From bea41995406be5cb3d7b2f477fafb4e97d4c146a Mon Sep 17 00:00:00 2001 From: Andrew Ziehl Date: Wed, 11 Jul 2018 20:50:29 -0700 Subject: [PATCH] Add Single Case logic. Enable Other Occurances tab for CR common files results. --- .../datamodel/AbstractSqlEamDb.java | 58 ++++++++++++++++++- .../centralrepository/datamodel/EamDb.java | 13 ++++- .../datamodel/SqliteEamDb.java | 19 ++++++ .../AllDataSourcesCommonFilesAlgorithm.java | 2 +- .../CentralRepositoryFileInstanceNode.java | 3 +- .../EamDbAttributeInstancesAlgorithm.java | 16 +++++ .../EamDbCommonFilesAlgorithm.java | 26 ++++----- .../SingleCaseEamDbCommonFilesAlgorithm.java | 2 +- 8 files changed, 116 insertions(+), 23 deletions(-) diff --git a/Core/src/org/sleuthkit/autopsy/centralrepository/datamodel/AbstractSqlEamDb.java b/Core/src/org/sleuthkit/autopsy/centralrepository/datamodel/AbstractSqlEamDb.java index 4651264478..ac286aa569 100644 --- a/Core/src/org/sleuthkit/autopsy/centralrepository/datamodel/AbstractSqlEamDb.java +++ b/Core/src/org/sleuthkit/autopsy/centralrepository/datamodel/AbstractSqlEamDb.java @@ -1880,7 +1880,7 @@ abstract class AbstractSqlEamDb implements EamDb { PreparedStatement preparedStatement = null; ResultSet resultSet = null; String tableName = EamDbUtil.correlationTypeToInstanceTableName(type); - StringBuilder sql = new StringBuilder(); + StringBuilder sql = new StringBuilder(3); sql.append("select * from "); sql.append(tableName); sql.append(" WHERE id = ?"); @@ -1925,7 +1925,7 @@ abstract class AbstractSqlEamDb implements EamDb { PreparedStatement preparedStatement = null; ResultSet resultSet = null; String tableName = EamDbUtil.correlationTypeToInstanceTableName(type); - StringBuilder sql = new StringBuilder(); + StringBuilder sql = new StringBuilder(7); sql.append("SELECT id, value, case_id FROM "); sql.append(tableName); sql.append(" WHERE value IN (SELECT value FROM "); // TODO should this select * so any field is available? @@ -1949,6 +1949,60 @@ abstract class AbstractSqlEamDb implements EamDb { } } + /** + * Process the Artifact instance in the EamDb + * + * @param type EamArtifact.Type to search for + * @param correlationCase CorrelationCase to filter by + * @param singleCase Single Case to filter by + * @param instanceTableCallback callback to process the instance + * @throws EamDbException + */ + @Override + public void processSingleCaseInstancesTable(CorrelationAttribute.Type type, CorrelationCase correlationCase, CorrelationCase singleCase,InstanceTableCallback instanceTableCallback) throws EamDbException { + if (type == null) { + throw new EamDbException("Correlation type is null"); + } + + if (instanceTableCallback == null) { + throw new EamDbException("Callback interface is null"); + } + + if(correlationCase == null) { + throw new EamDbException("Correlation Case is null"); + } + + Connection conn = connect(); + PreparedStatement preparedStatement = null; + ResultSet resultSet = null; + String tableName = EamDbUtil.correlationTypeToInstanceTableName(type); + StringBuilder sql = new StringBuilder(8); + sql.append("SELECT id, value, case_id FROM "); + sql.append(tableName); + sql.append(" WHERE value IN (SELECT value FROM "); // TODO should this select * so any field is available? + sql.append(tableName); + sql.append(" WHERE value IN (SELECT value FROM "); + sql.append(tableName); + sql.append(" WHERE case_id=? AND (known_status !