diff --git a/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/contentviewer/DataContentViewerOtherCases.java b/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/contentviewer/DataContentViewerOtherCases.java index 899f6d27be..16114388d8 100644 --- a/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/contentviewer/DataContentViewerOtherCases.java +++ b/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/contentviewer/DataContentViewerOtherCases.java @@ -134,7 +134,7 @@ public class DataContentViewerOtherCases extends javax.swing.JPanel implements D try { EamDb dbManager = EamDb.getInstance(); for (EamArtifact eamArtifact : correlatedArtifacts) { - percentage = dbManager.getCommonalityPercentageForTypeValue(eamArtifact); + percentage = dbManager.getCommonalityPercentageForTypeValue(eamArtifact.getCorrelationType(), eamArtifact.getCorrelationValue()); msg.append(Bundle.DataContentViewerOtherCases_correlatedArtifacts_byType(percentage, eamArtifact.getCorrelationType().getDisplayName(), eamArtifact.getCorrelationValue())); @@ -448,11 +448,11 @@ public class DataContentViewerOtherCases extends javax.swing.JPanel implements D * * @return A collection of correlated artifact instances from other cases */ - private Collection getCorrelatedInstances(EamArtifact eamArtifact, String dataSourceName, String deviceId) { + private Collection getCorrelatedInstances(EamArtifact.Type aType, String value, String dataSourceName, String deviceId) { String caseUUID = Case.getCurrentCase().getName(); try { EamDb dbManager = EamDb.getInstance(); - Collection artifactInstances = dbManager.getArtifactInstancesByTypeValue(eamArtifact).stream() + Collection artifactInstances = dbManager.getArtifactInstancesByTypeValue(aType, value).stream() .filter(artifactInstance -> !artifactInstance.getEamCase().getCaseUUID().equals(caseUUID) || !artifactInstance.getEamDataSource().getName().equals(dataSourceName) || !artifactInstance.getEamDataSource().getDeviceID().equals(deviceId)) @@ -530,7 +530,7 @@ public class DataContentViewerOtherCases extends javax.swing.JPanel implements D correlatedArtifacts.addAll(getArtifactsFromCorrelatableAttributes(node)); correlatedArtifacts.forEach((eamArtifact) -> { // get local instances - Collection eamArtifactInstances = getCorrelatedInstances(eamArtifact, dataSourceName, deviceId); + Collection eamArtifactInstances = getCorrelatedInstances(eamArtifact.getCorrelationType(), eamArtifact.getCorrelationValue(), dataSourceName, deviceId); // get global instances eamArtifactInstances.addAll(getReferenceInstancesAsArtifactInstances(eamArtifact)); diff --git a/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/datamodel/AbstractSqlEamDb.java b/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/datamodel/AbstractSqlEamDb.java index 0bab99d341..5a2fa9efa3 100644 --- a/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/datamodel/AbstractSqlEamDb.java +++ b/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/datamodel/AbstractSqlEamDb.java @@ -548,7 +548,7 @@ public abstract class AbstractSqlEamDb implements EamDb { * @return List of artifact instances for a given type/value */ @Override - public List getArtifactInstancesByTypeValue(EamArtifact eamArtifact) throws EamDbException { + public List getArtifactInstancesByTypeValue(EamArtifact.Type aType, String value) throws EamDbException { Connection conn = connect(); List artifactInstances = new ArrayList<>(); @@ -557,7 +557,7 @@ public abstract class AbstractSqlEamDb implements EamDb { PreparedStatement preparedStatement = null; ResultSet resultSet = null; - String tableName = EamDbUtil.correlationTypeToInstanceTableName(eamArtifact.getCorrelationType()); + String tableName = EamDbUtil.correlationTypeToInstanceTableName(aType); StringBuilder sql = new StringBuilder(); sql.append("SELECT cases.case_name, cases.case_uid, data_sources.name, device_id, file_path, known_status, comment FROM "); sql.append(tableName); @@ -571,7 +571,7 @@ public abstract class AbstractSqlEamDb implements EamDb { try { preparedStatement = conn.prepareStatement(sql.toString()); - preparedStatement.setString(1, eamArtifact.getCorrelationValue()); + preparedStatement.setString(1, value); resultSet = preparedStatement.executeQuery(); while (resultSet.next()) { artifactInstance = getEamArtifactInstanceFromResultSet(resultSet); @@ -651,14 +651,14 @@ public abstract class AbstractSqlEamDb implements EamDb { * ArtifactValue. */ @Override - public Long getCountArtifactInstancesByTypeValue(EamArtifact eamArtifact) throws EamDbException { + public Long getCountArtifactInstancesByTypeValue(EamArtifact.Type aType, String value) throws EamDbException { Connection conn = connect(); Long instanceCount = 0L; PreparedStatement preparedStatement = null; ResultSet resultSet = null; - String tableName = EamDbUtil.correlationTypeToInstanceTableName(eamArtifact.getCorrelationType()); + String tableName = EamDbUtil.correlationTypeToInstanceTableName(aType); StringBuilder sql = new StringBuilder(); sql.append("SELECT count(*) FROM "); sql.append(tableName); @@ -666,7 +666,7 @@ public abstract class AbstractSqlEamDb implements EamDb { try { preparedStatement = conn.prepareStatement(sql.toString()); - preparedStatement.setString(1, eamArtifact.getCorrelationValue()); + preparedStatement.setString(1, value); resultSet = preparedStatement.executeQuery(); resultSet.next(); instanceCount = resultSet.getLong(1); @@ -693,8 +693,8 @@ public abstract class AbstractSqlEamDb implements EamDb { * @return Int between 0 and 100 */ @Override - public int getCommonalityPercentageForTypeValue(EamArtifact eamArtifact) throws EamDbException { - Double uniqueTypeValueTuples = getCountUniqueCaseDataSourceTuplesHavingTypeValue(eamArtifact).doubleValue(); + public int getCommonalityPercentageForTypeValue(EamArtifact.Type aType, String value) throws EamDbException { + Double uniqueTypeValueTuples = getCountUniqueCaseDataSourceTuplesHavingTypeValue(aType, value).doubleValue(); Double uniqueCaseDataSourceTuples = getCountUniqueCaseDataSourceTuples().doubleValue(); Double commonalityPercentage = uniqueTypeValueTuples / uniqueCaseDataSourceTuples * 100; return commonalityPercentage.intValue(); @@ -711,14 +711,14 @@ public abstract class AbstractSqlEamDb implements EamDb { * @return Number of unique tuples */ @Override - public Long getCountUniqueCaseDataSourceTuplesHavingTypeValue(EamArtifact eamArtifact) throws EamDbException { + public Long getCountUniqueCaseDataSourceTuplesHavingTypeValue(EamArtifact.Type aType, String value) throws EamDbException { Connection conn = connect(); Long instanceCount = 0L; PreparedStatement preparedStatement = null; ResultSet resultSet = null; - String tableName = EamDbUtil.correlationTypeToInstanceTableName(eamArtifact.getCorrelationType()); + String tableName = EamDbUtil.correlationTypeToInstanceTableName(aType); StringBuilder sql = new StringBuilder(); sql.append("SELECT count(*) FROM (SELECT DISTINCT case_id, data_source_id FROM "); sql.append(tableName); @@ -728,7 +728,7 @@ public abstract class AbstractSqlEamDb implements EamDb { try { preparedStatement = conn.prepareStatement(sql.toString()); - preparedStatement.setString(1, eamArtifact.getCorrelationValue()); + preparedStatement.setString(1, value); resultSet = preparedStatement.executeQuery(); resultSet.next(); instanceCount = resultSet.getLong(1); @@ -792,16 +792,14 @@ public abstract class AbstractSqlEamDb implements EamDb { * associated with the caseDisplayName and dataSource of the given * eamArtifact instance. * - * @param eamInstance Instance with caseName and dataSource to search for - * - * @param eamInstance Instance with caseDisplayName and dataSource to search - * for + * @param caseUUID Case ID to search for + * @param dataSourceID Data source ID to search for * * @return Number of artifact instances having caseDisplayName and * dataSource */ @Override - public Long getCountArtifactInstancesByCaseDataSource(EamArtifactInstance eamInstance) throws EamDbException { + public Long getCountArtifactInstancesByCaseDataSource(String caseUUID, String dataSourceID) throws EamDbException { Connection conn = connect(); Long instanceCount = 0L; @@ -825,8 +823,8 @@ public abstract class AbstractSqlEamDb implements EamDb { preparedStatement = conn.prepareStatement(sql.toString()); for (int i = 0; i < artifactTypes.size(); ++i) { - preparedStatement.setString(2 * i + 1, eamInstance.getEamCase().getCaseUUID()); - preparedStatement.setString(2 * i + 