAGE(7, 50 * BYTES_PER_MB, 200 * BYTES_PER_MB, Bundle.SearchData_FileSize_XLARGE_displayName(), Bundle.SearchData_FileSize_50mbto200mb()),
|
||||
LARGE_IMAGE(8, 1 * BYTES_PER_MB, 50 * BYTES_PER_MB, Bundle.SearchData_FileSize_LARGE_displayName(), Bundle.SearchData_FileSize_1mbto50mb()),
|
||||
MEDIUM_IMAGE(9, 100000, 1 * BYTES_PER_MB, Bundle.SearchData_FileSize_MEDIUM_displayName(), Bundle.SearchData_FileSize_100kbto1mb()),
|
||||
SMALL_IMAGE(10, 16000, 100000, Bundle.SearchData_FileSize_SMALL_displayName(), Bundle.SearchData_FileSize_16kbto100kb()),
|
||||
XSMALL_IMAGE(11, 0, 16000, Bundle.SearchData_FileSize_XSMALL_displayName(), Bundle.SearchData_FileSize_upTo16kb());
|
||||
|
||||
private final int ranking; // Must be unique for each value
|
||||
private final long minBytes; // Note that the size must be strictly greater than this to match
|
||||
private final long maxBytes;
|
||||
private final String sizeGroup;
|
||||
private final String displaySize;
|
||||
final static long NO_MAXIMUM = -1;
|
||||
|
||||
FileSize(int ranking, long minB, long maxB, String displayName, String displaySize) {
|
||||
this.ranking = ranking;
|
||||
this.minBytes = minB;
|
||||
if (maxB >= 0) {
|
||||
this.maxBytes = maxB;
|
||||
} else {
|
||||
this.maxBytes = NO_MAXIMUM;
|
||||
}
|
||||
this.sizeGroup = displayName;
|
||||
this.displaySize = displaySize;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the enum corresponding to the given file size for image files.
|
||||
* The file size must be strictly greater than minBytes.
|
||||
*
|
||||
* @param size the file size
|
||||
*
|
||||
* @return the enum whose range contains the file size
|
||||
*/
|
||||
public static FileSize fromImageSize(long size) {
|
||||
if (size > XXLARGE_IMAGE.getMinBytes()) {
|
||||
return XXLARGE_IMAGE;
|
||||
} else if (size > XLARGE_IMAGE.getMinBytes()) {
|
||||
return XLARGE_IMAGE;
|
||||
} else if (size > LARGE_IMAGE.getMinBytes()) {
|
||||
return LARGE_IMAGE;
|
||||
} else if (size > MEDIUM_IMAGE.getMinBytes()) {
|
||||
return MEDIUM_IMAGE;
|
||||
} else if (size > SMALL_IMAGE.getMinBytes()) {
|
||||
return SMALL_IMAGE;
|
||||
} else {
|
||||
return XSMALL_IMAGE;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the enum corresponding to the given file size for video files.
|
||||
* The file size must be strictly greater than minBytes.
|
||||
*
|
||||
* @param size the file size
|
||||
*
|
||||
* @return the enum whose range contains the file size
|
||||
*/
|
||||
public static FileSize fromVideoSize(long size) {
|
||||
if (size > XXLARGE_VIDEO.getMinBytes()) {
|
||||
return XXLARGE_VIDEO;
|
||||
} else if (size > XLARGE_VIDEO.getMinBytes()) {
|
||||
return XLARGE_VIDEO;
|
||||
} else if (size > LARGE_VIDEO.getMinBytes()) {
|
||||
return LARGE_VIDEO;
|
||||
} else if (size > MEDIUM_VIDEO.getMinBytes()) {
|
||||
return MEDIUM_VIDEO;
|
||||
} else if (size > SMALL_VIDEO.getMinBytes()) {
|
||||
return SMALL_VIDEO;
|
||||
} else {
|
||||
return XSMALL_VIDEO;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the upper limit of the range.
|
||||
*
|
||||
* @return the maximum file size that will fit in this range.
|
||||
*/
|
||||
public long getMaxBytes() {
|
||||
return maxBytes;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the lower limit of the range.
|
||||
*
|
||||
* @return the maximum file size that is not part of this range
|
||||
*/
|
||||
public long getMinBytes() {
|
||||
return minBytes;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the rank for sorting.
|
||||
*
|
||||
* @return the rank (lower should be displayed first)
|
||||
*/
|
||||
public int getRanking() {
|
||||
return ranking;
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return sizeGroup + displaySize;
|
||||
}
|
||||
|
||||
public String getSizeGroup() {
|
||||
return sizeGroup;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the list of enums that are valid for most file sizes.
|
||||
*
|
||||
* @return Enums that can be used to filter most file including images
|
||||
* by size.
|
||||
*/
|
||||
public static List<FileSize> getDefaultSizeOptions() {
|
||||
return Arrays.asList(XXLARGE_IMAGE, XLARGE_IMAGE, LARGE_IMAGE, MEDIUM_IMAGE, SMALL_IMAGE, XSMALL_IMAGE);
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the list of enums that are valid for video sizes.
|
||||
*
|
||||
* @return enums that can be used to filter videos by size.
|
||||
*/
|
||||
public static List<FileSize> getOptionsForVideos() {
|
||||
return Arrays.asList(XXLARGE_VIDEO, XLARGE_VIDEO, LARGE_VIDEO, MEDIUM_VIDEO, SMALL_VIDEO, XSMALL_VIDEO);
|
||||
}
|
||||
}
|
||||
|
||||
//Discovery uses a different list of document mime types than FileTypeUtils.FileTypeCategory.DOCUMENTS
|
||||
private static final ImmutableSet<String> DOCUMENT_MIME_TYPES
|
||||
= new ImmutableSet.Builder<String>()
|
||||
.add("text/html", //NON-NLS
|
||||
"text/csv", //NON-NLS
|
||||
"application/rtf", //NON-NLS
|
||||
"application/pdf", //NON-NLS
|
||||
"application/xhtml+xml", //NON-NLS
|
||||
"application/x-msoffice", //NON-NLS
|
||||
"application/msword", //NON-NLS
|
||||
"application/msword2", //NON-NLS
|
||||
"application/vnd.wordperfect", //NON-NLS
|
||||
"application/vnd.openxmlformats-officedocument.wordprocessingml.document", //NON-NLS
|
||||
"application/vnd.ms-powerpoint", //NON-NLS
|
||||
"application/vnd.openxmlformats-officedocument.presentationml.presentation", //NON-NLS
|
||||
"application/vnd.ms-excel", //NON-NLS
|
||||
"application/vnd.ms-excel.sheet.4", //NON-NLS
|
||||
"application/vnd.openxmlformats-officedocument.spreadsheetml.sheet", //NON-NLS
|
||||
"application/vnd.oasis.opendocument.presentation", //NON-NLS
|
||||
"application/vnd.oasis.opendocument.spreadsheet", //NON-NLS
|
||||
"application/vnd.oasis.opendocument.text" //NON-NLS
|
||||
).build();
|
||||
|
||||
private static final ImmutableSet<String> IMAGE_UNSUPPORTED_DOC_TYPES
|
||||
= new ImmutableSet.Builder<String>()
|
||||
.add("application/pdf", //NON-NLS
|
||||
"application/xhtml+xml").build(); //NON-NLS
|
||||
|
||||
public static Collection<String> getDocTypesWithoutImageExtraction() {
|
||||
return Collections.unmodifiableCollection(IMAGE_UNSUPPORTED_DOC_TYPES);
|
||||
}
|
||||
|
||||
/**
|
||||
* Enum representing the type.
