• Title/Summary/Keyword: Anti-Forensic

Search Result 60, Processing Time 0.037 seconds

Web Log Scenario Make for Forensic (포렌식을 위한 웹로그 시나리오 작성 시스템)

  • Jang, Hae-Sook;Lee, Jin-Kwan;Lee, Jong-Chan;Park, Sang-Joon;Park, Ki-Hong
    • Proceedings of the Korean Society of Computer Information Conference
    • /
    • 2011.01a
    • /
    • pp.303-305
    • /
    • 2011
  • 수많은 웹로그 히스토리의 자료에서 컴퓨터 사이버범죄에 대한 증거자료로 채택되기 위한 기술적인 웹 포렌식 자료의 추출에 사용되는 웹 포렌식 알고리즘은 필수적인 요소이다. 본 논문에서는 웹 로그 시나리오 작성을 제안하고 설계하여, 웹 포렌식을 통한 컴퓨터 사이버범죄에 대한 학문적 기술적 발전에 기여하고자 하는데 본 논문의 목적이 있다. 수많은 웹로그 자료에서 컴퓨터 사이버 범죄에 대한 증거 자료로 채택되기 위한 기술적인 웹 포렌식 자료의 추출에 사용되는 웹 로그 분석 알고리즘은 필수적인 요소이다. 본 논문에서는 웹 포렌식 알고리즘을 제안하고 설계하여, 실제 기업의 웹 서버 시스템에 제안한 알고리즘을 구현해 본다. 웹 서버에서 웹 로그 분석을 위해 사용한 웹 포렌식 알고리즘과 플로우를 설계하고 코딩을 통한 구현을 한다. 구현 결과 웹 포렌식을 통한 컴퓨터 사이버 범죄에 대한 학문적 기술적 발전에 기여하고자 하는데 본 논문의 목적이 있다.

  • PDF

Study on SNS Application Data Decryption and Artifact (SNS 애플리케이션의 데이터 복호화 및 아티팩트 연구)

  • Shin, Sumin;Kang, Soojin;Kim, Giyoon;Kim, Jongsung
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.30 no.4
    • /
    • pp.583-592
    • /
    • 2020
  • With the popularization of smartphones, Social Networking Service (SNS) has become the means of communication for modern people. Due to the nature of the means of communication, SNS generates a variety of archive and preservation evidence. Therefore, it is a major analysis target in terms of digital forensic investigation. An application that provides SNS stores data in a central server or database in a smartphone inside for user convenience. Some applications provide encryption for privacy, which can be anti-forensic in terms of digital forensic investigation. Therefore, the study of the encryption method should be continuously preceded. In this paper, we analyzed two applications that provide SQLite-based database encryption through SQLCipher module. Each database was decrypted and key data was identified.

Build a Digital Evidence Map considered Log-Chain (로그 체인을 고려한 디지털증거지도 작성)

  • Park, Hojin;Lee, Sangjin
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.24 no.3
    • /
    • pp.523-533
    • /
    • 2014
  • It has been spent too much time to figure out the incident route when we are facing computer security incident. The incident often recurs moreover the damage is expanded because critical clues are lost while we are wasting time with hesitation. This paper suggests to build a Digital Evidence Map (DEM) in order to find out the incident cause speedy and accurately. The DEM is consist of the log chain which is a mesh relationship between machine data. And the DEM should be managed constantly because the log chain is vulnerable to various external facts. It could help handle the incident quickly and cost-effectively by acquainting it before incident. Thus we can prevent recurrence of incident by removing the root cause of it. Since the DEM has adopted artifacts in data as well as log, we could make effective response to APT attack and Anti-Forensic.

Anti-inflammatory effect of new calcium hydroxide paste containing silicon-substituted hydroxyapatite in lipopolysaccharide-stimulated macrophages

  • Roh, Ji-Yeon;Kim, Ki-Rim
    • Journal of Korean society of Dental Hygiene
    • /
    • v.18 no.4
    • /
    • pp.423-432
    • /
    • 2018
  • Objectives: Calcium hydroxide, a root canal temporary sealer, has long been used and it has anti-bacterial and anti-inflammatory activity. To investigate the properties of a newly developed calcium hydroxide paste comprising silicon-substituted hydroxyapatite (Si-HA), we examined the anti-inflammatory activity of the new calcium hydroxide paste in RAW 264.7 macrophages stimulated by lipopolysaccharide (LPS), which causes infection of the root canal. Methods: The test materials, including Calcipex II as control group and the newly developed TRC paste, were extracted from cell culture media and then diluted for experiment. In LPS-stimulated RAW 264.7 cells, the cytotoxicity and nitric oxide (NO) production of test materials were measured by MTT assay and Griess reagents, respectively. Also, the expression of the inducible nitric oxide synthase (iNOS) was assessed by western blotting. Results: The IC50 values of Calcipex II and TRC paste were $17.6mg/m{\ell}$ and $13.5mg/m{\ell}$, respectively. The level of NO, increased by LPS, was dose-dependently inhibited more by TRC paste than Calcipex II treatment. In addition, iNOS expression was decreased by 71% and 92% at concentrations of $2mg/m{\ell}$ and $20mg/m{\ell}$ of TRC paste, respectively. Conclusions: We demonstrated that the Si-HA calcium hydroxide paste has a slightly improved anti-inflammatory property and further studies are needed before clinical recommendations are proposed.