2, eamInstance.getEamDataSource().getDeviceID()); + preparedStatement.setString(2 * i + 1, caseUUID); + preparedStatement.setString(2 * i + 2, dataSourceID); } resultSet = preparedStatement.executeQuery(); @@ -1056,12 +1054,13 @@ public abstract class AbstractSqlEamDb implements EamDb { * Gets list of matching eamArtifact instances that have knownStatus = * "Bad". * - * @param eamArtifact Artifact containing Type and Value - * + * @param aType EamArtifact.Type to search for + * @param value Value to search for + * * @return List with 0 or more matching eamArtifact instances. */ @Override - public List getArtifactInstancesKnownBad(EamArtifact eamArtifact) throws EamDbException { + public List getArtifactInstancesKnownBad(EamArtifact.Type aType, String value) throws EamDbException { Connection conn = connect(); List artifactInstances = new ArrayList<>(); @@ -1070,7 +1069,7 @@ public abstract class AbstractSqlEamDb implements EamDb { PreparedStatement preparedStatement = null; ResultSet resultSet = null; - String tableName = EamDbUtil.correlationTypeToInstanceTableName(eamArtifact.getCorrelationType()); + String tableName = EamDbUtil.correlationTypeToInstanceTableName(aType); StringBuilder sql = new StringBuilder(); sql.append("SELECT cases.case_name, cases.case_uid, data_sources.name, device_id, file_path, known_status, comment FROM "); sql.append(tableName); @@ -1084,7 +1083,7 @@ public abstract class AbstractSqlEamDb implements EamDb { try { preparedStatement = conn.prepareStatement(sql.toString()); - preparedStatement.setString(1, eamArtifact.getCorrelationValue()); + preparedStatement.setString(1, value); preparedStatement.setString(2, TskData.FileKnown.BAD.name()); resultSet = preparedStatement.executeQuery(); while (resultSet.next()) { @@ -1105,19 +1104,20 @@ public abstract class AbstractSqlEamDb implements EamDb { /** * Count matching eamArtifacts instances that have knownStatus = "Bad". * - * @param eamArtifact Artifact containing Type and Value + * @param aType EamArtifact.Type to search for + * @param value Value to search for * * @return Number of matching eamArtifacts */ @Override - public Long getCountArtifactInstancesKnownBad(EamArtifact eamArtifact) throws EamDbException { + public Long getCountArtifactInstancesKnownBad(EamArtifact.Type aType, String value) throws EamDbException { Connection conn = connect(); Long badInstances = 0L; PreparedStatement preparedStatement = null; ResultSet resultSet = null; - String tableName = EamDbUtil.correlationTypeToInstanceTableName(eamArtifact.getCorrelationType()); + String tableName = EamDbUtil.correlationTypeToInstanceTableName(aType); StringBuilder sql = new StringBuilder(); sql.append("SELECT count(*) FROM "); sql.append(tableName); @@ -1125,7 +1125,7 @@ public abstract class AbstractSqlEamDb implements EamDb { try { preparedStatement = conn.prepareStatement(sql.toString()); - preparedStatement.setString(1, eamArtifact.getCorrelationValue()); + preparedStatement.setString(1, value); preparedStatement.setString(2, TskData.FileKnown.BAD.name()); resultSet = preparedStatement.executeQuery(); resultSet.next(); @@ -1145,7 +1145,8 @@ public abstract class AbstractSqlEamDb implements EamDb { * Gets list of distinct case display names, where each case has 1+ Artifact * Instance matching eamArtifact with knownStatus = "Bad". * - * @param eamArtifact Artifact containing Type and Value + * @param aType EamArtifact.Type to search for + * @param value Value to search for * * @return List of cases containing this artifact with instances marked as * bad @@ -1153,7 +1154,7 @@ public abstract class AbstractSqlEamDb implements EamDb { * @throws EamDbException */ @Override - public List getListCasesHavingArtifactInstancesKnownBad(EamArtifact eamArtifact) throws EamDbException { + public List getListCasesHavingArtifactInstancesKnownBad(EamArtifact.Type aType, String value) throws EamDbException { Connection conn = connect(); Collection caseNames = new LinkedHashSet<>(); @@ -1161,7 +1162,7 @@ public abstract class AbstractSqlEamDb implements EamDb { PreparedStatement preparedStatement = null; ResultSet resultSet = null; - String tableName = EamDbUtil.correlationTypeToInstanceTableName(eamArtifact.getCorrelationType()); + String