=? OR known_status IS NULL) GROUP BY value)"); + sql.append(" AND (case_id=? OR case_id=?) GROUP BY value HAVING COUNT(DISTINCT case_id) > 1) ORDER BY value"); + + try { + preparedStatement = conn.prepareStatement(sql.toString()); + preparedStatement.setInt(1, correlationCase.getID()); + preparedStatement.setByte(2, TskData.FileKnown.KNOWN.getFileKnownValue()); + preparedStatement.setInt(3, correlationCase.getID()); + preparedStatement.setInt(4, singleCase.getID()); + resultSet = preparedStatement.executeQuery(); + instanceTableCallback.process(resultSet); + } catch (SQLException ex) { + throw new EamDbException("Error getting all artifact instances from instances table", ex); + } finally { + EamDbUtil.closeStatement(preparedStatement); + EamDbUtil.closeResultSet(resultSet); + EamDbUtil.closeConnection(conn); + } + } + @Override public EamOrganization newOrganization(EamOrganization eamOrg) throws EamDbException { diff --git a/Core/src/org/sleuthkit/autopsy/centralrepository/datamodel/EamDb.java b/Core/src/org/sleuthkit/autopsy/centralrepository/datamodel/EamDb.java index 7fd81087e0..f9f37a86f0 100644 --- a/Core/src/org/sleuthkit/autopsy/centralrepository/datamodel/EamDb.java +++ b/Core/src/org/sleuthkit/autopsy/centralrepository/datamodel/EamDb.java @@ -19,7 +19,6 @@ package org.sleuthkit.autopsy.centralrepository.datamodel; import java.sql.SQLException; -import java.util.Collection; import java.util.List; import java.util.Set; import org.sleuthkit.datamodel.TskData; @@ -725,4 +724,16 @@ public interface EamDb { * @throws EamDbException */ void processCaseInstancesTable(CorrelationAttribute.Type type, CorrelationCase correlationCase, InstanceTableCallback instanceTableCallback) throws EamDbException; + + /** + * Process the Artifact instance in the EamDb + * + * @param type EamArtifact.Type to search for + * @param correlationCase CorrelationCase to filter by + * @param singleCase Single Case to filter by + * @param instanceTableCallback callback to process the instance + * @throws EamDbException + */ + void processSingleCaseInstancesTable(CorrelationAttribute.Type type, CorrelationCase correlationCase, CorrelationCase singleCase,InstanceTableCallback instanceTableCallback) throws EamDbException; + } diff --git a/Core/src/org/sleuthkit/autopsy/centralrepository/datamodel/SqliteEamDb.java b/Core/src/org/sleuthkit/autopsy/centralrepository/datamodel/SqliteEamDb.java index b2ebad1b32..a9f930fd0c 100644 --- a/Core/src/org/sleuthkit/autopsy/centralrepository/datamodel/SqliteEamDb.java +++ b/Core/src/org/sleuthkit/autopsy/centralrepository/datamodel/SqliteEamDb.java @@ -772,6 +772,25 @@ final class SqliteEamDb extends AbstractSqlEamDb { releaseSharedLock(); } } + + /** + * Process the Artifact instance in the EamDb + * + * @param type EamArtifact.Type to search for + * @param correlationCase CorrelationCase to filter by + * @param singleCase Single Case to filter by + * @param instanceTableCallback callback to process the instance + * @throws EamDbException + */ + @Override + public void processSingleCaseInstancesTable(CorrelationAttribute.Type type, CorrelationCase correlationCase, CorrelationCase singleCase,InstanceTableCallback instanceTableCallback) throws EamDbException { + try { + acquireSharedLock(); + super.processSingleCaseInstancesTable(type, correlationCase, singleCase, instanceTableCallback); + } finally { + releaseSharedLock(); + } + } /** * Check whether a reference set with the given name/version is in the diff --git a/Core/src/org/sleuthkit/autopsy/commonfilesearch/AllDataSourcesCommonFilesAlgorithm.java