DOI QR코드

DOI QR Code

A Study on the Methods of Building Tools and Equipment for Digital Forensics Laboratory

디지털증거분석실의 도구·장비 구축 방안에 관한 연구

  • 신수민 (성균관대학교 과학수사학과) ;
  • 박현민 (성균관대학교 과학수사학과) ;
  • 김기범 (성균관대학교 과학수사학과)
  • Received : 2022.11.29
  • Accepted : 2022.12.27
  • Published : 2022.12.31

Abstract

The use of digital information according to the development of information and communication technology and the 4th industrial revolution is continuously increasing and diversifying, and in proportion to this, crimes using digital information are also increasing. However, there are few cases of establishing an environment for processing and analysis of digital evidence in Korea. The budget allocated for each organization is different and the digital forensics laboratory built without solving the chronic problem of securing space has a problem in that there is no standard that can be referenced from the initial configuration stage. Based on this awareness of the problem, this thesis conducted an exploratory study focusing on tools and equipment necessary for building a digital forensics laboratory. As a research method, focus group interviews were conducted with 15 experts with extensive practical experience in the digital forensic laboratory or digital forensics field and experts' opinions were collected on the following 9 areas: network configuration, analyst computer, personal tools·equipment, imaging devices, dedicated software, open source software, common tools/equipment, accessories, and other considerations. As a result, a list of tools and equipment for digital forensic laboratories was derived.

디지털 정보는 정보통신의 발달로 지속적으로 증가 및 다양화되는 추세이며, 이를 악용한 범죄 또한 증가하고 있다. 하지만, 국내의 디지털증거에 대한 처리 및 분석을 위한 환경 구축 사례는 미비한 실정이다. 조직마다 할당된 예산이 상이하고 고질적인 문제인 공간 확보의 어려움을 해소하지 못한 상태에서 구축된 디지털증거분석실은 초기 구성단계에서부터 참조할 수 있는 기준이 없다. 본 논문은 디지털증거분석실 구축 시에 필요한 사항을 도구·장비 중심으로 탐색적 연구를 진행하였다. 연구방법으로 디지털증거분석실 구축 경험 또는 디지털포렌식 분야 근무 경험이 풍부한 전문가 15명을 대상으로 포커스 그룹 인터뷰를 수행하였다. 그 결과 네트워크 구성, 분석관 컴퓨터, 개인 도구·장비, 이미징 장치, 전용 SW, 오픈소스 SW, 공용 도구·장비, 액세서리, 기타 고려사항의 9가지 영역에 대해 전문가들의 의견을 수렴하고 디지털증거분석실의 도구·장비 목록을 도출하였다. 나아가 디지털증거분석실 구축 발전방안으로 공간/도구·장비 목록표준화, 디지털포렌식 도구·장비 민간 지원·위탁 체계 수립, 미래 디지털증거분석실 인프라 구조를 제시하였다. 이는 향후 디지털포렌식 기능을 신설하고 디지털증거분석실을 구축하고자 하는 기관/조직이 도구·장비 및 인프라 설계 등에 기여할 것이다.

