further improvements (cleanup, speed) in running regripper and pasco

This commit is contained in:
adam-m
2013-05-21 12:44:52 -04:00
parent 4021abec58
commit fa2bb0c2c9
3 changed files with 77 additions and 42 deletions
@@ -41,7 +41,8 @@ public final class ExecUtil {
/**
* Execute a process. Redirect asynchronously stdout to a string and stderr
* to nowhere. Use only for small outputs, otherwise use the execute() variant with Writer.
* to nowhere. Use only for small outputs, otherwise use the execute()
* variant with Writer.
*
* @param aCommand command to be executed
* @param params parameters of the command
@@ -100,10 +101,9 @@ public final class ExecUtil {
return output;
}
/**
* Execute a process. Redirect asynchronously stdout to a passed in writer and stderr
* to nowhere.
/**
* Execute a process. Redirect asynchronously stdout to a passed in writer
* and stderr to nowhere.
*
* @param stdoutWriter file writer to write stdout to
* @param aCommand command to be executed
@@ -128,12 +128,14 @@ public final class ExecUtil {
logger.log(Level.INFO, "Executing " + arrayCommandToLog.toString());
proc = rt.exec(arrayCommand);
if (false) {
try {
//give time to fully start the process
Thread.sleep(2000);
} catch (InterruptedException ex) {
logger.log(Level.WARNING, "Pause interrupted", ex);
}
}
//stderr redirect
errorStringRedirect = new ExecUtil.StreamToStringRedirect(proc.getErrorStream(), "ERROR");
@@ -148,17 +150,13 @@ public final class ExecUtil {
final int exitVal = proc.waitFor();
logger.log(Level.INFO, aCommand + " exit value: " + exitVal);
errorStringRedirect.stopRun();
errorStringRedirect = null;
outputWriterRedirect.stopRun();
outputWriterRedirect = null;
//gc process with its streams
proc = null;
}
/**
* Interrupt the running process and stop its stream redirect threads
*/
public synchronized void stop() {
logger.log(Level.INFO, "Stopping Execution of: " + command);
@@ -171,7 +169,7 @@ public final class ExecUtil {
outputStringRedirect.stopRun();
outputStringRedirect = null;
}
if (outputWriterRedirect != null) {
outputWriterRedirect.stopRun();
outputWriterRedirect = null;
@@ -210,15 +208,25 @@ public final class ExecUtil {
@Override
public final void run() {
final String SEP = System.getProperty("line.separator");
InputStreamReader isr = null;
BufferedReader br = null;
try {
final InputStreamReader isr = new InputStreamReader(this.is);
final BufferedReader br = new BufferedReader(isr);
isr = new InputStreamReader(this.is);
br = new BufferedReader(isr);
String line = null;
while (doRun && (line = br.readLine()) != null) {
this.output.append(line).append(SEP);
}
} catch (final IOException ex) {
logger.log(Level.WARNING, "Error redirecting stream to string buffer", ex);
} finally {
if (br != null) {
try {
br.close();
} catch (IOException ex) {
logger.log(Level.SEVERE, "Error closing stream reader", ex);
}
}
}
}
@@ -271,9 +279,11 @@ public final class ExecUtil {
@Override
public final void run() {
final String SEP = System.getProperty("line.separator");
InputStreamReader isr = null;
BufferedReader br = null;
try {
final InputStreamReader isr = new InputStreamReader(this.is);
final BufferedReader br = new BufferedReader(isr);
isr = new InputStreamReader(this.is);
br = new BufferedReader(isr);
String line = null;
while (doRun && (line = br.readLine()) != null) {
writer.append(line).append(SEP);
@@ -282,7 +292,13 @@ public final class ExecUtil {
logger.log(Level.SEVERE, "Error reading output and writing to file writer", ex);
} finally {
try {
writer.flush();
if (doRun) {
writer.flush();
}
if (br != null) {
br.close();
}
} catch (IOException ex) {
logger.log(Level.SEVERE, "Error flushing file writer", ex);
}
@@ -290,7 +306,7 @@ public final class ExecUtil {
}
/**
* Stop running the stream redirect. The thread will exit out gracefully