tableName = EamDbUtil.correlationTypeToInstanceTableName(aType); StringBuilder sql = new StringBuilder(); sql.append("SELECT DISTINCT case_name FROM "); sql.append(tableName); @@ -1175,7 +1176,7 @@ public abstract class AbstractSqlEamDb implements EamDb { try { preparedStatement = conn.prepareStatement(sql.toString()); - preparedStatement.setString(1, eamArtifact.getCorrelationValue()); + preparedStatement.setString(1, value); preparedStatement.setString(2, TskData.FileKnown.BAD.name()); resultSet = preparedStatement.executeQuery(); while (resultSet.next()) { @@ -1195,15 +1196,16 @@ public abstract class AbstractSqlEamDb implements EamDb { /** * Is the artifact known as bad according to the reference entries? * - * @param eamArtifact Artifact containing Type and Value + * @param aType EamArtifact.Type to search for + * @param value Value to search for * * @return Global known status of the artifact */ @Override - public boolean isArtifactlKnownBadByReference(EamArtifact eamArtifact) throws EamDbException { + public boolean isArtifactlKnownBadByReference(EamArtifact.Type aType, String value) throws EamDbException { // TEMP: Only support file correlation type - if (eamArtifact.getCorrelationType().getId() != EamArtifact.FILES_TYPE_ID) { + if (aType.getId() != EamArtifact.FILES_TYPE_ID) { return false; } @@ -1215,8 +1217,8 @@ public abstract class AbstractSqlEamDb implements EamDb { String sql = "SELECT count(*) FROM %s WHERE value=? AND known_status=?"; try { - preparedStatement = conn.prepareStatement(String.format(sql, EamDbUtil.correlationTypeToReferenceTableName(eamArtifact.getCorrelationType()))); - preparedStatement.setString(1, eamArtifact.getCorrelationValue()); + preparedStatement = conn.prepareStatement(String.format(sql, EamDbUtil.correlationTypeToReferenceTableName(aType))); + preparedStatement.setString(1, value); preparedStatement.setString(2, TskData.FileKnown.BAD.name()); resultSet = preparedStatement.executeQuery(); resultSet.next(); @@ -1413,7 +1415,8 @@ public abstract class AbstractSqlEamDb implements EamDb { * Add a new reference instance * * @param eamGlobalFileInstance The reference instance to add - * @param correlationType Correlation Type that this Reference Instance is + * @param correlationType Correlation Type that this Reference + * Instance is * * @throws EamDbException */ @@ -1453,7 +1456,7 @@ public abstract class AbstractSqlEamDb implements EamDb { try { // FUTURE: have a separate global_files table for each Type. String sql = "INSERT INTO %s(reference_set_id, value, known_status, comment) VALUES (?, ?, ?, ?) " - + getConflictClause(); + + getConflictClause(); bulkPs = conn.prepareStatement(String.format(sql, EamDbUtil.correlationTypeToReferenceTableName(contentType))); @@ -1477,7 +1480,7 @@ public abstract class AbstractSqlEamDb implements EamDb { /** * Get all reference entries having a given correlation type and value * - * @param aType Type to use for matching + * @param aType Type to use for matching * @param aValue Value to use for matching * * @return List of all global file instances with a type and value @@ -1517,6 +1520,7 @@ public abstract class AbstractSqlEamDb implements EamDb { * @param newType New type to add. * * @return ID of this new Correlation Type + * * @throws EamDbException */ @Override diff --git a/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/datamodel/EamDb.java b/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/datamodel/EamDb.java index d61f8f1b6b..c993d270e7 100644 --- a/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/datamodel/EamDb.java +++ b/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/datamodel/EamDb.java @@ -25,6 +25,7 @@ import java.util.Set; * Main interface for interacting with the database */ public interface EamDb { + public static final int SCHEMA_VERSION = 1; /** @@ -50,24 +51,22 @@ public interface EamDb { /** * Shutdown the connection pool. - * + * * This closes the connection pool including all idle database connections. - * It will not close active/in-use connections. - * Thus, it is vital that there are no in-use connections - * when you call this method. - * + * It will not close active/in-use connections. Thus, it is vital that there + * are no in-use connections