Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 8
No
1

디지털 수사 초동조치 대응인력 및 예비분석관들이 갖추어야 할 요건 KCI 등재

조슈아 제임스, 장윤식

국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제16권 제5호 2016.10 pp.49-54

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

디지털 증거를 다루는 범죄 사건 수사가 증가함에 따라 초동조치를 할 수 있는 인력과 개선된 수사절차 모델 의 필요성이 증가하고 있다. 최근 들어 디지털 포렌식 분류(triage)와 예비분석 등의 개념이 수사․연구기관에 각광을 받고 있다. 하지만 초동조치 대응인력 및 예비분석관들이 구체적으로 어떤 훈련을 받아야 하는지에 대한 연구는 그다 지 주목받지 못했다. 오히려 많은 조직에서 초동조치 대응인력이 전문적인 디지털 포렌식 분석관과 같은 실력을 갖추 어야 한다고 여기고 있다. 본 연구에서는 ‘이상적인’ 상황에서 디지털 수사의 초동조치 대응인력과 예비분석관들이 어 떤 능력을 갖추어야 하며, 하드웨어 및 소프트웨어 측면에서의 필요사항과, 어쩌면 가장 중요하다 할 수 있는 교육훈련 조건에 대해 논하고자 한다.

As investigations dealing with digital evidence increase, so to does the need for skilled first responders and improved investigation process models. Recently the concept of digital forensic triage and preliminary analysis has been gaining popularity in investigation laboratories. At the same time, however, there has been little focus on specific training needs of first response and preliminary analysts. Instead, many organizations consider these responders to need the same skills as full digital forensic analysts. In this work we describe the 'ideal' digital investigation first responder and preliminary analyst, hardware and software requirements and most importantly, required training.

2

산업기술 유출 수사 효율화를 위한 디지털 포렌식 프로세스 개선 및 가이드라인 제안 KCI 등재

최익서, 최근배, 박남제

국제문화기술진흥원 The Journal of the Convergence on Culture Technology (JCCT) Vol.11 No.3 2025.05 pp.239-251

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

본 논문은 산업기술유출 수사에서 디지털 포렌식의 효과적인 활용 방안을 제시한다. 기존의 7단계 침해사고 대응 프로세스를 4단계로 개선하여 신속성과 효율성을 높였다. 특히 사전 동의서 징수와 실시간 데이터 백업 시스템 구축의 중요성을 강조한다. 이를 통해 증거 능력 확보, 신속한 초기 대응, 디지털 증거의 법적 효력 강화 등의 효과를 기대할 수 있다. 결과적으로 기업의 기술유출 사고 대응 절차가 11단계에서 5단계로 간소화되어 피해 회복이 빨라질 것으로 예상된다. 기존 연구는 디지털포렌식 기법 중심으로 최신 기법이나 실제 수사한 사례를 활용한 연구가 대부분 이지만, 본 논문은 산업기술유출 수사에서 디지털 포렌식의 중요성을 강조하고 기업 입장에서 실질적인 가이드라인을 제공하고, 산업기술유출 수사에서 실무적인 활용 방안을 제시했다는 점에서 의의가 있다.

This paper presents an effective way to utilize digital forensics in industrial technology leak investigations. The existing 7-step breach incident response process was improved to 4 steps to increase speed and efficiency. In particular, the importance of collecting prior consent and establishing a real-time data backup system is emphasized. Through this, we can expect to secure evidentiary capacity, rapid initial response, and strengthen the legal effect of digital evidence. As a result, it is expected that the company's technology leak incident response process will be simplified from 11 steps to 5 steps, which will speed up damage recovery. While most of the existing studies have focused on digital forensics techniques and utilized the latest techniques or actual investigation cases, this paper is significant in that it emphasizes the importance of digital forensics in industrial technology leak investigations, provides practical guidelines from the corporate perspective, and suggests practical utilization methods in industrial technology leak investigations.

