애스크로AIPublic Preview
← 학술논문 검색
학술논문과학기술법연구2019.11 발행KCI 피인용 1

증거수집 방식으로서 작동중인 정보시스템에서의 포렌식 절차의 검토

A Review of live Forensic Procedures in Information Systems Operating as Evidence Gathering

김종호(호서대학교)

25권 4호, 37~86쪽

초록

지금까지 작동중인 정보시스템에서의 포렌식은 사고 대응의 수법의 1개로 알려졌지만 실제로는 조사 담당자의 역량 부족 및 유효성의 인식부족 등의 이유로 많이 활용되지 않았다. 하지만 현재는 사이버 범죄가 빈발하기 때문에 작동중인 정보시스템에서의 포렌식은 피해 단말기에 대한 사고 대응에서 뿐만 아니라, 공격자 단말기에 대한 해석에서도 빠뜨릴 수 없는 기술이다. 그러므로 현장의 요구에 대응하기 위해서 작동중인 정보시스템에서의 포렌식의 유효성을 명확히 이해한 후에 그 구체적 실시 기법을 체계적으로 정리하고 그것을 업무처리 지침으로 제정할 필요성이 요구되고 있다. 빅 데이터에 대응한 디지털 포렌식이 주목받고 있으며, 대량의 데이터를 효율적으로 해석하기 위한 연구가 진행되고 있다. 또, 인공지능을 바탕으로 한 기계학습 기술에 의한 자동분석 툴의 연구가 이루어지고 있으며 상용도구로서 제품화도 이루어지고 있다. 기존 디지털 포렌식에서는 현장에서의 해석을 피하고, 일단 보전작업자가 현장에서 증거품인 단말기를 가져간 뒤 분석센터에서 고도의 스킬을 가진 조사담당자가 시간을 들여 해석을 해왔다. 그러나 이러한 종래의 기법에서는 조사를 원활하게 진행할 수 없기 때문에 현장에서 할 수 있는 것은 가능한 현장에서 처리한다는 새로운 포렌식의 기법이 필요하게 되었다. 그래서 본 연구에서는 최근 유력한 해석기법으로 주목 받고 있는 실시간 대응이나 메모리 포렌식 기술에 주목하고 작동중인 정보시스템이나 단말기에 대한 실시간 포렌식을 실시할 경우 그 유효성을 검토한 뒤, 작동중인 정보시스템에서의 포렌식의 기법을 체계적으로 정비하고 구체적 실시 기법을 제안함을 목적으로 한다. 본 연구의 결론으로 조사담당자는 적극적으로 작동중인 정보시스템에서의 포렌식을 실시해야 한다. 본 연구에서는 실시간 대응이나 메모리 포렌식의 기술에 주목하고 작동상태 포렌식의 유효성 검토 및 구체적 실시기법의 제안을 했다. 향후의 과제로서는 새로 개발되는 도구나 법률 개정 등의 상황변화에 대해서 조사담당자가 뒤처짐이 없이 대응해야 할 점을 지적할 수 있다.

Abstract

Until now, live forensics has been known as one of the ways of responding to accidents, but in practice it has been rarely implemented due to lack of skill of investigators and lack of awareness of effectiveness. However, due to the high frequency of cyber crime, live forensics is an indispensable technique not only for responding to accidental terminals but also for interpreting attacker terminals. Therefore, in order to respond to the needs of the field, it is necessary to clearly understand the effectiveness of live forensics, and then systematically organize the specific implementation techniques and establish them as guidelines. Digital forensics corresponding to big data is attracting attention, and researches for efficiently analyzing large amounts of data are being conducted. In addition, research on automatic analysis tools based on machine learning technology based on artificial intelligence is being conducted, and commercialization is being made as a commercial tool. In the existing digital forensics, the analysis is avoided in the field, and once the maintenance worker takes the terminal as evidence in the field, the investigator with high skill in the analysis center spends time analyzing it. However, such a conventional method cannot be conducted smoothly, so a new forensic method that requires what can be done on site is required. Therefore, this study focuses on the technology of live response or memory forensics, which is attracting attention as a most promising interpretation technique, and examines the validity of live forensics for mobile terminals. The purpose of this study is to systematically improve the live forensic technique and to propose a concrete implementation technique. As a conclusion of this study, investigators should actively conduct live forensics. In this study, I focused on the technology of live response and memory forensics, and examined the validity of live forensics and suggested concrete implementation methods. As a future task, it is possible to point out that the investigators should respond to changes in the situation such as newly developed tools or legal amendments without delay.

발행기관:
과학기술법연구원
DOI:
http://dx.doi.org/10.32430/ilst.2019.25.4.37
분류:
기타법학

AI 법률 상담

이 논문의 주제에 대해 더 알고 싶으신가요?

460만+ 법률 자료에서 관련 판례·법령·해석례를 찾아 답변합니다

AI 상담 시작