when you call this method. + * * @throws EamDbException if there is a problem closing the connection pool. */ void shutdownConnections() throws EamDbException; /** * Update settings - * - * When using updateSettings, - * if any database settings have changed, you should call - * shutdownConnections() before using any API methods. - * That will ensure that any old connections are closed - * and all new connections will be made using the new settings. + * + * When using updateSettings, if any database settings have changed, you + * should call shutdownConnections() before using any API methods. That will + * ensure that any old connections are closed and all new connections will + * be made using the new settings. */ void updateSettings(); @@ -206,18 +205,19 @@ public interface EamDb { void addArtifact(EamArtifact eamArtifact) throws EamDbException; /** - * Retrieves eamArtifact instances from the database that are associated with - * the eamArtifactType and eamArtifactValue of the given eamArtifact. + * Retrieves eamArtifact instances from the database that are associated + * with the eamArtifactType and eamArtifactValue of the given eamArtifact. * - * @param eamArtifact The type/value to look up (artifact with 0 instances) + * @param aType EamArtifact.Type to search for + * @param value Value to search for * * @return List of artifact instances for a given type/value */ - List getArtifactInstancesByTypeValue(EamArtifact eamArtifact) throws EamDbException; + List getArtifactInstancesByTypeValue(EamArtifact.Type aType, String value) throws EamDbException; /** - * Retrieves eamArtifact instances from the database that are associated with - * the aType and filePath + * Retrieves eamArtifact instances from the database that are associated + * with the aType and filePath * * @param aType EamArtifact.Type to search for * @param filePath File path to search for @@ -232,13 +232,13 @@ public interface EamDb { * Retrieves number of artifact instances in the database that are * associated with the ArtifactType and artifactValue of the given artifact. * - * @param eamArtifact Artifact with artifactType and artifactValue to search - * for + * @param aType EamArtifact.Type to search for + * @param value Value to search for * * @return Number of artifact instances having ArtifactType and * ArtifactValue. */ - Long getCountArtifactInstancesByTypeValue(EamArtifact eamArtifact) throws EamDbException; + Long getCountArtifactInstancesByTypeValue(EamArtifact.Type aType, String value) throws EamDbException; /** * Using the ArtifactType and ArtifactValue from the given eamArtfact, @@ -246,24 +246,24 @@ public interface EamDb { * where Type/Value is found) divided by (The total number of unique * case_id/datasource_id tuples in the database) expressed as a percentage. * - * @param eamArtifact Artifact with artifactType and artifactValue to search - * for + * @param aType EamArtifact.Type to search for + * @param value Value to search for * * @return Int between 0 and 100 */ - int getCommonalityPercentageForTypeValue(EamArtifact eamArtifact) throws EamDbException; + int getCommonalityPercentageForTypeValue(EamArtifact.Type aType, String value) throws EamDbException; /** * Retrieves number of unique caseDisplayName / dataSource tuples in the * database that are associated with the artifactType and artifactValue of * the given artifact. * - * @param eamArtifact Artifact with artifactType and artifactValue to search - * for + * @param aType EamArtifact.Type to search for + * @param value Value to search for * * @return Number of unique tuples */ - Long getCountUniqueCaseDataSourceTuplesHavingTypeValue(EamArtifact eamArtifact) throws EamDbException; + Long getCountUniqueCaseDataSourceTuplesHavingTypeValue(EamArtifact.Type aType, String value) throws EamDbException; /** * Retrieves number of unique caseDisplayName/dataSource tuples in the @@ -278,15 +278,13 @@ public interface EamDb { * associated with the caseDisplayName and dataSource of the given * eamArtifact instance. * - * @param eamInstance Instance with caseName and dataSource to search for - * - * @param eamInstance Instance with caseDisplayName and dataSource to search - * for + * @param caseUUID Case ID to search for + * @param