Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 18
No
1

5,500원

국가핵심기술과 산업기술 유출에 따른 경제적 손실뿐만 아니라 국가안보에 미치는 피해가 커 짐에 따라 산업현장에서 즉각적으로 유출 사실을 파악하거나 기술유출의 차단과 원상회복 등의 산업보안조사가 필요하다. 하지만 산업보안조사는 임의적 행정조사로서 영장에 의한 강제처분을 할 수 있는 수사와 다르다. 이러한 이유로 조사대상자의 자발적인 동의에 의한 자료 등의 임의제 출을 통하여 조사를 할 수밖에 없는 한계가 있다. 특히 산업현장의 특성상 PC, 서버, 노트북, 외 장하드 등 디지털 기기에 대한 조사가 필수불가결한 상황이다. 하지만 디지털기기나 저장매체에 는 기업기밀이나 개인정보 또는 민감정보 등 다양하고 방대한 양의 디지털 정보들이 담겨있어 조사의 방법에 한계가 뒤따른다. 더욱이 수사에서처럼 법원이 발부한 영장에 의하여 조사를 실 시하는 것이 아니기 때문에 조사의 범위와 방법에 차이가 있다. 즉 대다수의 산업보안조사는 행 정조사의 방법으로 진행되기 때문에 임의적 조사의 형태로 진행된다. 따라서 산업보안조사에서 임의적 디지털포렌식 조사의 방법이 어떻게 진행되어야 하는지에 대한 연구가 필요하다. 우리 법원에서는 임의성 판단을 대상자의 권리보장을 절차에서 보장해 주었는지로 판단하고 있어 본 연구에서는 법원의 임의성 판단기준을 근거로 디지털포렌식 조사에서 어떠한 방법으로 대상자 의 권리를 보장해주고 임의성을 확보할 수 있는지를 연구하였다.

Damage to national security as well as economic loss has increased due to outflow of national core technology and industrial technology. Thus, it is necessary to immediately understand the outflow range at the industrial sites or to investigate industrial security such as preventing technology outflow and restoring them to original state. The industrial security investigation differs from the criminal investigation. Industrial security investigation is an arbitrary administrative investigation, on the other hands, criminal investigation is enforced with compulsion legal disposition by warrant. For this reason, there is a limitation that investigators enforce the investigation through voluntary submission of data by target with voluntary agreement. Especially, it is essential to investigate digital devices such as PC, server, laptop, and external hard drive due to the property of industrial site, however, digital devices and storage medias contain the various and massive digital information such as corporate secret, personal information, and sensitive information. It leads to limitation of method of investigation. Furthermore, there are some differences of range and method of investigation between industrial security investigation and criminal investigation because the industrial security investigation is not enforced by a court-issued warrant as in the criminal investigation. In other words, most industrial security investigations are enforced with a form of voluntary investigation because it is a method of administrative investigations. Consequently, research on how method of voluntary digital forensic investigation in the industrial security investigation should be enforced is needed. The court judges voluntariness based on whether the investigative agency guarantees the defendant’s rights. Therefore, this study focuses on how investigative agency guarantees the procedural rights to defendants in the process of digital forensic investigation in order to secure the voluntariness.

2

4,000원

본 논문에서는 최근 증가하고 있는 다양한 사이버범죄에 대한 대응강화를 위해 국내에서 발생하고 있는 사이버범죄의 발생현황과 경찰청의 디지털 포렌식 활용실태를 살펴 본 후 사이버범죄의 수사와 범인검거에 있어 좀 더 효율적으로 활용할 수 있는 사이버범죄 대응 디지털 포렌식 모델을 제안하고자 한다. 이 모델은 디지털 포렌식 분석기를 통하여 수집된 데이터를 언어지원시스템에 의해 다양한 개별언어를 표준화된 데이터로 처리하고, 처리된 데이터는 범죄혐의를 입증하는데 있어 법적 증명력이 있는지 여부를 검토하여 법적증명력이 있다고 분석된 데이터들은 다시 경찰 등의 수사기관에 알려주게 되어 신속한 수사를 가능하게 한다. 또한 수사기관은 파일시스템에 직접 접근하여 디지털 증거능력 여부를 조회 확인 할 수 있게 함으로써 보강수사에 대한 수사절차와 시간을 최소화 하고, 디지털 포렌식에 의해 분석된 데이터는 디지털 포렌식 저장기에 다시 저장하여 모아진 데이터를 통해 향후 범죄예측과 예방에 활용하게 함으로써 궁극적으로는 사이버범죄 감소의 효과를 가져 올 수 있다.

This study will show the digital forensic model which fights against cyber-crimes to prepare various cyber -crimes. The digital forensic model will be more useful about the investigation of cyber-crimes and arresting criminals after researching the uses of the digital forensic model and cyber-crime rates in South Korea. This model conduct the standardized data with various languages by the language support system through the digital forensic analyzer. This model will send the data to law enforcement reviewing whether or not we ought to prove criminal charges. Moreover, law enforcement can access the file system to find out admissibility of evidence. And this model simplifies lawful investigation about additional investigation. The data, which is conducted and saved by the digital forensic system, will be helpful to protect against the future crimes because of the data.

