|
|
|
 |
|
 |
|
|
 |
|
| |
ÄÚ½º¼³¸í |
|
°³Àλç¿ëÀÚ¸¦ ºñ·ÔÇÏ¿© ºñÁî´Ï½º¸¦ º¸´Ù ´É·üÀûÀÌ°í ¶Ç ´Ù¸¥
ºñÁî´Ï½º¿Í ÅëÇÕÇϱâ À§ÇÑ Àΰ£ÀÇ ¿å±¸´Â ¡®»çÀ̹ö ¹üÁËÀÚ¡¯¶ó´Â
»õ·Î¿î ŸÀÔÀÇ ¹üÁËÀÚ¸¦ »ý±â°Ô Çß´Ù. ÀÌÁ¦ ´õ ÀÌ»ó ¡®´ç½ÅÀÇ
±â¾÷ÀÌ ÇØÅ·À» ´çÇÏ°Ô µÉ °ÍÀΰ¡?¡¯ ÇÏ´Â ¹®Á¦°¡ ¾Æ´Ï¶ó ¡®¾ðÁ¦
ÇØÅ·À» ´çÇߴ°¡?¡± ÀÇ ¹®Á¦°¡ Áß¿äÇÏ°Ô µÉ °ÍÀÌ´Ù.
CHFIÄÚ½º´Â ½Ã½ºÅÛ¿¡
ħÀÔÇÑ ÈçÀûÀ» ã¾Æ³»°í, ¹üÁ˸¦ Áõ¸íÇϱâ À§ÇØ ÇÊ¿äÇÑ Áõ°Å¸¦
È®º¸ÇÒ ¼ö ÀÖ´Â ±â¼úÀ» Á¦°øÇÑ´Ù. ÀÌ ÄÚ½º´Â ¼ÒÇÁÆ®¿þ¾î
¹× Çϵå¿þ¾î»Ó¸¸ ¾Æ´Ï¶ó Ư¼ö±â¼ú µîÀ» Æ÷ÇÔÇÑ ÇöÁ¸ÇÏ´Â ÃÖ°íÀÇ
Æ÷·»Á÷ ±â¼úÀ» ¼Ò°³Çϰí Àִµ¥, ƯÈ÷ Áß¿äÇÑ °ÍÀº, ƯÁ¤ º¥´õ
Åø¿¡ ±¹ÇѵÇÁö ¾Ê°í(Vendor-neutral) ½ÃÁß¿¡¼ ±¸ÇÒ
¼ö ÀÖ´Â ´Ù¾çÇÑ Æ÷·»Á÷ ÅøÀ» Ȱ¿ëÇϴµ¥ ÀÖ´Ù. ¼ö°»ýµéÀº °¢
¸ðµâ º° ¼Ò°³µÇ´Â ¸¹Àº ÅøµéÀ» »ç¿ëÇØ º¼ ¼ö ÀÖ°í, ±× Ư¡µéÀ»
ÆÄ¾ÇÇÏ¿© ½ÇÁ¦ ¾÷¹« ½Ã ÇÊ¿äÇÑ Å½ºÅ©¸¦ ¼öÇàÇÒ ¼ö ÀÖ´Ù.
¸¸¾à ´ç½Å°ú ´ç½ÅÀÇ ±â¾÷ÀÌ »çÀ̹ö ¹üÁËÀÚ¸¦ ã¾Æ³»°í ÃßÀûÇϰí
±â¼ÒÇϱâ À§ÇÑ ±â¼ú°ú Áö½ÄÀÌ ÇÊ¿äÇÏ´Ù¸é ÀÌ ÄÚ½º´Â ¹Ù·Î ´ç½ÅÀ»
À§ÇÑ °ÍÀÌ µÉ °ÍÀÌ´Ù |
|
|
|
| |
´©±¸¿¡°ÔÇÊ¿äÇѰ¡? |
|
 |
µðÁöÅÐÆ÷·»Á÷
¼ö»ç°ü ¶Ç´Â Á¶»ç°ü |
|
 |
º¸¾È°ü¸®ÀÚ
, º¸¾ÈÄÁ¼³ÅÏÆ® |
|
 |
±ÝÀ¶
/ º¸Çè µî °ü·Ã¾÷°è Á¾»çÀÚ |
|
 |
°æÂû°ü,
¹ý·üÁýÇà°ü, ±¹¹æ°ü°èÀÚ |
|
 |
½Ã½ºÅÛ,
³×Æ®¿öÅ© µîÀ» ¿î¿µÇϰí ÀÖ´Â IT°ü¸®ÀÚ |
|
 |
Á¤º¸Åë½Å,
Á¤º¸º¸È£ Àü°ø Çлý/´ëÇпø»ý |
|
 |
º¸¾È,
À±¸®ÀûÇØÅ·¿¡ °ü½ÉÀÖ´ÂÀÚ |
|
|
|
| |
¾î¶²
Áö½ÄÀÌ ÇÊ¿äÇѰ¡? |
|
 |
±âº»Àû
PC»ç¿ë¹ý°ú PC¿¡ ´ëÇÑ ÀÌÇØ |
|
 |
º¸¾È°ü¸®ÀÚ
, º¸¾ÈÄÁ¼³ÅÏÆ® |
|
 |
OS
: MS, Linux, Unix |
|
 |
ÇÁ·Î±×·¡¹Ö
: C¾ð¾î (±âº»Àû Áö½Ä °¡´É) |
