• Title/Summary/Keyword: forensic study

Search Result 667, Processing Time 0.027 seconds

Study on Recovery Techniques for the Deleted or Damaged Event Log(EVTX) Files (삭제되거나 손상된 이벤트 로그(EVTX) 파일 복구 기술에 대한 연구)

  • Shin, Yonghak;Cheon, Junyoung;Kim, Jongsung
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.26 no.2
    • /
    • pp.387-396
    • /
    • 2016
  • As the number of people using digital devices has increased, the digital forensic, which aims at finding clues for crimes in digital data, has been developed and become more important especially in court. Together with the development of the digital forensic, the anti-forensic which aims at thwarting the digital forensic has also been developed. As an example, with anti-forensic technology the criminal would delete an digital evidence without which the investigator would be hard to find any clue for crimes. In such a case, recovery techniques on deleted or damaged information will be very important in the field of digital forensic. Until now, even though EVTX(event log)-based recovery techniques on deleted files have been presented, but there has been no study to retrieve event log data itself, In this paper, we propose some recovery algorithms on deleted or damaged event log file and show that our recovery algorithms have high success rate through experiments.

Forensic Analysis of chatting messenger service in KakaoTalk and Comparison Study of KakaoTalk and WhatsApp Artifacts (KakaoTalk의 채팅 메시지 포렌식 분석 연구 및 WhatsApp의 Artifacts 와의 비교 분석)

  • Yoon, JongCheol;Park, Yongsuk
    • Journal of the Korea Institute of Information and Communication Engineering
    • /
    • v.20 no.4
    • /
    • pp.777-785
    • /
    • 2016
  • IM(Instant Messenger) chatting service can carry user's various information including life style, geographical position, and psychology & crime history and thus forensic analysis on the IM service is desirable. But, forensic analysis for KakaoTalk's chatting service is not well studied yet. For this reason, we study KakaoTalk's forensic analysis focusing on chatting service. This paper first details a general method of IM forensics investigating the previous articles about IM forensics although there are not many articles. Second, we discuss methodologies for IM forensics wherein we present analysis of table structure and method for reconstruction of chatting message. These result in the basic element of forensic tools of KakaoTalk chatting message. Last, we compare artifacts of KakaoTalk with that of WhatsApp. We conclude that these applications are, at least, different in that table structures and the ways to reconstruct chatting messages are not same and therefore digital evidences or artifacts are not same and somewhat distinct.

Forensic data extracts of Android and Windows Mobile O.S. Smart Phone (Google Android와 Windows Mobile Smart Phone의 포렌식 자료 추출)

  • Chun, Woo-Sung;Park, Dea-Woo
    • Proceedings of the Korean Institute of Information and Commucation Sciences Conference
    • /
    • 2010.10a
    • /
    • pp.235-239
    • /
    • 2010
  • Use of mobile phones reached saturation point, the recent use of the iPhone, including the Smart Phone is increasing rapidly. How to extract forensic data from current mobile phones and SYN, JTAG, Revolving There are three ways. Mobile phone and Smart Phone, but the technology and how to use forensic data because of the difference must have different extraction methods. In this paper, in the Smart Phone will study how to extract forensic data. Commonly used in the Google Android Smart Phone and Windows Mobile Smart Phone OS in the specification and analysis for analysis, the data analysis. Also, Google Android and Windows Mobile Smart Phone to extract forensic data to generate evidence. The present study tested the Mobile Smart Phone technology research will contribute to the development of forensic techniques.

  • PDF

An Experimental Study on Melting Characteristics of Low-voltage Miniature Cartridge Fuse (저압용 소형 관형퓨즈의 용단 특성에 관한 실험적 연구)

  • Ji, H.K.;Kim, J.P.;Song, J.Y.;Choi, Y.W.;Park, C.S.;Park, N.K.;Kil, G.S.
    • Journal of the Korean Society of Safety
    • /
    • v.28 no.5
    • /
    • pp.15-20
    • /
    • 2013
  • This paper dealt with melting characteristics of low-voltage miniature cartridge fuse used for 220 V electronic equipment. The experimental sample is low-voltage miniature cartridge fuse with rating of 250 V(3A) and size of $5{\times}20$ mm. In order to evaluate melting and scattering characteristics of the fuse, we applied to 8/20 ${\mu}s$ surge current, overload current and external thermal stress such as flame of fire. From the experimental results, the fuse element was melted and scattered by applied surge current(above 0.79 kA) and overload current(above 4.5 A). It was also attached to the inner surface of the fuse tube. The fuse element was attached as a thin film on inner surface of fuse tube when large surge current was applied. It was confirmed, however, the fuse element was not changed by external thermal stress such as flame and hot-air.