3

5,800원

국가핵심기술, 방산기술, 중소기업기술, 영업비밀, 특허, 지식재산권 등은 값으로 환가할 수 없을 만큼 국가발전의 원동력이자 전략적 경제자원들이다. 국가안보에 큰 영향을 미치는 이러한 국부(國富)들은 디지털 파일의 형태로 기록・보관되어 손쉽게 유출되고 있는 상황이지만, 강제수 사를 제외한 현행 행정기관에 의한 산업기술유출 조사규정은 당사자의 동의를 구하는 임의조사 이고 기존의 아날로그적 조사방식이라는 점에서 개선이 필요하다. 일반적인 행정조사와 달리 기 술유출에 대한 행정조사는 형사사건으로 발전할 수 있다는 점에서 유출행위에 대한 조사가 필요 한데, 대다수의 유출형태가 디지털 기기를 이용하여 디지털 파일의 형태로 유출하기 때문에 디 지털포렌식에 의한 조사방법이 필요하다. 하지만 유출자의 조사거부시 행정기관이 실력을 행사 하여 강행하는 것은 원칙적으로 불가능하기 때문에 디지털 자료나 저장매체에 대한 접근조차 어 려운 상황이다. 따라서 본 연구에서는 디지털포렌식에 의한 산업보안조사 방식을 제언하면서 디 지털 자료가 갖는 특성으로 발생하는 산업보안조사의 한계와 실무상 문제점을 지적하고 그에 대 한 개선방안을 제시하였다. 헌법상 법률유보의 원칙을 천명하고 있는 상황에서 관련 법규정에 대한 문리적 해석이 필요하며 관련 연구자료들을 참고하여 본 연구를 진행하였다. 특히 디지털 자료에 대한 조사가 필요한 특수한 상황임을 감안하여 강제조사의 필요성을 제기하고 무엇보다 강제조사로 인하여 침해받을 수 있는 국민의 기본권 보장을 위한 영장주의 및 법률유보의 원칙 을 함께 제시하였다. 즉 법원의 행정영장을 통하여 행정조사에 대한 사법적 통제가 가능하고 관 계 법령에 디지털포렌식 조사규정을 신설함으로써 행정조사의 적법성을 판단할 수 있다.

They are the driving force of national development and strategic economic resources that cannot be exchanged for values such as national core technology, defense technology, SME technology, trade secrets, patents, and intellectual property rights. In a situation where countries around the world or other companies are fighting an invisible war to secure these technologies, we need to reflect on how much effort is being made to protect and protect them. These national wealth, which have a large impact on national security, exist in the form of files in the digital age and do not leave traces in that they are leaked in the form of files. has a difficulty. In this study, while proposing an industrial security investigation method based on digital forensics in the digital age, the limitations and problems of investigation caused by the characteristics of digital evidence were pointed out, and improvement measures were presented. Above all, since industrial security investigations are carried out as part of administrative investigations, it is proposed to prevent the abuse of investigation authority by administrative agencies that may occur during the investigation process, and to suggest institutional mechanisms to control and check them.

4

디지털 수사 초동조치 대응인력 및 예비분석관들이 갖추어야 할 요건 KCI 등재

조슈아 제임스, 장윤식

국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제16권 제5호 2016.10 pp.49-54

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

디지털 증거를 다루는 범죄 사건 수사가 증가함에 따라 초동조치를 할 수 있는 인력과 개선된 수사절차 모델 의 필요성이 증가하고 있다. 최근 들어 디지털 포렌식 분류(triage)와 예비분석 등의 개념이 수사․연구기관에 각광을 받고 있다. 하지만 초동조치 대응인력 및 예비분석관들이 구체적으로 어떤 훈련을 받아야 하는지에 대한 연구는 그다 지 주목받지 못했다. 오히려 많은 조직에서 초동조치 대응인력이 전문적인 디지털 포렌식 분석관과 같은 실력을 갖추 어야 한다고 여기고 있다. 본 연구에서는 ‘이상적인’ 상황에서 디지털 수사의 초동조치 대응인력과 예비분석관들이 어 떤 능력을 갖추어야 하며, 하드웨어 및 소프트웨어 측면에서의 필요사항과, 어쩌면 가장 중요하다 할 수 있는 교육훈련 조건에 대해 논하고자 한다.

As investigations dealing with digital evidence increase, so to does the need for skilled first responders and improved investigation process models. Recently the concept of digital forensic triage and preliminary analysis has been gaining popularity in investigation laboratories. At the same time, however, there has been little focus on specific training needs of first response and preliminary analysts. Instead, many organizations consider these responders to need the same skills as full digital forensic analysts. In this work we describe the 'ideal' digital investigation first responder and preliminary analyst, hardware and software requirements and most importantly, required training.

