Metadata Analysis and Encryption in Decentralized Messaging Applications using NIST SP 800-86

Authors

  • Firmansyah Firmansyah Universitas Ahmad Dahlan
  • Firmansyah Firmansyah Universitas Islam Al-Azhar
  • Imam Riadi Universitas Ahmad Dahlan
  • Sunardi Sunardi Universitas Ahmad Dahlan

DOI:

https://doi.org/10.33506/insect.v12i2.5702

Keywords:

Digital Forensics, NIST SP 800-86, Session, BitChat, Metadata Analysis

Abstract

This study conducted a digital forensic analysis of metadata on two decentralized messaging applications: Session, based on Oxen onion routing with E2EE Libsodium, and BitChat, based on an ephemeral Bluetooth mesh network. The main objective was to compare the metadata leakage resilience of both applications and the effectiveness of the NIST SP 800-86 framework in the investigation process. The study used a forensic simulation approach on a rooted Android device in a controlled environment. The process was carried out according to the four phases of NIST SP 800-86: Collection, Examination, Analysis, and Reporting. The analyzed data included volatile data RAM dumps, BLE packets, persistent storage database SQLCipher, network artifacts, and system logs. The results showed significant differences. In Session, 47 message metadata were successfully extracted from the signal.db file along with attachment paths and onion routing hops with a 65% recovery rate. Meanwhile, BitChat only generated 12 hop events along with RSSI proximity data with a 25% recovery rate, mostly from volatile memory due to its panic wipe feature and ephemeral nature. Session is more vulnerable to timeline reconstruction, while BitChat excels in resistance to local forensics. This study concludes that no privacy-by-design application is completely immune to digital forensics. Session is better suited for conventional investigations, while BitChat provides better protection in high-risk offline scenarios. Recommendations are provided for users, investigators, and application developers to improve anti-forensic mechanisms.

References

[1] A. Apriliani, K. Hijjayanti, And S. Suhairoh, “Analisis Keaslian Citra Dengan Menggunakan Exif Metadata,” Cess (Journal Of Computer Engineering, System And Science), Vol. 5, No. 1, 2020, doi: 10.24114/cess.v5i1.15600.

[2] M. Fransiskus And N. P, “Analisis Digital Forensik Metadata Pada Rekayasa Digital Image Sebagai Barang Bukti Digital,” Jurnal Sains Dan Komputer, Vol. 8, No. 01, 2024, doi: 10.61179/jurnalinfact.v8i01.439.

[3] K. Eka Purnama, C. Rozikin, And A. Ali Ridha, “Analisis Forensic Citra Digital Menggunakan Teknik Error Level Analysis Dan Metadata Berdasarkan Metode NIST,” Jati (Jurnal Mahasiswa Teknik Informatika), Vol. 7, No. 2, 2023, doi: 10.36040/jati.v7i2.6660.

[4] R. Anjelina And N. P, “Analisis Forensik Dengan Menerapkan Metadata Dan Hash Studi Kasus Pada Rekaman Video,” Informatik : Jurnal Ilmu Komputer, Vol. 20, No. 3, 2024, doi: 10.52958/iftk.v20i3.8770.

[5] H. A. Syuhrawardi, S. Anraeni, And E. I. Alwi, “Analisis Perbandingan Metadata Bukti Digital Gambar Dengan Menggunakan Tools Metadata++,” Linier: Literatur Informatika Dan Komputer, Vol. 2, No. 1, 2025, doi: 10.33096/linier.v2i1.2782.

[6] N. C. P. Trisuwita And R. P. Kristianto, “Analisis Metadata Exiftool Dan Framework NIST Untuk Deteksi Manipulasi Citra,” Jupiter : Journal Of Computer & Information Technology, Vol. 6, No. 2, 2025, doi: 10.53990/jupiter.v6i2.462.

[7] I. Riadi, A. Fadlil, And A. Fauzan, “A Study Of Mobile Forensic Tools Evaluation On Android-Based Line Messenger,” International Journal Of Advanced Computer Science And Applications, Vol. 9, No. 10, 2018, doi: 10.14569/ijacsa.2018.091024.