3

디지털 증거의 신뢰성 확보의 전제로서 디지털 포렌식에 대한 소고

탁희성

원광대학교 경찰학연구소 경찰학논총 제3권 제1호 2008.05 pp.173-198

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

디지털 증거의 압수수색을 용이하게 하고 압수한 디지털 데이터를 효율적으로 검색하고 분석하여 법원에 적법한 증거로 제출하기 위해 필요한 것이 디지털 증거분석도구이며, 이를 연구하는 분야를 디지털 포렌식이라 한다. 전세계에 약 150여개의 디지털 포렌식 도구가 존재하는데, 디지털 증거의 법적 효력을 확보하기 위해서는 정확성과 신뢰성, 무결성을 보장하는 포렌식 도구을 선택해야 한다. 이를 위해 필요한 것이 디지털 포렌식 도구에 대한 검증이며, 이러한 검증이 디지털 증거가 법정에서 증거로 활용될 수 있게 하는 전제조건이다. 포렌식 도구에 대한 검증은 여러 기관들과 조율이 가능하고, 중립성과 신뢰성이 있는 국가기관에서 실시해야 한다. 또한 재판과정에서 신뢰성 있는 증거로 허용되기 위해서는 증거수집절차 자체가 적정성 내지 적법성을 유지했음을 증명할 수 있는 체계적이고 표준화된 기준이 필요하다.

The purpose of digital forensic is to make digital evidence which can be accepted in court using well-organized technic and according to reasonable process in computer crime investigation. Digital forensic process consist of preparation, acquisition, preservation, examination, analysis and reporting. Digital evidence is difficult to treat, because digital information is easy to forge, alter, delete and modify. So several digital evidence collection tools and forensic tools are developed. However there are many problem of composition which is whole due process from evidence collection to submitting to the court because existing digital evidence collection process and tools have a vulnerability of guaranteeing integrity. Therefore, it is necessary to develop guideline for improvement and design of the digital data acquisition tool for computer forensics and standard procedures on computer forensics.

4

정부 ICT R&D 중장기전략과 ICT 패러다임 변화를 반영한 디지털 포렌식 표준정립을 위한 기술-정책적 통합프로세스 프레임워크

신준우

[Kisti 연계] 한국정보통신학회 한국정보통신학회논문지 Vol.18 No.7 2014 pp.1495-1504

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

인터넷 뱅킹과 같은 부가서비스, 채팅 등과 같은 대화형 서비스를 이용하는 정보화 사회가 정착되었고, 더욱이 스마트기기를 이용한 서비스 사용이 급속하게 발전함에 따라 신규 보안기술 분야로 디지털 포렌식에 관한 연구가 활발히 진행되고 있다. 본 논문에서는 디지털 포렌식에 관한 기존의 연구를 체계적으로 분석하고 앞으로 정부의 ICT R&D 중장기 전략과 ICT 패러다임 변화를 반영하여 첨단 IT기술과 우리나라 법체제를 융합하는 체계적인 디지털 포렌식 표준정립을 위한 기술-정책적 통합프로세스 프레임워크를 제안한다.

Currently information related service such as internet banking, chatting, social network services are quite well smeared into our daily life. Moreover, a rapid growth of service using smart devices brought an importance of security in internet services and a research activation of digital forensic in a crime investigation. This paper presented a previous digital forensic research trend and based on this, suggested a technology-strategy integrated digital forensic process platform, taking a mid-long term government leading ICT R&D strategy and ICT paradigm shift into account.

5

디지털 포렌식 수사 절차 모델 제안

신재룡, 이석희, 이상진

[Kisti 연계] 한국정보보호학회 한국정보보호학회 학술대회논문집 2006 pp.403-407

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

완벽한 디지털 범죄 수사를 위해서는 우수한 디지털 포렌식 기술이 우선적으로 요구되겠지만, 범죄수사의 특성상 기술이외에도 법적, 제도적 측면들이 적절하게 조합되어야만 한다. 본 논문에서는 디지털 포렌식의 제도 및 정책적인 면에서 디지털 범죄 수사의 절차가 현실적으로 적용 가능하고, 범죄 해결에 효율적이며 합법성을 유지하면서 진행될 수 있도록 새로운 형태의 디지털 포렌식 절차를 제안하고자 한다.

