728x90

1. ๋””์ง€ํ„ธ ํฌ๋ Œ์‹

๋””์ง€ํ„ธ ํฌ๋ Œ์‹์ด๋ž€?

Digital + Forensic

  • Forensic(๋ฒ•์˜ํ•™): ๋ฒ•๋ฅ  + ์˜๋ฃŒ / ๋ถ€๊ฒ€
  • ๋””์ง€ํ„ธ ๋ฒ”์ฃ„์˜ ๋ถ€๊ฒ€

โ–ถ ๋””์ง€ํ„ธ ์ฆ๊ฑฐ๋ฌผ(์Šค๋งˆํŠธํฐ, PC)์„ ์ˆ˜์ง‘, ๋ถ„์„ํ•˜์—ฌ ๋ฒ”์ฃ„์˜ ๋‹จ์„œ์™€ ์ฆ๊ฑฐ๋ฅผ ์ฐพ์•„๋‚ด๋Š” ๊ณผํ•™์ˆ˜์‚ฌ ๊ธฐ๋ฒ•

๋””์ง€ํ„ธ ํฌ๋ Œ์‹์˜ ๋Œ€์ƒ

  • ๋””์Šคํฌ ํฌ๋ Œ์‹ → ์ปดํ“จํ„ฐ ๋””์Šคํฌ(์œˆ๋„์šฐ, ๋ฆฌ๋ˆ…์Šค, MacOS/๊ฐœ์ธ, ์„œ๋ฒ„, ํด๋ผ์šฐ๋“œ)
  • ๋ฉ”๋ชจ๋ฆฌ ํฌ๋ Œ์‹ → ์ปดํ“จํ„ฐ ๋ฉ”๋ชจ๋ฆฌ(RAM)
  • ๋„คํŠธ์›Œํฌ ํฌ๋ Œ์‹ → ๋„คํŠธ์›Œํฌ ํŒจํ‚ท, ๋„คํŠธ์›Œํฌ ์žฅ๋น„ ๋กœ๊ทธ, ๋„คํŠธ์›Œํฌ ๊ด€๋ จ ์„ค์ •๋“ค
  • ๋ชจ๋ฐ”์ผ ํฌ๋ Œ์‹ → ๋ชจ๋ฐ”์ผ ๋””๋ฐ”์ด์Šค(์ €์žฅ์†Œ, ๋ฉ”๋ชจ๋ฆฌ) / IoT๋””๋ฐ”์ด์Šค
  • ๊ธฐํƒ€ → ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํฌ๋ Œ์‹, ์•”ํ˜ธ ํฌ๋ Œ์‹, ํšŒ๊ณ„ ํฌ๋ Œ์‹, ์†Œ์Šค์ฝ”๋“œ ํฌ๋ Œ์‹ ๋“ฑ

ํŠธ๋ž™์—์„œ ๋ฐฐ์šธ ๊ฒƒ

๋””์ง€ํ„ธ ํฌ๋ Œ์‹ ์ˆ˜์‚ฌ๊ด€์ด๋ผ๊ณ  ๊ฐ€์ •ํ•˜๊ณ , ์‚ฌ๊ฑด์ด ํ„ฐ์กŒ์„ ๋•Œ ์–ด๋–ป๊ฒŒ ์ˆ˜์‚ฌํ•  ๊ฒƒ์ธ๊ฐ€์— ๊ด€ํ•ด


2. ์Šคํ…Œ๊ฐ€๋…ธ๊ทธ๋ž˜ํ”ผ

์Šคํ…Œ์นด๋…ธ๊ทธ๋ž˜ํ”ผ๋ž€?