5

클라우드 환경에서 수사 실무와 법적 과제 KCI 등재

조슈아 제임스, 장윤식

국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제14권 제6호 2014.12 pp.33-39

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

클라우드 컴퓨팅 서비스의 확산으로 범죄수사를 위한 증거수집의 관점에서 불확실성으로 인한 다양한 실무적이고 법적인 문제가 제기되고 있다. 이 논문은 클라우드 환경에 대한 일반적인 수사상의 논점을 개관하고, 관할과 국제공조를 비롯한 문제점을 진단한다. 실무적으로 직접적으로 수사관이 접속하는 경우와 서비스제공자의 협조를 받는 경우의 장단점을 비교하여 실무적 개선방안을 논의하고 이에 따른 관할의 중복과 서비스 약정 및 포렌식적으로 무결한 데이터 수집 등 법률적 쟁점을 정리한다.

An area presenting new opportunities for both legitimate business, as well as criminal organizations, is Cloud computing. This work gives a strong background in current digital forensic science, as well as a basic understanding of the goal of Law Enforcement when conducting digital forensic investigations. These concepts are then applied to digital forensic investigation of cloud environments in both theory and practice, and supplemented with current literature on the subject. Finally, legal challenges with digital forensic investigations in cloud environments are discussed.

6

산업스파이 범죄수사에 있어서 디지털 증거의 과학적 분석 및 처리절차에 관한 연구 -디지털포렌식 기법을 중심으로- KCI 등재후보

정진홍

한국과학수사학회 과학수사학 Vol.4 No.2 2010.12 pp.173-182

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

산업스파이 범죄에 의한 기업의 첨단기술 유출수법이 날로 지능화되고 첨단화 되어가고 있다. 그리고 개정된 형사소송법에서 적법절차의 요건이 강화되었고, 법정에서의 증거에 대한 증거능력의 인정절차와 방법이 과거와는 달리 매우 엄격한 수사를 요구하고 있다. 이처럼 많은 변화가 있어 산업스파이범죄와 같은 중대한 경제안보 범죄를 수사할 경우에 증거수집의 절차와 방법에 있어서 적법절차에 따른 과학적인 수사기법이 더욱 요구되어 지고 있다. 그러므로 본 논문에서는 이와 같은 수사의 제반 환경의 변화에 맞추어 수사실무 과정에서 중요시 되고 있는 포렌식기법을 중심으로 과학적인 수사기법에 관하여 연구하였다.

Industrial espionage and stealing trade secrets and high end technology are becoming more sophisticated and cutting edge. Also, the revised Criminal Procedural Law strictly requires the due process of law, and the procure for the admissibility of evidence at the court requires very strict investigation. Therefore, when investigating major crimes against economic security, the importance of the scientific investigation technique and the procedure for collecting evidence are more emphasized. Therefore, this thesis researched on scientific investigation technique focusing on digital forensic investigation technique, which has been adjusted to and emphasized during the investigation stage and its surrounding circumstances.

7

산업기술 유출 수사 효율화를 위한 디지털 포렌식 프로세스 개선 및 가이드라인 제안 KCI 등재

최익서, 최근배, 박남제

국제문화기술진흥원 The Journal of the Convergence on Culture Technology (JCCT) Vol.11 No.3 2025.05 pp.239-251

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

본 논문은 산업기술유출 수사에서 디지털 포렌식의 효과적인 활용 방안을 제시한다. 기존의 7단계 침해사고 대응 프로세스를 4단계로 개선하여 신속성과 효율성을 높였다. 특히 사전 동의서 징수와 실시간 데이터 백업 시스템 구축의 중요성을 강조한다. 이를 통해 증거 능력 확보, 신속한 초기 대응, 디지털 증거의 법적 효력 강화 등의 효과를 기대할 수 있다. 결과적으로 기업의 기술유출 사고 대응 절차가 11단계에서 5단계로 간소화되어 피해 회복이 빨라질 것으로 예상된다. 기존 연구는 디지털포렌식 기법 중심으로 최신 기법이나 실제 수사한 사례를 활용한 연구가 대부분 이지만, 본 논문은 산업기술유출 수사에서 디지털 포렌식의 중요성을 강조하고 기업 입장에서 실질적인 가이드라인을 제공하고, 산업기술유출 수사에서 실무적인 활용 방안을 제시했다는 점에서 의의가 있다.

This paper presents an effective way to utilize digital forensics in industrial technology leak investigations. The existing 7-step breach incident response process was improved to 4 steps to increase speed and efficiency. In particular, the importance of collecting prior consent and establishing a real-time data backup system is emphasized. Through this, we can expect to secure evidentiary capacity, rapid initial response, and strengthen the legal effect of digital evidence. As a result, it is expected that the company's technology leak incident response process will be simplified from 11 steps to 5 steps, which will speed up damage recovery. While most of the existing studies have focused on digital forensics techniques and utilized the latest techniques or actual investigation cases, this paper is significant in that it emphasizes the importance of digital forensics in industrial technology leak investigations, provides practical guidelines from the corporate perspective, and suggests practical utilization methods in industrial technology leak investigations.