* Stop running the stream redirect. The thread will exit out gracefully
* after the current readLine() on stream unblocks
*/
public void stopRun() {
@@ -26,12 +26,9 @@ package org.sleuthkit.autopsy.recentactivity;
import java.io.File;
import java.io.FileInputStream;
import java.io.FileNotFoundException;
import java.io.FileWriter;
import java.io.IOException;
import java.io.UnsupportedEncodingException;
// SQL imports
import java.sql.ResultSet;
import java.sql.SQLException;
import java.io.Writer;
//Util Imports
import java.text.ParseException;
@@ -392,19 +389,15 @@ public class ExtractIE extends Extract implements IngestModuleImage {
}
boolean success = true;
Writer writer = null;
try {
StringBuilder command = new StringBuilder();
command.append(" -cp");
command.append(" \"").append(PASCO_LIB_PATH).append("\"");
command.append(" isi.pasco2.Main");
command.append(" -T history");
command.append(" \"").append(indexFilePath).append("\"");
command.append(" > \"").append(PASCO_RESULTS_PATH).append("\\" + filename + "\"");
// command.add(" > " + "\"" + PASCO_RESULTS_PATH + File.separator + Long.toString(bbId) + "\"");
String cmd = command.toString();
final String pascoOutFile = PASCO_RESULTS_PATH + File.separator + filename;
logger.log(Level.INFO, "Writing pasco results to: " + pascoOutFile);
writer = new FileWriter(pascoOutFile);
execPasco = new ExecUtil();
execPasco.execute("\"" + JAVA_PATH + " " + cmd + "\"");
execPasco.execute(writer, JAVA_PATH,
"-cp", PASCO_LIB_PATH,
"isi.pasco2.Main", "-T", "history", indexFilePath );
} catch (IOException ex) {
success = false;
@@ -413,6 +406,16 @@ public class ExtractIE extends Extract implements IngestModuleImage {
success = false;
logger.log(Level.SEVERE, "Pasco has been interrupted, failed to extract some web history from Internet Explorer.", ex);
}
finally {
if (writer != null) {
try {
writer.flush();
writer.close();
} catch (IOException ex) {
logger.log(Level.WARNING, "Error closing writer stream after for Pasco result", ex);
}
}
}
return success;
}
@@ -165,34 +165,50 @@ public class ExtractRegistry extends Extract implements IngestModuleImage {
String txtPath = regFilePath + Integer.toString(fileIndex) + ".txt";
String type = "";
Writer writer = null;
try {
if (regFilePath.toLowerCase().contains("system")) {
type = "autopsysystem";
}
if (regFilePath.toLowerCase().contains("software")) {
else if (regFilePath.toLowerCase().contains("software")) {
type = "autopsysoftware";
}
if (regFilePath.toLowerCase().contains("ntuser")) {
else if (regFilePath.toLowerCase().contains("ntuser")) {
type = "autopsy";
}
if (regFilePath.toLowerCase().contains("default")) {
else if (regFilePath.toLowerCase().contains("default")) {
type = "1default";
}
if (regFilePath.toLowerCase().contains("sam")) {
else if (regFilePath.toLowerCase().contains("sam")) {
type = "1sam";
}
if (regFilePath.toLowerCase().contains("security")) {
else if (regFilePath.toLowerCase().contains("security")) {
type = "1security";
}
String command = "\"" + RR_PATH + "\" -r \"" + regFilePath + "\" -f " + type + " > \"" + txtPath + "\" 2> NUL";
else {
type = "1default";
}
logger.log(Level.INFO, "Writing RegRipper results to: " + txtPath);
writer = new FileWriter(txtPath);
execRR = new ExecUtil();
execRR.execute("\"" + command + "\"");
execRR.execute(writer, RR_PATH,
"-r", regFilePath, "-f", type);
} catch (IOException ex) {
logger.log(Level.SEVERE, "Unable to RegRipper and process parse some registry files.", ex);
} catch (InterruptedException ex) {
logger.log(Level.SEVERE, "RegRipper has been interrupted, failed to parse registry.", ex);
}
finally {
if (writer != null) {
try {
writer.close();
} catch (IOException ex) {
logger.log(Level.SEVERE, "Error closing output writer after running RegRipper", ex);
}
}
}
return txtPath;
}