• Title/Summary/Keyword: 수사절차

Search Result 78, Processing Time 0.022 seconds

Cloud Services for the forensic aspects of the investigative methods (클라우드 서비스에 대한 포렌식 측면의 수사 방법)

  • Park, Gi-Hong;No, Si-Young
    • Journal of Korea Society of Industrial Information Systems
    • /
    • v.17 no.1
    • /
    • pp.39-46
    • /
    • 2012
  • In this paper, for the cloud system by explaining how the forensic aspects of the investigation. Smartphone Growth Entering a variety of applications were developed which cloud systems of personal information and information assets sharing applications as during incidents on the case evidence collection, an important factor, whereas such systematic investigative methods, born in the course of my investigation of the can be confusing. This paper on the forensic aspects of the cloud system by proposing a crime scene investigation procedures, investigative support, and aiding in the systematic collection of data to support evidence.

Digital Investigation First Responder and Preliminary Analyst Requirements (디지털 수사 초동조치 대응인력 및 예비분석관들이 갖추어야 할 요건)

  • James, Joshua Issac;Jang, Yunsik
    • The Journal of the Institute of Internet, Broadcasting and Communication
    • /
    • v.16 no.5
    • /
    • pp.49-54
    • /
    • 2016
  • As investigations dealing with digital evidence increase, so to does the need for skilled first responders and improved investigation process models. Recently the concept of digital forensic triage and preliminary analysis has been gaining popularity in investigation laboratories. At the same time, however, there has been little focus on specific training needs of first response and preliminary analysts. Instead, many organizations consider these responders to need the same skills as full digital forensic analysts. In this work we describe the 'ideal' digital investigation first responder and preliminary analyst, hardware and software requirements and most importantly, required training.

The application of digital forensic investigation for response of cyber-crimes (사이버범죄의 대응강화를 위한 디지털 포렌식 수사 활용방안)

  • Oh, Sei-Youen
    • Journal of Digital Convergence
    • /
    • v.13 no.4
    • /
    • pp.81-87
    • /
    • 2015
  • This study will show the digital forensic model which fights against cyber-crimes to prepare various cyber-crimes. The digital forensic model will be more useful about the investigation of cyber-crimes and arresting criminals after researching the uses of the digital forensic model and cyber-crime rates in South Korea. This model conduct the standardized data with various languages by the language support system through the digital forensic analyzer. This model will send the data to law enforcement reviewing whether or not we ought to prove criminal charges. Moreover, law enforcement can access the file system to find out admissibility of evidence. And this model simplifies lawful investigation about additional investigation. The data, which is conducted and saved by the digital forensic system, will be helpful to protect against the future crimes because of the data.

A Study on the Correlation between the Investigation on the Violation Crime of Intellectual Property Rights and the Goods Inspection in Customs Law (관세법상 지식재산권 침해사범 수사와 물품검사와의 상호관계)

  • Ye, Sangkyun
    • International Commerce and Information Review
    • /
    • v.19 no.3
    • /
    • pp.197-214
    • /
    • 2017
  • It requires professional knowledge and much time to judge intellectual property rights infringement. The duties of customs administration are the balance between the propositon of trade facilitation through rapid clearance and the thesis of social security through exact examination. There is a view that the criminal procedure law control is necessary to the goods inspection of clearnce procedure if it is related to crimianl investigation. However, it seems that the customs law does not consider the goods inspection investigation as the investigation under judicial control, but only the mere administrative investigation. It can be said that the inspection of goods by customs law functioning as a clue of investigation is confined to the ordinary goods inspection, including the screening test. Searching for specific articles by specific informaition should be under the control of criminal procedure law because it constitutes the commencement of criminal investigation in criminal cases. This interpretation could be an opportunity as a harmonious operation between the goods inspection of customs clearance and the search and seizure of criminal procedure.

