Add Single Case logic. Enable Other Occurances tab for CR common files results.

This commit is contained in:
Andrew Ziehl
2018-07-11 20:50:29 -07:00
parent c16a41c0ed
commit bea4199540
8 changed files with 116 additions and 23 deletions
@@ -1880,7 +1880,7 @@ abstract class AbstractSqlEamDb implements EamDb {
PreparedStatement preparedStatement = null;
ResultSet resultSet = null;
String tableName = EamDbUtil.correlationTypeToInstanceTableName(type);
StringBuilder sql = new StringBuilder();
StringBuilder sql = new StringBuilder(3);
sql.append("select * from ");
sql.append(tableName);
sql.append(" WHERE id = ?");
@@ -1925,7 +1925,7 @@ abstract class AbstractSqlEamDb implements EamDb {
PreparedStatement preparedStatement = null;
ResultSet resultSet = null;
String tableName = EamDbUtil.correlationTypeToInstanceTableName(type);
StringBuilder sql = new StringBuilder();
StringBuilder sql = new StringBuilder(7);
sql.append("SELECT id, value, case_id FROM ");
sql.append(tableName);
sql.append(" WHERE value IN (SELECT value FROM "); // TODO should this select * so any field is available?
@@ -1949,6 +1949,60 @@ abstract class AbstractSqlEamDb implements EamDb {
}
}
/**
* Process the Artifact instance in the EamDb
*
* @param type EamArtifact.Type to search for
* @param correlationCase CorrelationCase to filter by
* @param singleCase Single Case to filter by
* @param instanceTableCallback callback to process the instance
* @throws EamDbException
*/
@Override
public void processSingleCaseInstancesTable(CorrelationAttribute.Type type, CorrelationCase correlationCase, CorrelationCase singleCase,InstanceTableCallback instanceTableCallback) throws EamDbException {
if (type == null) {
throw new EamDbException("Correlation type is null");
}
if (instanceTableCallback == null) {
throw new EamDbException("Callback interface is null");
}
if(correlationCase == null) {
throw new EamDbException("Correlation Case is null");
}
Connection conn = connect();
PreparedStatement preparedStatement = null;
ResultSet resultSet = null;
String tableName = EamDbUtil.correlationTypeToInstanceTableName(type);
StringBuilder sql = new StringBuilder(8);
sql.append("SELECT id, value, case_id FROM ");
sql.append(tableName);
sql.append(" WHERE value IN (SELECT value FROM "); // TODO should this select * so any field is available?
sql.append(tableName);
sql.append(" WHERE value IN (SELECT value FROM ");
sql.append(tableName);
sql.append(" WHERE case_id=? AND (known_status !=? OR known_status IS NULL) GROUP BY value)");
sql.append(" AND (case_id=? OR case_id=?) GROUP BY value HAVING COUNT(DISTINCT case_id) > 1) ORDER BY value");
try {
preparedStatement = conn.prepareStatement(sql.toString());
preparedStatement.setInt(1, correlationCase.getID());
preparedStatement.setByte(2, TskData.FileKnown.KNOWN.getFileKnownValue());
preparedStatement.setInt(3, correlationCase.getID());
preparedStatement.setInt(4, singleCase.getID());
resultSet = preparedStatement.executeQuery();
instanceTableCallback.process(resultSet);
} catch (SQLException ex) {
throw new EamDbException("Error getting all artifact instances from instances table", ex);
} finally {
EamDbUtil.closeStatement(preparedStatement);
EamDbUtil.closeResultSet(resultSet);
EamDbUtil.closeConnection(conn);
}
}
@Override
public EamOrganization newOrganization(EamOrganization eamOrg) throws EamDbException {
@@ -19,7 +19,6 @@
package org.sleuthkit.autopsy.centralrepository.datamodel;
import java.sql.SQLException;
import java.util.Collection;
import java.util.List;
import java.util.Set;
import org.sleuthkit.datamodel.TskData;
@@ -725,4 +724,16 @@ public interface EamDb {
* @throws EamDbException
*/
void processCaseInstancesTable(CorrelationAttribute.Type type, CorrelationCase correlationCase, InstanceTableCallback instanceTableCallback) throws EamDbException;
/**
* Process the Artifact instance in the EamDb
*
* @param type EamArtifact.Type to search for
* @param correlationCase CorrelationCase to filter by
* @param singleCase Single Case to filter by
* @param instanceTableCallback callback to process the instance
* @throws EamDbException
*/
void processSingleCaseInstancesTable(CorrelationAttribute.Type type, CorrelationCase correlationCase, CorrelationCase singleCase,InstanceTableCallback instanceTableCallback) throws EamDbException;
}
@@ -772,6 +772,25 @@ final class SqliteEamDb extends AbstractSqlEamDb {
releaseSharedLock();
}
}
/**
* Process the Artifact instance in the EamDb
*
* @param type EamArtifact.Type to search for
* @param correlationCase CorrelationCase to filter by
* @param singleCase Single Case to filter by
* @param instanceTableCallback callback to process the instance
* @throws EamDbException
*/
@Override
public void processSingleCaseInstancesTable(CorrelationAttribute.Type type, CorrelationCase correlationCase, CorrelationCase singleCase,InstanceTableCallback instanceTableCallback) throws EamDbException {
try {
acquireSharedLock();
super.processSingleCaseInstancesTable(type, correlationCase, singleCase, instanceTableCallback);
} finally {
releaseSharedLock();
}
}
/**