|
||||
*/
|
||||
@NbBundle.Messages({
|
||||
"SearchData.FileType.Audio.displayName=Audio",
|
||||
"SearchData.FileType.Video.displayName=Video",
|
||||
"SearchData.FileType.Image.displayName=Image",
|
||||
"SearchData.FileType.Documents.displayName=Documents",
|
||||
"SearchData.FileType.Executables.displayName=Executables",
|
||||
"SearchData.AttributeType.Domain.displayName=Domains",
|
||||
"SearchData.FileType.Other.displayName=Other/Unknown"})
|
||||
public enum Type {
|
||||
|
||||
IMAGE(0, Bundle.SearchData_FileType_Image_displayName(), FileTypeUtils.FileTypeCategory.IMAGE.getMediaTypes(), new ArrayList<>()),
|
||||
AUDIO(1, Bundle.SearchData_FileType_Audio_displayName(), FileTypeUtils.FileTypeCategory.AUDIO.getMediaTypes(), new ArrayList<>()),
|
||||
VIDEO(2, Bundle.SearchData_FileType_Video_displayName(), FileTypeUtils.FileTypeCategory.VIDEO.getMediaTypes(), new ArrayList<>()),
|
||||
EXECUTABLE(3, Bundle.SearchData_FileType_Executables_displayName(), FileTypeUtils.FileTypeCategory.EXECUTABLE.getMediaTypes(),new ArrayList<>()),
|
||||
DOCUMENTS(4, Bundle.SearchData_FileType_Documents_displayName(), DOCUMENT_MIME_TYPES, new ArrayList<>()),
|
||||
DOMAIN(6, Bundle.SearchData_AttributeType_Domain_displayName(), new ArrayList<>(), DOMAIN_ARTIFACT_TYPES),
|
||||
OTHER(5, Bundle.SearchData_FileType_Other_displayName(), new ArrayList<>(), new ArrayList<>());
|
||||
|
||||
|
||||
private final int ranking; // For ordering in the UI
|
||||
private final String displayName;
|
||||
private final Collection<String> mediaTypes;
|
||||
private final Collection<BlackboardArtifact.ARTIFACT_TYPE> artifactTypes;
|
||||
|
||||
Type(int value, String displayName, Collection<String> mediaTypes, Collection<BlackboardArtifact.ARTIFACT_TYPE> artifactTypes) {
|
||||
this.ranking = value;
|
||||
this.displayName = displayName;
|
||||
this.mediaTypes = mediaTypes;
|
||||
this.artifactTypes = artifactTypes;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the MIME types matching this category.
|
||||
*
|
||||
* @return Collection of MIME type strings
|
||||
*/
|
||||
public Collection<String> getMediaTypes() {
|
||||
return Collections.unmodifiableCollection(mediaTypes);
|
||||
}
|
||||
|
||||
public Collection<BlackboardArtifact.ARTIFACT_TYPE> getArtifactTypes() {
|
||||
return Collections.unmodifiableCollection(artifactTypes);
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return displayName;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the rank for sorting.
|
||||
*
|
||||
* @return the rank (lower should be displayed first)
|
||||
*/
|
||||
public int getRanking() {
|
||||
return ranking;
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
/**
|
||||
* Enum representing the score of the item.
|
||||
*/
|
||||
@NbBundle.Messages({
|
||||
"SearchData.Score.notable.displayName=Notable",
|
||||
"SearchData.Score.interesting.displayName=Interesting",
|
||||
"SearchData.Score.unknown.displayName=Unknown",})
|
||||
public enum Score {
|
||||
NOTABLE(0, Bundle.SearchData_Score_notable_displayName()),
|
||||
INTERESTING(1, Bundle.SearchData_Score_interesting_displayName()),
|
||||
UNKNOWN(2, Bundle.SearchData_Score_unknown_displayName());
|
||||
|
||||
private final int ranking;
|
||||
private final String displayName;
|
||||
|
||||
Score(int ranking, String displayName) {
|
||||
this.ranking = ranking;
|
||||
this.displayName = displayName;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the rank for sorting.
|
||||
*
|
||||
* @return the rank (lower should be displayed first)
|
||||
*/
|
||||
public int getRanking() {
|
||||
return ranking;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the list of enums that are valid for filtering.
|
||||
*
|
||||
* @return enums that can be used to filter
|
||||
*/
|
||||
public static List<Score> getOptionsForFiltering() {
|
||||
return Arrays.asList(NOTABLE, INTERESTING);
|
||||
}
|
||||
|
||||
@Override
|
||||
public String toString() {
|
||||
return displayName;
|
||||
}
|
||||
}
|
||||
|
||||
private SearchData() {
|
||||
// Class should not be instantiated
|
||||
}
|
||||
}
|
||||
|
||||
@@ -21,10 +21,10 @@ package org.sleuthkit.autopsy.discovery.search;
|
||||
import org.sleuthkit.autopsy.centralrepository.datamodel.CorrelationAttributeInstance;
|
||||
import org.sleuthkit.autopsy.centralrepository.datamodel.CorrelationAttributeNormalizationException;
|
||||
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepoException;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData.FileSize;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData.FileType;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData.Frequency;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData.Score;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData.FileSize;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData.Type;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData.Frequency;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData.Score;
|
||||
import org.sleuthkit.datamodel.AbstractFile;
|
||||
import org.sleuthkit.datamodel.DataSource;
|
||||
import org.sleuthkit.datamodel.SleuthkitCase;
|
||||
@@ -54,9 +54,9 @@ public class SearchFiltering {
|
||||
*
|
||||
* @return
|
||||
*/
|
||||
static List<ResultFile> runQueries(List<AbstractFilter> filters, SleuthkitCase caseDb, CentralRepository centralRepoDb) throws FileSearchException {
|
||||
static List<ResultFile> runQueries(List<AbstractFilter> filters, SleuthkitCase caseDb, CentralRepository centralRepoDb) throws DiscoveryException {
|
||||
if (caseDb == null) {
|
||||
throw new FileSearchException("Case DB parameter is null"); // NON-NLS
|
||||
throw new DiscoveryException("Case DB parameter is null"); // NON-NLS
|
||||
}
|
||||
// Combine all the SQL queries from the filters into one query
|
||||
String combinedQuery = "";
|
||||
@@ -71,12 +71,12 @@ public class SearchFiltering {
|
||||
|
||||
if (combinedQuery.isEmpty()) {
|
||||
// The file search filter is required, so this should never be empty.
|
||||
throw new FileSearchException("Selected filters do not include a case database query");
|
||||
throw new DiscoveryException("Selected filters do not include a case database query");
|
||||
}
|
||||
try {
|
||||
return getResultList(filters, combinedQuery, caseDb, centralRepoDb);
|
||||
} catch (TskCoreException ex) {
|
||||
throw new FileSearchException("Error querying case database", ex); // NON-NLS
|
||||
throw new DiscoveryException("Error querying case database", ex); // NON-NLS
|
||||
}
|
||||
}
|
||||
|
||||
@@ -92,9 +92,9 @@ public class SearchFiltering {
|
||||
* @return An ArrayList of ResultFiles returned by the query.
|
||||
*
|
||||
* @throws TskCoreException
|
||||
* @throws FileSearchException
|
||||
* @throws DiscoveryException
|
||||
*/
|
||||
private static List<ResultFile> getResultList(List<AbstractFilter> filters, String combinedQuery, SleuthkitCase caseDb, CentralRepository centralRepoDb) throws TskCoreException, FileSearchException {
|
||||
private static List<ResultFile> getResultList(List<AbstractFilter> filters, String combinedQuery, SleuthkitCase caseDb, CentralRepository centralRepoDb) throws TskCoreException, DiscoveryException {
|
||||
// Get all matching abstract files
|
||||
List<ResultFile> resultList = new ArrayList<>();
|
||||
List<AbstractFile> sqlResults = caseDb.findAllFilesWhere(combinedQuery);
|
||||
@@ -431,14 +431,14 @@ public class SearchFiltering {
|
||||
*/
|
||||
public static class FileTypeFilter extends AbstractFilter {
|
||||
|
||||
private final List<FileType> categories;
|
||||
private final List<Type> categories;
|
||||
|
||||
/**
|
||||
* Create the FileTypeFilter
|
||||
*
|
||||
* @param categories List of file types to filter on
|
||||
*/
|
||||
public FileTypeFilter(List<FileType> categories) {
|
||||
public FileTypeFilter(List<Type> categories) {
|
||||
this.categories = categories;
|
||||
}
|
||||
|
||||
@@ -447,7 +447,7 @@ public class SearchFiltering {
|
||||
*
|
||||
* @param category the file type to filter on
|
||||
*/
|
||||
public FileTypeFilter(FileType category) {
|
||||
public FileTypeFilter(Type category) {
|
||||
this.categories = new ArrayList<>();
|
||||
this.categories.add(category);
|
||||
}
|
||||
@@ -455,7 +455,7 @@ public class SearchFiltering {
|
||||
@Override
|
||||
public String getWhereClause() {
|
||||
String queryStr = ""; // NON-NLS
|
||||
for (FileType cat : categories) {
|
||||
for (Type cat : categories) {
|
||||
for (String type : cat.getMediaTypes()) {
|
||||
if (!queryStr.isEmpty()) {
|
||||
queryStr += ","; // NON-NLS
|
||||
@@ -474,7 +474,7 @@ public class SearchFiltering {
|
||||
@Override
|
||||
public String getDesc() {
|
||||
String desc = "";
|
||||
for (FileType cat : categories) {
|
||||
for (Type cat : categories) {
|
||||
if (!desc.isEmpty()) {
|
||||
desc += Bundle.SearchFiltering_FileTypeFilter_or();
|
||||
}
|
||||
@@ -515,12 +515,12 @@ public class SearchFiltering {
|
||||
|
||||
@Override
|
||||
public List<ResultFile> applyAlternateFilter(List<ResultFile> currentResults, SleuthkitCase caseDb,
|
||||
CentralRepository centralRepoDb) throws FileSearchException {
|
||||
CentralRepository centralRepoDb) throws DiscoveryException {
|
||||
|
||||
// We have to have run some kind of SQL filter before getting to this point,
|
||||
// and should have checked afterward to see if the results were empty.
