Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 11
No
1

개인정보 보호를 위한 네트워크 보안장비의 로그 가시화 방법 연구 KCI 등재후보

심희연, 김형종

한국융합보안학회 융합보안논문지 제8권 제4호 2008.12 pp.31-40

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

최근 들어 단순히 시스템에 남아있는 단서들을 분석하는 디스크 포렌식에서 공격자의 추적을 위해 시스템이 포함하는 네트워크의 침입 관련 정보를 분석하여 네트워크 포렌식의 연구가 활발해지고 있다. Firewall이나 IDS, 웹서버 로그의 상호 관계와 분석은 네트워크 포렌식 절차에서 중요한 역할을 한다. 이 연구는 네트워크 포랜식에서 개인정보 노출 감시를 위한 통합 GUI를 제시한다. 본 논문에서는 네트워크 포렌식을 위한 다양한 로그 정보들의 필요성을 제시하고 개인정보 누출을 모니터하는 보안 관리자를 위한 GUI를 설계한다.

2

Improving Analysis Phase in Network Forensics By Using Attack Intention Analysis SCOPUS

Mohammad Rasmi, Khaled E. Al-Qawasmi

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.5 2016.05 pp.297-308

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

The increasing amount of cyber crimes has motivated network forensics researchers to develop new techniques to analyze and investigate these crimes. Reconstructing useful evidence of a cybercrime is difficult due to the vagueness of the analysis phase processes. The analysis phase is challenging because it provides detailed information on the intention and strategy of the attack. This paper aims to show the importance of reconstructing attack intentions in order to improve the analysis phase in network forensics. Intentions are identified through an algorithm called Attack Intention Analysis, which predicts cyber crime intentions by combining mathematical evidence theory and a probabilistic technique. In this paper, the attack intention model will be improved to present the motivation behind cyber crimes. The results of the comparison of the attack intention analysis methods prove that the AIA algorithm is more accurate.

3

An Improved Kernel Clustering Algorithm for Mixed-Type Data in Network Forensic SCOPUS

Min Ren, Peiyu Liu, Zhihao Wang, Lin Lü

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.10 No.1 2016.01 pp.343-354

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

Clustering algorithm is a common analysis technology for network forensics, which, lacking of any prior knowledge, can effectively find out the invasions by analyzing the collected real-time communication data flowing through the network. This paper proposed an improved dynamic kernel clustering algorithm for mixed numeric and categorical network communication data. First, centroid prototype based on the mean and distribution centroid was put forward to represent the cluster center. Then by using Gaussian kernel function, the paper introduced a new dissimilarity measure between the data object and the centroid prototype in combination with the significance of different categorical values. On this basis, the objective function was defined, which took into account both the compact degree in a cluster and the discrete degree among the clusters. After that an improved kernel clustering algorithm was designed. In the process of clustering, centroid prototype and the value of the clustering parameter dynamically updated for a better description of the characteristics of clusters’ change. Finally, in order to verify the feasibility and effectiveness of the algorithm, the paper further applied it to network forensics, and the experimental results showed that the method could mine the intrusion behavior more accurately.

4

Design and Research of Hybrid Network Electronic Forensics Model Based on Cloud Computing SCOPUS

Tian Junfeng, Li Weiping

보안공학연구지원센터(IJGDC) International Journal of Grid and Distributed Computing Vol.9 No.12 2016.12 pp.75-86

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

With the increase of computer network crimes and the changes of the forms, the work of the network electronic forensics is becoming more and more important, and it is required that the technology of electronic forensics should be adapted to the development of complex network crimes. In this paper, the traditional electronic evidence collection technology and the electronic evidence collection method in recent years are studied, and then the hybrid network electronic evidence collection model based on cloud computing environment is proposed, which can work for electronic forensics in dynamic, fast and real-time ways so as to fight against network crimes more effectively.