8

HBase에 대한 디지털 포렌식 조사 기법 연구

박아란, 정두원, 이상진

[Kisti 연계] 한국정보처리학회 정보처리학회논문지/컴퓨터 및 통신 시스템 Vol.6 No.2 2017 pp.95-104

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 스마트 기기의 발전과 소셜 네트워크 서비스(SNS)의 대중화로 기존 관계형 데이터베이스(RDBMS)에서는 처리하기 어려운 데이터들이 증가하고 있다. 이러한 대용량의 비정형 데이터를 실시간으로 처리하기 위한 대안으로 비관계형 데이터베이스(NoSQL DBMS)가 각광 받고 있다. 데이터베이스 디지털 포렌식 조사 기법은 대부분 관계형 데이터베이스를 대상으로 연구되어왔으나, 최근 NoSQL DBMS를 도입하는 기업이 증가하면서 NoSQL DBMS에 대한 디지털 포렌식 기법의 수요도 증가하고 있다. NoSQL DBMS는 정규화할 스키마가 존재하지 않고, 데이터베이스 종류나 운영환경에 따라 저장방식이 상이하기 때문에 디지털 포렌식 조사 시 이를 고려한 새로운 기법들이 필요하다. NoSQL DBMS 중 문서형 데이터베이스에 대한 연구는 진행되어 왔지만, 이를 다른 종류의 NoSQL DBMS에 그대로 적용하기엔 한계가 있다. 이에 본 논문에서는 NoSQL DBMS 중 컬럼형 데이터베이스인 HBase의 구동 방식과 데이터 모델을 소개하고, 운영환경 파악과 아티팩트 수집 및 분석, 삭제된 데이터의 복구 방안에 대해 제안하여 이를 바탕으로 HBase에 대한 디지털 포렌식 조사 기법에 대해 연구하였다. 또한 실험 시나리오를 통해 제안된 HBase에 대한 디지털 포렌식 조사 기법을 검증한다.

As the technology in smart device is growing and Social Network Services(SNS) are becoming more common, the data which is difficult to be processed by existing RDBMS are increasing. As a result of this, NoSQL databases are getting popular as an alternative for processing massive and unstructured data generated in real time. The demand for the technique of digital investigation of NoSQL databases is increasing as the businesses introducing NoSQL database in their system are increasing, although the technique of digital investigation of databases has been researched centered on RDMBS. New techniques of digital forensic investigation are needed as NoSQL Database has no schema to normalize and the storage method differs depending on the type of database and operation environment. Research on document-based database of NoSQL has been done but it is not applicable as itself to other types of NoSQL Database. Therefore, the way of operation and data model, grasp of operation environment, collection and analysis of artifacts and recovery technique of deleted data in HBase which is a NoSQL column-based database are presented in this paper. Also the proposed technique of digital forensic investigation to HBase is verified by an experimental scenario.

9

MongoDB에 대한 디지털 포렌식 조사 기법 연구

윤종성, 정두원, 강철훈, 이상진

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.24 No.1 2014 pp.123-134

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 데이터의 대용량화로 인해 관계형 데이터베이스 관리 시스템(RDBMS)과 빅데이터 처리를 위한 NoSQL DBMS에 대한 수요가 꾸준히 늘고 있다. 관계형 DBMS에 대한 디지털 포렌식 조사 기법은 활발히 연구되어 왔으나 최근 사용이 급증하고 있는 NoSQL DBMS에 대한 포렌식 조사 기법에 대한 연구는 거의 없는 실정이다. 본 논문에서는 NoSQL DBMS 중 가장 많이 사용되고 있는 MongoDB에 대한 디지털 포렌식 조사 절차와 기법을 제안한다.

As the data gets bigger recently, the demand for relational database management system (RDBMS) and NoSQL DBMS to process big data has been increased consistently. The digital forensic investigation method for RDBMS has been studied actively, but that for NoSQL DBMS, which is popularly used nowadays, has almost no research. This paper proposes the digital forensic investigation process and method for MongoDB, the most popularly used among NoSQL DBMS.

10

HBase에 대한 디지털 포렌식 조사 기법 연구

박아란, 정두원, 이상진

[NRF 연계] 한국정보처리학회 KIPS Transactions on Computer and Communication Systems Vol.6 No.2 2017.02 pp.95-104

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 스마트 기기의 발전과 소셜 네트워크 서비스(SNS)의 대중화로 기존 관계형 데이터베이스(RDBMS)에서는 처리하기 어려운 데이터들이 증가하고 있다. 이러한 대용량의 비정형 데이터를 실시간으로 처리하기 위한 대안으로 비관계형 데이터베이스(NoSQL DBMS)가 각광받고 있다. 데이터베이스 디지털 포렌식 조사 기법은 대부분 관계형 데이터베이스를 대상으로 연구되어왔으나, 최근 NoSQL DBMS를 도입하는 기업이 증가하면서 NoSQL DBMS에 대한 디지털 포렌식 기법의 수요도 증가하고 있다. NoSQL DBMS는 정규화할 스키마가 존재하지 않고, 데이터베이스 종류나 운영환경에 따라 저장방식이 상이하기 때문에 디지털 포렌식 조사 시 이를 고려한 새로운 기법들이 필요하다. NoSQL DBMS 중 문서형 데이터베이스에 대한 연구는 진행되어 왔지만, 이를 다른 종류의 NoSQL DBMS에 그대로 적용하기엔 한계가 있다. 이에 본 논문에서는 NoSQL DBMS 중 컬럼형 데이터베이스인 HBase의 구동 방식과 데이터 모델을 소개하고, 운영환경 파악과 아티팩트 수집 및 분석, 삭제된 데이터의 복구 방안에 대해 제안하여 이를 바탕으로 HBase에 대한 디지털 포렌식 조사 기법에 대해 연구하였다. 또한 실험 시나리오를 통해 제안된 HBase에 대한 디지털 포렌식 조사 기법을 검증한다.