Method Validation for the Simultaneous Analysis of Organophosphorous Pesticides in Blood by GC/MS (GC/MS를 이용한 혈액 중 유기인제류 농약의 동시 분석에 관한 방법의 유효화)

  • Park Mee Jung;Yang Ja Youl;Kim Ki Wook;Park Yoo Shin;Chung Hee Sun;Lee Sang Ki
    • Environmental Analysis Health and Toxicology
    • /
    • v.20 no.4 s.51
    • /
    • pp.297-302
    • /
    • 2005
  • The purpose of this study was to provide the standard method for the analysis of organophosphorous pesticides such as chlorpyrifos, diazinon, malathion and parathion in blood. We performed method validation for these pesticides in blood according to EURACHEM (A focus For Analytical Chemistry in Europe) guide. For the analysis of the pesticides, we used solid-phase extraction ,column (Waters Oasis $HLB^{(R)}$. After the extraction, the supernatants were evaporated to dryness under the nitrogen stream. They were analyzed by gas chromatography/mass spectrometry (GC/MS) after reconstituting with ethanol. Terbufos was used as an internal standard. To validate this method, we performed verification procedures with the following parameters: selectivity, linearity of calibration, accuracy, precision, limit of detection and quantification. Validation data according to Eurachem guide were adequate for our purpose for the analysis of chlorpyrifos, diazinon, malathion and parathion in blood.

Effect of Weld Elastic Modulus on Simulation of Stress Concentration and Fatigue Life for Boiler Vessel (ADINA & WINLIFE 활용한 압력용기 용접부 피로파괴 해석)

  • Choe, Byung Hak;Lee, Bum Gyu;Shim, Jong Heon;Park, Chan Sung;Kim, Jin Pyo;Park, Nam Gyu
    • Journal of Welding and Joining
    • /
    • v.34 no.5
    • /
    • pp.47-53
    • /
    • 2016
  • The aim of this study is to consider effect of weld elastic modulus on simulations of stress concentration and fatigue life for pressure vessel. The investigations include analysis with ADINA and WINLIFE softwares for whole body model about using condition of the boiler vessel. Values of weld elastic modulus were divided by 5 steps in butt weld area of the boiler vessel body. The stress concentration of the butt weld more was increased in case of higher elastic modulus of weld area because of higher difference of material properties between matrix and weld. It was concluded that the fatigue lives were decreased along increasing stress concentration due to high elastic modulus of weld. The matrix microstructure was estimated as pearlitic structure of ${\alpha}$ ferrite and pearlite. And the microstructures of welds along 5 steps of elastic modulus were estimated as bainitic fine pearlite and martensite as increasing elastic modulus.

Analysis on Mobile Forensic of Smishing Hacking Incident (Smishing 사고에 대한 Mobile Forensic 분석)

  • Park, Dea-Woo
    • Proceedings of the Korean Institute of Information and Commucation Sciences Conference
    • /
    • 2014.05a
    • /
    • pp.207-210
    • /
    • 2014
  • Damage is increasing by (Smishing) hacking attack Smishing you use a smart phone after entering 2013. Takeover of personal information and direct financial damage in collaboration with graphics sewing machine hacking attack has occurred. Monetary damage that leads to Internet payment service (ISP) and secure payment system in conjunction with graphics sewing machine hacking attack on a smartphone has occurred. In this paper, I will study analysis in the laboratory examples of actual infringement vinegar sewing machine hacking attack. It is a major power security measures to prevent damage to the secure payment system that a case analysis and practical principle technical nest sewing machine hacking attack, using Smishing. In this paper, I will be to research to be able to through a smart phone, to the online payment safer and more convenient.

