RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    로그분석과 포렌식 모델 적용을 통한 리눅스 시스템 포렌식스 기법에 관한 연구 = (A) study on the forensics techniques of linux system applying log analysis and forensic model

    한글로보기

    https://www.riss.kr/link?id=T10303071

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수
    인용문이 복사되었습니다.

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    컴퓨터범죄는 해마다 증가되고 있다. CERT/CC는 2003년에 135,000 건의 침해사고가 발생하였고 2004년과 2005년에 더욱 증가하고 있음을 알려주고 있다. 이로 인해, 컴퓨터범죄를 발견하기 위한 포렌식 기술과 도구의 요구가 갈수록 높아지고 있다.$$a$$a불법적인 시스템의 침입이 있을 경우, 침입 증거를 찾고 불법 침입자를 수사/검거 하기 위해서는 먼저 침입 흔적을 찾아야 한다. 이는 비단 컴퓨터 범죄 뿐만 아니라, 일반 범죄 수사에서도 적용되는 원리이다. 컴퓨터는 인간에 의해서 움직이는 기계에 불과하므로, 사용하는 방법과 요령에 따라서, 일반 범죄보다 쉽게 흔적이 기록될 수 있으며, 수사에 쉽게 이용할 수도 있다.$$a$$a컴퓨터 운영체제와 응용 프로그램에 관계없이, 침입흔적은 로그라는 형태로 시스템에 남게 되고, 이 로그를 바탕으로 침입흔적의 조사 및 증거를 확보할 수 있다. 웹 사이트 방문, 로그인 기록, 인터넷 접속 등에 대한 로그기록이 남아있을 경우 불법침입자에 대한 추적은 비교적 쉽게 진행될 수 있다.$$a$$a그러나, 한편으로 컴퓨터 포렌식을 전문가의 직관적인 능력에만 의존하여 비공식적인 절차로 수행되는 것이 현재 대부분의 컴퓨터범죄의 수사 방식에 해당되지만, 이로 인해 수사의 효율성과 신뢰성에 금이 가는 것 또한 사실이다. 보다 공식화된 모델을 통해 포렌식 절차를 구축하고 이를 통해 컴퓨터범죄의 수사를 진행하는 것이 컴퓨터 포렌식 분야의 발전을 위해 필요하다.$$a$$a컴퓨터 포렌식은 '법정에서 수용되는 방식으로 디지털 증거를 식별하고, 보존하고, 분석하고, 제시하는 프로세스'로 정의 된다. 간혹, 포렌식 컴퓨팅, 디지털 포렌식, 네트워크 포렌식 등으로 불려지나, 공통의 목적은 법적 요구사항을 만족하는 방식으로 증거를 보존하는 것이다. 그러므로, 절차가 엄격하게 정의되고 정확함을 보장하는 것은 중요하다.$$a$$a본 논문은 로그분석의 다양한 기법을 상세하게 정의하고, 이를 공식적인 포렌식 모델을 적용하여 체계적인 방법으로 컴퓨터 범죄 수사를 진행하는데 일조를 하고자 작성되었다. 본 논문을 통하여, 갈수록 광범위해지는 컴퓨터 범죄에 맞서 다양한 컴퓨터 시스템을 수사하는 수사관들에게 도움이 되었으면 한다.$$a$$a
    번역하기

    컴퓨터범죄는 해마다 증가되고 있다. CERT/CC는 2003년에 135,000 건의 침해사고가 발생하였고 2004년과 2005년에 더욱 증가하고 있음을 알려주고 있다. 이로 인해, 컴퓨터범죄를 발견하기 위한 포...

    컴퓨터범죄는 해마다 증가되고 있다. CERT/CC는 2003년에 135,000 건의 침해사고가 발생하였고 2004년과 2005년에 더욱 증가하고 있음을 알려주고 있다. 이로 인해, 컴퓨터범죄를 발견하기 위한 포렌식 기술과 도구의 요구가 갈수록 높아지고 있다.$$a$$a불법적인 시스템의 침입이 있을 경우, 침입 증거를 찾고 불법 침입자를 수사/검거 하기 위해서는 먼저 침입 흔적을 찾아야 한다. 이는 비단 컴퓨터 범죄 뿐만 아니라, 일반 범죄 수사에서도 적용되는 원리이다. 컴퓨터는 인간에 의해서 움직이는 기계에 불과하므로, 사용하는 방법과 요령에 따라서, 일반 범죄보다 쉽게 흔적이 기록될 수 있으며, 수사에 쉽게 이용할 수도 있다.$$a$$a컴퓨터 운영체제와 응용 프로그램에 관계없이, 침입흔적은 로그라는 형태로 시스템에 남게 되고, 이 로그를 바탕으로 침입흔적의 조사 및 증거를 확보할 수 있다. 웹 사이트 방문, 로그인 기록, 인터넷 접속 등에 대한 로그기록이 남아있을 경우 불법침입자에 대한 추적은 비교적 쉽게 진행될 수 있다.$$a$$a그러나, 한편으로 컴퓨터 포렌식을 전문가의 직관적인 능력에만 의존하여 비공식적인 절차로 수행되는 것이 현재 대부분의 컴퓨터범죄의 수사 방식에 해당되지만, 이로 인해 수사의 효율성과 신뢰성에 금이 가는 것 또한 사실이다. 보다 공식화된 모델을 통해 포렌식 절차를 구축하고 이를 통해 컴퓨터범죄의 수사를 진행하는 것이 컴퓨터 포렌식 분야의 발전을 위해 필요하다.$$a$$a컴퓨터 포렌식은 '법정에서 수용되는 방식으로 디지털 증거를 식별하고, 보존하고, 분석하고, 제시하는 프로세스'로 정의 된다. 간혹, 포렌식 컴퓨팅, 디지털 포렌식, 네트워크 포렌식 등으로 불려지나, 공통의 목적은 법적 요구사항을 만족하는 방식으로 증거를 보존하는 것이다. 그러므로, 절차가 엄격하게 정의되고 정확함을 보장하는 것은 중요하다.$$a$$a본 논문은 로그분석의 다양한 기법을 상세하게 정의하고, 이를 공식적인 포렌식 모델을 적용하여 체계적인 방법으로 컴퓨터 범죄 수사를 진행하는데 일조를 하고자 작성되었다. 본 논문을 통하여, 갈수록 광범위해지는 컴퓨터 범죄에 맞서 다양한 컴퓨터 시스템을 수사하는 수사관들에게 도움이 되었으면 한다.$$a$$a