As the technology in smart device is growing and Social Network Services(SNS) are becoming more common, the data which is difficult to be processed by existing RDBMS are increasing. As a result of this, NoSQL databases are getting popular as an alternative for processing massive and unstructured data generated in real time. The demand for the technique of digital investigation of NoSQL databases is increasing as the businesses introducing NoSQL database in their system are increasing, although the technique of digital investigation of databases has been researched centered on RDMBS. New techniques of digital forensic investigation are needed as NoSQL Database has no schema to normalize and the storage method differs depending on the type of database and operation environment. Research on document-based database of NoSQL has been done but it is not applicable as itself to other types of NoSQL Database. Therefore, the way of operation and data model, grasp of operation environment, collection and analysis of artifacts and recovery technique of deleted data in HBase which is a NoSQL column-based database are presented in this paper. Also the proposed technique of digital forensic investigation to HBase is verified by an experimental scenario.

11

도커 기반 호스트에 대한 디지털 포렌식 조사 기법

김현승, 이상진

[Kisti 연계] 한국정보처리학회 정보처리학회논문지/컴퓨터 및 통신 시스템 Vol.6 No.2 2017 pp.75-86

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

오늘날 다양한 서버 내 가상화 기술 중 도커(Docker)는 기존의 방식보다 경량화된 서비스 운영 환경을 제공함으로써 많은 기업 환경에 도입되고 있다. 도커는 이미지, 컨테이너 개념을 통해 서버 환경 구축, 업데이트, 이동을 효율적으로 할 수 있게 지원한다. 도커가 많이 보급될수록 도커 이미지를 배포하는 서버나 도커 기반의 호스트에 대한 공격 유인이 증가할 것이다. 이에 본 논문에서 도커 데몬이 비활성화 된 상태에서도 컨테이너의 파일 시스템을 추출할 수 있는 방안을 포함하여 도커를 사용하는 호스트에 대한 포렌식 조사 기법과 그 절차를 제시하였다.

Docker, which is one of the various virtualization technology in server systems, is getting popular as it provides more lightweight environment for service operation than existing virtualization technology. It supports easy way of establishment, update, and migration of server environment with the help of image and container concept. As the adoption of docker technology increases, the attack motive for the server for the distribution of docker images and the incident case of attacking docker-based hosts would also increase. Therefore, the method and procedure of digital forensic investigation of docker-based host including the way to extract the filesystem of containers when docker daemon is inactive are presented in this paper.

12

도커 기반 호스트에 대한 디지털 포렌식 조사 기법

김현승, 이상진

[NRF 연계] 한국정보처리학회 KIPS Transactions on Computer and Communication Systems Vol.6 No.2 2017.02 pp.75-86

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

오늘날 다양한 서버 내 가상화 기술 중 도커(Docker)는 기존의 방식보다 경량화된 서비스 운영 환경을 제공함으로써 많은 기업 환경에 도입되고 있다. 도커는 이미지, 컨테이너 개념을 통해 서버 환경 구축, 업데이트, 이동을 효율적으로 할 수 있게 지원한다. 도커가 많이 보급될수록 도커 이미지를 배포하는 서버나 도커 기반의 호스트에 대한 공격 유인이 증가할 것이다. 이에 본 논문에서 도커 데몬이 비활성화된 상태에서도 컨테이너의 파일 시스템을 추출할 수 있는 방안을 포함하여 도커를 사용하는 호스트에 대한 포렌식 조사 기법과 그 절차를 제시하였다.

Docker, which is one of the various virtualization technology in server systems, is getting popular as it provides more lightweight environment for service operation than existing virtualization technology. It supports easy way of establishment, update, and migration of server environment with the help of image and container concept. As the adoption of docker technology increases, the attack motive for the server for the distribution of docker images and the incident case of attacking docker-based hosts would also increase. Therefore, the method and procedure of digital forensic investigation of docker-based host including the way to extract the filesystem of containers when docker daemon is inactive are presented in this paper.

13

디지털 포렌식 수사 절차 모델 제안

신재룡, 이석희, 이상진

[Kisti 연계] 한국정보보호학회 한국정보보호학회 학술대회논문집 2006 pp.403-407

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

완벽한 디지털 범죄 수사를 위해서는 우수한 디지털 포렌식 기술이 우선적으로 요구되겠지만, 범죄수사의 특성상 기술이외에도 법적, 제도적 측면들이 적절하게 조합되어야만 한다. 본 논문에서는 디지털 포렌식의 제도 및 정책적인 면에서 디지털 범죄 수사의 절차가 현실적으로 적용 가능하고, 범죄 해결에 효율적이며 합법성을 유지하면서 진행될 수 있도록 새로운 형태의 디지털 포렌식 절차를 제안하고자 한다.