[8] M. H. A. Husen And F. Firmansyah, “Implementation Of Mikhmon Server For Qos Optimization And Traffic Control On Mikhmon Hotspot Network At Amicom Net,” Mobile And Forensics, Vol. 7, No. 2, 2025, doi: 10.12928/mf.v7i2.14076.

[9] F. Firmansyah, B. Wibisana, And M. Jordan, “Analyze Threats In A Virtual Lab Network Using Live Forensic Methods On Metarouter,” International Journal Of Engineering And Computer Science Applications (Ijecsa), Vol. 4, No. 1, 2025, doi: 10.30812/ijecsa.v4i1.4784.

[10] I. Riadi, A. Yudhana, And G. P. I. Fanani, “Comparative Analysis Of Forensic Software On Android-Based Michat Using Acpo And Dfrws Framework,” Jurnal Resti, Vol. 7, No. 2, 2023, doi: 10.29207/resti.v7i2.4547.

[11] I. Riadi, Herman, And N. H. Siregar, “Mobile Forensic Analysis Of Signal Messenger Application On Android Using Digital Forensic Research Workshop (Dfrws) Framework,” Ingenierie Des Systemes D’information, Vol. 27, No. 6, 2022, doi: 10.18280/isi.270606.

[12] I. Riadi, Sunardi, And P. Widiandana, “Cyberbullying Detection On Instant Messaging Services Using Rocchio And Digital Forensics Research Workshop Framework,” Journal Of Engineering Science And Technology, Vol. 17, No. 2, 2022.

[13] I. Riadi, R. Umar, And M. I. Syahib, “Akuisisi Bukti Digital Viber Messenger Android Menggunakan Metode National Institute Of Standards And Technology (NIST),” Jurnal Resti, Vol. 5, No. 1, 2021, doi: 10.29207/resti.v5i1.2626.

[14] W. Panggah, S. Sunardi, And I. Riadi, “Forensik Digital Cyberbullying Pada Grup Whatsapp Menggunakan National Institute Of Standards And Technology,” Insect (Informatics And Security) : Jurnal Teknik Informatika, Vol. 12, No. 1, Pp. 34–41, Mar. 2026, doi: https://doi.org/10.33506/insect.v12i01.5275.

[15] Y. Safitri, F. Firmansyah, And M. A. Mu’min, “Mobile Forensic Analysis On Imo Messenger Application Using Acpo And Nij Frameworks,” Insect (Informatics And Security): Jurnal Teknik Informatika, Vol. 11, No. 1, 2025, doi: 10.33506/insect.v10i2.4052.

[16] F. R. Adriani And I. Riadi, “Forensic Analysis Of Website In Cyberbullying Cases On Instagram Using National Institute Of Justice Method,” Int. J. Comput. Appl., Vol. 187, No. 38, 2025, doi: 10.5120/Ijca2025925678.

[17] S. A. Putri And I. Riadi, “Mobile Forensic Analysis Of Michat Application In Human Trafficking Cases Using National Institute Of Justice Method,” Int. J. Comput. Appl., Vol. 187, No. 37, 2025, doi: 10.5120/ijca2025925638.

[18] A. N. Mansur And I. Riadi, “Digital Forensic Analysis Of Tiktok Application In Defamation Cases Using Digital Forensics Research Workshop Method,” Int. J. Comput. Appl., Vol. 187, No. 47, 2025, doi: 10.5120/ijca2025925795.

[19] N. Anwar And I. Riadi, “Analisis Investigasi Forensik Whatsapp Messanger Smartphone Terhadap Whatsapp Berbasis Web,” Jurnal Ilmiah Teknik Elektro Komputer Dan Informatika, Vol. 3, No. 1, 2017, doi: 10.26555/jiteki.v3i1.6643.

[20] H. S. Alawi, I. Riadi, And S. Sunardi, “Analisis Forensik Digital Terhadap Kasus Penipuan Pada E-Commerce Menggunakan Metode Acpo,” Jurnal Informatika: Jurnal Pengembangan It, Vol. 10, No. 3, 2025, doi: 10.30591/jpit.v10i3.8604.