|
 |
³×Æ®¿öÅ·
: ³×Æ®¿öÅ© Àü¹ÝÀûÀÎ Áö½Ä°ú °æÇè ÇÊ¿ä |
|
 |
±âŸ
: ¿µ¾î (±³Àç ¹× ½ÃÇè¹®Á¦ ÇØ¼®) |
|
 |
CEH
±ÇÀå (not Çʼö) |
|
|
|
| |
±³À°½Ã°£
: ±³À°½Ã°£Àº ¼ö°»ýÀÇ ±âº»Àû Áö½Ä¼öÁØ ¹× °æÇè/°æ·Â
µî¿¡ µû¶ó ¼±ÅÃÇÒ ¼ö ÀÖ½À´Ï´Ù |
|
 |
¼Ó¼º
: 40½Ã°£ ÀÌÇÏ |
|
 |
´Ü±â
: 40½Ã°£(¾à5Àϰ£) |
|
 |
Á¤±Ô
: 60~80½Ã°£(¾à 6~8ÁÖ°£) - °¢ ATC¿¡ µû¶ó °³º° Æí¼º(½Ã°£,
¿äÀÏ, ÃÑ ±³À°±â°£µî) |
|
 |
ÆÐŰÁö
: °¢ ATC¿¡ µû¶ó ÀÚÀ¯·ÎÀÌ Æí¼º (¿¹ : CEH + CHFI,
CEH + ECVP, CHFI + ECSA/LPT µî |
|
|
| |
| |
½ÃÇèÁ¤º¸ |
|
 |
½ÃÇè¸í
: CHFI - Computer Hacking Forensic Investigator |
|
 |
½ÃÇè¹®Á¦
: 50¹®Ç× (°´°ü½Ä, ´Ù´äÇü ¹®Á¦ ÀÖÀ½) |
|
 |
½ÃÇè¾ð¾î
: ¿µ¾î |
|
 |
½ÃÇè½Ã°£
: 2½Ã°£ |
|
 |
ÇÕ°ÝÁ¡¼ö
: 70% ÀÌ»ó |
|
 |
¹®Á¦À¯Çü
: ½Ã³ª¸®¿À ¹× ½Ç¹« À§ÁÖÀÇ °´°ü½Ä ¹®Á¦ |
|
 |
½ÃÇèÀÏÁ¤
: ¼ö½Ã(¿øÇϴ³¯Â¥ÀÇ 2ÁÖÀü Çʼö ¿¹¾à, ÁÖ¸» ÈÞÀÏ Á¦¿Ü) |
|
 |
½ÃÇèÀå¼Ò
: Á¾·Î5°¡¿ª »ï¾ç»ç ºôµù ³» ÁöÁ¤Àå¼Ò |
|
 |
ÀÚ°Ý¿ä°Ç
: ½ÅûÀýÂ÷ ÂüÁ¶(¼·ù½É»ç ÈÄ ½ÃÇèÀÀ½Ã°¡´É¿©ºÎ ÆÇÁ¤) |
|
 |
Àç½ÃÇè¿©ºÎ
: Ƚ¼ö Á¦ÇÑ ¾øÀ½(´Ü, ½ÃÇèÀÀ½Ã±Ç À籸¸Å ÈÄ, ±³Àç À籸¸Å´Â ÇÊ¿ä¾øÀ½) |
|
|
| |
| |
Legal
Agreement (¹ý·üÀû µ¿ÀÇ) |
|
 |
ÀÌÄÚ½º¸¦
¼ö°Çϱâ Àü¿¡ ¾î¶°ÇÑ Àǵµ·Îµµ °úÁ¤ Áß¿¡ ¹è¿î ±â¼úÀ» ºÒ¹ýÀûÀ̰ųª
¾ÇÀÇÀûÀ¸·Î ÇØÅ· °ø°Ý¿¡ »ç¿ëÇÏÁö ¾Ê´Â´Ù´Â µ¿ÀǼ¿¡ ¼¸íÇØ¾ß ÇÔ |
|
 |
º»
°úÁ¤Àº ATC¸¦ ÅëÇØ Á¤½Ä°úÁ¤À» ¼ö·áÇÏ¿´°Å³ª, ½ÅûÀÚ°¡ È®ÀÎ °¡´ÉÇÑ
½Ç¹«°æ·ÂÀ» Áõ¸íÇÑÀÚ¸¸ÀÌ Áö¿øÇÒ ¼ö ÀÖÀ½ |
|
|
|
 |
|
| ±³À°¸í |
±³À°³»¿ë |
±³À°½Ç½À
¼¼ºÎ³»¿ë |
Module
01 |
Computer
Forensic in Today’s World |