|
||||
if (currentResults.isEmpty()) {
|
||||
throw new FileSearchException("Can not run on empty list"); // NON-NLS
|
||||
throw new DiscoveryException("Can not run on empty list"); // NON-NLS
|
||||
}
|
||||
|
||||
// Set the frequency for each file
|
||||
@@ -835,16 +835,16 @@ public class SearchFiltering {
|
||||
|
||||
@Override
|
||||
public List<ResultFile> applyAlternateFilter(List<ResultFile> currentResults, SleuthkitCase caseDb,
|
||||
CentralRepository centralRepoDb) throws FileSearchException {
|
||||
CentralRepository centralRepoDb) throws DiscoveryException {
|
||||
|
||||
if (centralRepoDb == null) {
|
||||
throw new FileSearchException("Can not run Previously Notable filter with null Central Repository DB"); // NON-NLS
|
||||
throw new DiscoveryException("Can not run Previously Notable filter with null Central Repository DB"); // NON-NLS
|
||||
}
|
||||
|
||||
// We have to have run some kind of SQL filter before getting to this point,
|
||||
// and should have checked afterward to see if the results were empty.
|
||||
if (currentResults.isEmpty()) {
|
||||
throw new FileSearchException("Can not run on empty list"); // NON-NLS
|
||||
throw new DiscoveryException("Can not run on empty list"); // NON-NLS
|
||||
}
|
||||
|
||||
// The matching files
|
||||
@@ -865,7 +865,7 @@ public class SearchFiltering {
|
||||
}
|
||||
return notableResults;
|
||||
} catch (CentralRepoException | CorrelationAttributeNormalizationException ex) {
|
||||
throw new FileSearchException("Error querying central repository", ex); // NON-NLS
|
||||
throw new DiscoveryException("Error querying central repository", ex); // NON-NLS
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -32,12 +32,12 @@ import org.sleuthkit.autopsy.discovery.search.DiscoveryKeyUtils.GroupKey;
|
||||
*/
|
||||
class SearchResults {
|
||||
|
||||
private final FileGroup.GroupSortingAlgorithm groupSortingType;
|
||||
private final Group.GroupSortingAlgorithm groupSortingType;
|
||||
private final FileSearch.AttributeType attrType;
|
||||
private final FileSorter fileSorter;
|
||||
|
||||
private final Map<GroupKey, FileGroup> groupMap = new HashMap<>();
|
||||
private List<FileGroup> groupList = new ArrayList<>();
|
||||
private final Map<GroupKey, Group> groupMap = new HashMap<>();
|
||||
private List<Group> groupList = new ArrayList<>();
|
||||
|
||||
private static final long MAX_OUTPUT_FILES = 2000; // For debug UI - maximum number of lines to print
|
||||
|
||||
@@ -50,7 +50,7 @@ class SearchResults {
|
||||
* @param fileSortingMethod The method that should be used to
|
||||
* sortGroupsAndFiles the files in each group.
|
||||
*/
|
||||
SearchResults(FileGroup.GroupSortingAlgorithm groupSortingType, FileSearch.AttributeType attrType,
|
||||
SearchResults(Group.GroupSortingAlgorithm groupSortingType, FileSearch.AttributeType attrType,
|
||||
FileSorter.SortingMethod fileSortingMethod) {
|
||||
this.groupSortingType = groupSortingType;
|
||||
this.attrType = attrType;
|
||||
@@ -62,7 +62,7 @@ class SearchResults {
|
||||
* the search is finished.
|
||||
*/
|
||||
SearchResults() {
|
||||
this.groupSortingType = FileGroup.GroupSortingAlgorithm.BY_GROUP_NAME;
|
||||
this.groupSortingType = Group.GroupSortingAlgorithm.BY_GROUP_NAME;
|
||||
this.attrType = new FileSearch.FileSizeAttribute();
|
||||
this.fileSorter = new FileSorter(FileSorter.SortingMethod.BY_FILE_NAME);
|
||||
}
|
||||
@@ -78,7 +78,7 @@ class SearchResults {
|
||||
GroupKey groupKey = attrType.getGroupKey(file);
|
||||
|
||||
if (!groupMap.containsKey(groupKey)) {
|
||||
groupMap.put(groupKey, new FileGroup(groupSortingType, groupKey));
|
||||
groupMap.put(groupKey, new Group(groupSortingType, groupKey));
|
||||
}
|
||||
groupMap.get(groupKey).addFile(file);
|
||||
}
|
||||
@@ -91,7 +91,7 @@ class SearchResults {
|
||||
void sortGroupsAndFiles() {
|
||||
|
||||
// First sortGroupsAndFiles the files
|
||||
for (FileGroup group : groupMap.values()) {
|
||||
for (Group group : groupMap.values()) {
|
||||
group.sortFiles(fileSorter);
|
||||
}
|
||||
|
||||
@@ -108,7 +108,7 @@ class SearchResults {
|
||||
}
|
||||
|
||||
long count = 0;
|
||||
for (FileGroup group : groupList) {
|
||||
for (Group group : groupList) {
|
||||
result += group.getDisplayName() + "\n";
|
||||
|
||||
for (ResultFile file : group.getFiles()) {
|
||||
@@ -143,7 +143,7 @@ class SearchResults {
|
||||
if (groupName != null) {
|
||||
final String modifiedGroupName = groupName.replaceAll(" \\([0-9]+\\)$", "");
|
||||
|
||||
java.util.Optional<FileGroup> fileGroup = groupList.stream().filter(p -> p.getDisplayName().equals(modifiedGroupName)).findFirst();
|
||||
java.util.Optional<Group> fileGroup = groupList.stream().filter(p -> p.getDisplayName().equals(modifiedGroupName)).findFirst();
|
||||
if (fileGroup.isPresent()) {
|
||||
return fileGroup.get().getFiles();
|
||||
}
|
||||
@@ -156,14 +156,14 @@ class SearchResults {
|
||||
*
|
||||
* @return The grouped and sorted results.
|
||||
*/
|
||||
Map<GroupKey, List<ResultFile>> toLinkedHashMap() throws FileSearchException {
|
||||
Map<GroupKey, List<ResultFile>> toLinkedHashMap() throws DiscoveryException {
|
||||
Map<GroupKey, List<ResultFile>> map = new LinkedHashMap<>();
|
||||
|
||||
// Sort the groups and files
|
||||
sortGroupsAndFiles();
|
||||
|
||||
// groupList is sorted and a LinkedHashMap will preserve that order.
|
||||
for (FileGroup group : groupList) {
|
||||
for (Group group : groupList) {
|
||||
map.put(group.getGroupKey(), group.getFiles());
|
||||
}
|
||||
|
||||
|
||||
@@ -32,8 +32,6 @@ import javax.swing.JSplitPane;
|
||||
import javax.swing.event.ListSelectionEvent;
|
||||
import javax.swing.event.ListSelectionListener;
|
||||
import org.apache.commons.lang3.StringUtils;
|
||||
import org.sleuthkit.autopsy.discovery.search.AttributeSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchFiltering;
|
||||
|
||||
@@ -67,25 +65,11 @@ abstract class AbstractFiltersPanel extends JPanel implements ActionListener, Li
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the broad ResultType, such as files or attributes.
|
||||
* Get the type of results this filters panel is for.
|
||||
*
|
||||
* @return
|
||||
* @return The type of results this panel filters.
|
||||
*/
|
||||
abstract SearchData.ResultType getResultType();
|
||||
|
||||
/**
|
||||
* Get the file type of results this filters panel is for.
|
||||
*
|
||||
* @return The file type of results this panel filters.
|
||||
*/
|
||||
abstract FileSearchData.FileType getFileType();
|
||||
|
||||
/**
|
||||
* Get the attribute type of results this filters panel is for.
|
||||
*
|
||||
* @return The attribute type of results this panel filters.