5

증거 암호패킷 수집시 네트워크포렌식의 신뢰 방안

정석화, 변종문, 전문석, 도경화

[NRF 연계] 한국IT정책경영학회 한국IT정책경영학회 논문지 Vol.7 No.3 2015.06 pp.19-25

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

일반적으로 디지털포렌식은 몇가지 분야 중에서 특히 시스템포렌식에 전적으로 의존하고 있다. 그러나 시스템포렌식은 안티 포렌식 기술의 발전으로 실체적 진실을 규명하는데 점차 한계에 이르고 있다. 따라서 이 한계를 극복할 방법으로 네트워크포렌식 방안이 제시되고 있다. 네트워크포렌식은 기본적으로 전송중이면서 동시에 휘발성 특징이 있는 디지털 패킷을 다루는 분야이다. 네트워크포렌식은 원본 패킷이 아닌 사본 패킷에 의하여 사실을 규명해야 하며 패킷이 암호화 되어있을 경우 해독해야 하는 문제가 발생한다. 이 논문에서는 기존 네트워크포렌식의 문제점과 암호화된 패킷을 해독하는 방안에 대해 고찰하고자 한다. 또한 전송중이 패킷이 디지털증거로서 증거능력을 갖추기 위한 합법적이고 절차적인 방안도 함께 제시하고자 한다.

The digital forensic is typically dependent on ‘system forensic’ among several fields. But, using system forensic skills to discover the truth is getting difficult due to improvement of anti-forensic techniques. Therefore, ‘Network forensic’ filed has been suggested gradually as a way to overcome the limits of system forensic. The network forensic is one of forensic fileds dealing with volatile digital packets that are transmitted in real-time. In network forensic methods, several problems are occurred that the copy of digital packets must be used during analysis not original packets. Also the decryption procedure is often necessary in the case of that digital packets are encrypted. This paper focuses on problems of existing network forensic filed, and methods to decrypt encrypted network packets. Also it suggestes how the real-time transmitted packets are reliable digital evidence, legally and procedurally.

6

UCC와 관련된 인터넷 범죄에 대한 네트워크 포렌식 연구

이규안, 박대우, 신용태

[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.13 No.2 2008 pp.143-151

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

인터넷 이용자의 74%가 UCC를 이용하고 있고, You Tube를 이용한 총기범죄가 발생하였다. 인터넷 범죄는 온라인에서 비대면성, 익명성, 은닉성으로 발생되고 있다. 본 논문에서는, 인터넷 UCC속에 나타난 인터넷 범죄의 양태를 분석하고 추적하는 네트워크 포렌식 방법과 기법을 연구한다. 인터넷 UCC의 범죄와 관련된 경찰과 검찰의 UCC 검색 방법 연구와 저장방법을 이용한 UCC의 증거 자료 수집 및 네트워크 포렌식을 통한 ID, IP 역추적과 위치 추적을 연구한다. 증거자료는 암호화하여 저장하며 접근제어와 사용자 인증을 통한 전송 및 저장 후에 무결성 검증을 통해 법정의 증거자료로 채택되도록 연구한다. 본 연구를 통해 인터넷 범죄 모의와 발생 등을 사전에 차단할 수 있도록 추진하고, 수사기관의 인터넷 범죄에 대한 포렌식 연구 발전에 기여하게 될 것이다.

74% of Internet users use the UCC, and You Tube using firearms in a crime occurred. Internet crime occurred in the online, non-face transaction, anonymous, encapsulation. In this paper, we are studied a Network Forensic Way and a technique analyze an aspect criminal the Internet haying appeared at Internet UCC, and to chase. Study ID, IP back-tracking and position chase through corroborative facts collections of the UCC which used UCC search way study of the police and a public prosecutor and storage way and network forensic related to crimes of Internet UCC. Proof data encrypt, and store, and study through approach control and user authentication so that they are adopted to legal proof data through integrity verification after transmission and storages. This research via the Internet and criminal conspiracy to block the advance promotion, and for the criminal investigative agencies of the Internet will contribute to the advancement forensics research.

7

자동화된 침해사고대응시스템에서의 네트웍 포렌식 정보에 대한 연구

박종성, 문종섭, 최운호

[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2004 pp.253-255

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

포렌식에 관한 연구는 현재까지 시스템에 남은 흔적을 수집하고 가공, 보관하는 시스템 포렌식에 치우쳐 있었다. 최근 들어 단순히 시스템에 남은 흔적만을 분석하는 것이 아닌 시스템이 속한 전체 네트웍에서 침입 관련 정보를 얻고 분석하려는 네트웍 포렌식에 대한 연구가 활발하다. 특히나 자동화된 침해사고대응시스템에서는 전체 네트웍에 대한 침임 흔적을 다루어야 하기 때문에 네트웍 포렌식의 중요성이 크다고 할 수 있다. 본 논문에서는 자동화된 침해사고대응시스템에서 네트웍 포렌식을 위해 수집되어야 할 정보들을 정의한다. 자동화된 침해사고대응시스템의 여러 장비들과 정보들 중 컴퓨터 범죄 발생시 증거(Evidence)가 되는 포렌식로 수집되어야 할 항목들을 제시하고 필요성에 대해 언급할 것이다.