6

디지털 증거의 신뢰성 확보의 전제로서 디지털 포렌식에 대한 소고

탁희성

[NRF 연계] 원광대학교 경찰학연구소 경찰학논총 Vol.3 No.1 2008.05 pp.173-198

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

디지털 증거의 압수수색을 용이하게 하고 압수한 디지털 데이터를 효율적으로 검색하고 분석하여 법원에 적법한 증거로 제출하기 위해 필요한 것이 디지털 증거분석도구이며, 이를 연구하는 분야를 디지털 포렌식이라 한다. 전세계에 약 150여개의 디지털 포렌식 도구가 존재하는데, 디지털 증거의 법적 효력을 확보하기 위해서는 정확성과 신뢰성, 무결성을 보장하는 포렌식 도구을 선택해야 한다. 이를 위해 필요한 것이 디지털 포렌식 도구에 대한 검증이며, 이러한 검증이 디지털 증거가 법정에서 증거로 활용될 수 있게 하는 전제조건이다. 포렌식 도구에 대한 검증은 여러 기관들과 조율이 가능하고, 중립성과 신뢰성이 있는 국가기관에서 실시해야 한다. 또한 재판과정에서 신뢰성 있는 증거로 허용되기 위해서는 증거수집절차 자체가 적정성 내지 적법성을 유지했음을 증명할 수 있는 체계적이고 표준화된 기준이 필요하다.

The purpose of digital forensic is to make digital evidence which can be accepted in court using well-organized technic and according to reasonable process in computer crime investigation. Digital forensic process consist of preparation, acquisition, preservation, examination, analysis and reporting. Digital evidence is difficult to treat, because digital information is easy to forge, alter, delete and modify. So several digital evidence collection tools and forensic tools are developed. However there are many problem of composition which is whole due process from evidence collection to submitting to the court because existing digital evidence collection process and tools have a vulnerability of guaranteeing integrity. Therefore, it is necessary to develop guideline for improvement and design of the digital data acquisition tool for computer forensics and standard procedures on computer forensics.

7

ʻ드루킹의 인터넷상 불법댓글 사건ʼ을 통해 본 디지털포렌식 수사절차의 적법성 연구

강구민, 허익범

[NRF 연계] 대검찰청 형사법의 신동향 Vol.73 2021.12 pp.217-250

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

2018년 대한민국 정치계를 소용돌이로 빠지게한 소위 ‘드루킹 여론조작 사건’의진상규명을 책임지게 된 「드루킹의 인터넷상 불법댓글 사건 특별검사」(이하 ‘특검’)에서는 수사대상자들로부터 28TB의 방대한 디지털 증거물을 확보하고 분석하였다. 디지털 증거를 수집하고 분석하여 법정에 증거로 제출하는 ‘디지털포렌식’은 당시 특검의 주된 수사방법이었고, 디지털포렌식 수사에 의해 수사의 성패가 결정된다는 점에서 적법한 절차와 인권을 도모한 실체적 진실을 찾아야만 했다. 디지털이라는 신기술에 대하여 사법제도가 따라가지 못하는 현실에서 특검의 디지털포렌식 수사는 디지털 시대의 변화적 요청에 따라 법률적 지식과 분석기술을 융합한 새로운 수사기법을 우리 형사사법 환경에 적용하고자 노력하였다. 디지털 시대에 나올 수 있는 다양한디지털 기기와 증거들이 수사과정에서 압수되었고, 각기 다른 형태의 디지털 증거와저장매체에 대한 압수절차 및 분석기법 등이 요구되었다. 특검의 디지털포렌식 수사는‘인권’, ‘적법절차’, ‘실체적 진실발견’이라는 형사소송의 이념과 원칙을 중심으로 증거가 가리키는 방향으로 나아갔다. 특히 디지털포렌식 수사에서 준수되어야 할 형사소송법상의 적법절차의 선언적 규정을 실무적으로 어떻게 구현할 것인가에 대하여 많은고민을 하였고, 그 해답을 현장에서 찾았다. 본 연구에서는 60일이라는 한정된 특검의 수사기간 동안 디지털포렌식 수사에서 수행되었던 수사의 적법절차 및 그 과정에서우리가 지켜야 할 인간의 보편적 가치인 기본권 보장에 관하여 고민하였던 점을 기록하였다. 무엇보다 디지털포렌식 수사절차에서 수사 대상자들의 절차적 권리를 보장해주고 그로부터 특검 수사의 적법성을 어떻게 확보하였는지를 각 쟁점별로 정리하였다. 일반적으로 수사기관에 적법절차의 준수를 요구하고 있지만, 특히 디지털포렌식 수사와관련해서는 실무적으로 어떻게 적법절차를 구현할 것인가에 대한 명확한 규정이 없기때문에 본 연구에서는 디지털포렌식 수사에서의 적법절차와 절차적 기본권 보장 등의실무적 사례를 제시하였다. 본 연구에서 제시한 디지털포렌식 수사절차는 특검의 수사과정에서 수행되었던 방법이기 때문에 모든 디지털포렌식 수사절차의 전가보도(傳家 寶刀)는 아니다. 다만 본 연구가 향후 디지털포렌식 수사의 시행착오를 최대한 줄이는데 도움이 됐으면 하는 바람이다.