ÄÄÇ»ÅÍ
Æ÷·»½ÄÀÇ °³¿ä ¹× ¿ª»ç, ±ÔÄ¢, ¼ö»çÀÇ ÀýÂ÷, °áÁ¡°ú ¸®½ºÆ®, ¹ýÀûÀ̽´ |
Module
02 |
Law
and Computer Forensics |
•»çÀ̹ö
¹üÁË ¼ö»çÀÇ ÀýÂ÷, FBI ÄÄÇ»ÅÍ ¹üÁË ¼ö»ç¹æ¹ý, ¹üÁË ¼ö»ç
±â°üÀÇ Á¾·ù, ÀÎÅÍ³Ý ¹üÁË ¹æÁö ÆÁ
• ÀÎÅÍ³Ý °ü·Ã ¹ý·ü, ÁöÀûÀç»ê±Ç, ÄÄÇ»ÅÍ Æ÷·»½Ä°ú
°ü·ÃµÈ ±¹Á¦¹ý·ü, °ü·Ã ¹üÁË º¸°í |
Module
03 |
Computer
Investigation Prcess |
•ÄÄÇ»ÅÍ
¹üÁËÀÇ Á¶»ç¹æ¹ý, ÀýÂ÷ ¹× ÀýÂ÷ °³¹ß, ±â¾÷Á¤Ã¥ À§¹ÝÀÇ Á¶»ç¹æ¹ý
• Á¶»ç(¼ö»ç)°èȹ → ¼ö»ö¿µÀåÀÇ È¹µæ
→ Á¶»ç(¼ö»çÀÇ ¼öÇà)
• °æ°í¹è³Ê, ÄÄÇ»ÅÍ Shut down ¹æ¹ý,
Áõ°Å µð½ºÅ©ÀÇ À̹Ì¡, ÄÉÀ̽º Ŭ·Î¡, ÄÉÀ̽º Æò°¡ |
Module
04 |
First
Responder Procedure |
•ÀüÀÚÁõ°Å,
Æ÷·»½Ä ÀýÂ÷, Ãʱâ´ëÀÀ ÀýÂ÷, ¹üÁË Á¾·ù¿¡ µû¸¥ Æ÷·»½Ä Á¶»ç
½Àµæ¹°, Áõ°Å ¼öÁý Åø°ú Àåºñ
• °ü¸®ÀÚ¸¦ À§ÇÑ Ãʱ⠴ëÀÀ ¹æ¹ý, ºñ Àü¹®°¡¿¡
ÀÇÇÑ Ãʱ⠴ëÀÀ ¹æ¹ý, Àü¹®°¡¿¡ ÀÇÇÑ Ãʱ⠴ëÀÀ ¹æ¹ý |
Module
05 |
CSIRT |
•Ãë¾à¼º¿¡
°üÇÑ Åë°è, »ç°Ç º¸°íÀÇ Çü½Ä, World CERTs
• »ç°ÇÀÇ °³¿ä → »ç°ÇÀÇ Ãë±Þ, »ç°ÇÃë±ÞÀ»
À§ÇÑ ÀýÂ÷ → »ç°ÇÀÇ °ü¸® → »ç°ÇÀÇ ºñ¿ë
ÃøÁ¤ → »ç°ÇÀÇ º¸°í → »ç°ÇÀÇ ºÐ·ù
• CISRTÀÇ °³¿ä¿Í ¿ªÇÒ, ±¸¼º¿ø, ¼ºñ½º,
±¸¼ºÇϱâ À§ÇÑ ÃÖÀûÀÇ ÇÁ·¢Æ¼½º, È¿°ú¿¡ ´ëÇÑ ÇѰè |
Module
06 |
Computer
Forensic Lab |
•¿¹»ê
¹èÁ¤, ¹°¸®Àû À§Ä¡¿¡ ´ëÇÑ Á¶°Ç, ¾÷¹«È¯°æ, ÀϹÝÀûÀÎ ·¦ ±¸¼º,
Àåºñ¿¡ ´ëÇÑ Á¶°Ç, ÁÖº¯ ȯ°æ, ¼³°è¿¡ ´ëÇÑ °í·Á»çÇ×
• ¹°¸®Àû º¸¾È¿¡ ´ëÇÑ ±ÇÀå »çÇ×, Áõ°Å º¸°üÇÔ¿¡
´ëÇÑ ±ÇÀå »çÇ×
• Æ÷·»½Ä ·¦¿¡ ´ëÇÑ °Ë»ç, ¶óÀ̼¾½º ÇʼöÁ¶°Ç,
¿ä±¸»çÇ×, ¾²±â¹æÁö µð¹ÙÀ̽º¿Í ŰƮ, ¾ÆÄ«À̺ê¿Í º¹±¸ Àåºñ,
µð¹ÙÀ̽º
• ÆÄ¶óº¥ Æ÷·»½Ä Àåºñ, ·¦ÀÇ ¿ä±¸»çÇ×, Àåºñ