|
||||
*/
|
||||
abstract AttributeSearchData.AttributeType getArtifactType();
|
||||
abstract SearchData.Type getType();
|
||||
|
||||
/**
|
||||
* Add a DiscoveryFilterPanel to the specified column with the specified
|
||||
@@ -264,10 +248,10 @@ abstract class AbstractFiltersPanel extends JPanel implements ActionListener, Li
|
||||
synchronized List<AbstractFilter> getFilters() {
|
||||
|
||||
List<AbstractFilter> filtersToUse = new ArrayList<>();
|
||||
if (getResultType().equals(SearchData.ResultType.FILE)) {
|
||||
filtersToUse.add(new SearchFiltering.FileTypeFilter(getFileType()));
|
||||
} else if (getResultType().equals(SearchData.ResultType.ATTRIBUTE)) {
|
||||
if (getType().equals(SearchData.Type.DOMAIN)) {
|
||||
|
||||
} else {
|
||||
filtersToUse.add(new SearchFiltering.FileTypeFilter(getType()));
|
||||
}
|
||||
|
||||
for (AbstractDiscoveryFilterPanel filterPanel : filters) {
|
||||
|
||||
@@ -23,7 +23,7 @@ import javax.swing.DefaultListModel;
|
||||
import javax.swing.JCheckBox;
|
||||
import javax.swing.JLabel;
|
||||
import javax.swing.JList;
|
||||
import org.sleuthkit.autopsy.discovery.search.AttributeSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData;
|
||||
import org.sleuthkit.datamodel.BlackboardArtifact;
|
||||
|
||||
/**
|
||||
@@ -49,7 +49,7 @@ class ArtifactTypeFilterPanel extends AbstractDiscoveryFilterPanel {
|
||||
int count = 0;
|
||||
DefaultListModel<ArtifactTypeItem> artifactTypeModel = (DefaultListModel<ArtifactTypeItem>) jList1.getModel();
|
||||
artifactTypeModel.removeAllElements();
|
||||
for (BlackboardArtifact.ARTIFACT_TYPE artifactType : AttributeSearchData.AttributeType.DOMAIN.getBlackboardTypes()) {
|
||||
for (BlackboardArtifact.ARTIFACT_TYPE artifactType : SearchData.Type.DOMAIN.getArtifactTypes()) {
|
||||
artifactTypeModel.add(count, new ArtifactTypeItem(artifactType));
|
||||
count++;
|
||||
}
|
||||
|
||||
@@ -37,15 +37,13 @@ import org.sleuthkit.autopsy.casemodule.NoCurrentCaseException;
|
||||
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepoException;
|
||||
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
|
||||
import org.sleuthkit.autopsy.coreutils.Logger;
|
||||
import org.sleuthkit.autopsy.discovery.search.AttributeSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.DiscoveryEventUtils;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileGroup;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileGroup.GroupSortingAlgorithm;
|
||||
import static org.sleuthkit.autopsy.discovery.search.FileGroup.GroupSortingAlgorithm.BY_GROUP_SIZE;
|
||||
import org.sleuthkit.autopsy.discovery.search.Group;
|
||||
import org.sleuthkit.autopsy.discovery.search.Group.GroupSortingAlgorithm;
|
||||
import static org.sleuthkit.autopsy.discovery.search.Group.GroupSortingAlgorithm.BY_GROUP_SIZE;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearch;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearch.GroupingAttributeType;
|
||||
import static org.sleuthkit.autopsy.discovery.search.FileSearch.GroupingAttributeType.PARENT_PATH;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSorter;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSorter.SortingMethod;
|
||||
import static org.sleuthkit.autopsy.discovery.search.FileSorter.SortingMethod.BY_FILE_NAME;
|
||||
@@ -76,9 +74,7 @@ final class DiscoveryDialog extends javax.swing.JDialog {
|
||||
private SearchWorker searchWorker = null;
|
||||
private static DiscoveryDialog discDialog;
|
||||
private static volatile boolean shouldUpdate = false;
|
||||
private SearchData.ResultType resultType = SearchData.ResultType.FILE;
|
||||
private FileSearchData.FileType fileType = FileSearchData.FileType.IMAGE;
|
||||
private AttributeSearchData.AttributeType artifactType = null;
|
||||
private SearchData.Type type = SearchData.Type.IMAGE;
|
||||
private final PropertyChangeListener listener;
|
||||
private final Set<BlackboardAttribute> objectsDetected = new HashSet<>();
|
||||
private final Set<BlackboardAttribute> interestingItems = new HashSet<>();
|
||||
@@ -140,9 +136,7 @@ final class DiscoveryDialog extends javax.swing.JDialog {
|
||||
imagesButton.setEnabled(false);
|
||||
imagesButton.setBackground(SELECTED_COLOR);
|
||||
imagesButton.setForeground(Color.BLACK);
|
||||
resultType = SearchData.ResultType.FILE;
|
||||
fileType = FileSearchData.FileType.IMAGE;
|
||||
artifactType = null;
|
||||
type = SearchData.Type.IMAGE;
|
||||
add(imageFilterPanel, CENTER);
|
||||
imageFilterPanel.addPropertyChangeListener(listener);
|
||||
updateComboBoxes();
|
||||
@@ -175,8 +169,8 @@ final class DiscoveryDialog extends javax.swing.JDialog {
|
||||
private void updateComboBoxes() {
|
||||
groupByCombobox.removeAllItems();
|
||||
// Set up the grouping attributes
|
||||
for (FileSearch.GroupingAttributeType type : FileSearch.GroupingAttributeType.getOptionsForGrouping()) {
|
||||
addTypeToGroupByComboBox(type);
|
||||
for (FileSearch.GroupingAttributeType groupingType : FileSearch.GroupingAttributeType.getOptionsForGrouping()) {
|
||||
addTypeToGroupByComboBox(groupingType);
|
||||
}
|
||||
groupByCombobox.setSelectedItem(PARENT_PATH);
|
||||
orderByCombobox.removeAllItems();
|
||||
@@ -223,25 +217,11 @@ final class DiscoveryDialog extends javax.swing.JDialog {
|
||||
groupByCombobox.addItem(type);
|
||||
}
|
||||
|
||||
/**
|
||||
* Validate the current filter settings of the selected type.
|
||||
*/
|
||||
synchronized void validateDialog() {
|
||||
switch (resultType) {
|
||||
case FILE:
|
||||
validateFileDialog();
|
||||
break;
|
||||
case ATTRIBUTE:
|
||||
validateArtifactDialog();
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Validate the filter settings for File type filters.
|
||||
*/
|
||||
private synchronized void validateFileDialog() {
|
||||
switch (fileType) {
|
||||
synchronized void validateDialog() {
|
||||
switch (type) {
|
||||
case IMAGE:
|
||||
if (imageFilterPanel != null) {
|
||||
imageFilterPanel.validateFields();
|
||||
@@ -257,16 +237,6 @@ final class DiscoveryDialog extends javax.swing.JDialog {
|
||||
documentFilterPanel.validateFields();
|
||||
}
|
||||
break;
|
||||
default:
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Validate the filter settings for Artifact type filters.
