Browse > Article
http://dx.doi.org/10.13089/JKIISC.2013.23.1.057

A Study on the Design and Implementation of an Digital Evidence Collection Application on Windows based computer  

Lee, SeungWon (MKE Cyber Security Center)
Roh, YoungSup (Seoul Venture University)
Han, Changwoo (MKE Cyber Security Center)
Abstract
Lately, intrusive incidents (including system hacking, viruses, worms, homepage alterations, and data leaks) have not involved the distribution of an virus or worm, but have been designed to acquire private information or trade secrets. Because an attacker uses advanced intelligence and attack techniques that conceal and alter data in a computer, the collector cannot trace the digital evidence of the attack. In an initial incident response first responser deals with the suspect or crime scene data that needs investigative leads quickly, in accordance with forensic process methodology that provides the identification of digital evidence in a systematic approach. In order to an effective initial response to first responders, this paper analyzes the collection data such as user usage profiles, chronology timeline, and internet data according to CFFPM(computer forensics field triage process model), proceeds to design, and implements a collection application to deploy the client/server architecture on the Windows based computer.
Keywords
digital forensics; digital evidence; evidence collection; collection software;
Citations & Related Records
Times Cited By KSCI : 1  (Citation Analysis)
연도 인용수 순위
1 "디지털 증거 처리 가이드라인", 고려대학교 디지털 포렌식연구센터, 2012. http://forensic.korea. ac.kr/sub_guideline/download/guid eline_1.pdf
2 Marcus K Rogers et al, "Computer Forensic Field Triage Process Model," Conference on Digital Forensics, Security and Law, Las Vegas, Nevada, USA, pp. 27-40, April 20-21, 2006.
3 침해사고 분석 절차 안내서, 방송통산위원회․한국인터넷진흥원, 2010.1.
4 허건일, 박찬욱, 박원형, 국광호, "윈도우 기반 악성 코드 증거 수집 모듈 개선에 관한 연구", 정보․보안논문지, 제10권, 제3호, pp 61-68, 2010.9.
5 백은주, 성진원, 임경수, 이상진, "윈도우 활성 시스템상의 디지털 증거수집 도구 설계 및 구현," 정보보안․논문지, 제7권, 제2호, pp 91-100, 2007.6.
6 백은주, "윈도우 시스템에서의 활성 데이터 수집 도구 설계 및 구현," 석사학위 논문, 고려대학교, pp 8-13, 2007.12.
7 Special Agent Jesse Kornblum, "Preservation of Fragile Digital Evidence by First Responders," Air Force Office of Special Investigations, pp 1-11, Aug. 2002.
8 Chris, Kevin, "Incident Response & Computer Forensics," 2nd. ed, McGraw-Hill. pp. 114-115, July 17, 2003.
9 이석희, 김현상, 이상진, 임종인, "윈도우 시스템에서 디지털 포렌식 관점에서의 메모리 정보 수집 및 분석 방법에 대한 고찰", 정보보호학회 논문지, 16(1), pp 87-96, 2006.2.
10 송대완, "디지털 증거의 법적 증명력을 위한 디지털 포렌식에 관한연구(Windows Forensic을 중심으로)", 석사학위논문, 한남대학교, pp15-30, 2006.12.
11 신삼신, "윈도우 파일 시스템의 직접접근을 통한 초기단계 포렌식 증거수집", 석사학위논문, 전남대학교, pp 4-43, 2008.2.