ABOUT ME

-

Today
-
Yesterday
-
Total
-
  • ๋””์ง€ํ„ธ ํฌ๋ Œ์‹์ด๋ž€? :: ๋„คํŠธ์›Œํฌ ํฌ๋ Œ์‹, ๋ชจ๋ฐ”์ผ ํฌ๋ Œ์‹, ๋””์Šคํฌ ํฌ๋ Œ์‹
    SECURITY/FORENSICS 2020. 10. 25. 20:10

    0. ๋””์ง€ํ„ธ ํฌ๋ Œ์‹์ด๋ž€? (Digital Forensic)

     

    : ๋””์ง€ํ„ธ ๊ธฐ๊ธฐ ๋˜๋Š” ์ธํ„ฐ๋„ท ์ƒ์— ๋‚จ์•„ ์žˆ๋Š” ๊ฐ์ข… ๋””์ง€ํ„ธ ์ •๋ณด๋ฅผ ๋ถ„์„ํ•ด ๋ฒ”์ฃ„ ๋‹จ์„œ๋ฅผ ์ฐพ๋Š” ์ˆ˜์‚ฌ ๊ธฐ๋ฒ•

     

    ์ปดํ“จํ„ฐ์™€ ์ธํ„ฐ๋„ท์„ ํ†ตํ•œ ์ •๋ณด์˜ ํ๋ฆ„์„ ์กฐ์‚ฌํ•˜๊ณ  ๋ฒ”์ฃ„ ์‚ฌ์‹ค์— ๋Œ€ํ•œ ์ฆ๊ฑฐ๋ฅผ ํ™•๋ณดํ•˜๋Š” ๊ธฐ์ˆ ์„ ๋งํ•œ๋‹ค.

     

    ํฌ๊ฒŒ ์ฆ๊ฑฐ ์ˆ˜์ง‘, ์ฆ๊ฑฐ ๋ถ„์„, ์ฆ๊ฑฐ ์ œ์ถœ๊ณผ ๊ฐ™์€ ์ ˆ์ฐจ๋กœ ๊ตฌ๋ถ„๋œ๋‹ค.

     

    - ์ฆ๊ฑฐ ์ˆ˜์ง‘: ๋””์ง€ํ„ธ ์ €์žฅ ๋งค์ฒด์— ์žˆ๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ์ทจํ•ฉํ•˜๋Š” ๊ณผ์ •.

      ์›๋ณธ ๋ฐ์ดํ„ฐ์˜ ๋ฌด๊ฒฐ์„ฑ์„ ๋ณด์žฅํ•˜๋Š” ์ด๋ฏธ์ง• ๊ธฐ์ˆ  ๋“ฑ์„ ์‚ฌ์šฉํ•œ๋‹ค.

    - ์ฆ๊ฑฐ ๋ถ„์„: ์ˆ˜์‚ฌ์— ํ•„์š”ํ•œ ์œ ์šฉํ•œ ์ •๋ณด๋ฅผ ๋ฐ์ดํ„ฐ ์†์—์„œ ๋Œ์–ด๋‚ด๊ธฐ ์œ„ํ•ด ๋ถ„์„ํ•˜๋Š” ๊ฐ€์ •.

      ์ผ๋ถ€ ๋ฐ์ดํ„ฐ๊ฐ€ ์ˆจ๊ฒจ์ ธ ์žˆ์„ ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ ์‚ญ์ œ๋œ ํŒŒ์ผ์„ ๋ณต๊ตฌํ•˜๊ฑฐ๋‚˜ ์•”ํ˜ธํ™”๋œ ํŒŒ์ผ์„ ํ•ด๋…ํ•˜๋Š” ๊ธฐ์ˆ  ๋“ฑ์„ ์‚ฌ์šฉํ•œ๋‹ค.

    - ์ฆ๊ฑฐ ์ œ์ถœ: ์ฆ๊ฑฐ ์ž๋ฃŒ์˜ ์‹ ๋ขฐ์„ฑ์„ ํ™•๋ณดํ•˜๊ณ  ๋ฒ•์ • ์ฆ๊ฑฐ๋กœ ์ฑ„ํƒ๋˜๊ธฐ ์œ„ํ•ด ์ œ์ถœ.