[21] C. Umam, L. B. Handoko, C. A. Sari, E. H. Rachmawanto, And L. A. R. Hakim, “Kombinasi Vigenere Dan Autokey Cipher Dalam Proses Proteksi Sms Berbasis Android,” Prosiding Sains Nasional Dan Teknologi, Vol. 12, No. 1, 2022, doi: 10.36499/psnst.v12i1.7108.

[22] M. Alda And M. I. Rifki, “Implementasi Metode Triple Des Pada Aplikasi Keamanan Pesan Berbasis Mobile,” Jointecs (Journal Of Information Technology And Computer Science), Vol. 7, No. 1, 2022, doi: 10.31328/jointecs.v7i1.3281.

[23] D. Darmansyah And A. Halim Hasugian, “Enkripsi Pesan Chat Menggunakan Algoritma Chacha20 Pada Aplikasi Komunikasi Real-Time,” Rabit : Jurnal Teknologi Dan Sistem Informasi Univrab, Vol. 10, No. 2, 2025, doi: 10.36341/rabit.v10i2.6220.

[24] R. Herzallah, “Probabilistic Message Passing For Decentralized Control Of Stochastic Complex Systems,” IEEE Access, Vol. 7, 2019, doi: 10.1109/access.2019.2961165.

[25] K. Takeuchi, “Decentralized Generalized Approximate Message-Passing For Tree-Structured Networks,” IEEE Trans. Inf. Theory, Vol. 70, No. 10, 2024, doi: 10.1109/tit.2024.3449321.

[26] X. Huang And S. Zhou, “Qmnet: Importance-Aware Message Exchange For Decentralized Multi-Agent Reinforcement Learning,” IEEE Trans. Mob. Comput., Vol. 23, No. 5, 2024, doi: 10.1109/tmc.2023.3296726.

[27] S. Evangelatos Et Al., “Adaptive Policy-Oriented Cybersecurity: A Decentralized Framework Using Message Passing Algorithms For Dynamic Threat Mitigation,” IEEE Access, Vol. 13, 2025, doi: 10.1109/access.2025.3559428.

[28] B. M. Jeong, D. S. Jang, And H. L. Choi, “Decentralized Message Passing Algorithm For Heterogeneous Multi-Depot Vehicle Routing Problems,” Operations Research Perspectives, Vol. 14, 2025, doi: 10.1016/j.orp.2025.100341.

[29] S. Liu, H. Zhang, And Q. Zou, “Decentralized Channel Estimation For The Uplink Of Grant-Free Massive Machine-Type Communications,” IEEE Transactions On Communications, Vol. 70, No. 2, 2022, doi: 10.1109/tcomm.2021.3126619.

[30] Q. Xie, P. Zheng, Z. Ding, X. Tan, And B. Hu, “Provable Secure And Lightweight Vehicle Message Broadcasting Authentication Protocol With Privacy Protection For Vanets,” Security And Communication Networks, Vol. 2022, 2022, doi: 10.1155/2022/3372489.

[31] Z. Zhang, Y. Dong, K. Long, X. Wang, And X. Dai, “Decentralized Baseband Processing With Gaussian Message Passing Detection For Uplink Massive Mu-Mimo Systems,” IEEE Trans. Veh. Technol., Vol. 71, No. 2, 2022, doi: 10.1109/tvt.2021.3133111.

[32] S. Sen And H. Artuner, “Emulator Forensics Investigation Model (Efim),” IEEE Access, Vol. 13, 2025, doi: 10.1109/access.2025.3585096.

[33] R. Pratiwi, L. C. Utami, R. Bima Sakti, And Triase, “Perancangan Keamanan Data Pesan Dengan Menggunakan Metode Kriptografi Caesar Cipher,” Bulletin Of Information Technology (Bit), Vol. 3, No. 4, 2022, doi: 10.47065/bit.V3i4.420.