|
||||
*/
|
||||
private synchronized void validateArtifactDialog() {
|
||||
switch (artifactType) {
|
||||
case DOMAIN:
|
||||
if (domainFilterPanel != null) {
|
||||
domainFilterPanel.validateFields();
|
||||
@@ -497,9 +467,7 @@ final class DiscoveryDialog extends javax.swing.JDialog {
|
||||
imagesButton.setEnabled(false);
|
||||
imagesButton.setBackground(SELECTED_COLOR);
|
||||
imagesButton.setForeground(Color.BLACK);
|
||||
resultType = SearchData.ResultType.FILE;
|
||||
artifactType = null;
|
||||
fileType = FileSearchData.FileType.IMAGE;
|
||||
type = SearchData.Type.IMAGE;
|
||||
imageFilterPanel.addPropertyChangeListener(listener);
|
||||
validateDialog();
|
||||
pack();
|
||||
@@ -515,9 +483,7 @@ final class DiscoveryDialog extends javax.swing.JDialog {
|
||||
videosButton.setBackground(SELECTED_COLOR);
|
||||
videosButton.setForeground(Color.BLACK);
|
||||
videoFilterPanel.addPropertyChangeListener(listener);
|
||||
resultType = SearchData.ResultType.FILE;
|
||||
artifactType = null;
|
||||
fileType = FileSearchData.FileType.VIDEO;
|
||||
type = SearchData.Type.VIDEO;
|
||||
validateDialog();
|
||||
pack();
|
||||
repaint();
|
||||
@@ -531,9 +497,7 @@ final class DiscoveryDialog extends javax.swing.JDialog {
|
||||
documentsButton.setEnabled(false);
|
||||
documentsButton.setBackground(SELECTED_COLOR);
|
||||
documentsButton.setForeground(Color.BLACK);
|
||||
resultType = SearchData.ResultType.FILE;
|
||||
artifactType = null;
|
||||
fileType = FileSearchData.FileType.DOCUMENTS;
|
||||
type = SearchData.Type.DOCUMENTS;
|
||||
documentFilterPanel.addPropertyChangeListener(listener);
|
||||
validateDialog();
|
||||
pack();
|
||||
@@ -587,11 +551,11 @@ final class DiscoveryDialog extends javax.swing.JDialog {
|
||||
filters = new ArrayList<>();
|
||||
}
|
||||
|
||||
DiscoveryEventUtils.getDiscoveryEventBus().post(new DiscoveryEventUtils.SearchStartedEvent(resultType, fileType, artifactType));
|
||||
DiscoveryEventUtils.getDiscoveryEventBus().post(new DiscoveryEventUtils.SearchStartedEvent(type));
|
||||
|
||||
// Get the grouping attribute and group sorting method
|
||||
FileSearch.AttributeType groupingAttr = groupByCombobox.getItemAt(groupByCombobox.getSelectedIndex()).getAttributeType();
|
||||
FileGroup.GroupSortingAlgorithm groupSortAlgorithm = groupSortingComboBox.getItemAt(groupSortingComboBox.getSelectedIndex());
|
||||
Group.GroupSortingAlgorithm groupSortAlgorithm = groupSortingComboBox.getItemAt(groupSortingComboBox.getSelectedIndex());
|
||||
|
||||
// Get the file sorting method
|
||||
FileSorter.SortingMethod fileSort = (FileSorter.SortingMethod) orderByCombobox.getSelectedItem();
|
||||
@@ -619,9 +583,7 @@ final class DiscoveryDialog extends javax.swing.JDialog {
|
||||
domainsButton.setEnabled(false);
|
||||
domainsButton.setBackground(SELECTED_COLOR);
|
||||
domainsButton.setForeground(Color.BLACK);
|
||||
resultType = SearchData.ResultType.ATTRIBUTE;
|
||||
artifactType = AttributeSearchData.AttributeType.DOMAIN;
|
||||
fileType = null;
|
||||
type = SearchData.Type.DOMAIN;
|
||||
documentFilterPanel.addPropertyChangeListener(listener);
|
||||
validateDialog();
|
||||
pack();
|
||||
|
||||
@@ -38,7 +38,6 @@ import org.openide.windows.TopComponent;
|
||||
import org.openide.windows.WindowManager;
|
||||
import org.sleuthkit.autopsy.coreutils.ThreadConfined;
|
||||
import org.sleuthkit.autopsy.discovery.search.DiscoveryEventUtils;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData.ResultType;
|
||||
|
||||
/**
|
||||
* Create a dialog for displaying the Discovery results.
|
||||
@@ -286,13 +285,7 @@ public final class DiscoveryTopComponent extends TopComponent {
|
||||
void handleSearchStartedEvent(DiscoveryEventUtils.SearchStartedEvent searchStartedEvent) {
|
||||
newSearchButton.setText(Bundle.DiscoveryTopComponent_cancelButton_text());
|
||||
progressMessageTextArea.setForeground(Color.red);
|
||||
String text = Bundle.DiscoveryTopComponent_searchError_text();
|
||||
if (searchStartedEvent.getResultType() == ResultType.FILE) {
|
||||
text = Bundle.DiscoveryTopComponent_searchInProgress_text(searchStartedEvent.getFileType().name());
|
||||
} else if (searchStartedEvent.getResultType() == ResultType.ATTRIBUTE) {
|
||||
text = Bundle.DiscoveryTopComponent_searchInProgress_text(searchStartedEvent.getAttributeType().name());
|
||||
}
|
||||
progressMessageTextArea.setText(text);
|
||||
progressMessageTextArea.setText(Bundle.DiscoveryTopComponent_searchInProgress_text(searchStartedEvent.getType().name()));
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
@@ -19,8 +19,6 @@
|
||||
package org.sleuthkit.autopsy.discovery.ui;
|
||||
|
||||
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
|
||||
import org.sleuthkit.autopsy.discovery.search.AttributeSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData;
|
||||
|
||||
/**
|
||||
@@ -29,7 +27,7 @@ import org.sleuthkit.autopsy.discovery.search.SearchData;
|
||||
final class DocumentFilterPanel extends AbstractFiltersPanel {
|
||||
|
||||
private static final long serialVersionUID = 1L;
|
||||
private static final FileSearchData.FileType FILE_TYPE = FileSearchData.FileType.DOCUMENTS;
|
||||
private static final SearchData.Type TYPE = SearchData.Type.DOCUMENTS;
|
||||
|
||||
/**
|
||||
* Constructs a new DocumentFilterPanel.
|
||||
@@ -37,7 +35,7 @@ final class DocumentFilterPanel extends AbstractFiltersPanel {
|
||||
DocumentFilterPanel() {
|
||||
super();
|
||||
initComponents();
|
||||
SizeFilterPanel sizeFilterPanel = new SizeFilterPanel(FILE_TYPE);
|
||||
SizeFilterPanel sizeFilterPanel = new SizeFilterPanel(TYPE);
|
||||
int[] sizeIndicesSelected = {3, 4, 5};
|
||||
addFilter(sizeFilterPanel, true, sizeIndicesSelected, 0);
|
||||
addFilter(new DataSourceFilterPanel(), false, null, 0);
|
||||
@@ -47,7 +45,7 @@ final class DocumentFilterPanel extends AbstractFiltersPanel {
|
||||
} else {
|
||||
pastOccurrencesIndices = new int[]{2, 3, 4};
|
||||
}
|
||||
addFilter(new PastOccurrencesFilterPanel(), true, pastOccurrencesIndices, 0);
|
||||
addFilter(new PastOccurrencesFilterPanel(TYPE), true, pastOccurrencesIndices, 0);
|
||||
addFilter(new HashSetFilterPanel(), false, null, 1);
|
||||
addFilter(new InterestingItemsFilterPanel(), false, null, 1);
|
||||
addFilter(new ParentFolderFilterPanel(), false, null, 1);
|
||||
@@ -94,21 +92,11 @@ final class DocumentFilterPanel extends AbstractFiltersPanel {
|
||||
add(documentFiltersScrollPane, java.awt.BorderLayout.CENTER);
|
||||
}// </editor-fold>//GEN-END:initComponents
|
||||
@Override
|
||||
FileSearchData.FileType getFileType() {
|
||||
return FILE_TYPE;
|
||||
SearchData.Type getType() {
|
||||
return TYPE;
|
||||
}
|
||||
// Variables declaration - do not modify//GEN-BEGIN:variables
|
||||
private javax.swing.JSplitPane documentsFiltersSplitPane;
|
||||
// End of variables declaration//GEN-END:variables
|
||||
|
||||
@Override
|
||||
SearchData.ResultType getResultType() {
|
||||
return SearchData.ResultType.FILE;
|
||||
}
|
||||
|
||||
@Override
|
||||
AttributeSearchData.AttributeType getArtifactType() {
|
||||
throw new UnsupportedOperationException("Not supported yet."); //To change body of generated methods, choose Tools | Templates.
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
@@ -29,7 +29,7 @@ import javax.swing.JList;
|
||||
import javax.swing.ListCellRenderer;
|
||||
import org.openide.util.NbBundle.Messages;
|
||||
import org.sleuthkit.autopsy.corecomponents.AutoWrappingJTextPane;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData;
|
||||
|
||||
/**
|
||||
* Class which displays a preview and details about a document.
|
||||
@@ -164,7 +164,7 @@ class DocumentPanel extends javax.swing.JPanel implements ListCellRenderer<Docum
|
||||
if (value.getSummary().getNumberOfImages() > 0) {
|
||||
numberOfImagesLabel.setText(Bundle.DocumentPanel_numberOfImages_text(value.getSummary().getNumberOfImages()));
|
||||
sampleImageLabel.setIcon(new ImageIcon(value.getSummary().getSampleImage()));
|
||||
} else if (FileSearchData.getDocTypesWithoutImageExtraction().contains(value.getResultFile().getFirstInstance().getMIMEType())) {
|
||||
} else if (SearchData.getDocTypesWithoutImageExtraction().contains(value.getResultFile().getFirstInstance().getMIMEType())) {
|
||||
numberOfImagesLabel.setText(Bundle.DocumentPanel_noImageExtraction_text());
|
||||
sampleImageLabel.setIcon(DiscoveryUiUtils.getUnsupportedImageThumbnail());
|
||||
} else {
|
||||
|
||||
@@ -19,8 +19,6 @@
|
||||
package org.sleuthkit.autopsy.discovery.ui;
|
||||
|
||||
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
|
||||
import org.sleuthkit.autopsy.discovery.search.AttributeSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData;
|
||||
|
||||
/**
|
||||
@@ -29,7 +27,7 @@ import org.sleuthkit.autopsy.discovery.search.SearchData;
|
||||
public class DomainFilterPanel extends AbstractFiltersPanel {
|
||||
|
||||
private static final long serialVersionUID = 1L;
|
||||
private static final AttributeSearchData.AttributeType ARTIFACT_TYPE = AttributeSearchData.AttributeType.DOMAIN;
|
||||
private static final SearchData.Type TYPE = SearchData.Type.DOMAIN;
|
||||
|
||||
/**
|
||||
* Creates new form DomainFilterPanel.
