Cybercrime is a new form of criminal activity that has emerged alongside the advancement of information and communication technology (ICT). Unlike traditional crimes that occur in physical space, cybercrimes unfold in the intangible environment of cyberspace. These crimes are generally classified into two categories: cyber-dependent crimes, which cannot occur without the use of computers and networks and cyber-enabled crimes, which are conventional crimes transformed through digital means. Definitions and classifications vary by country and international organization, reflecting the diverse nature of the phenomenon. The widespread adoption of digital technologies and the normalization of cyberspace have significantly diversified and intensified cybercrime patterns, exposing limitations in traditional investigative systems. While cybercrimes leave behind digital traces such as logs, communication records, cryptocurrency transactions, social media content, and dark web data, these clues are often unstructured, decentralized, and perishable, thereby requiring immediate and systematic collection and analysis. This study aims to classify the types and characteristics of investigative clues in cybercrime and proposes an integrated analytical framework to systematically collect, process, analyze, and utilize them. The framework consists of automated multi-source clue collection, data preprocessing and metadata processing, knowledge graph-based social network analysis, AI-driven suspect inference and risk assessment, and visualization with investigator feedback. It reflects key attributes of cybercrime clues— unstructuredness, real-timeness, concealability, and legal sensitivity—and is designed to improve both the efficiency and accuracy of cyber investigations. To enhance the practical utility of the framework, policy recommendations include establishing a national information-sharing system, developing a cross-agency investigative platform, improving institutional AI acceptance, building living-lab testing environments, and fostering specialized human resources. Future research should focus on empirical validation of performance and legal compatibility of AI-based inference systems.
한국어
사이버 범죄는 정보통신기술의 발달과 함께 등장한 새로운 유형의 범죄로, 기존의 물리적 공 간을 기반으로 한 전통 범죄와 달리 사이버 공간이라는 비물질적 환경에서 발생한다. 이러한 사 이버 범죄는 컴퓨터와 네트워크가 없이는 성립할 수 없는 ‘사이버 의존 범죄’와 전통적 범죄가 사 이버 공간을 수단으로 변형된 ‘사이버 가능 범죄’로 구분되며, 그 정의와 분류는 국가 및 국제기 구마다 다양하게 존재한다. 디지털 기술의 확산과 사이버 공간의 일상화는 사이버 범죄의 양상 과 수법을 다변화하고 고도화시키며, 전통적 수사체계의 한계를 드러내고 있다. 사이버 범죄는 로그, 통신기록, 암호화폐 거래정보, SNS 및 다크웹 정보 등 수많은 디지털 흔적을 단서로 남기 고 있으나, 이러한 단서들은 비정형적이고 분산되어 있으며, 실시간 수집과 분석이 이루어지지 않을 경우 증거로서의 가치를 상실하기 쉬운 특성을 가진다. 본 연구는 사이버 범죄 수사에서 핵 심이 되는 수사단서의 특성과 유형을 분류하고, 이를 체계적으로 수집·분석·활용하기 위한 통 합 분석 프레임워크를 설계하였다. 제안된 프레임워크는 다중 출처 단서의 자동 수집, 데이터 전 처리 및 메타처리, 지식그래프 기반 사회연결망 분석, AI 기반 용의자 추론 및 위험도 평가, 시각 화 및 수사 피드백 순환 구조로 구성된다. 이 과정은 수사단서의 비정형성, 실시간성, 고도의 은 닉성, 법적 민감성 등 사이버 단서의 특수성을 반영하여 설계되었으며, 수사 효율성과 정확도를 동시에 제고하는 데 목적이 있다. 프레임워크의 효율성을 높이기 위해서는 수사정보 공유체계 정비, 범정부 통합 플랫폼 구축, AI 기술 수용성 확대, 리빙랩 기반의 실증 환경 조성, 수사 전문 인력 양성 등이 필요하다. 후속연구에서는 실증 기반의 성능 평가 및 법적 정합성 검토 등이 이 루어져야 할 것이다.
목차
요약 Ⅰ. 서론 Ⅱ. 이론적 배경 Ⅲ. 수사단서 통합 분석 프레임워크 설계 Ⅳ. 결론 및 정책적 시사점 참고문헌 【Abstract】