• DIBS ¸ð¹ÙÀÏ Æ÷·»½Ä ¿öÅ©½ºÅ×À̼Ç, RAID
• ·¦±â¹Ý À̹Ì¡ ½Ã½ºÅÛÀÇ ±â¼úÀû »ç¾ç, µ¥ÀÌÅÍ
ÆÄ±« »ê¾÷ ±âÁØ/Ç¥ÁØ |
Module
07 |
Understanding
File System and Hard Disks |
•µð½ºÅ©
µå¶óÀ̺ê, ÇÏµå µð½ºÅ©, Çϵåµð½ºÅ© ÀÎÅÍÆäÀ̽º Á¾·ù
• µð½ºÅ© ÆÄƼ¼Ç, ¸¶½ºÅÍ ºÎÆ® ·¹ÄÚµå, FAT
µð½ºÅ©ÀÇ Á¶»ç, NTFS ½Ã½ºÅÛ ÆÄÀÏ
• ÆÄÀÏ ½Ã½ºÅÛÀÇ ÀÌÇØ, Á¾·ù, ¸®´ª½º ÆÄÀÏ ½Ã½ºÅÛ,
½ã ¼Ö¶ó¸®½º 10 ÆÄÀÏ ½Ã½ºÅÛ(ZFS), ¸Æ OS X ÆÄÀÏ ½Ã½ºÅÛ,
À©µµ¿ì ÆÄÀÏ ½Ã½ºÅÛ, À©µµ¿ì XP ½Ã½ºÅÛ ÆÄÀÏ, À©µµ¿ì ºÎÆ®
ÇÁ·Î¼¼½º
• EFS º¹±¸ Ű ¿¡ÀÌÀüÆ®, ·¹Áö½ºÆ®¸® µ¥ÀÌÅÍÀÇ
Á¶»ç, FAT vs NFTS |
Module
08 |
Windows
Forensic |
•À©µµ¿ì
½Ã½ºÅÛ»óÀÇ Áõ°Å À§Ä¡, Èֹ߼º Áõ°Å(Volatile Evidence)
¼öÁý, À©µµ¿ì Æ÷·»½Ä Åø(Helix)
• À©µµ¿ì ÆÄÀÏ ½½·¢ Á¶»ç, ÆÄÀÏ ½Ã½ºÅÛÀÇ Á¶»ç,
·¹Áö½ºÆ®¸® üũ, ¸Þ¸ð¸® ´ýÇÁ, °¡»ó ¸Þ¸ð¸®, ÀÎÅÍ³Ý »ç¿ëÈçÀûÀÇ
Á¶»ç, ADS StreamÀÇ Á¶»ç |
Module
09 |
Linux
Forensci |
•
Æ÷·»½Ä Åø·Î¼ ¸®´ª½º »ç¿ë, ¸®´ª½º µð½ºÅ© Æ÷·»½ÄÀÇ µµÀü °úÁ¦,
ÀαâÀÖ´Â ¸®´ª½º Æ÷·»½Ä Åøµé
• ¸®´ª½º¿¡¼ÀÇ ÆÄƼ¼Ç È®ÀÎ, ÆÄÀÏ ½Ã½ºÅÛ °³¿ä,
ºÎÆ® ÇÁ·Î¼¼½º
• Case Study : ¸®´ª½º »ç¿ëÇÏ¿© Ç÷ÎÇǵð½ºÅ©,
Çϵåµð½ºÅ©·ÎºÎÅÍ Áõ°Å¸¦ ÃßÃâÇÏ´Â ¹æ¹ý |
Module
10 |
Data
Acquisition and Duplication |
•ÃÖÀûÀÇ
µ¥ÀÌÅÍ È¹µæ ¹æ¹ý °áÁ¤(Bit stream Disk-to-image
file, Bit Stream Disk-to-disk copy,
Sparse data copy of a folder or file)
• µ¥ÀÌÅÍ È¹µæ ½Ã ¿ì¹ßÀû »ç°í¿¡ ´ëÇÑ ºñ»ó º¹±¸
°èȹ, µ¥ÀÌÅÍ È¹µæ Åøµé(Image MASSter solo,
LinkMASSter, RoadMASSter)
• µ¥ÀÌÅÍ º¹Á¦(ÀÌÁßÈ)ÀÇ Çʿ伺, Åøµé(R-drive
Image, DriveLook, DiskExplorer, Save-N-Sync,
