RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    윈도우 환경에서 Migration 활용 보안 메신저의 데이터 획득 방안

    한글로보기

    https://www.riss.kr/link?id=T17387837

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
      • URL 복사
    • 오류접수
    인용문이 복사되었습니다.

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    As demands for privacy and anonymity in digital environments grow, the use of secure messengers based on end-to-end encryption technology is increasing. Secure messengers are being misused for various criminal activities beyond legitimate purposes, such as drug trafficking and the distribution of illegal recordings. End-to-end encryption technology and manufacturers' non-cooperative policies make it difficult to obtain conversation content during criminal investigations.
    This study proposes a method to acquire data from secure messengers by migrating automatically logged-in sessions without decrypting conversation content. An experimental environment was established targeting ten secure messengers that provide official Windows desktop clients: Telegram Desktop, Session, Jami, Signal, Element, WhatsApp, Wire, Zalo, Viber, and AWS Wickr. Static analysis examined each messenger's AppData directory, configuration files, and databases to verify the presence of auto-login sessions. In environments with auto-login enabled, we validated session restoration feasibility through four methods: AppData-based migration, Windows credential-based access, NTLM hash restoration access, and HIVE file modification-based access.
    The results showed that session restoration using only the AppData directory was possible for only three messengers (Telegram Desktop, Session, Jami). Most secure messengers employed the operating system's DPAPI-based encryption structure, making session restoration impossible through AppData migration alone. Conversely, when migrating disk copies after obtaining the Windows account password, session restoration was possible for all 10 messengers. The NTLM hash restoration method also yielded the same result when password cracking succeeded. The HIVE file modification-based approach enabled session restoration only in 5 types (Telegram Desktop, Session, Jami, Viber, AWS Wickr). This was confirmed to stem from a structural characteristic where the newly generated encryption key during the password reset process does not match the existing session token.
    Based on the experimental results, a step-by-step procedure for acquiring secure messenger data applicable in seizure and search scenarios was proposed. The procedure consists of an initial verification stage, a secure messenger identification and classification stage, a decryption attempt stage in environments without auto-login, a migration stage in auto-login environments, and a data acquisition termination and documentation stage. Each stage was designed to reflect differences in session storage methods and operating system authentication systems across messengers. Furthermore, the experimental results obtained in this study were incorporated into the procedure design to establish criteria for determining the presence of auto-login and selecting the session restoration method.
    This study is significant in that it verifies session migration techniques for acquiring digital evidence from desktop security messengers and presents procedures applicable during search and seizure operations. By demonstrating the practical feasibility of securing data from security messengers through session migration, it contributes to investigative practice. However, environments exist where session migration is restricted due to factors like BitLocker encryption and two-factor authentication, necessitating future research on acquiring desktop secure messengers from diverse perspectives. Future development of technology to automate the collection of conversations and media from the GUI screen after session restoration is required.
    It is hoped that this research will enhance the feasibility of accessing desktop secure messengers during future search and seizure operations and contribute to securing core data essential for proving criminal allegations.
    번역하기

    As demands for privacy and anonymity in digital environments grow, the use of secure messengers based on end-to-end encryption technology is increasing. Secure messengers are being misused for various criminal activities beyond legitimate purposes, su...