Keywords

References

  1. Korea Data Agency, 2020 Data Industry White Paper(23), pp. 8-30, 2020.12.
  2. National Police Agency, Digital Evidence Analysis Status(https://www.police.go.kr/user/bbs/BD_selectBbs.do?q_bbsCode=1025&q_bbscttSn=20210929074259890&q_tab=&q_code=&q_deta ilCode=&q_searchKeyTy=sj___1002&q_searchVal=%EB%94%94%EC%A7%80%ED%84%B8&q_rowPerPage=10&q_currPage=1&q_sortName=&q_sortOrder=&, Search date: 2022.03.14.)
  3. Byung-Min Park, Judicial Policy Research Institute, Research on Improving Search and Seizure of Digital Evidence_Focusing on Discussions of Legislative Measures, pp. 16-19, 2021.3.
  4. Yang-Sub Kwon, A Study on Korean Digital Forensic Investigation Procedure and Construct ion of Verification System, Journal of Digital Forensics 15(1), pp. 67-82, 2021.3,
  5. Jang Yoon-sik, National Police Agency, Digital Forensics Laboratory Standard Design Study, p.129, 2017.10
  6. Korea Maritime & Ocean University Industry-University Cooperation Foundation, A study on cybercrime countermeasures according to changes in the maritime environment based on advanced technology, p.139, 2021
  7. Korea Laboratory Accreditation Scheme(KOLAS) - Authorized Agency Search - Search laboratory (https://www.knab.go.kr/usr/inf/srh/InfoTestInsttSearchList.do, Search date: 2022.3.14.)
  8. ANSI National Accreditation Board(ANAB) - Directory Of Accredited Organizations - Search - Korea Copyright Protection Agency Digital Forensic Center (https://search.anab.org/?__hstc =4076783.bbcd7009c961d220b5a5fbfb857fdf74.1645512838108.1645512838108.1647222145934.2&__hssc=4076783.3.1647222145934&__hsfp=1858334220, Search date: 2022.3.14.)
  9. Lawrence, Troy, Umit Karabiyik, and Narasimh a Shashidhar. "Equipping a digital forensic lab on a budget." 2018 6th International Symposium on Digital Forensic and Security (ISDFS). IEEE, 2018.
  10. O'Connor, Rory V. "Software selection: towards an understanding of forensic software tool selection in industrial practice." International Journal of Technology, Policy and Management 5.4, pp. 311-329, 2005. https://doi.org/10.1504/IJTPM.2005.008633
  11. Hibshi, Hanan, Timothy Vidas, and Lorrie Cranor. "Usability of forensics tools: a user study." 2011 Sixth International Conference on IT Security Incident Management and IT Forensics. IEEE, 2011.
  12. Nodeland, Brooke, and Scott Belshaw. "Establishing a criminal justice cyber lab to develop and enhance professional and educational opportunities." Security and Privacy 3.5, e123, 2020.
  13. Roman, Rodrigo Fernando Morocho, et al. "Digital forensics tools." International Journal of Applied Engineering Research 11.19, pp. 9754-9762, 2016.
  14. Ghazinour, Kambiz, et al. "A study on digital forensic tools." 2017 IEEE international conference on power, control, signals and instrumentation engineering (ICPCSI). IEEE, 2017.
  15. Padmanabhan, Radhika, et al. "Comparative analysis of commercial and open source mobile device forensic tools." 2016 Ninth International Conference on Contemporary Computing (IC3). IEEE, 2016.
  16. Jiyoon Ham, Joshua I.James, "A Feature Comparison of Modern Digital Forensic Imaging software", The Journal of The Institute of Internet, Broadcasting and Communication (IIBC) Vol. 19, No. 6, pp. 15-20, Dec. 31, 2019.
  17. Donghyun Kim, Jaehyeok Han, Sangjin Lee. A study on forensic analysis for Windows search utility Everything. Journal of Digital Forensics, 14(3), pp, 279-289, 2020 https://doi.org/10.22798/KDFS.2020.14.3.279
  18. Seung-Kyu Kim, Mu-Seok Kim, Gu-Min Kang. "A Study on the Development of Mobile Forensic Tool for the Response to Hidden Camera Crime." Journal of Digital Forensics, 14(3), pp. 290-304, 2020 https://doi.org/10.22798/KDFS.2020.14.3.290
  19. Kim, Min-Seo, and Sang-jin Lee. "Development of Windows forensic tool for verifying a set of data." Journal of the Korea Institute of Information Security & Cryptology 25.6, pp. 1421-1433, 2015 https://doi.org/10.13089/JKIISC.2015.25.6.1421
  20. Morgan, D. L., "The focus group guidebook: focus group kit 1". Thousand Oaks, CA: Sage, 1998.
  21. DAVID L. MORGAN(Transferred to the Korean Society of Qualitative Research Nursing), Focus groups as qualitative research, Gunja Publishing House, p.42, 2007.
  22. Supreme Prosecutor's Office Scientific Investigation Division, Law and Science: December issue, pp 50-56, 2021.12