현대 디지털 수사에서 사용자 행위를 추정하기위해서는 메신저, 협업도구, 생산성도구 등의 다양한 개별 애플리케이션의 데이터를 분석해야한다. 각 애플리케이션 데이터를 분석하기 위해...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T17372157
서울 : 국민대학교 일반대학원, 2025
학위논문(박사) -- 국민대학교 일반대학원 , 정보융합보안전공 , 2026. 2
2025
영어
서울
v, 51 ; 26 cm
지도교수: 김종성
I804:11014-200000961400
0
상세조회0
다운로드현대 디지털 수사에서 사용자 행위를 추정하기위해서는 메신저, 협업도구, 생산성도구 등의 다양한 개별 애플리케이션의 데이터를 분석해야한다. 각 애플리케이션 데이터를 분석하기 위해...
현대 디지털 수사에서 사용자 행위를 추정하기위해서는 메신저, 협업도구, 생산성도구 등의 다양한 개별 애플리케이션의 데이터를 분석해야한다. 각 애플리케이션 데이터를 분석하기 위해서는 적용된 보안 기술을 해제해고 데이터 구조 분석이 선행되어야 한다. 특히 암호화된 데이터가 존재하는 경우 이를 복호화하지 않으면 데이터 분석이 불가능하다. 따라서 다양한 애플리케이션 데이터를 수사에 활용하기 위해서는 데이터를 복호화하고 이를 분석하는 연구가 지속적으로 이루어져야 한다. 이때, 암호화 키가 존재하는 위치와 사용된 암호 알고리즘을 특정할 수 있다면 관련 라이브러리 함수 등을 추적하여 분석과정을 단축할 수 있다. 본 연구에서는 이러한 선행 연구를 효율적으로 수행하기 위해 간단한 실험을 통해 암호화에 사용된 키가 존재하는 위치를 식별하는 프레임워크를 제시합니다. 또한 식별된 키의 위치를 기반으로 애플리케이션 클라이언트를 분석에 활용하는 방법론을 제안합니다.
다국어 초록 (Multilingual Abstract)
In modern digital forensics, inferring user behavior requires analyzing data from various individual applications, such as messengers, collaboration tools, and productivity software. To analyze the data from each application, it is necessary to bypass...
In modern digital forensics, inferring user behavior requires analyzing data from various individual applications, such as messengers, collaboration tools, and productivity software. To analyze the data from each application, it is necessary to bypass its applied security technologies and first conduct an analysis of its data structure. In particular, if encrypted data exists, data analysis is impossible without decrypting it. Therefore, to utilize diverse application data in investigations, continuous research into decrypting and analyzing this data is essential. At this juncture, if the location of the encryption key and the specific encryption algorithm used can be identified, the analysis process can be shortened by tracing related library functions. In this study, we propose a framework, developed through simple experiments, to efficiently perform this prerequisite analysis by identifying the location of the keys used in encryption. Furthermore, we propose a methodology for utilizing the application client in the analysis based on the identified key locations.
목차 (Table of Contents)