    As demands for privacy and anonymity in digital environments grow, the use of secure messengers based on end-to-end encryption technology is increasing. Secure messengers are being misused for various criminal activities beyond legitimate purposes, such as drug trafficking and the distribution of illegal recordings. End-to-end encryption technology and manufacturers' non-cooperative policies make it difficult to obtain conversation content during criminal investigations.
    This study proposes a method to acquire data from secure messengers by migrating automatically logged-in sessions without decrypting conversation content. An experimental environment was established targeting ten secure messengers that provide official Windows desktop clients: Telegram Desktop, Session, Jami, Signal, Element, WhatsApp, Wire, Zalo, Viber, and AWS Wickr. Static analysis examined each messenger's AppData directory, configuration files, and databases to verify the presence of auto-login sessions. In environments with auto-login enabled, we validated session restoration feasibility through four methods: AppData-based migration, Windows credential-based access, NTLM hash restoration access, and HIVE file modification-based access.
    The results showed that session restoration using only the AppData directory was possible for only three messengers (Telegram Desktop, Session, Jami). Most secure messengers employed the operating system's DPAPI-based encryption structure, making session restoration impossible through AppData migration alone. Conversely, when migrating disk copies after obtaining the Windows account password, session restoration was possible for all 10 messengers. The NTLM hash restoration method also yielded the same result when password cracking succeeded. The HIVE file modification-based approach enabled session restoration only in 5 types (Telegram Desktop, Session, Jami, Viber, AWS Wickr). This was confirmed to stem from a structural characteristic where the newly generated encryption key during the password reset process does not match the existing session token.
    Based on the experimental results, a step-by-step procedure for acquiring secure messenger data applicable in seizure and search scenarios was proposed. The procedure consists of an initial verification stage, a secure messenger identification and classification stage, a decryption attempt stage in environments without auto-login, a migration stage in auto-login environments, and a data acquisition termination and documentation stage. Each stage was designed to reflect differences in session storage methods and operating system authentication systems across messengers. Furthermore, the experimental results obtained in this study were incorporated into the procedure design to establish criteria for determining the presence of auto-login and selecting the session restoration method.
    This study is significant in that it verifies session migration techniques for acquiring digital evidence from desktop security messengers and presents procedures applicable during search and seizure operations. By demonstrating the practical feasibility of securing data from security messengers through session migration, it contributes to investigative practice. However, environments exist where session migration is restricted due to factors like BitLocker encryption and two-factor authentication, necessitating future research on acquiring desktop secure messengers from diverse perspectives. Future development of technology to automate the collection of conversations and media from the GUI screen after session restoration is required.
    It is hoped that this research will enhance the feasibility of accessing desktop secure messengers during future search and seizure operations and contribute to securing core data essential for proving criminal allegations.

    더보기

    국문 초록 (Abstract) kakao i 다국어 번역

    디지털 환경에서 프라이버시와 익명성에 대한 요구가 높아지면서, 종단 간 암호화 기술을 기반으로 하는 보안 메신저의 사용이 증가하고 있다. 보안 메신저는 합법적 목적 외에 마약 밀매, 불법 촬영물 유통 등 다양한 범죄 행위에 악용되고 있다. 종단 간 암호화 기술과 제조사의 비협조 정책은 범죄 수사 시 대화 내용 확보를 어렵게 만드는 요인이다.
    본 연구는 보안 메신저의 대화 내용을 복호화하지 않고, 자동 로그인된 세션을 마이그레이션하여 보안 메신저의 데이터를 획득하는 방안을 제안하였다. Windows 데스크톱용 공식 클라이언트를 제공하는 Telegram Desktop, Session, Jami, Signal, Element, WhatsApp, Wire, Zalo, Viber, AWS Wickr 총 10종의 보안 메신저를 대상으로 실험 환경을 구축하였다. 정적 분석을 통해서 각 보안 메신저의 AppData 디렉터리, 설정 파일, 데이터베이스 등을 분석하여 자동 로그인 세션의 존재 여부를 확인하였다. 자동 로그인이 설정된 환경에서 AppData 기반 마이그레이션, Windows 자격 증명 기반 접근, NTLM 해시 복원을 통한 접근, HIVE 파일 수정 기반 접근 등 네 가지 방식으로 세션 복원 가능성을 검증하였다.
    실험 결과 AppData 디렉터리만으로 세션 복원이 가능한 메신저는 3종(Telegram Desktop, Session, Jami)에 한정되었고, 대부분의 보안 메신저는 운영체제의 DPAPI 기반 암호화 구조를 사용하여 AppData 마이그레이션만으로는 세션 복원이 불가능하였다. 반면 Windows 계정 비밀번호를 제공받아 디스크 복제본을 마이그레이션한 경우 10종 모두에서 세션 복원이 가능하였고, NTLM 해시 복원 방식도 비밀번호 크랙 성공 시 동일한 결과를 보였다. HIVE 파일 수정 기반 접근은 5종(Telegram Desktop, Session, Jami, Viber, AWS Wickr)에서만 세션 복원 가능하였고, 이는 비밀번호 초기화 과정에서 새롭게 생성된 암호화 키가 기존 세션 토큰과 일치하지 않는 구조적 특성으로 확인된다.
    실험 결과를 바탕으로 압수ㆍ수색 현장에서 적용할 수 있는 단계적 보안 메신저 데이터 획득 절차를 제안하였다. 절차는 초기 확인 단계, 보안 메신저 식별 및 유형 분류 단계, 자동 로그인 미설정 환경에서의 복호화 시도 단계, 자동 로그인 환경에서의 마이그레이션 단계, 획득 종료 및 문서화 단계로 구성되며, 각 단계는 메신저별 세션 저장 방식과 운영체제 인증 체계의 차이를 반영하여 설계되었다. 또한, 본 연구에서 얻은 실험 결과를 절차 설계에 반영하여 자동 로그인 여부 판단과 세션 복원 방식 선택의 기준을 정립하였다.
    본 연구는 데스크톱용 보안 메신저의 디지털 증거를 획득하기 위한 세션 마이그레이션 기법을 검증하고, 압수수색 과정에서 적용할 수 있는 절차를 제시하였다는 점에서 의의를 가진다. 세션 마이그레이션을 통해 보안 메신저의 데이터를 확보할 수 있는 실질적 가능성을 제시했다는 점에서 수사 실무에 기여할 수 있을 것이다. 다만 BitLocker 암호화, 2단계 인증 등으로 인해 세션 마이그레이션이 제한되는 환경이 존재하므로 향후 다양한 관점에서 데스크톱용 보안 메신저 획득 연구가 필요하다. 향후 세션 복원 후 GUI 화면에서의 대화 내용과 미디어 채증을 자동화할 수 있는 기술 개발이 요구된다.
    본 연구가 향후 압수수색 현장에서 데스크톱용 보안 메신저에 대한 접근 가능성을 높이고, 범죄 혐의 입증에 필요한 핵심 데이터를 확보하는 데 기여하기를 기대한다.
    번역하기