  • PDF

Study on Hashing of CD-R Media from the Viewpoint of Digital Forensics (디지털 포렌식 관점에서 CD-R 미디어의 해쉬 값 생성에 관한 연구)

  • Park, Jung-Heum;Kim, Kwon-Youp;Lee, Sang-Jin;Lim, Jong-In
    • Proceedings of the Korean Society of Broadcast Engineers Conference
    • /
    • 2008.02a
    • /
    • pp.167-170
    • /
    • 2008
  • 해쉬 알고리즘은 디지털 포렌식 수사에서 디지털 증거의 무결성을 증명하기 위해 널리 사용되고 있다. 디지털 증거의 무결성은 동일한 데이터에서만 같은 해쉬 값이 계산된다는 성질에 의하여 증명된다. 일반적으로 동일한 데이터에 대한 해쉬 값은 서로 다른 포렌식 툴을 이용해서 계산을 해도 항상 같은 값이 출력될 것이라고 인식하고 있다. 하지만, CD-R 미디어의 경우에는 해쉬를 계산하는 포렌식 툴에 따라 값이 다르다는 특성이 있다. 이것은 해쉬 값이 CD 제작 도구에서 CD-R 미디어에 데이터를 기록하는 방식과 각 포렌식 툴 별로 CD-R 미디어를 인식하는 방식에 의해 영향을 받기 때문이다. 이러한 특성은 CD-R 미디어의 무결성 증명 시에 문제가 될 여지가 있기 때문에 디지털 포렌식 수사 절차에서 반드시 고려되어야 한다. 본 논문에서는 CD-R 미디어의 해쉬 값에 영향을 주는 요소에 대해 기술하고, 실험용 CD-R 미디어를 제작하여 대표적인 디지털 포렌식 도구들을 이용해서 확인한다. 이를 통해, 디지털 포렌식 수사 절차에서 CD-R 미디어에 대한 해쉬 값을 계산할 때 고려해야 할 사항을 제안한다.

  • PDF

A Digital Forensic Procedure and Service of Ship with VTS and Navigation Device (VTS 및 소형선박 항해장비의 항적추출을 통한 디지털 포렌식 절차 및 모델서비스)

  • Lee, Byung-Gil;Choi, Byeong-Chel
    • Proceedings of the Korean Institute of Navigation and Port Research Conference
    • /
    • 2019.11a
    • /
    • pp.243-245
    • /
    • 2019
  • In the VTS, the predictions of vessel mobility and situation awareness of maritime environment are basic function. In recent years, pilotage information is an essential aware element of VTS personnel for vessel traffic management. So, we designed the structure of pilotage information service with VTS and tested in real environment. In the future, similar pilotage information can be used as a useful VTS service.

  • PDF

A Study on the Introduction of Obstruction of Justice Contents (사법방해죄 도입에 대한 고찰)

  • Jeong, Byeong-Gon
    • The Journal of the Korea Contents Association
    • /
    • v.11 no.12
    • /
    • pp.734-741
    • /
    • 2011
  • The beginning that the 'Obstruction of Justice' in the United States is commonly known to Korea is through the impeachment of former president W. J. Clinton in 1998. The 'Obstruction of Justice' in the federal law of the United States is comprehensively provided with a general and a particular rule laying emphasis on the obstruction of legal judiciary proceedings. But, according to the Korean Criminal Act and court decisions, there are no such system like the 'Obstruction of Justice' in the United States. In this result, in terms of the criminal-judicial system, some cases even telling a lies has more benefits than revealing the truth and it is discouraged to cooperate the achievement of judicial justice, which make difficulties in investigation and realizing real truth. For this reason, the Ministry of Justice in Korea makes efforts to introduce the 'Obstruction of Justice'. Nevertheless we should examine from all angles that the introduction of 'Obstruction of Justice' is indeed the alternative in our circumstances. Most of the discussions on the introduction of 'Obstruction of Justice' and also the revised bill of the Ministry of Justice are questions of 'False Statement of Suspect and Witness' for investigation of investigative agency, rather than for the introduction of a general rule on the 'Obstruction of Justice'. The introduction of 'False Statement of Suspect and Witness' for investigation of investigative agency needs to consider concern about human rights infringement and witness protection system should be reinforced in the first place. In other words, the introduction of 'False Statement of Suspect and Witness' for investigation process of investigative agency is undesirable now.