14

디지털 포렌식 수사의 문제점과 개선방안

곽병선

[NRF 연계] 한국법학회 법학연구 Vol.42 2011.05 pp.171-191

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

디지털 증거는 기존의 물리적 증거와는 다른 특성을 가지고 있으므로, 수사절차 전반에 새로운 패러다임을 요구하고 있다. 디지털 증거의 압수수색은 디지털 포렌식으로 대변되고 있다. 디지털 영역의 확장으로 디지털 매체에서 수집되어지는 디지털 증거가 증가함에 따라 범죄 수사에 있어서 디지털 포렌식의 중요성은 더욱 부각되어지고 있다. 완벽한 디지털 수사를 위해서 우수한 디지털 포렌식 기술이 우선적으로 요구되겠지만, 수집된 디지털 증거가 법적으로 인정받지 못한다면 디지털 포렌식만으로는 아무런 의미가 존재하지 않는다. 즉, 범죄수사의 특성상 과학적 기술이외에도 법적ㆍ제도적 측면들이 함께 고려되어야 한다. 디지털 포렌식을 통해 수집된 디지털 증거가 법정에서 증거로서의 가치를 인정받기 위해서는 기본적으로 형사소송법 등에 디지털 증거가 포섭되어야 하며, 디지털 증거가 사실인정의 근거로서 법정에서 인정받을 수 있는 법적 근거가 명시되어야 한다. 또한 디지털 포렌식의 신뢰성을 확보하고 현행 법률체계에 적합한 표준절차가 제도적 차원에서 제공되어야 한다. 디지털 기술은 매우 빠르게 진화하고 있으므로, 디지털 포렌식에 사용되어지는 수집 및 분석 도구에 대한 기술적 지원도 함께 이루어져야 한다.

In Korean Code of Criminal Procedure, there is no method to prove the authenticity of digital evidence. However, since the digital evidence as non-hearsay evidence can sufficiently be used as evidence, the stipulated provision is required for this case. However, for the digital evidence to be used as evidence, the authenticity must be proved. Nevertheless, the proof of authenticity is limited in terms of the efficiency of litigation. Therefore, for the case where the digital evidence was collected through a special procedure such as digital forensic, it is necessary to make such proof straightforward. Korea still has not established the standards for digital forensic by the neutral institution. While making the proof of authenticity effortless by establishing the standards for digital forensic, the systematic device to guarantee the flawlessness of evidence should be established at the same time. In order for the digital evidence to be recognized as authentic, the total process of collection, analysis and process should secure the credibility. Therefore, the verification of digital forensic procedure and tools should be performed by establishing a separate verification institution. No matter how advanced the forensic technology was in collecting evidence, the verification process is mandatory for the evidence to be credible.

15

디지털 포렌식 조사에서 효율적인 파일 복구를 위한 레코드 파일 카빙 기법

박민수, 이상진, 박정흠

[NRF 연계] 한국정보처리학회 KIPS Transactions on Computer and Communication Systems Vol.2 No.2 2013.02 pp.93-102

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 대부분의 범죄에 디지털 매체가 사용되면서 디지털 데이터는 필수 조사 대상이 되었다. 하지만 디지털 데이터는 비교적 쉽게 삭제 및변조가 가능하다. 따라서 디지털 증거 획득을 위해 삭제된 데이터의 복구가 필요하며, 파일 카빙은 컴퓨터 포렌식 조사에서 증거를 획득할 수있는 중요한 요소이다. 하지만 현재 사용되는 파일 카빙 도구들은 포렌식 조사를 위한 데이터의 선별을 고려하지 않고 있다. 또 기존의 파일카빙 기법들은 파일의 일부 영역이 덮어써지거나 조각날 경우 복구가 불가능한 단점이 있다. 따라서 본 논문에서는 포렌식 조사시 유용한 정보를 획득할 수 있는 파일을 제안하고, 기존의 파일 카빙 기법보다 효과적으로 데이터를 복구할 수 있는 레코드 파일 카빙 기법을 제시한다.

These days digital data have become essential for digital investigation because most of the crime was occurred by using the digital devices. However, digital data is very easier to falsify or delete. If digital data was deleted, it is necessary to recover the deleted data for obtain digital evidence. Even though file carving is the most important thing to gather. digital evidence in digital forensic investigation,most of popular carving tools don't contemplate methods of selection or restoration for digital forensic investigation. The goal of this research is suggested files which can obtain useful information for digital forensic investigation and proposed new record file carving technique to be able to recover data effectively than before it.