Steganography

  • Stegano(๊ฐ์ถฐ์ง„) + Graphy(๊ธ€) = ๊ฐ์ถฐ์ง„ ๊ธ€
  • ์ „๋‹ฌํ•˜๋ ค๋Š” ๊ธฐ๋ฐ€ ์ •๋ณด๋ฅผ ๋‹ค๋ฅธ ํŒŒ์ผ, ๋ฉ”์‹œ์ง€, ์ด๋ฏธ์ง€ ๋˜๋Š” ๋น„๋””์˜ค ์•ˆ์— ์ˆจ๊ธฐ๋Š” ์‹ฌ์ธต ์•”ํ˜ธ ๊ธฐ์ˆ 

์Šคํ…Œ๊ฐ€๋…ธ๊ทธ๋ž˜ํ”ผ ์‹ค์Šต

์Šคํ…Œ๊ฐ€๋…ธ๊ทธ๋ž˜ํ”ผ ํˆด

Forensically

Image Steganography

StegOnline

HxD


3. ๋„คํŠธ์›Œํฌ ํฌ๋ Œ์‹

๋„คํŠธ์›Œํฌ ํฌ๋ Œ์‹์ด๋ž€?

๋„คํŠธ์›Œํฌ๋ฅผ ํ†ตํ•˜์—ฌ ์ „์†ก๋˜๋Š” ๋ฐ์ดํ„ฐ, ์•”ํ˜ธ ๋“ฑ์„ ํŠน์ •๋„๊ตฌ๋ฅผ ์ด์šฉํ•ญ ๊ฐ€๋กœ์ฑ„๊ฑฐ๋‚˜ ์„œ๋ฒ„์— ๋กœ๊ทธํ˜•ํƒœ๋กœ ์ €์žฅ๋œ ๊ฒƒ์„ ์ ‘๊ทผํ•˜์—ฌ ๋ถ„์„ํ•˜๋Š” ํฌ๋ Œ์‹ ๋ถ„์•ผ

  • ๋„คํŠธ์›Œํฌ ํŒจํ‚ท: ๋„คํŠธ์›Œํฌ์—์„œ ๋ฐ์ดํ„ฐ๋ฅผ ์ฃผ๊ณ ๋ฐ›์„ ๋•Œ ์‚ฌ์šฉ๋˜๋Š” ๋ฐ์ดํ„ฐ ์กฐ๊ฐ

ํŒจํ‚ท ๋ถ„์„ ๋„๊ตฌ

WireShark

๋„คํŠธ์›Œํฌ ํŒจํ‚ท์„ ๊ฐ์‹œ ๋ฐ ๋ถ„์„ํ•˜๋Š” ํ”„๋กœ๊ทธ๋žจ์œผ๋กœ,

ํŒจํ‚ท ๋ถ„์„ ๋„๊ตฌ ์ค‘ ์ด๋ฆ„์ด ๊ฐ€์žฅ ๋„๋ฆฌ ์•Œ๋ ค์ง„ ์†Œํ”„ํŠธ์›จ์–ด

  • GNU GPLv2 ๋ผ์ด์„ ์Šค(์ž์œ  ์†Œํ”„ํŠธ์›จ์–ด)
  • ํฌ๋กœ์Šค ํ”Œ๋žซํผ(Windows, Linus, Mac ๋“ฑ ์ง€์›)
  • ํŒจํ‚ท ๋ถ„์„์„ ์œ„ํ•œ GUI ์ œ๊ณต
  • ๋ฌด์ฐจ๋ณ„ ๋ชจ๋“œ(promiscuous mode) ์ง€์›
  • Loopback ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ์‹œ์Šคํ…œ์˜ ๋„คํŠธ์›Œํฌ ์–ด๋Œ‘ํ„ฐ๋„ ๋ถ„์„ ๊ฐ€๋Šฅ
  • ํŒŒ์ผ ํ˜•ํƒœ๋กœ ๊ธฐ๋ก ๊ฐ€๋Šฅ

 

'E-COPS > 15th ๋น„๊ธฐ๋„ˆ' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

WEEK3 - WEB HACKING  (2) 2024.11.11
WEEK3 - ๋„คํŠธ์›Œํฌํฌ๋ Œ์‹ ๋„๊ตฌ ์‚ฌ์šฉ ๋ฐฉ๋ฒ•  (0) 2024.10.11
WEEK3 - REVERSING  (7) 2024.10.08
WEEK2 QUIZ - VCS, Buffer  (0) 2024.10.08
WEEK2 - Git, Flask  (1) 2024.10.08

+ Recent posts