  • PDF

Thermodynamic Studies on the Adsorption of 4-Octylphenol on Carboxen by GC/MS Analysis (GC/MS 분석에 의한 4-Octylphenol의 Carboxen 흡착에 대한 열역학적 연구)

  • Lee, Joon-Bae;Park, Woo-Yong;Shon, Shungkun;Jung, Ji Eun;Jeong, Yong Ae;Gong, Bokyoung;Kim, Yu-Na;Kwon, O-Seong;Paeng, Ki Jung
    • Applied Chemistry for Engineering
    • /
    • v.29 no.3
    • /
    • pp.356-361
    • /
    • 2018
  • It is common to analyze volatile organic compound (VOC) or semi-VOC (SVOC) in a sample composed of a complex matrix consisting of multiple components such as bloods through a separation process. Adsorption is a physical phenomenon in which certain components accumulate on the surface of other phases. In order to overcome difficulties in the pretreatment process, an adsorption is frequently used. Solid phase microextraction (SPME) equipment with porous carbon carboxen (CAR) is an example of adsorption application. In this study, the adsorption of 4-octylphenol to carboxen was examined. To do so, the extraction efficiency for such solvents as dichloromethane ($CH_2Cl_2$, DCM), ethylacetate ($CH_3COOC_2H_5$, EA) and diethylether ($C_2H_5OC_2H_5$, $Et_2O$) was studied and also the derivatization reaction for 4-octylphenol with reagents of bistrimethylsilyltrifluoroacetamide (BSTFA), methylchloroformate (MCF) and pentafluorobenzylbromide (PFBBr) was compared. The combination of DCM and BSTFA showed good performance thus they were adopted for this study. Thermodynamic adsorption experiments showed that the adsorption process was endothermic and Freundlich isotherm equation was more suitable than Langmuir isotherm. It was also found that the adsorption followed a pseudo-$2^{nd}$ order kinetic model.

A case study on the fire victim in the vehicle by GC/MS through derivatization of cyanide with pentafluorobenzyl bromide (PFBBr) (시안화이온의 pentafluorobenzyl bromide (PFBBr)에 의한 유도체화 후 GC/MS 분석에 의한 차량화재 변사체 사인규명에 관한 사례연구)

  • Lee, Joon-Bae;Shon, Sung Kun;Woo, Sang Hee;Park, Se Yeon;Hwang, Jung Ho;Kwon, O-Seong;Kim, Nam Yi;Paeng, Ki Jung
    • Analytical Science and Technology
    • /
    • v.29 no.2
    • /
    • pp.73-78
    • /
    • 2016
  • Hydrogen cyanide (HCN) is an extremely toxic gas frequently produced during the incineration of plastics, such as acrylonitrile-butadiene-styrene (ABS). A victim of a fire who has inhaled smoke could have cyanide in the blood. Therefore, cyanide could be a good marker for a post-mortem examination of a fire as well as carboxyhemoglobine (COHb) test of blood samples. For a particular fire case, a burned body with a suicide note was found inside a burned vehicle. Even though the COHb value is conclusive evidence, measuring the COHb for denatured blood might be difficult due to severe thermal denaturation or the formation of methemoglobin (MetHb). To overcome this difficulty, cyanide could be used as an indicator when investigating the death of a fire victim. In this study, gas chromatography/mass spectrometry (GC/MS) was adopted to measure the levels of cyanide in the blood through derivatization with pentafluorobenzyl bromide (PFBBr) under cation surfactant by scan and SIM mode. The concentration of cyanide in the blood of heart blood and brain of the victim was found to be 0.36 µg/mL and 1.20 µg/mL respectively, which was higher than the average value (0.041 µg/mL) found in the blood of 14 people who smoked.

The application of digital forensic investigation for response of cyber-crimes (사이버범죄의 대응강화를 위한 디지털 포렌식 수사 활용방안)

  • Oh, Sei-Youen
    • Journal of Digital Convergence
    • /
    • v.13 no.4
    • /
    • pp.81-87
    • /
    • 2015
  • This study will show the digital forensic model which fights against cyber-crimes to prepare various cyber-crimes. The digital forensic model will be more useful about the investigation of cyber-crimes and arresting criminals after researching the uses of the digital forensic model and cyber-crime rates in South Korea. This model conduct the standardized data with various languages by the language support system through the digital forensic analyzer. This model will send the data to law enforcement reviewing whether or not we ought to prove criminal charges. Moreover, law enforcement can access the file system to find out admissibility of evidence. And this model simplifies lawful investigation about additional investigation. The data, which is conducted and saved by the digital forensic system, will be helpful to protect against the future crimes because of the data.