16

타임라인 분석 기법을 이용한 디지털 증거 분석 방법론

이근기, 황성진, 이창훈, 이상진

[Kisti 연계] 한국항행학회 한국항행학회논문지 Vol.18 No.1 2014 pp.50-55

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 다양한 유형의 증거 분석에서 디지털 증거 분석 기법의 도입이 가속화되고 있으며 중요도가 증가하고 있다. 하지만 개인용 디스크 용량이 커지면서 저장하는 파일의 용량의 수가 증가하면서 전체 데이터를 모두 분석하는 것은 시간과 노력이 많이 소요된다. 대부분의 디지털 증거는 항상 시간정보를 저장하고 있으며, 시간 정보는 디지털 증거 분석에서 가장 중요한 요소 중 하나이다. 하지만 시간 유형이 다양하여 단순히 저장된 시간을 기준으로 사건을 분석하면 잘못된 분석결과를 도출할 가능성이 크다. 따라서 본 논문에서는 다양한 디지털 증거의 시간 유형에 대하여 고찰하고, 하나의 시간 축을 기준으로 디지털 증거 분석을 수행할 수 있는 타임라인 분석 기법에 대하여 설명한다.

Recently, importance of digital forensics has increased and using analysis methods of digital evidence in the analysis of evidence of various types. However, analysis time and effort is steadily increasing because personal disk capacity is too big and it has many number of files. Most digital evidence has time property, such as access time, creation time, and modification time. These time information of digital evidence is one of most important factors in the digital forensic area. But if digital examiner simply analyze based on binary source only, it is possible to have wrong result because time has various types. In this paper, we classify various type of time in the digital evidence and describe advanced analysis method based on timeline chart for digital forensic investigation.

17

임의조사로서의 디지털 포렌식

정혜욱

[NRF 연계] 중앙법학회 중앙법학 Vol.23 No.2 2021.06 pp.161-188

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

기업을 경영하는 입장에서 제일 우선되는 관심사는 물론 이윤의 극대화 일 것이지만 소속 임직원의 업무수행이 준법의 틀 내에서 이루어지도록 하는 일도 장기적인 측면에서 이윤추구 못지않게 중요한 일이다. 기업체의 준법감시 기능을 수행하는 감사실과 같은 조직의 입장에서는 업무수행에서의 위법의 가능성을 방지하고 싶다. 이를 위하여 위법한 업무수행의 흔적을 찾아내서 적시에 적절한 조치를 취하여야 한다. 이러한 흔적이 과거에는 대부분 종이 서류에 남아있었다. 그런데 모든 업무가 거의 다 전산화가 되면서 종이 기록보다 전자 기록이 점차 더 큰 중요성을 가지고 되고 있다. 전자 기록을 들여다보지 않고는 위법의 흔적 가운데 많은 부분을 놓치게 되었다. 이 때문에 기업체에서도 위법행위의 증거를 찾기 위한 디지털 포렌식이 필요하게 되었다. 그런데 디지털 포렌식은 그 분야에 대한 전문지식을 필요로 하는 영역이다. 그러한 인력을 단위 기업체가 자체적으로 보유하는 것은 비용 측면에서 감당하기 힘든 일이다. 이러한 상황에서 디지털 포렌식 전문 업체가 등장하였고 기업체는 이들 업체에게 디지털 포렌식 업무를 외주 주고 있다. 디지털 포렌식 업무를 위탁받은 업체는 보통 다음과 같은 절차로 그 임무를 수행한다: ① 업무용 컴퓨터 수거, ② 수거된 컴퓨터 외관 검사, ③ 하드디스크 적출, ④ 이미징 방식으로 하드디스크 복제, ⑤ 주제어 검색을 통한 내용 분석. 이와 같은 작업을 수행하기 직전에 디지털 포렌식 업체는 기업체 임직원들로부터 업무용 컴퓨터에 저장되어 있는 전자기록을 수집, 복제, 열람해도 좋다는 취지의 동의서를 받고 있다. 그런데 디지털 포렌식 업체가 기업체 임직원들 퇴근 이후에 업무용 컴퓨터들을 수거하기 위해서는 사무실 공간에 들어가야 한다. 이렇게 사무실 공간에 들어가는 점에 대해서는 동의서에 아무런 언급이 되어 있지 않다. 만약 기업체의 사무공간의 주거권자가 사용자라면 아무 문제가 되지 않을 것이다. 이 문제는 사용자와 노동자 가운데 누가 사무공간의 주거권자인가에 따라 결론이 달라진다. 형법 제319조에서 정하고 있는 주거침입죄의 보호법익은 ‘사실상의 주거의 평온’이라고 보는 것이 타당하다. 판례의 입장도 같다. 따라서 사무실 공간의 주거권자는 현재 그 공간을 사실상 지배하고 있는 노동자들이라고 보아야 한다. 해당 공간의 주거권자인 임직원들의 동의가 없다면 그 공간에 들어가는 것은 주거권자의 의사에 반하여 들어가는 것이라고 보아야 한다. 디지털 포렌식 관련 동의서는 자발적으로 서명하는 것이라고 보기 어렵다. 그렇기 때문에 더구나 동의서에 언급이 되어 있지 않은 부분까지 묵시적으로 동의했다고 보는 것은 부당하다. 이 문제는 동의서의 내용을 보완함으로써 해결하여야 한다. 기업체 임직원의 업무용 컴퓨터에는 거래처 연락처, 고객 연락처, 이메일 주소록 등 엄청난 분량의 개인정보가 저장되어 있다. 기업체가 개인정보처리자임은 명백하다. 그리고 디지털 포렌식 업체가 개인정보 처리를 회사로부터 위탁받는 것이 아니므로 제3자에 해당한다. 개인정보처리자가 제3자에게 개인정보를 제공하려면 정보주체의 동의가 있거나 법률에 의해서 허용하는 사유가 인정되어야 한다. 디지털 포렌식의 경우에는 두 가지 모두 해당하지 않는다. 따라서 개인정보보호법 위반이고 형사처벌 대상이다. ...