dataSourceID Data source ID to search for * * @return Number of artifact instances having caseDisplayName and * dataSource */ - Long getCountArtifactInstancesByCaseDataSource(EamArtifactInstance eamInstance) throws EamDbException; + Long getCountArtifactInstancesByCaseDataSource(String caseUUID, String dataSourceID) throws EamDbException; /** * Adds an eamArtifact to an internal list to be later added to DB. Artifact @@ -309,52 +307,57 @@ public interface EamDb { void bulkInsertCases(List cases) throws EamDbException; /** - * Sets an eamArtifact instance as knownStatus = "Bad". If eamArtifact exists, - * it is updated. If eamArtifact does not exist nothing happens + * Sets an eamArtifact instance as knownStatus = "Bad". If eamArtifact + * exists, it is updated. If eamArtifact does not exist nothing happens * * @param eamArtifact Artifact containing exactly one (1) ArtifactInstance. */ void setArtifactInstanceKnownBad(EamArtifact eamArtifact) throws EamDbException; /** - * Gets list of matching eamArtifact instances that have knownStatus = "Bad". + * Gets list of matching eamArtifact instances that have knownStatus = + * "Bad". * - * @param eamArtifact Artifact containing Type and Value + * @param aType EamArtifact.Type to search for + * @param value Value to search for * * @return List with 0 or more matching eamArtifact instances. */ - List getArtifactInstancesKnownBad(EamArtifact eamArtifact) throws EamDbException; + List getArtifactInstancesKnownBad(EamArtifact.Type aType, String value) throws EamDbException; /** * Count matching eamArtifacts instances that have knownStatus = "Bad". * - * @param eamArtifact Artifact containing Type and Value + * @param aType EamArtifact.Type to search for + * @param value Value to search for * * @return Number of matching eamArtifacts */ - Long getCountArtifactInstancesKnownBad(EamArtifact eamArtifact) throws EamDbException; + Long getCountArtifactInstancesKnownBad(EamArtifact.Type aType, String value) throws EamDbException; /** * Gets list of distinct case display names, where each case has 1+ Artifact * Instance matching eamArtifact with knownStatus = "Bad". * - * @param eamArtifact Artifact containing Type and Value + * @param aType EamArtifact.Type to search for + * @param value Value to search for * * @return List of cases containing this artifact with instances marked as * bad * * @throws EamDbException */ - List getListCasesHavingArtifactInstancesKnownBad(EamArtifact eamArtifact) throws EamDbException; + List getListCasesHavingArtifactInstancesKnownBad(EamArtifact.Type aType, String value) throws EamDbException; /** * Is the artifact known as bad according to the reference entries? * - * @param eamArtifact Artifact containing Type and Value + * @param aType EamArtifact.Type to search for + * @param value Value to search for * * @return Global known status of the artifact */ - boolean isArtifactlKnownBadByReference(EamArtifact eamArtifact) throws EamDbException; + boolean isArtifactlKnownBadByReference(EamArtifact.Type aType, String value) throws EamDbException; /** * Add a new organization @@ -411,12 +414,13 @@ public interface EamDb { * Add a new reference instance * * @param eamGlobalFileInstance The reference instance to add - * @param correlationType Correlation Type that this Reference Instance is + * @param correlationType Correlation Type that this Reference + * Instance is * * @throws EamDbException */ - void addReferenceInstance(EamGlobalFileInstance eamGlobalFileInstance, EamArtifact.Type correlationType) throws EamDbException ; - + void addReferenceInstance(EamGlobalFileInstance eamGlobalFileInstance, EamArtifact.Type correlationType) throws EamDbException; + /** * Add a new global file instance to the bulk collection * @@ -425,13 +429,13 @@ public interface EamDb { * @throws EamDbException */ // void prepareGlobalFileInstance(EamGlobalFileInstance eamGlobalFileInstance) throws EamDbException; - /** * Insert the bulk collection of Global File Instances * - * @param globalInstances a Set of EamGlobalFileInstances to insert into the db. - * @param contentType the Type of the global instances - * + * @param globalInstances a Set of EamGlobalFileInstances to insert into the + * db. + * @param contentType the