[34] S. N. Nugraha, “Penerapan Algoritma Kriptografi Elgamal Pada Aplikasi Pengamanan Pesan Berbasis Website,” Jurnal Informatika Dan Teknik Elektro Terapan, Vol. 12, No. 3, 2024, doi: 10.23960/jitet.v12i3.4794.

[35] Shravan Vilas Mate, Utkarsha Anandrao Tembhurkar, Vedant Keshawanad Nikhare, Prof. Vaishali Patil, And Saurabh Baijlal Yelekar, “Secure Messaging Application With Steganography-Based Encryption,” International Journal Of Advanced Research In Science, Communication And Technology, 2025, doi: 10.48175/ijarsct-29873.

[36] R. Karthikeyan, Mopuru Deepika, Nelamala Yashwanth, Athikayala Pranay Kumar Yadav, And Duvuru Mohith Reddy, “Identifying Drug Traffickers On Encrypted Messaging Apps,” International Journal Of Scientific Research In Computer Science, Engineering And Information Technology, Vol. 11, No. 2, 2025, doi: 10.32628/cseit25112818.

[37] W. A. Prabowo, F. Mohsen, And S. R. Selamat, “Whatsapp Mobile Applications In The Lens Of Digital Forensics: Deciphering The Msgstore.Db.Crypt14 File,” Journal Of Cyber Security And Mobility, Vol. 14, No. 4, 2025, doi: 10.13052/jcsm2245-1439.1443.

[38] E. C. T. T. Totnay, M. M. Seran, V. V. Y. Tusala, S. T. Mau, And H. L. To, “Enkripsi End-To-End Pada Aplikasi Whatsapp Menggunakan Metode Aes-256,” Blantika: Multidisciplinary Journal, Vol. 3, No. 7, 2025, doi: 10.57096/blantika.v3i7.380.

[39] A. Pujol, L. Murphy, And C. Thorpe, “Fedoram: A Federated Oblivious Ram Scheme,” IEEE Access, Vol. 8, 2020, doi: 10.1109/access.2020.3027516.

[40] W. S. Ong And N. H. Ab Rahman, “A Forensic Analysis Visualization Tool For Mobile Instant Messaging Apps,” International Journal On Information And Communication Technology (Ijoict), Vol. 6, No. 2, 2020, doi: 10.21108/ijoict.2020.62.530.

[41] D. Wijnberg And N. A. Le-Khac, “Identifying Interception Possibilities For Whatsapp Communication,” Forensic Science International: Digital Investigation, Vol. 38, 2021, doi: 10.1016/j.fsidi.2021.301132.

[42] A. Ffaizal And A. Luthfi, “Comparison Study Of NIST Sp 800-86 And Iso/Iec 27037 Standards As A Framework For Digital Forensic Evidence Analysis,” Journal Of Information Systems And Informatics, Vol. 6, No. 2, 2024, doi: 10.51519/journalisi.v6i2.717.

[43] D. Hariyadi, M. W. Indriyanto, And M. Habibi, “Investigasi Dan Analisis Forensik Digital Pada Percakapan Grup Whatsapp Menggunakan NIST Sp 800-86 Dan Support Vector Machine,” Cyber Security Dan Forensik Digital, Vol. 3, No. 2, 2020, doi: 10.14421/csecurity.2020.3.2.2193.

[44] K. Kent, S. Chevalier, T. Grance, And H. Dang, “Special Publication 800-86 Guide To Integrating Forensic Techniques Into Incident Response Recommendations Of The National Institute Of Standards And Technology.”

Downloads

Published

19-08-2026

How to Cite

Firmansyah, F., Firmansyah, F., Riadi, I., & Sunardi, S. (2026). Metadata Analysis and Encryption in Decentralized Messaging Applications using NIST SP 800-86. Insect (Informatics and Security): Jurnal Teknik Informatika, 12(2), 168–180. https://doi.org/10.33506/insect.v12i2.5702

Similar Articles

<< < 1 2 3 > >> 

You may also start an advanced similarity search for this article.