The Recovery Method for MySQL InnoDB Using Feature of IBD Structure (IBD 구조적특징을이용한 MySQL InnoDB의레코드복구기법)

  • Jang, Jeewon;Jeoung, Doowon;Lee, Sang Jin
    • KIPS Transactions on Computer and Communication Systems
    • /
    • v.6 no.2
    • /
    • pp.59-66
    • /
    • 2017
  • MySQL database is the second place in the market share of the current database. Especially InnoDB storage engine has been used in the default storage engine from the version of MySQL5.5. And many companies are using the MySQL database with InnoDB storage engine. Study on the structural features and the log of the InnoDB storage engine in the field of digital forensics has been steadily underway, but for how to restore on a record-by-record basis for the deleted data, has not been studied. In the process of digital forensic investigation, database administrators damaged evidence for the purpose of destruction of evidence. For this reason, it is important in the process of forensic investigation to recover deleted record in database. In this paper, We proposed the method of recovering deleted data on a record-by-record in database by analyzing the structure of MySQL InnoDB storage engine. And we prove this method by tools. This method can be prevented by database anti forensic, and used to recover deleted data when incident which is related with MySQL InnoDB database is occurred.

Anti-proliferation Effects of Isorhamnetin on Lung Cancer Cells in Vitro and in Vivo

  • Li, Qiong;Ren, Fu-Qiang;Yang, Chun-Lei;Zhou, Li-Ming;Liu, Yan-You;Xiao, Jing;Zhu, Ling;Wang, Zhen-Grong
    • Asian Pacific Journal of Cancer Prevention
    • /
    • v.16 no.7
    • /
    • pp.3035-3042
    • /
    • 2015
  • Background: Isorhamnetin (Iso), a novel and essential monomer derived from total flavones of Hippophae rhamnoides that has long been used as a traditional Chinese medicine for angina pectoris and acute myocardial infarction, has also shown a spectrum of antitumor activity. However, little is known about the mechanisms of action Iso on cancer cells. Objectives: To investigate the effects of Iso on A549 lung cancer cells and underlying mechanisms. Materials and Methods: A549 cells were treated with $10{\sim}320{\mu}g/ml$ Iso. Their morphological and cellular characteristics were assessed by light and electronic microscopy. Growth inhibition was analyzed by MTT, clonogenic and growth curve assays. Apoptotic characteristics of cells were determined by flow cytometry (FCM), DNA fragmentation, single cell gel electrophoresis (comet) assay, immunocytochemistry and terminal deoxynucleotidyl transferase nick end labeling (TUNEL). Tumor models were setup by transplanting Lewis lung carcinoma cells into C57BL/6 mice, and the weights and sizes of tumors were measured. Results: Iso markedly inhibited the growth of A549 cells with induction of apoptotic changes. Iso at $20{\mu}g/ml$, could induce A549 cell apoptosis, up-regulate the expression of apoptosis genes Bax, Caspase-3 and P53, and down-regulate the expression of Bcl-2, cyclinD1 and PCNA protein. The tumors in tumor-bearing mice treated with Iso were significantly smaller than in the control group. The results of apoptosis-related genes, PCNA, cyclinD1 and other protein expression levels of transplanted Lewis cells were the same as those of A549 cells in vitro. Conclusions: Iso, a natural single compound isolated from total flavones, has antiproliferative activity against lung cancer in vitro and in vivo. Its mechanisms of action may involve apoptosis of cells induced by down-regulation of oncogenes and up-regulation of apoptotic genes.

A Design on the Multimedia Fingerprinting code based on Feature Point for Forensic Marking (포렌식 마킹을 위한 특징점 기반의 동적 멀티미디어 핑거프린팅 코드 설계)