    디지털 환경에서 프라이버시와 익명성에 대한 요구가 높아지면서, 종단 간 암호화 기술을 기반으로 하는 보안 메신저의 사용이 증가하고 있다. 보안 메신저는 합법적 목적 외에 마약 밀매, ...

    디지털 환경에서 프라이버시와 익명성에 대한 요구가 높아지면서, 종단 간 암호화 기술을 기반으로 하는 보안 메신저의 사용이 증가하고 있다. 보안 메신저는 합법적 목적 외에 마약 밀매, 불법 촬영물 유통 등 다양한 범죄 행위에 악용되고 있다. 종단 간 암호화 기술과 제조사의 비협조 정책은 범죄 수사 시 대화 내용 확보를 어렵게 만드는 요인이다.
    본 연구는 보안 메신저의 대화 내용을 복호화하지 않고, 자동 로그인된 세션을 마이그레이션하여 보안 메신저의 데이터를 획득하는 방안을 제안하였다. Windows 데스크톱용 공식 클라이언트를 제공하는 Telegram Desktop, Session, Jami, Signal, Element, WhatsApp, Wire, Zalo, Viber, AWS Wickr 총 10종의 보안 메신저를 대상으로 실험 환경을 구축하였다. 정적 분석을 통해서 각 보안 메신저의 AppData 디렉터리, 설정 파일, 데이터베이스 등을 분석하여 자동 로그인 세션의 존재 여부를 확인하였다. 자동 로그인이 설정된 환경에서 AppData 기반 마이그레이션, Windows 자격 증명 기반 접근, NTLM 해시 복원을 통한 접근, HIVE 파일 수정 기반 접근 등 네 가지 방식으로 세션 복원 가능성을 검증하였다.
    실험 결과 AppData 디렉터리만으로 세션 복원이 가능한 메신저는 3종(Telegram Desktop, Session, Jami)에 한정되었고, 대부분의 보안 메신저는 운영체제의 DPAPI 기반 암호화 구조를 사용하여 AppData 마이그레이션만으로는 세션 복원이 불가능하였다. 반면 Windows 계정 비밀번호를 제공받아 디스크 복제본을 마이그레이션한 경우 10종 모두에서 세션 복원이 가능하였고, NTLM 해시 복원 방식도 비밀번호 크랙 성공 시 동일한 결과를 보였다. HIVE 파일 수정 기반 접근은 5종(Telegram Desktop, Session, Jami, Viber, AWS Wickr)에서만 세션 복원 가능하였고, 이는 비밀번호 초기화 과정에서 새롭게 생성된 암호화 키가 기존 세션 토큰과 일치하지 않는 구조적 특성으로 확인된다.
    실험 결과를 바탕으로 압수ㆍ수색 현장에서 적용할 수 있는 단계적 보안 메신저 데이터 획득 절차를 제안하였다. 절차는 초기 확인 단계, 보안 메신저 식별 및 유형 분류 단계, 자동 로그인 미설정 환경에서의 복호화 시도 단계, 자동 로그인 환경에서의 마이그레이션 단계, 획득 종료 및 문서화 단계로 구성되며, 각 단계는 메신저별 세션 저장 방식과 운영체제 인증 체계의 차이를 반영하여 설계되었다. 또한, 본 연구에서 얻은 실험 결과를 절차 설계에 반영하여 자동 로그인 여부 판단과 세션 복원 방식 선택의 기준을 정립하였다.
    본 연구는 데스크톱용 보안 메신저의 디지털 증거를 획득하기 위한 세션 마이그레이션 기법을 검증하고, 압수수색 과정에서 적용할 수 있는 절차를 제시하였다는 점에서 의의를 가진다. 세션 마이그레이션을 통해 보안 메신저의 데이터를 확보할 수 있는 실질적 가능성을 제시했다는 점에서 수사 실무에 기여할 수 있을 것이다. 다만 BitLocker 암호화, 2단계 인증 등으로 인해 세션 마이그레이션이 제한되는 환경이 존재하므로 향후 다양한 관점에서 데스크톱용 보안 메신저 획득 연구가 필요하다. 향후 세션 복원 후 GUI 화면에서의 대화 내용과 미디어 채증을 자동화할 수 있는 기술 개발이 요구된다.
    본 연구가 향후 압수수색 현장에서 데스크톱용 보안 메신저에 대한 접근 가능성을 높이고, 범죄 혐의 입증에 필요한 핵심 데이터를 확보하는 데 기여하기를 기대한다.