Type of the global instances + * * @throws EamDbException */ void bulkInsertReferenceTypeEntries(Set globalInstances, EamArtifact.Type contentType) throws EamDbException; @@ -439,7 +443,7 @@ public interface EamDb { /** * Get all reference entries having a given correlation type and value * - * @param aType Type to use for matching + * @param aType Type to use for matching * @param aValue Value to use for matching * * @return List of all global file instances with a type and value @@ -454,6 +458,7 @@ public interface EamDb { * @param newType New type to add. * * @return Type.ID for newType + * * @throws EamDbException */ public int newCorrelationType(EamArtifact.Type newType) throws EamDbException; diff --git a/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/eventlisteners/IngestEventsListener.java b/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/eventlisteners/IngestEventsListener.java index bce503eab7..333bb93f84 100644 --- a/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/eventlisteners/IngestEventsListener.java +++ b/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/eventlisteners/IngestEventsListener.java @@ -102,7 +102,7 @@ public class IngestEventsListener { // query db for artifact instances having this TYPE/VALUE and knownStatus = "Bad". // if gettKnownStatus() is "Unknown" and this artifact instance was marked bad in a previous case, // create TSK_INTERESTING_ARTIFACT_HIT artifact on BB. - List caseDisplayNames = dbManager.getListCasesHavingArtifactInstancesKnownBad(eamArtifact); + List caseDisplayNames = dbManager.getListCasesHavingArtifactInstancesKnownBad(eamArtifact.getCorrelationType(), eamArtifact.getCorrelationValue()); if (!caseDisplayNames.isEmpty()) { postCorrelatedBadArtifactToBlackboard(bbArtifact, caseDisplayNames); diff --git a/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/ingestmodule/IngestModule.java b/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/ingestmodule/IngestModule.java index 5411a8c983..d64f06a56a 100644 --- a/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/ingestmodule/IngestModule.java +++ b/CentralRepository/src/org/sleuthkit/autopsy/centralrepository/ingestmodule/IngestModule.java @@ -101,15 +101,13 @@ class IngestModule implements FileIngestModule { return ProcessResult.OK; } - EamArtifact eamArtifact = new EamArtifact(filesType, md5); - // If unknown to both the hash module and as a globally known artifact in the EAM DB, correlate to other cases if (af.getKnown() == TskData.FileKnown.UNKNOWN) { // query db for artifact instances having this MD5 and knownStatus = "Bad". try { // if af.getKnown() is "UNKNOWN" and this artifact instance was marked bad in a previous case, // create TSK_INTERESTING_FILE artifact on BB. - List caseDisplayNames = dbManager.getListCasesHavingArtifactInstancesKnownBad(eamArtifact); + List caseDisplayNames = dbManager.getListCasesHavingArtifactInstancesKnownBad(filesType, md5); if (!caseDisplayNames.isEmpty()) { postCorrelatedBadFileToBlackboard(af, caseDisplayNames); } @@ -121,7 +119,7 @@ class IngestModule implements FileIngestModule { // Make a TSK_HASHSET_HIT blackboard artifact for global known bad files try { - if (dbManager.isArtifactlKnownBadByReference(eamArtifact)) { + if (dbManager.isArtifactlKnownBadByReference(filesType, md5)) { postCorrelatedHashHitToBlackboard(af); } } catch (EamDbException ex) { @@ -130,6 +128,7 @@ class IngestModule implements FileIngestModule { } try { + EamArtifact eamArtifact = new EamArtifact(filesType, md5); EamArtifactInstance cefi = new EamArtifactInstance( eamCase, eamDataSource, @@ -167,7 +166,7 @@ class IngestModule implements FileIngestModule { LOGGER.log(Level.SEVERE, "Error doing bulk insert of artifacts.", ex); // NON-NLS } try { - Long count = dbManager.getCountArtifactInstancesByCaseDataSource(new EamArtifactInstance(eamCase, eamDataSource)); + Long count = dbManager.getCountArtifactInstancesByCaseDataSource(eamCase.getCaseUUID(), eamDataSource.getDeviceID()); LOGGER.log(Level.INFO, "{0} artifacts in db for case: {1} ds:{2}", new Object[]{count, eamCase.getDisplayName(), eamDataSource.getName()}); // NON-NLS } catch (EamDbException ex) { LOGGER.log(Level.SEVERE, "Error counting artifacts.", ex); // NON-NLS