• Àüü
  • ÀüÀÚ/Àü±â
  • Åë½Å
  • ÄÄÇ»ÅÍ
´Ý±â

»çÀÌÆ®¸Ê

Loading..

Please wait....

±¹³» ³í¹®Áö

Ȩ Ȩ > ¿¬±¸¹®Çå > ±¹³» ³í¹®Áö > Çѱ¹Á¤º¸Ã³¸®ÇÐȸ ³í¹®Áö > Á¤º¸Ã³¸®ÇÐȸ ³í¹®Áö ÄÄÇ»ÅÍ ¹× Åë½Å½Ã½ºÅÛ

Á¤º¸Ã³¸®ÇÐȸ ³í¹®Áö ÄÄÇ»ÅÍ ¹× Åë½Å½Ã½ºÅÛ

Current Result Document :

ÇѱÛÁ¦¸ñ(Korean Title) Stick-PCÀÇ À̹ÌÁö ¼öÁý ¹× »ç¿ëÈçÀû ºÐ¼®¿¡ ´ëÇÑ ¿¬±¸
¿µ¹®Á¦¸ñ(English Title) A Study on Image Acquisition and Usage Trace Analysis of Stick-PC
ÀúÀÚ(Author) ÀÌÇÑÇü   ¹æ½Â±Ô   ¹éÇö¿ì   Á¤µÎ¿ø   ÀÌ»óÁø   Han Hyoung Lee   Seung Gyu Bang   Hyun Woo Baek   Doo Won Jeong   Sang Jin Lee  
¿ø¹®¼ö·Ïó(Citation) VOL 06 NO. 07 PP. 0307 ~ 0314 (2017. 07)
Çѱ۳»¿ë
(Korean Abstract)
½ºÆ½-PC(Stick-PC)´Â Å©±â°¡ ÀÛ°í ÈÞ´ë°¡ ¿ëÀÌÇÏ¿© ¾ðÁ¦ ¾îµð¼­µç ¸ð´ÏÅͳª TV µîÀÇ µð½ºÇ÷¹ÀÌ ÀåÄ¡¿¡ ¿¬°áÇÏ¸é µ¥½ºÅ©Å¾ PC(Desktop PC)ó·³ »ç¿ëÀÌ °¡´ÉÇÏ´Ù. ÀÌ¿¡ µû¶ó ½ºÆ½-PC(Stick-PC)µµ ÀÏ¹Ý PCó·³ °¢Á¾ ¹üÁË·Î ¿¬°áµÉ ¼ö ÀÖÀ¸¸ç ´Ù¾çÇÑ Áõ°ÅµéÀÌ ³²¾ÆÀÖÀ» ¼ö ÀÖ´Ù. ½ºÆ½-PC(Stick-PC)´Â ÀÏ¹Ý µ¥½ºÅ©Å¾ PC(Desktop PC)¿Í °°Àº À©µµ¿ìÁî(Windows) ¹öÀüÀÇ ¿î¿µÃ¼Á¦¸¦ »ç¿ëÇÏ°í ÀÖ¾î ºÐ¼®ÇØ¾ß ÇÒ ¾ÆƼÆÑÆ®µéÀº µ¿ÀÏÇÏ´Ù. ÇÏÁö¸¸ µ¥½ºÅ©Å¾ PC(Desktop PC)¿Í ´Þ¸® À̵¿¼ºÀÌ ÀÖ¾î ½Ã½ºÅÛ ºÐ¼® Àü¿¡ ÁÖº¯ ±â±â ¿¬°á ÈçÀûÀ» ã¾Æ ½Ç»ç¿ëÀÚ È®ÀÎ ¹× »ç¿ë ÈçÀûÀ» ÆľÇÇÏ´Â °ÍÀÌ ÀÌ·ç¾îÁö¸é Æ÷·»½Ä Á¶»ç ½Ã »ó´çÈ÷ ÀÇ¹Ì ÀÖ´Â Á¤º¸·Î »ç¿ëµÉ ¼ö ÀÖ´Ù. µû¶ó¼­ º» ³í¹®Àº ½ºÆ½-PC(Stick-PC)ÀÇ À̹ÌÁö ¼öÁý ¹æ¹ý Áß ÇϳªÀÎ Bootable OS¸¦ ÀÌ¿ëÇÏ¿© À̹ÌÁö¸¦ ¼öÁýÇÏ´Â ¹æ¹ýÀ» Á¦½ÃÇÑ´Ù. ¶ÇÇÑ ·¹Áö½ºÆ®¸®¿Í À̺¥Æ®·Î±×¸¦ ÅëÇØ µð½ºÇ÷¹ÀÌ, ºí·çÅõ½º(Bluetooth) µîÀÇ ÁÖº¯±â±â ¿¬°á ÈçÀû°ú ³×Æ®¿öÅ© ¿¬°á ÈçÀûÀ» ºÐ¼®ÇÏ´Â ¹æ¹ýÀ» Á¦½ÃÇÏ°í ½ÇÇè ½Ã³ª¸®¿À¸¦ ÅëÇØ Æ÷·»½Ä °üÁ¡¿¡¼­ È°¿ë ¹æ¾ÈÀ» Á¦½ÃÇÑ´Ù.
¿µ¹®³»¿ë
(English Abstract)
Stick-PC is small and portable, So it can be used like a desktop if you connect it to a display device such as a monitor or TV anytime and anywhere. Accordingly, Stick-PC can related to various crimes, and various evidence may remain. Stick-PC uses the same Windows version of the operating system as the regular Desktop, the artifacts to be analyzed are the same. However, unlike the Desktop, it can be used as a meaningful information for forensic investigation if it is possible to identify the actual user and trace the usage by finding the traces of peripheral devices before analyzing the system due to the mobility. In this paper, We presents a method of collecting images using Bootable OS, which is one of the image collection methods of Stick-PC. In addition, we show how to analyze the trace of peripheral connection and network connection trace such as Display, Bluetooth through the registry and event log, and suggest the application method from the forensic point of view through experimental scenario.
Å°¿öµå(Keyword) ÁÖº¯±â±â   µðÁöÅÐ Æ÷·»½Ä   ½ºÆ½-PC   ¿¬°á ÈçÀû   À̹ÌÁö ¼öÁý   Peripheral Device   Digital Forensic   Stick-PC   Connection Trace   Image Acquisition  
ÆÄÀÏ÷ºÎ PDF ´Ù¿î·Îµå