b/Core/src/org/sleuthkit/autopsy/commonfilesearch/AllDataSourcesCommonFilesAlgorithm.java index 111cf4aed9..a53572d093 100644 --- a/Core/src/org/sleuthkit/autopsy/commonfilesearch/AllDataSourcesCommonFilesAlgorithm.java +++ b/Core/src/org/sleuthkit/autopsy/commonfilesearch/AllDataSourcesCommonFilesAlgorithm.java @@ -27,7 +27,7 @@ import org.sleuthkit.datamodel.TskData.FileKnown; */ final public class AllDataSourcesCommonFilesAlgorithm extends CommonFilesMetadataBuilder { - private static final String WHERE_CLAUSE = "%s md5 in (select md5 from tsk_files where (known != "+ FileKnown.KNOWN.getFileKnownValue() + " OR known IS NULL)%s GROUP BY md5 HAVING COUNT(DISTINCT data_source_obj_id) > 1) order by md5"; //NON-NLS + private static final String WHERE_CLAUSE = "%s md5 in (select md5 from tsk_files where (known != "+ FileKnown.KNOWN.getFileKnownValue() + " OR known IS NULL)%s GROUP BY md5 HAVING COUNT(DISTINCT data_source_obj_id) > 1) order by md5"; //NON-NLS /** * Implements the algorithm for getting common files across all data diff --git a/Core/src/org/sleuthkit/autopsy/commonfilesearch/CentralRepositoryFileInstanceNode.java b/Core/src/org/sleuthkit/autopsy/commonfilesearch/CentralRepositoryFileInstanceNode.java index 056c489431..d85d5bf644 100644 --- a/Core/src/org/sleuthkit/autopsy/commonfilesearch/CentralRepositoryFileInstanceNode.java +++ b/Core/src/org/sleuthkit/autopsy/commonfilesearch/CentralRepositoryFileInstanceNode.java @@ -51,8 +51,7 @@ public class CentralRepositoryFileInstanceNode extends DisplayableItemNode { private final AbstractFile md5Reference; public CentralRepositoryFileInstanceNode(CorrelationAttributeInstance content, AbstractFile md5Reference) { - super(Children.LEAF, Lookups.fixed(content)); // TODO, using md5Reference enables Other Occurances..but for the incorrect file path - + super(Children.LEAF, Lookups.fixed(md5Reference)); // Using md5Reference enables Other Occurances..but for the current file path this.crFile = content; this.setDisplayName(new File(this.crFile.getFilePath()).getName()); this.md5Reference = md5Reference; diff --git a/Core/src/org/sleuthkit/autopsy/commonfilesearch/EamDbAttributeInstancesAlgorithm.java b/Core/src/org/sleuthkit/autopsy/commonfilesearch/EamDbAttributeInstancesAlgorithm.java index fa6baaa34d..4fcf89d3cd 100644 --- a/Core/src/org/sleuthkit/autopsy/commonfilesearch/EamDbAttributeInstancesAlgorithm.java +++ b/Core/src/org/sleuthkit/autopsy/commonfilesearch/EamDbAttributeInstancesAlgorithm.java @@ -76,6 +76,22 @@ final class EamDbAttributeInstancesAlgorithm { logger.log(Level.SEVERE, "Error accessing EamDb processing CaseInstancesTable.", ex); } + } + + void processSingleCaseCorrelationCaseAttributeValues(Case currentCase, CorrelationCase singleCase) { + + try { + EamDbAttributeInstancesCallback instancetableCallback = new EamDbAttributeInstancesCallback(); + EamDb DbManager = EamDb.getInstance(); + CorrelationAttribute.Type fileType = DbManager.getCorrelationTypeById(CorrelationAttribute.FILES_TYPE_ID); + DbManager.processSingleCaseInstancesTable(fileType, DbManager.getCase(currentCase), singleCase, instancetableCallback); + + intercaseCommonValuesMap.putAll(instancetableCallback.getCorrelationIdValueMap()); + intercaseCommonCasesMap.putAll(instancetableCallback.getCorrelationIdToCaseMap()); + } catch (EamDbException ex) { + logger.log(Level.SEVERE, "Error accessing EamDb processing CaseInstancesTable.", ex); + } + } Map getIntercaseCommonValuesMap() { diff --git