In 2018, one case, which is called “Druking”, was occurred and it threw Korean political community into the confusion. Therefore, Independent Prosecutors’Office for the Investigation into allegations concerning Illegal Manipulation of Online Comments by Druking(IPO) was launched to redeem the existing insufficient investigation. IPO was in duty to secure and analyse the 28TB of digital evidences from subjects. At that time, digital forensic with seizing and analysing digital evidences for submitting to court was largely used. Various digital devices and files were seized in the digital forensic investigation and various analysing techniques and seizure processes were demanded for each evidences. Criminal Procedure’s ideology such as human rights, due process, and finding truth is emphasized in the IPO’s igital forensic investigation. In particular, we concerned how to realize the declaratory regulation of due process under the Criminal Procedure Act, which should be complied with in the new digital forensic investigation, and we attempt to find the solution in the practical field. In this study, due process and concrete case of digital forensic that appeard in the sixty days of IPO’s investigation period are presented

8

디지털 검증의 현재와 그 부당성 — 소위 ‘왕재산’ 사건을 대상으로 —

오길영

[NRF 연계] 민주주의법학연구회 민주법학 Vol.48 2012.03 pp.159-195

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

이 글은 최근의 공안사건 가운데 가장 뜨거운 이슈가 되고 있는 소위 ‘왕재산’ 사건에 대한 경험적 연구의 산물이다. 필자가 디지털 증거 전반에 관하여 자문의 목적으로 참가하게 된 본 재판은, 디지털 증거와 관련한 본격적인 공방이 오간 최초의 판결로 기록될 것이다. 글의 구성은 다음과 같다. 먼저 디지털 증거의 증거능력에 대한 일반론으로서 대표적인 요건인 진정성․무결성․신뢰성에 관하여 살펴보고, 이를 토대로 한 검증의 원칙과 절차를 검토한다. 다음으로 본 사건에 대한 구체적인 검토를 수행한다. 즉 ‘진정성․무결성․신뢰성’이라는 디지털 증거능력의 요건을 기준으로, 실제 재판에서 진행된 구체적인 검증절차를 대상으로 한 면밀한 검토를 통해 그 부당성을 밝힌다. 마지막으로 합리적인 의심의 관점에서 이러한 검증절차를 통해 도출된 검증결과의 모순들을 적시한다. 검증절차 전반에 흐르는 절차적 부당성이 결국 의혹의 재탄생으로 귀결된 본 사건의 부당성을 제대로 밝혀내기 위함이다.

This paper is a product of an empirical analysis of the so-called ‘Wangjaesan’ case that, among the national security law cases, gave rise to the most controversial issues these days. This case will be recorded as the first trial in which a fierce debate has been raged over digital evidence. The author has participated in the hearing as a digital expert for the defense. This paper deals with the issue of digital evidence in three ways as follows:Firstly, the author identifies the general principle on digital evidence that three elements of authenticity, integrity and reliability shall be demonstrated if the admissibility of digital evidence can be established;Secondly, the author performs a detailed but critical examination of the courtroom scene concerning digital evidence, based on the above-mentioned principle; and Finally, he reveals instances of injustice done in this case concerning the inspection of digital evidence: proving the logical and physical authenticity is denied; identifying the integrity is refused, cheated or omitted; and the process and equipments to deal with digital evidence is unreliable. In short, this article successfully shows that these doubtable results have been caused by the unreasonable procedures on forensic examination of digital evidence.

 
페이지 저장