From the perspective of managing a company, of course, the most important concern is maximization of profits, but ensuring that employees' work is performed within the framework of compliance is as important as pursuing profits from a long-term perspective. From the point of view of a department such as the audit office that performs the corporate compliance function, we want to prevent the possibility of illegality in the performance of our business. To this end, it is necessary to find traces of illegal business practices and take appropriate measures promptly. Most of these traces were left on paper documents in the past. However, as almost all tasks are computerized, electronic records are increasingly becoming more important than paper records. Without looking at the electronic records, many of the traces of the offense were missed. Because of this, digital forensics is needed to find evidence of misconduct in businesses as well. However, digital forensics is an area that requires expertise in the field. It is cost prohibitive for a company to have such a workforce on its own. In this situation, digital forensics companies have appeared, and companies outsource digital forensics work to these companies. A company entrusted with digital forensic work usually carries out its duties in the following manner: ① Collection of business computers, ② Visual inspection of the collected computer, ③ Hard disk extraction, ④ Hard disk copying by imaging method, ⑤ Search by keyword content analysis. Just before carrying out such work, digital forensics companies are obtaining consent from corporate executives and employees to the effect that they may collect, reproduce, and view electronic records stored in business computers. However, in order for digital forensics companies to collect work computers after corporate employees leave the office, they have to enter the office space. Nothing is stated in the consent form regarding this entry into the office space. If the owner of the corporate office space is the user, it will not be a problem. The conclusion of this issue differs depending on who is the owner of the office space, the employer or the worker. It is reasonable to view the protection and interest of the crime of trespassing under Article 319 of the Criminal Act as ‘de facto serenity of residence. The position of the courts is also the same. Therefore, the right to reside in the office space should be regarded as the workers who currently dominate the space. Without the consent of the executives and employees who are the right to live in the space, entering the space should be regarded as entering against the will of the owner of the space. A digital forensic-related agreement cannot be regarded as a voluntary signature. Therefore, it is unreasonable to assume that they implicitly consented to the parts not mentioned in the consent form. This issue should be resolved by supplementing the contents of the consent form. A huge amount of personal information such as business contacts, customer contacts, and e-mail address books is stored on the work computers of corporate executives and employees. It is clear that the enterprise is the controller of personal data. And since the digital forensic company does not entrust the processing of personal information from the company, it is a third party. In order for the personal information controller to provide personal information to a third party, the consent of the information subject or reasons permitted by law must be recognized. In the case of digital forensics, neither is the case. Therefore, it is a violation of the Personal Information Protection Act and is subject to criminal punishment. There is currently no solution to this problem. For the time being, corporate digital forensics as a discretional investigation should not be done. You can't commit an offense to find out what's wrong.

18

모바일 포렌식 증거능력 확보 방안 연구

어수웅, 조우연, 이석준, 손태식

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.26 No.1 2016 pp.135-152

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

모바일 포렌식은 스마트폰의 대중화와 다양한 모바일 기기의 증가로 인해 그 중요성 및 필요성이 급격히 증가하고 있다. 하지만 그 방안 및 절차는 아직 모바일 포렌식의 특성에 충분히 맞게 적용되고 있지 않다. 이에 따라 본 논문에서는 현재 모바일 포렌식이 직면한 문제점을 파악하기 위해 법 제도 기술적 관점에서의 분석을 수행하였으며 이를 통해 모바일 기기에 대해서는 현재 디지털 포렌식 수사과정에서 큰 이슈가 되고 있는 선별압수에 있어서 제약사항이 있음을 확인하였다. 또한 모바일 포렌식에서 디지털 증거 수집 방안에 대한 분석 및 실사용 도구의 무결성 연구를 진행함으로써 현재 기술의 적합성 검증 및 추후 발생될 문제점에 대해 분석하였으며 결과적으로 모바일 포렌식에서 수집된 데이터가 증거능력을 확보할 수 있는 방안을 위해 전반적인 고려사항을 제시하였다.

Because of the evolution of mobile devices such as smartphone, the necessity of mobile forensics is increasing. In spite of this necessity, the mobile forensics does not fully reflect the characteristic of the mobile device. For this reason, this paper analyzes the legal, institutional, and technical considerations for figuring out facing problems of mobile forensics. Trough this analysis, this study discuss the limits of screening seizure on the mobile device. Also, analyzes and verify the mobile forensic data acquisition methods and tools for ensuring the admissibility of mobile forensic evidence in digital investigation.

 
페이지 저장