a/Core/src/org/sleuthkit/autopsy/commonfilesearch/EamDbCommonFilesAlgorithm.java b/Core/src/org/sleuthkit/autopsy/commonfilesearch/EamDbCommonFilesAlgorithm.java index 39db0fcf7b..8b34e6dfad 100644 --- a/Core/src/org/sleuthkit/autopsy/commonfilesearch/EamDbCommonFilesAlgorithm.java +++ b/Core/src/org/sleuthkit/autopsy/commonfilesearch/EamDbCommonFilesAlgorithm.java @@ -69,26 +69,24 @@ public abstract class EamDbCommonFilesAlgorithm extends CommonFilesMetadataBuild protected CommonFilesMetadata findFiles(CorrelationCase correlationCase) throws TskCoreException, NoCurrentCaseException, SQLException, EamDbException, Exception { - //TODO separate if case for correlationCase Map> interCaseCommonFiles = new HashMap<>(); - // Need to include current Cases results for specific case comparison EamDbAttributeInstancesAlgorithm eamDbAttrInst = new EamDbAttributeInstancesAlgorithm(); - eamDbAttrInst.processCorrelationCaseAttributeValues(Case.getCurrentCase()); + if(correlationCase != null) { + // Filter by matches both within current case and a specific case. + // TODO, move to Single class + eamDbAttrInst.processSingleCaseCorrelationCaseAttributeValues(Case.getCurrentCase(), correlationCase); + } else { + // Filter by matches of current case md5s. + eamDbAttrInst.processCorrelationCaseAttributeValues(Case.getCurrentCase()); + } interCaseCommonFiles = gatherIntercaseResults(eamDbAttrInst.getIntercaseCommonValuesMap(), eamDbAttrInst.getIntercaseCommonCasesMap()); + //TODO, only use to filter mimeType in memory against currentCase against, unless mimeType is added to CR // Builds intercase-only matches metadata return new CommonFilesMetadata(interCaseCommonFiles); } - //TODO, only use to filter mimeType in memory against currentCase against, unless mimeType is added to CR -// private Map> getMetadataForCurrentCase() throws NoCurrentCaseException, TskCoreException, SQLException, Exception { -// //we need the list of files in the present case so we can compare against the central repo -// CommonFilesMetadata metaData = super.findFiles(); -// Map> commonFiles = metaData.getMetadata(); -// return commonFiles; -// } - /** * @param artifactInstances all 'common files' in central repo * @param commonFiles matches must ultimately have appeared in this collection @@ -106,16 +104,12 @@ public abstract class EamDbCommonFilesAlgorithm extends CommonFilesMetadataBuild } try { - // TODO, pass proper Case int caseId = commonFileCases.get(commonAttrId); CorrelationCase autopsyCrCase = dbManager.getCaseById(caseId); final String correlationCaseDisplayName = autopsyCrCase.getDisplayName(); // we don't *have* all the information for the rows in the CR, // so we need to consult the present case via the SleuthkitCase object - - - - + // Later, when the FileInstanceNodde is built. Therefore, build node generators for now. if(interCaseCommonFiles.containsKey(md5)) { //Add to intercase metaData diff --git a/Core/src/org/sleuthkit/autopsy/commonfilesearch/SingleCaseEamDbCommonFilesAlgorithm.java b/Core/src/org/sleuthkit/autopsy/commonfilesearch/SingleCaseEamDbCommonFilesAlgorithm.java index 8aad5414a8..339d0846a1 100644 --- a/Core/src/org/sleuthkit/autopsy/commonfilesearch/SingleCaseEamDbCommonFilesAlgorithm.java +++ b/Core/src/org/sleuthkit/autopsy/commonfilesearch/SingleCaseEamDbCommonFilesAlgorithm.java @@ -28,7 +28,7 @@ import org.sleuthkit.datamodel.TskCoreException; /** * - * TODO + * */ public class SingleCaseEamDbCommonFilesAlgorithm extends EamDbCommonFilesAlgorithm {