메뉴 건너뛰기
.. 내서재 .. 알림
소속 기관/학교 인증
인증하면 논문, 학술자료 등을  무료로 열람할 수 있어요.
한국대학교, 누리자동차, 시립도서관 등 나의 기관을 확인해보세요
(국내 대학 90% 이상 구독 중)
로그인 회원가입 고객센터 ENG
주제분류

추천
검색

논문 기본 정보

자료유형
학위논문
저자정보

이민병 (고려대학교, 고려대학교 정보보호대학원)

지도교수
이상진
발행연도
2020
저작권
고려대학교 논문은 저작권에 의해 보호받습니다.

이용수6

표지
AI에게 요청하기
추천
검색

이 논문의 연구 히스토리 (2)

초록· 키워드

오류제보하기
파일의 시간정보는 파일시스템과 응용 프로그램, 사용자의 사용행위에 따라 다양하게 나타날 수 있기 때문에, 시간정보를 분석하면 사용자의 행위를 추적할 수 있는 단서가 될 수 있다. 특히 압수수색 과정에서 클라우드 스토리지 서비스와 동기화된 디지털 증거를 발견하였을 경우, 클라우드 서비스가 제공하는 동기화 기능으로 인해 디지털 포렌식 조사자는 사용자의 행위가 해당 기기에서 발생하였는지, 또는 외부기기에서 발생하여 동기화된 것인지 고려해야 한다. 본 논문에서는 대표적인 동기화 클라우드 서비스인 Google Drive, iCloud Drive, One Drive, Dropbox, Naver Cloud에 대한 디지털 포렌식 조사 시 로컬에서 발견된 클라우드 스토리지 파일의 시간정보를 분석하여 사용자의 클라우드 스토리지 사용행위를 추적한다.

목차

제 1 장 서 론 ·········································································· 1
제 2 장 관련 연구 및 배경지식 ·············································· 2
2.1. 관련 연구 ···························································································· 3
2.2. 배경지식 ······························································································ 4
2.2.1. NTFS ··························································································· 4
2.2.1.1. MFT Entry ········································································· 5
2.2.1.2. 속성 ······················································································· 6
2.2.2. 시간정보 분석 ············································································ 7
2.2.2.1. NTFS의 시간정보 ······························································ 8
2.2.2.2. FAT의 시간정보 ·································································· 9
2.2.3. 웹 스토리지 서비스 ································································ 10
2.2.3.1. 클라우드 스토리지 ·························································· 10
2.2.3.2. 클라우드 시그니처(Cloud Signature) ·························· 11
제 3 장 클라우드 스토리지 사용 행위정보 획득 ············ 13
3.1. 클라우드 서비스 제공자로부터 획득 ········································· 13
3.2. 계정접속을 통한 획득 ··································································· 14
3.3. 클라우드 시그니처(Cloud Signature) ······································· 15
3.3.1. 웹 브라우저 아티팩트 ···························································· 15
3.3.2. 클라우드 클라이언트 로그파일 ············································ 15
3.3.2.1. 구글 드라이브(Google Drive) ····································· 16
3.3.2.2. 아이 클라우드(iCloud) ··················································· 17- iii -
3.3.2.3. 드롭박스(Dropbox) ··························································· 18
3.3.2.4. 원 드라이브(One Drive) ··············································· 19
3.3.2.5. 네이버 클라우드(Naver Cloud) ··································· 20
3.3.3. 클라우드 클라이언트 로그파일 ············································ 21
3.4. 파일의 시간정보 ············································································· 22
제 4 장 클라우드 서비스별 시간정보 변화 ······················ 23
4.1. 실험 환경 및 방법 ········································································· 23
4.2. 사용행위에 따른 시간정보 변화 ················································· 25
4.2.1. 구글 드라이브(Google Drive) ············································· 26
4.2.2. 아이 클라우드(iCloud) ··························································· 27
4.2.3. 드롭박스(Dropbox) ································································ 28
4.2.4. 원 드라이브(One Drive) ······················································· 29
4.2.5. 네이버 클라우드(Naver Cloud) ·········································· 30
4.3. FAT 파일시스템에서의 복사와 비교 ········································· 31
4.4. mac OS 파일시스템에서 시간정보의 변화 ······························ 32
4.4.1. Document Revisions ···························································· 33
4.4.2. Metadata ·················································································· 34
제 5 장 결론 ············································································ 36
참고문헌 ···················································································· 38

최근 본 자료

전체보기

댓글(0)

0