A Feature Comparison of Modern Digital Forensic Imaging Software (현대 디지털 포렌식 이미징 소프트웨어 도구 특징 비교에 대한 연구)

  • Ham, Jiyoon;James, Joshua I.
    • The Journal of the Institute of Internet, Broadcasting and Communication
    • /
    • v.19 no.6
    • /
    • pp.15-20
    • /
    • 2019
  • Fundamental processes in digital forensic investigation - such as disk imaging - were developed when digital investigation was relatively young. As digital forensic processes and procedures matured, these fundamental tools, that are the pillars of the reset of the data processing and analysis phases of an investigation, largely stayed the same. This work is a study of modern digital forensic imaging software tools. Specifically, we will examine the feature sets of modern digital forensic imaging tools, as well as their development and release cycles to understand patterns of fundamental tool development. Based on this survey, we show the weakness in current digital investigation fundamental software development and maintenance over time. We also provide recommendations on how to improve fundamental tools.

A Study of Digital Forensic Problems Based on Gruop 'il-sim' Adjudication (일심회 판결로 살펴본 디지털 포렌식의 문제점 연구)

  • Chun, Woo-Sung;Park, Dea-Woo;Lee, Gyu-An
    • Proceedings of the Korean Institute of Information and Commucation Sciences Conference
    • /
    • 2011.05a
    • /
    • pp.455-458
    • /
    • 2011
  • 일명 일심회 사건으로 디지털 포렌식이 과학수사에서 활용되는 가운데 판결한 최근 사례로서 1심 판결과 2심 판결에서 디지털 증거의 채택여부를 달리하였다. 학계와 법조계의 의견이 분분한 가운데 일심회 판결문의 1심 판결에 대한 중요성은 수차례에 걸쳐 연구되고 논의되었으나 2심 판결에서 이를 번복하므로 디지털 증거의 인정여부를 위한 문제점과 해결, 절차에 대한 연구가 다시 시작할 시점에 이르렀다. 본 연구에서는 디지털 증거가 법적증거로 인정될 수 있는가에 대한 논의를 시작으로, 일심회 사건의 1심과 2심의 판결을 중심으로 디지털 포렌식 증거의 분석을 통해서 문제점과 해결방안을 제시한다. 본 연구결과 디지털 포렌식의 수사현장에서 필요한 조건을 검토하고, 이를 이행함으로써 과학수사의 일환으로 디지털 증거가 법정에서 채택할 수 있도록 한다.

  • PDF

Analysis of Unexpected Shutdown Based on Windows Event Log(EVTX) and its Applications in forensic (윈도우 이벤트 로그 기반 PC 비정상 종료 분석 및 활용방안)

  • Kim, Ha-Young;Park, Hyeon-Min;Kim, Gi-Bum
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2022.05a
    • /
    • pp.33-36
    • /
    • 2022
  • 이벤트 로그(Event Log)는 윈도우 운영체제에서 시스템 로그를 기록하는 형식으로 시스템 운영에 대한 정보를 체계적으로 관리한다. 이벤트는 시스템 자체 또는 사용자의 특정 행위로 인해 발생할 수 있고, 그러한 이벤트 로그는 시스템의 시작과 종료뿐만 아니라 기업 보안 감사, 악성코드 탐지 등 행위의 근거로 사용될 수 있다. 본 논문에서는 PC 종료 관련 실험을 통해 이벤트 로그와 ID를 분석하였다. 분석 결과를 통해 PC의 정상 및 비정상 종료 여부를 판단하여, 현장 압수·수색 시 해당 저장매체에 대해 선별압수·매체압수의 해당 여부 식별이 가능하다. 본 연구는 현장수사관이 디지털증거 압수·수색 시 절차적 적법성과 증거능력 확보의 근거 활용에 기여할 수 있다.