* Check whether a reference set with the given name/version is in the
@@ -27,7 +27,7 @@ import org.sleuthkit.datamodel.TskData.FileKnown;
*/
final public class AllDataSourcesCommonFilesAlgorithm extends CommonFilesMetadataBuilder {
private static final String WHERE_CLAUSE = "%s md5 in (select md5 from tsk_files where (known != "+ FileKnown.KNOWN.getFileKnownValue() + " OR known IS NULL)%s GROUP BY md5 HAVING COUNT(DISTINCT data_source_obj_id) > 1) order by md5"; //NON-NLS
private static final String WHERE_CLAUSE = "%s md5 in (select md5 from tsk_files where (known != "+ FileKnown.KNOWN.getFileKnownValue() + " OR known IS NULL)%s GROUP BY md5 HAVING COUNT(DISTINCT data_source_obj_id) > 1) order by md5"; //NON-NLS
/**
* Implements the algorithm for getting common files across all data
@@ -51,8 +51,7 @@ public class CentralRepositoryFileInstanceNode extends DisplayableItemNode {
private final AbstractFile md5Reference;
public CentralRepositoryFileInstanceNode(CorrelationAttributeInstance content, AbstractFile md5Reference) {
super(Children.LEAF, Lookups.fixed(content)); // TODO, using md5Reference enables Other Occurances..but for the incorrect file path
super(Children.LEAF, Lookups.fixed(md5Reference)); // Using md5Reference enables Other Occurances..but for the current file path
this.crFile = content;
this.setDisplayName(new File(this.crFile.getFilePath()).getName());
this.md5Reference = md5Reference;
@@ -76,6 +76,22 @@ final class EamDbAttributeInstancesAlgorithm {
logger.log(Level.SEVERE, "Error accessing EamDb processing CaseInstancesTable.", ex);
}
}
void processSingleCaseCorrelationCaseAttributeValues(Case currentCase, CorrelationCase singleCase) {
try {
EamDbAttributeInstancesCallback instancetableCallback = new EamDbAttributeInstancesCallback();
EamDb DbManager = EamDb.getInstance();
CorrelationAttribute.Type fileType = DbManager.getCorrelationTypeById(CorrelationAttribute.FILES_TYPE_ID);
DbManager.processSingleCaseInstancesTable(fileType, DbManager.getCase(currentCase), singleCase, instancetableCallback);
intercaseCommonValuesMap.putAll(instancetableCallback.getCorrelationIdValueMap());
intercaseCommonCasesMap.putAll(instancetableCallback.getCorrelationIdToCaseMap());
} catch (EamDbException ex) {
logger.log(Level.SEVERE, "Error accessing EamDb processing CaseInstancesTable.", ex);
}
}
Map<Integer, String> getIntercaseCommonValuesMap() {
@@ -69,26 +69,24 @@ public abstract class EamDbCommonFilesAlgorithm extends CommonFilesMetadataBuild
protected CommonFilesMetadata findFiles(CorrelationCase correlationCase) throws TskCoreException, NoCurrentCaseException, SQLException, EamDbException, Exception {
//TODO separate if case for correlationCase
Map<Integer, List<Md5Metadata>> interCaseCommonFiles = new HashMap<>();
// Need to include current Cases results for specific case comparison
EamDbAttributeInstancesAlgorithm eamDbAttrInst = new EamDbAttributeInstancesAlgorithm();
eamDbAttrInst.processCorrelationCaseAttributeValues(Case.getCurrentCase());
if(correlationCase != null) {
// Filter by matches both within current case and a specific case.
// TODO, move to Single class
eamDbAttrInst.processSingleCaseCorrelationCaseAttributeValues(Case.getCurrentCase(), correlationCase);
} else {
// Filter by matches of current case md5s.
eamDbAttrInst.processCorrelationCaseAttributeValues(Case.getCurrentCase());
}
interCaseCommonFiles = gatherIntercaseResults(eamDbAttrInst.getIntercaseCommonValuesMap(), eamDbAttrInst.getIntercaseCommonCasesMap());
//TODO, only use to filter mimeType in memory against currentCase against, unless mimeType is added to CR
// Builds intercase-only matches metadata
return new CommonFilesMetadata(interCaseCommonFiles);
}
//TODO, only use to filter mimeType in memory against currentCase against, unless mimeType is added to CR
// private Map<Integer, List<Md5Metadata>> getMetadataForCurrentCase() throws NoCurrentCaseException, TskCoreException, SQLException, Exception {
// //we need the list of files in the present case so we can compare against the central repo
// CommonFilesMetadata metaData = super.findFiles();
// Map<Integer, List<Md5Metadata>> commonFiles = metaData.getMetadata();
// return commonFiles;
// }
/**
* @param artifactInstances all 'common files' in central repo
* @param commonFiles matches must ultimately have appeared in this collection
@@ -106,16 +104,12 @@ public abstract class EamDbCommonFilesAlgorithm extends CommonFilesMetadataBuild
}
try {
// TODO, pass proper Case
int caseId = commonFileCases.get(commonAttrId);
CorrelationCase autopsyCrCase = dbManager.getCaseById(caseId);
final String correlationCaseDisplayName = autopsyCrCase.getDisplayName();
// we don't *have* all the information for the rows in the CR,
// so we need to consult the present case via the SleuthkitCase object
// Later, when the FileInstanceNodde is built. Therefore, build node generators for now.
if(interCaseCommonFiles.containsKey(md5)) {
//Add to intercase metaData
@@ -28,7 +28,7 @@ import org.sleuthkit.datamodel.TskCoreException;
/**
*
* TODO
*
*/
public class SingleCaseEamDbCommonFilesAlgorithm extends EamDbCommonFilesAlgorithm {