|
||||
@@ -44,7 +42,7 @@ public class DomainFilterPanel extends AbstractFiltersPanel {
|
||||
if (CentralRepository.isEnabled()) {
|
||||
pastOccurrencesIndices = new int[]{2, 3, 4};
|
||||
}
|
||||
addFilter(new PastOccurrencesFilterPanel(SearchData.ResultType.ATTRIBUTE), true, pastOccurrencesIndices, 0);
|
||||
addFilter(new PastOccurrencesFilterPanel(TYPE), true, pastOccurrencesIndices, 0);
|
||||
addPanelsToScrollPane(domainFiltersSplitPane);
|
||||
}
|
||||
|
||||
@@ -91,19 +89,10 @@ public class DomainFilterPanel extends AbstractFiltersPanel {
|
||||
}// </editor-fold>//GEN-END:initComponents
|
||||
|
||||
@Override
|
||||
FileSearchData.FileType getFileType() {
|
||||
throw new UnsupportedOperationException("Not supported yet."); //To change body of generated methods, choose Tools | Templates.
|
||||
SearchData.Type getType() {
|
||||
return TYPE;
|
||||
}
|
||||
|
||||
@Override
|
||||
SearchData.ResultType getResultType() {
|
||||
return SearchData.ResultType.ATTRIBUTE;
|
||||
}
|
||||
|
||||
@Override
|
||||
AttributeSearchData.AttributeType getArtifactType() {
|
||||
return ARTIFACT_TYPE;
|
||||
}
|
||||
|
||||
|
||||
// Variables declaration - do not modify//GEN-BEGIN:variables
|
||||
|
||||
@@ -31,9 +31,9 @@ import javax.swing.SwingUtilities;
|
||||
import org.openide.util.NbBundle.Messages;
|
||||
import org.sleuthkit.autopsy.discovery.search.DiscoveryEventUtils;
|
||||
import org.sleuthkit.autopsy.discovery.search.DiscoveryKeyUtils.GroupKey;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileGroup;
|
||||
import org.sleuthkit.autopsy.discovery.search.Group;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearch;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData.FileType;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData.Type;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSorter;
|
||||
|
||||
/**
|
||||
@@ -42,11 +42,11 @@ import org.sleuthkit.autopsy.discovery.search.FileSorter;
|
||||
final class GroupListPanel extends javax.swing.JPanel {
|
||||
|
||||
private static final long serialVersionUID = 1L;
|
||||
private FileType fileType = null;
|
||||
private Type type = null;
|
||||
private Map<GroupKey, Integer> groupMap = null;
|
||||
private List<AbstractFilter> searchfilters;
|
||||
private FileSearch.AttributeType groupingAttribute;
|
||||
private FileGroup.GroupSortingAlgorithm groupSort;
|
||||
private Group.GroupSortingAlgorithm groupSort;
|
||||
private FileSorter.SortingMethod fileSortMethod;
|
||||
private GroupKey selectedGroupKey;
|
||||
|
||||
@@ -64,7 +64,7 @@ final class GroupListPanel extends javax.swing.JPanel {
|
||||
*/
|
||||
@Subscribe
|
||||
void handleSearchStartedEvent(DiscoveryEventUtils.SearchStartedEvent searchStartedEvent) {
|
||||
fileType = searchStartedEvent.getFileType();
|
||||
type = searchStartedEvent.getType();
|
||||
groupKeyList.setListData(new GroupKey[0]);
|
||||
}
|
||||
|
||||
@@ -175,7 +175,7 @@ final class GroupListPanel extends javax.swing.JPanel {
|
||||
if (selectedGroup.equals(groupKey)) {
|
||||
selectedGroupKey = groupKey;
|
||||
DiscoveryEventUtils.getDiscoveryEventBus().post(new DiscoveryEventUtils.GroupSelectedEvent(
|
||||
searchfilters, groupingAttribute, groupSort, fileSortMethod, selectedGroupKey, groupMap.get(selectedGroupKey), fileType));
|
||||
searchfilters, groupingAttribute, groupSort, fileSortMethod, selectedGroupKey, groupMap.get(selectedGroupKey), type));
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -19,8 +19,6 @@
|
||||
package org.sleuthkit.autopsy.discovery.ui;
|
||||
|
||||
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
|
||||
import org.sleuthkit.autopsy.discovery.search.AttributeSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData;
|
||||
|
||||
/**
|
||||
@@ -29,7 +27,7 @@ import org.sleuthkit.autopsy.discovery.search.SearchData;
|
||||
final class ImageFilterPanel extends AbstractFiltersPanel {
|
||||
|
||||
private static final long serialVersionUID = 1L;
|
||||
private static final FileSearchData.FileType FILE_TYPE = FileSearchData.FileType.IMAGE;
|
||||
private static final SearchData.Type TYPE = SearchData.Type.IMAGE;
|
||||
|
||||
/**
|
||||
* Creates new form ImageFilterPanel.
|
||||
@@ -37,7 +35,7 @@ final class ImageFilterPanel extends AbstractFiltersPanel {
|
||||
ImageFilterPanel() {
|
||||
super();
|
||||
initComponents();
|
||||
SizeFilterPanel sizeFilterPanel = new SizeFilterPanel(FILE_TYPE);
|
||||
SizeFilterPanel sizeFilterPanel = new SizeFilterPanel(TYPE);
|
||||
int[] sizeIndicesSelected = {3, 4, 5};
|
||||
addFilter(sizeFilterPanel, true, sizeIndicesSelected, 0);
|
||||
addFilter(new DataSourceFilterPanel(), false, null, 0);
|
||||
@@ -47,7 +45,7 @@ final class ImageFilterPanel extends AbstractFiltersPanel {
|
||||
} else {
|
||||
pastOccurrencesIndices = new int[]{2, 3, 4};
|
||||
}
|
||||
addFilter(new PastOccurrencesFilterPanel(), true, pastOccurrencesIndices, 0);
|
||||
addFilter(new PastOccurrencesFilterPanel(TYPE), true, pastOccurrencesIndices, 0);
|
||||
addFilter(new UserCreatedFilterPanel(), false, null, 1);
|
||||
addFilter(new HashSetFilterPanel(), false, null, 1);
|
||||
addFilter(new InterestingItemsFilterPanel(), false, null, 1);
|
||||
@@ -99,21 +97,12 @@ final class ImageFilterPanel extends AbstractFiltersPanel {
|
||||
}// </editor-fold>//GEN-END:initComponents
|
||||
|
||||
@Override
|
||||
FileSearchData.FileType getFileType() {
|
||||
return FILE_TYPE;
|
||||
SearchData.Type getType() {
|
||||
return TYPE;
|
||||
}
|
||||
|
||||
// Variables declaration - do not modify//GEN-BEGIN:variables
|
||||
private javax.swing.JSplitPane imageFiltersSplitPane;
|
||||
// End of variables declaration//GEN-END:variables
|
||||
|
||||
@Override
|
||||
SearchData.ResultType getResultType() {
|
||||
return SearchData.ResultType.FILE;
|
||||
}
|
||||
|
||||
@Override
|
||||
AttributeSearchData.AttributeType getArtifactType() {
|
||||
throw new UnsupportedOperationException("Not supported yet."); //To change body of generated methods, choose Tools | Templates.