      ๋””์ง€ํ„ธ ํฌ๋ Œ์‹์— ๋Œ€ํ•œ ํ‘œ์ค€ ์ ˆ์ฐจ๋ฟ ์•„๋‹ˆ๋ผ ์ฆ๊ฑฐ ์ˆ˜์ง‘ ๋ฐ ๋ถ„์„์— ์‚ฌ์šฉ๋œ ํฌ๋ Œ์‹ ํˆด์— ๋Œ€ํ•œ ๊ฒ€์ฆ ์ ˆ์ฐจ๋„ ์ด๋ค„์ง„๋‹ค.

     

    ๋˜, ๋””์ง€ํ„ธ ํฌ๋ Œ์‹์€ ๋„คํŠธ์›Œํฌ ํฌ๋ Œ์‹, ๋ชจ๋ฐ”์ผ ํฌ๋ Œ์‹, ๋””์Šคํฌ ํฌ๋ Œ์‹์œผ๋กœ ๋‚˜๋ˆŒ ์ˆ˜ ์žˆ๋‹ค.

     

    ๊ฐ ๋ถ„์•ผ๊ฐ€ ๋ฌด์—‡์„ ์กฐ์‚ฌํ•˜๋Š”์ง€์™€ ์–ด๋–ค ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•˜๋Š”์ง€ ์•Œ์•„๋ณด์ž.

     

    1. ๋„คํŠธ์›Œํฌ ํฌ๋ Œ์‹

    : ๋„คํŠธ์›Œํฌ ๊ธฐ๋ฐ˜์œผ๋กœ ์ƒ๊ฒจ๋‚œ ๋ฐ์ดํ„ฐ ๋ถ„์„ ๊ธฐ๋ฒ•.

    ๋„คํŠธ์›Œํฌ๋ฅผ ํ†ตํ•ด ์ „์†ก๋˜๋Š” ๋ฐ์ดํ„ฐ, ํŒจ์Šค์›Œ๋“œ, ์ ‘์† ๊ธฐ๋ก ๋“ฑ ๋ฐ์ดํ„ฐ ํ”„๋ž˜ํ”ฝ ๋ถ„์„, ๋„คํŠธ์›Œํฌ ํ™˜๊ฒฝ ์กฐ์‚ฌ ๋“ฑ์„ ์ˆ˜ํ–‰ํ•œ๋‹ค.

     

    ๋„คํŠธ์›Œํฌ ๋ฐ์ดํ„ฐ๋“ค(ํŒจํ‚ท, ๋กœ๊ทธ ๋“ฑ)์€ ํœ˜๋ฐœ์„ฑ์ด ๊ฐ•ํ•˜์—ฌ ์ฆ๊ฑฐ๋ฅผ ์ˆ˜์ง‘ํ•˜๊ณ  ์ธ์ •๋ฐ›๋Š” ๊ฒŒ ์–ด๋ ต๊ณ , ๋งŽ์€ ๋ฐ์ดํ„ฐ ์–‘์œผ๋กœ ์ธํ•ด ๋ถ„์„ํ•˜๊ณ  ์ฆ๊ฑฐ๋กœ์„œ์˜ ๊ฐ€์น˜๋ฅผ ๋งŒ๋“ค์–ด ๋‚ด๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•˜๋‹ค.

     

     

    ์‚ฌ์šฉ ๋„๊ตฌ๋กœ๋Š” CapTipper, Network Miner, Wireshark ๋“ฑ์ด ์žˆ๋‹ค.

     

    1.1 CapTipper

    : Python ๊ธฐ๋ฐ˜์˜ ์•…์„ฑ ํŠธ๋ž˜ํ”ฝ ๋ถ„์„ ๋„๊ตฌ

    ํŠธ๋ž˜ํ”ฝ ๋‚ด์—์„œ ํŒŒ์ผ์„ ์ถ”์ถœํ•˜๊ณ , ํ๋ฆ„ ๋ถ„์„์„ ํ•  ์ˆ˜ ์žˆ๋‹ค.