  • Rhee, Kang-Hyeon
    • Journal of the Institute of Electronics Engineers of Korea CI
    • /
    • v.48 no.4
    • /
    • pp.27-34
    • /
    • 2011
  • In this paper, it was presented a design on the dynamic multimedia fingerprinting code for anti-collusion code(ACC) in the protection of multimedia content. Multimedia fingerprinting code for the conventional ACC, is designed with a mathematical method to increase k to k+1 by transform from BIBD's an incidence matrix to a complement matrix. A codevector of the complement matrix is allowanced fingerprinting code to a user' authority and embedded into a content. In the proposed algorithm, the feature points were drawing from a content which user bought, with based on these to design the dynamical multimedia fingerprinting code. The candidate codes of ACC which satisfied BIBD's v and k+1 condition is registered in the codebook, and then a matrix is generated(Below that it calls "Rhee matrix") with ${\lambda}+1$ condition. In the experimental results, the codevector of Rhee matrix based on a feature point of the content is generated to exist k in the confidence interval at the significance level ($1-{\alpha}$). Euclidean distances between row and row and column and column each other of Rhee matrix is working out same k value as like the compliment matrices based on BIBD and Graph. Moreover, first row and column of Rhee matrix are an initial firing vector and to be a forensic mark of content protection. Because of the connection of the rest codevectors is reported in the codebook, when trace a colluded code, it isn't necessity to solve a correlation coefficient between original fingerprinting code and the colluded code but only search the codebook then a trace of the colluder is easy. Thus, the generated Rhee matrix in this paper has an excellent robustness and fidelity more than the mathematically generated matrix based on BIBD as ACC.

Study on Windows Event Log-Based Corporate Security Audit and Malware Detection (윈도우 이벤트 로그 기반 기업 보안 감사 및 악성코드 행위 탐지 연구)

  • Kang, Serim;Kim, Soram;Park, Myungseo;Kim, Jongsung
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.28 no.3
    • /
    • pp.591-603
    • /
    • 2018
  • Windows Event Log is a format that records system log in Windows operating system and methodically manages information about system operation. An event can be caused by system itself or by user's specific actions, and some event logs can be used for corporate security audits, malware detection and so on. In this paper, we choose actions related to corporate security audit and malware detection (External storage connection, Application install, Shared folder usage, Printer usage, Remote connection/disconnection, File/Registry manipulation, Process creation, DNS query, Windows service, PC startup/shutdown, Log on/off, Power saving mode, Network connection/disconnection, Event log deletion and System time change), which can be detected through event log analysis and classify event IDs that occur in each situation. Also, the existing event log tools only include functions related to the EVTX file parse and it is difficult to track user's behavior when used in a forensic investigation. So we implemented new analysis tool in this study which parses EVTX files and user behaviors.

On the CIC from the view of Anti Sexual Violence Crime (반(反)성폭력 관점에서 본 친고죄)

  • Park, Sun-Hee;Chae, Jong-Min
    • Journal of forensic and investigative science
    • /
    • v.1 no.1
    • /
    • pp.54-71
    • /
    • 2006
  • The definition of Crime Indictable Upon Complaint (CIC) is crimes which can be prosecuted only with complaints from the victim or his/her direct parents. Sex crimes are the representative examples, rapes and indecent assaults. According to the research referenced in this paper, 74% of sex crimes which had been penalized based on Republic of Korea (ROK) Criminal Code amounts rape and indecent assault are CIC. However, only 20% of perpetrators were confined, and the rest received non-confinement or non-prosecution determination. The review of criminal history checks reveals that 67% of the perpetrators had criminal histories and 39% of them had more than three documented offenses. The CIC was established in order to protect the victim's rights and dignity, respecting the victim's opinion regarding the incident. All kinds of sex crimes then should have been the CIC, but those crimes such as Injury Resulting from Rape, Special Rape, Rape by Special Modus Operandi, Sexual Assault among Relatives and Domestic Violence which have to guarantee the opinion of the victims are prescribed as non-CIC. We therefore conclude that the CIC should be abolished. The abolition of CIC will play an important role in crime prevention because severe penalties for sex crimes will be imposed on the perpetrators. In addition, it will help the sex crime victims retrieve their dignity by spreading recognition widely through the community that sexual assault is not only a social assault but an infringement against human rights.

  • PDF

Simultaneous Analysis of Several Non-Steroidal Anti-Inflammatory Drugs in Urine by Gas Chromatograph/Negative Chemical Ionization-Mass Spectrometry (기체 크로마토그래프-질량분석법을 이용한 뇨중 비스테로이드성 소염진통제 (NSAIDs)의 동시 분석법)

  • Myung, Seung-Woon;Park, Joon-Ho;Kim, Myung-Soo;Cho, Hyun-Woo
    • Analytical Science and Technology
    • /
    • v.12 no.6
    • /
    • pp.571-576
    • /
    • 1999
  • Screening method for NSAIDs (Hon-Steroidal Anti-Inflammatory Drugs) in urine was developed using GC/NCI-MS. Derivatized six fenamates with pentafluoropropionic anhydride showed high sensitivity in NCI-MS. The conditions of the derivatization reaction and chromatographic conditions were established for screening with a trace analysis. Limit of detection was in the range of 4-25 pg/mL. This method may be used to the equine doping analysis for NSAIDs and forensic analysis.

  • PDF