8

네트워크 포렌직을 위한 트래픽의 실시간 비손실 압축에 관한 연구

유상현, 김기창

[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2004 pp.382-384

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 가파른 증가세를 보이며 그 기법 또한 다양해지고 있는 공격에 대한 사후처리와 동일 침입 방지를 위해, 네트워크 포렌직에 대한 관심이 커지고 있다. 포렌직을 위해서는 정보의 손실 없는 네트워크 트래픽을 수집하여 보존하는 것이 필요하지만, 그 양이 막대하며, 이는 더 큰 용량의 디스크를 필요로 한다. 이를 해결하기 위해서는 압축을 수행하는 것이 필요하며, 또한 IP와 같이 필요로 하는 몇몇 정보를 압축해제 없이 접근할 수 있게 한다면, 간단한 작업을 위해서도 압축을 풀기 위해 컴퓨팅 파워와 시간을 줄일 수 있을 것이다. 따라서, 이 논문에서는 수집한 패킷마다 압축을 수행할 부분과 수행하지 않을 부분으로 나누고, 압축을 수행한 뒤, 해당 정보를 4바이트의 헤더로 만들어 덧붙임으로써, 기존 트래픽을 압축함과 동시에 패킷들에 대한 간단한 정보들을 압축해제 없이 접근할 수 있는 모델을 제안하였다.

9

컴퓨터 및 네트워크 환경 하에서 Forensics 적용 동향 및 구현 기술

박연규, 이필중

[Kisti 연계] 한국정보보호학회 한국정보보호학회 학술대회논문집 2002 pp.537-543

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

컴퓨터와 인터넷의 발전과 함께 컴퓨터 범죄가 급속히 증가하고 있는 추세이다. 이에 대응하기 위해 시작된 분야가 컴퓨터 포렌식스(Computer and Network Forensics)이다. 본 논문에서는 컴퓨터 포렌식스의 몇 가지 예를 통해 일반적인 단계와 각 단계에서 이루어지는 절차에 대해 알아본다. 그리고 컴퓨터 포렌식스의 중요한 구성요소로써 사용되는 IDS와 IDS를 적용한 컴퓨터 포렌식스 절차에 대해 살펴보며 마지막으로 보다 효율적이고 체계적인 컴퓨터 포렌식스 준비를 위한 로컬 정책 수립에 기본적인 기준을 제시한다.

10

디지털 포렌식 관점의 P2P 네트워크 정보 수집 망안 연구

성진원, 백은주, 변근덕, 이상진, 임종인

[Kisti 연계] 한국방송공학회 한국방송공학회 학술대회논문집 Vol.2007 2007 pp.173-176

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

컴퓨터 포렌식 수사에서 인터넷 사용에 대한 분석은 증거 획득에서 중요한 부분을 차지한다. 인터넷 사용 분석에는 웹브라우저 분석, 메신저 분석 그리고 Peer to Peer (P2P) 분석 등이 그 대상이 된다 그 중 본 논문에서는 최근 중요성이 대두되고 있는 P2P를 분석함으로써 P2P에서 컴퓨터 포렌식 수사에 도움이 되는 정보에 대해 알아보고 분석 방법을 제시한다.

11

네트워크 서비스 환경에서 MPEG-21을 활용한 디지털 콘텐츠 보호 및 컴퓨터 포렌식스 증거 관리 메커니즘

장은겸, 이범석

[Kisti 연계] 디지털산업정보학회 디지털산업정보학회논문지 Vol.6 No.2 2010 pp.129-141

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

In network service environment, cultures from diversified fields are easily accessible thanks to the convenient digital content services. Unfortunately, unauthorized access and indiscreet misuse behaviors have deprived content owners of their copyrights. This study suggests an integrity-ensured model applicable for forensic evidence of digital content infringement in network service environment. The suggested model is based on MPEG-21 core components for digital content protection and the system is designed in connection with the components of digital content forensics. Also, the present study suggests an efficient technology to protect and manage computer forensic evidence and digital content by authorizing digital content use and catching infringing logs of authorized users without lag in network environment for the benefit of network security and reliability.

 
페이지 저장