     

    ๊ฐ€์ƒ ์„œ๋ฒ„๋ฅผ ํ†ตํ•œ ์‹œ๋ฎฌ๋ ˆ์ด์…˜ ๊ธฐ๋Šฅ์„ ์ง€์›ํ•ด์„œ, ๋ถ„์„ํ•˜๊ณ ์ž ํ•˜๋Š” pcap ํŒŒ์ผ์„ ๋กœ๋“œํ•˜๋ฉด ๋กœ์ปฌ ํ˜ธ์ŠคํŠธ ์ƒ์˜ ๊ฐ€์ƒ ์„œ๋ฒ„๊ฐ€ ๊ตฌ๋™๋˜๋ฉด์„œ ์‹ค์ œ ํŠธ๋ž˜ํ”ฝ์ด ์˜ค๊ณ  ๊ฐ”๋˜ ํ™”๋ฉด์„ ๊ทธ๋Œ€๋กœ ์žฌ์—ฐํ•  ์ˆ˜ ์žˆ๋‹ค.

    ๋˜ํ•œ, ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ ๋‚ด ํฌํ•จ๋œ iframe ์ฝ”๋“œ๋ฅผ ์ž๋™์œผ๋กœ ์ฐพ์•„์ฃผ๊ฑฐ๋‚˜, ๋ฐ”์ด๋Ÿฌ์Šค ํ† ํƒˆ API ๋ฅผ ํ†ตํ•ด ์ž๋™์œผ๋กœ ๋ถ„์„ ๊ฒฐ๊ณผ๋ฅผ ์—…๋กœ๋“œ/์กฐํšŒํ•  ์ˆ˜๋„ ์žˆ๋‹ค.

     

    1.2 Network Miner, Wireshark 

    : ํŒจํ‚ท ๋ถ„์„ ๋„๊ตฌ

    ์ฐธ์กฐ-> 2020/09/17 - [SECURITY/FORENSICS] - FORENSICS ์‹œ์ž‘ํ•˜๊ธฐ - ํŒจํ‚ท ๋ถ„์„ ๋„๊ตฌ :: Wireshark, NetworkMiner

    .

     

     

    2. ๋ชจ๋ฐ”์ผ ํฌ๋ Œ์‹

    : ๋ชจ๋ฐ”์ผ ์žฅ์น˜์˜ ๋””์ง€ํ„ธ ์ฆ๊ฑฐ๋‚˜ ๋ฐ์ดํ„ฐ ๋ถ„์„ ๊ธฐ๋ฒ•.

     

    ์‚ฌ์šฉ ๋„๊ตฌ๋กœ๋Š” GMD, MD-Smart(GMD systems ์—์„œ ์ œ์ž‘ํ•œ ์†Œํ”„ํŠธ์›จ์–ด), Cellebrite, XRY, MPE(Mobile Phone Examiner), Digital FACT, Final Mobile ๋“ฑ์ด ์žˆ๋‹ค.

     

    ์ฐธ๊ณ -> forensic.korea.ac.kr/DFWIKI/index.php/%EC%8A%A4%EB%A7%88%ED%8A%B8%ED%8F%B0_%ED%8F%AC%EB%A0%8C%EC%8B%9D_%EB%8F%84%EA%B5%AC

     

     

    3. ๋””์Šคํฌ ํฌ๋ Œ์‹

    : ๋ฌผ๋ฆฌ์ ์ธ ์ €์žฅ์žฅ์น˜์ธ ํ•˜๋“œ๋””์Šคํฌ, ํ”Œ๋กœํ”ผ๋””์Šคํฌ, CD-ROM ๋“ฑ ๊ฐ์ข… ๋ณด์กฐ ์žฅ์น˜์˜ ๋ฐ์ดํ„ฐ๋ฅผ ๋ถ„์„ํ•˜๋Š” ๊ธฐ๋ฒ•.

     

    ์‚ฌ์šฉ ๋„๊ตฌ๋กœ๋Š” ํ•˜๋“œ ๋“œ๋ผ์ด๋ธŒ์˜ ๋ฐ์ดํ„ฐ๋ฅผ ๋ณต๊ตฌํ•˜๋ ค๊ณ  ๊ณ ์•ˆ๋œ Data Compass, (์†Œํ”„ํŠธ์›จ์–ด ์ฐจ์›์—์„œ์˜ ์ด๋ฏธ์ง•์„ ์ˆ˜ํ–‰ํ•˜๋Š”) FTK Imager ๋“ฑ์ด ์žˆ๋‹ค.

     

    Ref.

    [1] terms.naver.com/entry.nhn?docId=3432471&cid=58445&categoryId=58445

     

    .

    ๋Œ“๊ธ€

Designed by Tistory.