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    Computer crimes increases every year. CERT/CC was infiltrated 135,000 times in 2003, and such illegal infiltrations increased in 2004 and 2005. Thus, forensics technology and tools are more and more required to identify computer crimes.$$a$$aIt is necessary above all to find a clue to infiltration in order to investigate and arrest the illegal infiltrator into a computer system. This is a principle applied to ordinary criminal investigators as well as computer crimes. Since the computer is a mere machine operated by human beings, traces of computer crimes may be more easily recorded to be useful clues to investigation, depending on methods or paths of using the computer.$$a$$aTraces of infiltration into a computer remain as a form of log in the system, regardless of its operating systems or application programs, and therefore, it may be possible to investigate traces of infiltrations or find their evidences based on such logs. In case a record of log remains for website visit, login or internet access, it will be relatively easy to trace the illegal infiltrator.$$a$$aOn the other hand, the current practice of computer crime investigations depends informally and wholly on computer forensic experts''s intuitive ability, and therefore, computer crime investigations may be neither efficient nor reliable, indeed. So, it is essential to construct a forensic procedure using a formal model for efficient and reliable computer crime investigations as well as development of forensic technology.$$a$$aComputer forensic is defined as 'a process of identifying, preserving, analyzing and presenting a digital evidence acceptable to the court'. Sporadically, it is called forensic computing, digital forensic or network forensic, but the common goal of these terms is to preserve the evidences in a way meeting the legal requirements. Hence, it is important to determine the procedure strictly and ensure it precisely.$$a$$aThis study was motivated by the intention to define diverse techniques of log analysis in details and thereby, apply them to the formal forensic model to be conducive to computer crime investigations. Lastly, it is hoped that this study will be useful to computer crime investigators who should face ever-diversifying computer crimes.$$a$$a
    번역하기

    Computer crimes increases every year. CERT/CC was infiltrated 135,000 times in 2003, and such illegal infiltrations increased in 2004 and 2005. Thus, forensics technology and tools are more and more required to identify computer crimes.$$a$$aIt is nec...

    Computer crimes increases every year. CERT/CC was infiltrated 135,000 times in 2003, and such illegal infiltrations increased in 2004 and 2005. Thus, forensics technology and tools are more and more required to identify computer crimes.$$a$$aIt is necessary above all to find a clue to infiltration in order to investigate and arrest the illegal infiltrator into a computer system. This is a principle applied to ordinary criminal investigators as well as computer crimes. Since the computer is a mere machine operated by human beings, traces of computer crimes may be more easily recorded to be useful clues to investigation, depending on methods or paths of using the computer.$$a$$aTraces of infiltration into a computer remain as a form of log in the system, regardless of its operating systems or application programs, and therefore, it may be possible to investigate traces of infiltrations or find their evidences based on such logs. In case a record of log remains for website visit, login or internet access, it will be relatively easy to trace the illegal infiltrator.$$a$$aOn the other hand, the current practice of computer crime investigations depends informally and wholly on computer forensic experts''s intuitive ability, and therefore, computer crime investigations may be neither efficient nor reliable, indeed. So, it is essential to construct a forensic procedure using a formal model for efficient and reliable computer crime investigations as well as development of forensic technology.$$a$$aComputer forensic is defined as 'a process of identifying, preserving, analyzing and presenting a digital evidence acceptable to the court'. Sporadically, it is called forensic computing, digital forensic or network forensic, but the common goal of these terms is to preserve the evidences in a way meeting the legal requirements. Hence, it is important to determine the procedure strictly and ensure it precisely.$$a$$aThis study was motivated by the intention to define diverse techniques of log analysis in details and thereby, apply them to the formal forensic model to be conducive to computer crime investigations. Lastly, it is hoped that this study will be useful to computer crime investigators who should face ever-diversifying computer crimes.$$a$$a

    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