|
||||
}
|
||||
}
|
||||
|
||||
@@ -28,10 +28,10 @@ import org.sleuthkit.autopsy.coreutils.Logger;
|
||||
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
|
||||
import org.sleuthkit.autopsy.discovery.search.DiscoveryEventUtils;
|
||||
import org.sleuthkit.autopsy.discovery.search.DiscoveryKeyUtils.GroupKey;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileGroup;
|
||||
import org.sleuthkit.autopsy.discovery.search.Group;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearch;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchException;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.DiscoveryException;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSorter;
|
||||
import org.sleuthkit.autopsy.discovery.search.ResultFile;
|
||||
|
||||
@@ -44,12 +44,12 @@ final class PageWorker extends SwingWorker<Void, Void> {
|
||||
private static final String USER_NAME_PROPERTY = "user.name"; //NON-NLS
|
||||
private final List<AbstractFilter> searchfilters;
|
||||
private final FileSearch.AttributeType groupingAttribute;
|
||||
private final FileGroup.GroupSortingAlgorithm groupSort;
|
||||
private final Group.GroupSortingAlgorithm groupSort;
|
||||
private final FileSorter.SortingMethod fileSortMethod;
|
||||
private final GroupKey groupKey;
|
||||
private final int startingEntry;
|
||||
private final int pageSize;
|
||||
private final FileSearchData.FileType resultType;
|
||||
private final SearchData.Type resultType;
|
||||
private final CentralRepository centralRepo;
|
||||
private final List<ResultFile> results = new ArrayList<>();
|
||||
|
||||
@@ -70,8 +70,8 @@ final class PageWorker extends SwingWorker<Void, Void> {
|
||||
* @param centralRepo The central repository to be used.
|
||||
*/
|
||||
PageWorker(List<AbstractFilter> searchfilters, FileSearch.AttributeType groupingAttribute,
|
||||
FileGroup.GroupSortingAlgorithm groupSort, FileSorter.SortingMethod fileSortMethod, GroupKey groupKey,
|
||||
int startingEntry, int pageSize, FileSearchData.FileType resultType, CentralRepository centralRepo) {
|
||||
Group.GroupSortingAlgorithm groupSort, FileSorter.SortingMethod fileSortMethod, GroupKey groupKey,
|
||||
int startingEntry, int pageSize, SearchData.Type resultType, CentralRepository centralRepo) {
|
||||
this.searchfilters = searchfilters;
|
||||
this.groupingAttribute = groupingAttribute;
|
||||
this.groupSort = groupSort;
|
||||
@@ -93,7 +93,7 @@ final class PageWorker extends SwingWorker<Void, Void> {
|
||||
groupSort,
|
||||
fileSortMethod, groupKey, startingEntry, pageSize,
|
||||
Case.getCurrentCase().getSleuthkitCase(), centralRepo));
|
||||
} catch (FileSearchException ex) {
|
||||
} catch (DiscoveryException ex) {
|
||||
logger.log(Level.SEVERE, "Error running file search test", ex);
|
||||
cancel(true);
|
||||
}
|
||||
|
||||
@@ -24,9 +24,9 @@ import javax.swing.JLabel;
|
||||
import javax.swing.JList;
|
||||
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
|
||||
import org.sleuthkit.autopsy.discovery.search.AbstractFilter;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData.Frequency;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData.ResultType;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData.Frequency;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData.Type;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchFiltering;
|
||||
|
||||
/**
|
||||
@@ -35,21 +35,12 @@ import org.sleuthkit.autopsy.discovery.search.SearchFiltering;
|
||||
final class PastOccurrencesFilterPanel extends AbstractDiscoveryFilterPanel {
|
||||
|
||||
private static final long serialVersionUID = 1L;
|
||||
private final ResultType type;
|
||||
private final Type type;
|
||||
|
||||
/**
|
||||
* Creates new form PastOccurrencesFilterPanel.
|
||||
*/
|
||||
PastOccurrencesFilterPanel() {
|
||||
initComponents();
|
||||
type = ResultType.FILE;
|
||||
setUpFrequencyFilter();
|
||||
}
|
||||
|
||||
/**
|
||||
* Creates new form PastOccurrencesFilterPanel.
|
||||
*/
|
||||
PastOccurrencesFilterPanel(ResultType type) {
|
||||
PastOccurrencesFilterPanel(Type type) {
|
||||
initComponents();
|
||||
this.type = type;
|
||||
setUpFrequencyFilter();
|
||||
@@ -111,17 +102,17 @@ final class PastOccurrencesFilterPanel extends AbstractDiscoveryFilterPanel {
|
||||
*/
|
||||
private void setUpFrequencyFilter() {
|
||||
int count = 0;
|
||||
DefaultListModel<FileSearchData.Frequency> frequencyListModel = (DefaultListModel<FileSearchData.Frequency>) crFrequencyList.getModel();
|
||||
DefaultListModel<SearchData.Frequency> frequencyListModel = (DefaultListModel<SearchData.Frequency>) crFrequencyList.getModel();
|
||||
frequencyListModel.removeAllElements();
|
||||
if (!CentralRepository.isEnabled()) {
|
||||
if (type != ResultType.ATTRIBUTE) {
|
||||
for (FileSearchData.Frequency freq : FileSearchData.Frequency.getOptionsForFilteringWithoutCr()) {
|
||||
if (type != Type.DOMAIN) {
|
||||
for (SearchData.Frequency freq : SearchData.Frequency.getOptionsForFilteringWithoutCr()) {
|
||||
frequencyListModel.add(count, freq);
|
||||
}
|
||||
}
|
||||
} else {
|
||||
for (FileSearchData.Frequency freq : FileSearchData.Frequency.getOptionsForFilteringWithCr()) {
|
||||
if (type == ResultType.FILE || freq != FileSearchData.Frequency.KNOWN) {
|
||||
for (SearchData.Frequency freq : SearchData.Frequency.getOptionsForFilteringWithCr()) {
|
||||
if (type != Type.DOMAIN || freq != SearchData.Frequency.KNOWN) {
|
||||
frequencyListModel.add(count, freq);
|
||||
}
|
||||
}
|
||||
@@ -136,7 +127,7 @@ final class PastOccurrencesFilterPanel extends AbstractDiscoveryFilterPanel {
|
||||
|
||||
@Override
|
||||
void configurePanel(boolean selected, int[] indicesSelected) {
|
||||
boolean canBeFilteredOn = type == ResultType.FILE || CentralRepository.isEnabled();
|
||||
boolean canBeFilteredOn = type != Type.DOMAIN || CentralRepository.isEnabled();
|
||||
pastOccurrencesCheckbox.setEnabled(canBeFilteredOn);
|
||||
pastOccurrencesCheckbox.setSelected(selected && canBeFilteredOn);
|
||||
|
||||
|
||||
@@ -40,9 +40,9 @@ import org.sleuthkit.datamodel.AbstractFile;
|
||||
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
|
||||
import org.sleuthkit.autopsy.discovery.search.DiscoveryEventUtils;
|
||||
import org.sleuthkit.autopsy.discovery.search.DiscoveryKeyUtils.GroupKey;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileGroup;
|
||||
import org.sleuthkit.autopsy.discovery.search.Group;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearch;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSorter;
|
||||
import org.sleuthkit.autopsy.discovery.search.ResultFile;
|
||||
import org.sleuthkit.autopsy.textsummarizer.TextSummary;
|
||||
@@ -60,12 +60,12 @@ final class ResultsPanel extends javax.swing.JPanel {
|
||||
private final DocumentPreviewViewer documentPreviewViewer;
|
||||
private List<AbstractFilter> searchFilters;
|
||||
private FileSearch.AttributeType groupingAttribute;
|
||||
private FileGroup.GroupSortingAlgorithm groupSort;
|
||||
private Group.GroupSortingAlgorithm groupSort;
|
||||
private FileSorter.SortingMethod fileSortMethod;
|
||||
private GroupKey selectedGroupKey;
|
||||
private int currentPage = 0;
|
||||
private int previousPageSize = 10;
|
||||
private FileSearchData.FileType resultType;
|
||||
private SearchData.Type resultType;
|
||||
private int groupSize = 0;
|
||||
private PageWorker pageWorker;
|
||||
private final List<SwingWorker<Void, Void>> resultContentWorkers = new ArrayList<>();
|
||||
@@ -81,7 +81,7 @@ final class ResultsPanel extends javax.swing.JPanel {
|
||||
videoThumbnailViewer = new VideoThumbnailViewer();
|
||||
documentPreviewViewer = new DocumentPreviewViewer();
|
||||
videoThumbnailViewer.addListSelectionListener((e) -> {
|
||||
if (resultType == FileSearchData.FileType.VIDEO) {
|
||||
if (resultType == SearchData.Type.VIDEO) {
|
||||
if (!e.getValueIsAdjusting()) {
|
||||
//send populateMesage
|
||||
DiscoveryEventUtils.getDiscoveryEventBus().post(new DiscoveryEventUtils.PopulateInstancesListEvent(getInstancesForSelected()));
|
||||
@@ -92,7 +92,7 @@ final class ResultsPanel extends javax.swing.JPanel {
|
||||
}
|
||||
});
|
||||
imageThumbnailViewer.addListSelectionListener((e) -> {
|
||||
if (resultType == FileSearchData.FileType.IMAGE) {
|
||||
if (resultType == SearchData.Type.IMAGE) {
|
||||
if (!e.getValueIsAdjusting()) {
|
||||
//send populateMesage
|
||||
DiscoveryEventUtils.getDiscoveryEventBus().post(new DiscoveryEventUtils.PopulateInstancesListEvent(getInstancesForSelected()));
|
||||
@@ -104,7 +104,7 @@ final class ResultsPanel extends javax.swing.JPanel {
|
||||
}
|
||||
});
|
||||
documentPreviewViewer.addListSelectionListener((e) -> {
|
||||
if (resultType == FileSearchData.FileType.DOCUMENTS) {
|
||||
if (resultType == SearchData.Type.DOCUMENTS) {
|
||||
if (!e.getValueIsAdjusting()) {
|
||||
//send populateMesage
|
||||
DiscoveryEventUtils.getDiscoveryEventBus().post(new DiscoveryEventUtils.PopulateInstancesListEvent(getInstancesForSelected()));
|
||||
|
||||
@@ -29,9 +29,9 @@ import org.sleuthkit.autopsy.coreutils.Logger;
|
||||
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
|
||||
import org.sleuthkit.autopsy.discovery.search.DiscoveryEventUtils;
|
||||
import org.sleuthkit.autopsy.discovery.search.DiscoveryKeyUtils.GroupKey;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileGroup;
|
||||
import org.sleuthkit.autopsy.discovery.search.Group;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearch;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchException;
|
||||
import org.sleuthkit.autopsy.discovery.search.DiscoveryException;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSorter;
|
||||
|
||||
/**
|
||||
@@ -44,7 +44,7 @@ final class SearchWorker extends SwingWorker<Void, Void> {
|
||||
private final List<AbstractFilter> filters;
|
||||
private final FileSearch.AttributeType groupingAttr;
|
||||
private final FileSorter.SortingMethod fileSort;
|
||||
private final FileGroup.GroupSortingAlgorithm groupSortAlgorithm;
|
||||
private final Group.GroupSortingAlgorithm groupSortAlgorithm;
|
||||
private final CentralRepository centralRepoDb;
|
||||
private final Map<GroupKey, Integer> results = new LinkedHashMap<>();
|
||||
|
||||
@@ -58,7 +58,7 @@ final class SearchWorker extends SwingWorker<Void, Void> {
|
||||
* @param groupSort The Algorithm to sort groups by.
