Internet of Things(IoT) 환경에서 Digital Forensic에 위한 많은 연구가 이루어지고 있으며, 실제 IoT 장치 분석 사례 및 범죄 사건에 IoT 장치의 데이터를 이용한 사례들이 발생하고 있다. 하지만 IoT 기...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T15470063
춘천 : 한림대학교 대학원, 2019
학위논문(석사) -- 한림대학교 대학원 , 국제학과 Legal Informatics and Forensic Science , 2019. 8
2019
영어
강원특별자치도
83 ; 26 cm
지도교수: Joshua I. James, 장윤식
I804:42014-200000222397
0
상세조회0
다운로드Internet of Things(IoT) 환경에서 Digital Forensic에 위한 많은 연구가 이루어지고 있으며, 실제 IoT 장치 분석 사례 및 범죄 사건에 IoT 장치의 데이터를 이용한 사례들이 발생하고 있다. 하지만 IoT 기...
Internet of Things(IoT) 환경에서 Digital Forensic에 위한 많은 연구가 이루어지고 있으며, 실제 IoT 장치 분석 사례 및 범죄 사건에 IoT 장치의 데이터를 이용한 사례들이 발생하고 있다. 하지만 IoT 기반의 인프라에서 Digital forensic investigation을 수행하는데 수사관들이 쓸 수 있는 실용적이고 포괄적인 절차는 완성되지 않았으며, IoT 환경에서 데이터를 획득, 분석하여 증거로서 채택하는 것은 법원과 Digital forensic 수사관에게는 아직까지 도전 과제이다. 본 논문은 IoT 장치를 분석한 경험과 IoT 분석 사례 연구를 기반으로 IoT Data Acquisition 절차를 제안하고, 실제 IoT 장치(인공지능스피커)를 이용한 실험을 통해 제시된 절차를 검증하였다. 실험은 IoT 장치마다 Cloud, Network, Client(PC, Mobile), Device 측으로 나누어 Data Acquisition이 수행되었으며, 실험 목적은 IoT 장치를 이용하여 제시된 절차를 따라 Data Acquisition 수행하여 데이터 획득가능 여부와 얼마나 많은 데이터를 획득할 수 있는지 확인한다. 실험결과는 각 측면마다 데이터를 추출이 가능하였으며, 데이터 습득은 관련된 장치들과 가능한한 함께 수행되어져야 함을 나타냈다. 그 이유는 첫째, 각 측면마다 얻을 수 있는 데이터가 다를 수 있기 때문이다. 예를 들어, 클라우드에는 저장되어 있지 않은 데이터가 장치에 저장되어 있을 수 있다. 둘째, 클라우드 데이터에 접근가능한 자격증명정보는 클라우드 측과 디바이스 측에서 모두 얻을 수 있었다. 이것은 만약 클라이언트 측의 데이터 획득이 불가 할 때는 디바이스에서 얻을 수 있음을 나타냈다. 이러한 테스트 결과를 통하여 본 논문은 IoT 수사 절차도 함께 제시한다. IoT 생태계의 모든 측면에서 데이터 획득을 진행하기 위해서는 클라이언트 측에서 얻은 데이터를 분석할 필요가 있으며, 획득과 분석을 하면서 장치구성정보, 연결된 장치와 같은 정보를 얻을 수 있다. 이처럼 연결된 다른 IoT 장치의 정보를 확인함으로써, IoT 수사는 다시 식별 단계를 거쳐야 할 수 있다. 제시된 절차는 IoT 장치를 조사하기 위해 어디서부터 시작하고, 다음단계는 무엇인지 가이드라인의 역할을 할 것이다. 또한 디지털 포렌식 분야의 수사관과 연구자에게 데이터 획득 프로세스를 용이하게 하며, 데이터 획득 도구를 개발하는 데 기여할 수 있다.
다국어 초록 (Multilingual Abstract)
There are previous studies about digital forensics in terms of the Internet of Things (IoT) environment, and cases using IoT device data for crime investigations. However, the acquisition and analysis of data in the IoT environment are still a challen...
There are previous studies about digital forensics in terms of the Internet of Things (IoT) environment, and cases using IoT device data for crime investigations. However, the acquisition and analysis of data in the IoT environment are still a challenge for digital forensic investigators. In addition, there are no accepted practical and comprehensive digital forensic procedures for investigators and law enforcement agencies to perform digital forensic investigations on IoT-based environments.
This work proposes a new model for IoT Forensic specifically for the Data Acquisition procedure from the IoT ecosystem. The model is tested using experiments conducted on IoT devices. The experiment includes the research aspect of investigating the actual IoT devices in order to provide a complete picture of the model. The experiment was divided into Cloud, Network, Client (PC, Mobile) and Device/hub side for each IoT device.
The results from the experiments showed that data can be extracted from each category of cloud, network, client, and device, and that the data should be collected as soon as possible with the related devices and collected as much as possible. This is because the data available in the device and in the specified categories can vary depending on the storage and processing capabilities. For example, the device side may have data that the cloud side does not have. The data can be key evidence for a crime scene. And the cloud side includes the more complete update and historical data, while the client and device side include cache data that may be incomplete, outdated, or partially overwritten.
Through these test results, this paper also presents the IoT investigation procedure. In order to proceed with data collection from all aspects of IoT ecosystem, it is necessary to analyze data obtained from the client side. Information such as device configuration information and connected devices can be obtained by acquiring and analyzing them. By checking the information of the other connected IoT devices, the investigation can go through the identification step again. The proposed procedure will serve as a guideline from where to start to investigate IoT devices and what the next step is. It will also facilitate investigators and researchers in the digital forensics field to facilitate the data acquisition process and develop data collection tools. This procedure should be tested and verified against a variety of IoT devices until a comprehensive procedure for IoT data acquisition.
목차 (Table of Contents)