    더보기

    목차 (Table of Contents)

    • 제1장 서 론 1
    • 제1절 연구 배경 및 필요성 1
    • 1. 연구 배경 1
    • 2. 연구 필요성 2
    • 제2절 연구 범위와 방법 3
    • 제1장 서 론 1
    • 제1절 연구 배경 및 필요성 1
    • 1. 연구 배경 1
    • 2. 연구 필요성 2
    • 제2절 연구 범위와 방법 3
    • 1. 연구 범위 3
    • 2. 연구 방법 3
    • 제2장 보안 메신저 포렌식 현황 및 선행 연구 5
    • 제1절 보안 메신저 포렌식 현황 5
    • 제2절 보안 메신저 포렌식 선행연구 6
    • 1. 보안 메신저 분석 연구 6
    • 2. 크리덴셜 활용 연구 9
    • 3. 마이그레이션 활용 연구 12
    • 제3장 보안 메신저의 데이터 획득 실험 14
    • 제1절 실험 설계 14
    • 1. 목적과 대상 14
    • 2. 주요 내용 15
    • 3. 환경과 도구 15
    • 4. 절차와 방법 16
    • 제2절 데스크톱용 보안 메신저의 자동 로그인 여부 판별 18
    • 1. 실험 설계 18
    • 2. 실험 결과 분석 19
    • 제3절 데스크톱용 보안 메신저의 마이그레이션 실행 30
    • 1. AppData 기반 마이그레이션 30
    • 2. 사용자 자격 증명 확보 조건 마이그레이션 33
    • 3. NTLM 해시 기반 마이그레이션 36
    • 4. HIVE 파일 수정 기반 마이그레이션 39
    • 제4절 요약 및 한계 43
    • 제4장 압수수색 현장에서 보안 메신저 데이터 획득 절차 46
    • 제1절 보안 메신저 유형 분류 46
    • 제2절 보안 메신저 단계별 압수ㆍ수색 방법 48
    • 1. 접근 가능 여부 판단 단계 48
    • 2. 보안 메신저 식별 및 유형 분류 단계 48
    • 3. 자동 로그인 미설정 환경에서의 복호화 시도 단계 49
    • 4. 자동 로그인 환경에서의 마이그레이션 단계 49
    • 5. 획득 종료 및 문서화 단계 51
    • 제3절 보안 메신저 압수ㆍ수색 절차 제안 52
    • 제5장 결론 53
    • 참 고 문 헌 56
    • ABSTRACT 59
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