|
||||
* @param fileSortMethod The SortingMethod to use for files.
|
||||
*/
|
||||
SearchWorker(CentralRepository centralRepo, List<AbstractFilter> searchfilters, FileSearch.AttributeType groupingAttribute, FileGroup.GroupSortingAlgorithm groupSort, FileSorter.SortingMethod fileSortMethod) {
|
||||
SearchWorker(CentralRepository centralRepo, List<AbstractFilter> searchfilters, FileSearch.AttributeType groupingAttribute, Group.GroupSortingAlgorithm groupSort, FileSorter.SortingMethod fileSortMethod) {
|
||||
centralRepoDb = centralRepo;
|
||||
filters = searchfilters;
|
||||
groupingAttr = groupingAttribute;
|
||||
@@ -75,7 +75,7 @@ final class SearchWorker extends SwingWorker<Void, Void> {
|
||||
groupSortAlgorithm,
|
||||
fileSort,
|
||||
Case.getCurrentCase().getSleuthkitCase(), centralRepoDb));
|
||||
} catch (FileSearchException ex) {
|
||||
} catch (DiscoveryException ex) {
|
||||
logger.log(Level.SEVERE, "Error running file search test", ex);
|
||||
cancel(true);
|
||||
}
|
||||
|
||||
@@ -25,8 +25,8 @@ import javax.swing.DefaultListModel;
|
||||
import javax.swing.JCheckBox;
|
||||
import javax.swing.JLabel;
|
||||
import javax.swing.JList;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData.FileSize;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData.FileSize;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchFiltering;
|
||||
|
||||
/**
|
||||
@@ -41,7 +41,7 @@ final class SizeFilterPanel extends AbstractDiscoveryFilterPanel {
|
||||
*
|
||||
* @param type The type of result being searched for.
|
||||
*/
|
||||
SizeFilterPanel(FileSearchData.FileType type) {
|
||||
SizeFilterPanel(SearchData.Type type) {
|
||||
initComponents();
|
||||
setUpSizeFilter(type);
|
||||
}
|
||||
@@ -136,7 +136,7 @@ final class SizeFilterPanel extends AbstractDiscoveryFilterPanel {
|
||||
/**
|
||||
* Initialize the file size filter.
|
||||
*/
|
||||
private void setUpSizeFilter(FileSearchData.FileType fileType) {
|
||||
private void setUpSizeFilter(SearchData.Type fileType) {
|
||||
int count = 0;
|
||||
DefaultListModel<FileSize> sizeListModel = (DefaultListModel<FileSize>) sizeList.getModel();
|
||||
sizeListModel.removeAllElements();
|
||||
@@ -145,7 +145,7 @@ final class SizeFilterPanel extends AbstractDiscoveryFilterPanel {
|
||||
sizeListModel.add(count, size);
|
||||
}
|
||||
} else {
|
||||
List<FileSearchData.FileSize> sizes;
|
||||
List<SearchData.FileSize> sizes;
|
||||
switch (fileType) {
|
||||
case VIDEO:
|
||||
sizes = FileSize.getOptionsForVideos();
|
||||
|
||||
@@ -19,8 +19,6 @@
|
||||
package org.sleuthkit.autopsy.discovery.ui;
|
||||
|
||||
import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepository;
|
||||
import org.sleuthkit.autopsy.discovery.search.AttributeSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.FileSearchData;
|
||||
import org.sleuthkit.autopsy.discovery.search.SearchData;
|
||||
|
||||
/**
|
||||
@@ -29,7 +27,7 @@ import org.sleuthkit.autopsy.discovery.search.SearchData;
|
||||
final class VideoFilterPanel extends AbstractFiltersPanel {
|
||||
|
||||
private static final long serialVersionUID = 1L;
|
||||
private static final FileSearchData.FileType FILE_TYPE = FileSearchData.FileType.VIDEO;
|
||||
private static final SearchData.Type TYPE = SearchData.Type.VIDEO;
|
||||
|
||||
/**
|
||||
* Creates new form VideoFilterPanel.
|
||||
@@ -37,7 +35,7 @@ final class VideoFilterPanel extends AbstractFiltersPanel {
|
||||
VideoFilterPanel() {
|
||||
super();
|
||||
initComponents();
|
||||
SizeFilterPanel sizeFilterPanel = new SizeFilterPanel(FILE_TYPE);
|
||||
SizeFilterPanel sizeFilterPanel = new SizeFilterPanel(TYPE);
|
||||
int[] sizeIndicesSelected = {3, 4, 5};
|
||||
addFilter(sizeFilterPanel, true, sizeIndicesSelected, 0);
|
||||
addFilter(new DataSourceFilterPanel(), false, null, 0);
|
||||
@@ -47,7 +45,7 @@ final class VideoFilterPanel extends AbstractFiltersPanel {
|
||||
} else {
|
||||
pastOccurrencesIndices = new int[]{2, 3, 4};
|
||||
}
|
||||
addFilter(new PastOccurrencesFilterPanel(), true, pastOccurrencesIndices, 0);
|
||||
addFilter(new PastOccurrencesFilterPanel(TYPE), true, pastOccurrencesIndices, 0);
|
||||
addFilter(new UserCreatedFilterPanel(), false, null, 1);
|
||||
addFilter(new HashSetFilterPanel(), false, null, 1);
|
||||
addFilter(new InterestingItemsFilterPanel(), false, null, 1);
|
||||
@@ -100,22 +98,12 @@ final class VideoFilterPanel extends AbstractFiltersPanel {
|
||||
add(videoFiltersScrollPane, java.awt.BorderLayout.CENTER);
|
||||
}// </editor-fold>//GEN-END:initComponents
|
||||
@Override
|
||||
FileSearchData.FileType getFileType() {
|
||||
return FILE_TYPE;
|
||||
SearchData.Type getType() {
|
||||
return TYPE;
|
||||
}
|
||||
|
||||
// Variables declaration - do not modify//GEN-BEGIN:variables
|
||||
private javax.swing.JSplitPane videoFiltersSplitPane;
|
||||
// End of variables declaration//GEN-END:variables
|
||||
|
||||
@Override
|
||||
SearchData.ResultType getResultType() {
|
||||
return SearchData.ResultType.FILE;
|
||||
}
|
||||
|
||||
@Override
|
||||
AttributeSearchData.AttributeType getArtifactType() {
|
||||
throw new UnsupportedOperationException("Not supported yet."); //To change body of generated methods, choose Tools | Templates.
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user