ImageMASSter 6007 SAS, Disk Jockey
IT, SCSIPAK, IBM DFSMSdss, QuickCopy) |
Module
11 |
Computer
Forensic Tools |
•¼ÒÇÁÆ®¿þ¾î
ÄÄÇ»ÅÍ Æ÷·»½Ä Åø : Visual TimAnalyzer, Evidor,
Forensic sorter, Directory snoop,
FileMon, @Stake, Cookie viewer, Maresware,
NTI tools, FTK, Encase, Parben, Network
E-mail Exminer, Chat Examiner, Resistry
Analyzer, ASR Data’s SMART,
Oxygen Phone Manager, Aroruns, Autostart
Viewer µî
•Çϵå¿þ¾î ÄÄÇ»ÅÍ Æ÷·»½Ä Åø : PDBlock,
Write-blocker, NoWrite, FireWire DriveDock,
Handheld First Responder Kit, LockDown,
StrongHold Bag, Wireless StrongHold
Tent, Project-a-phone, Wireless StrongHold
Bag, USB Serial DB9 Adapter, Write
Protect Card Reader, Drive Lock IDE,
Serial-ATA DriveLock Kit, Wipe MASSter,
ImageMASSter solo-3 IT, ImageMASSter
4002i, ImageMASSter 3002SCSI, ImageMASSter
3004SATA |
Module
12 |
Forensics
Investigation Using Encase |
•
Áõ°ÅÆÄÀÏ, ÆÄÀÏ ¹«°á¼º °ËÁõ, ÇØ½Ì, À̹ÌÁö ȹµæ
• Encase ±¸¼º(ȯ°æ¼³Á¤, ȸé, ¸Þ´º ÅÇ
µî), ºÎÆ®µð½ºÅ©, °Ë»ö, ºÏ¸¶Å©
• FAT/NTFS ÆÄƼ¼Ç¿¡¼ »èÁ¦µÈ ÆÄÀÏ/Æú´õ
º¹±¸, º¹±¸µÈ ÆÄÀÏ º¸±â, ¸¶½ºÅÍ ºÎÆ® ·¹ÄÚµå, NTFS ½ÃÀÛÁ¡,
»èÁ¦µÈ ÆÄƼ¼Ç º¹±¸, ÇØ½Ã°ª(ÇØ½Ã¼¼Æ® »ý¼º, MD5 ÇØ½Ã, ÇØ½Ã
»ý¼º), ÆÄÀÏ ºä¾î, ¼¸í ºÐ¼®, À̸ÞÀÏ º¹±¸, ¸®Æ÷ÆÃ
|
Module
13 |
Recovering
Deleted Files and Deleted partitions |
•»èÁ¦µÈ
ÆÄÀÏÀÇ º¹±¸ - ÆÄÀÏ »èÁ¦, ÆÄÀÏ »èÁ¦ ½Ã ¹ß»ýÇÏ´Â Çö»ó, FAT/NTFS
½Ã½ºÅÛ¿¡¼ ÈÞÁöÅë ÀúÀå °ø°£, ÈÞÁöÅë ÀÛµ¿¿ø¸®, ¸®´ª½º¿¡¼ µ¥ÀÌÅÍ
º¹±¸, µ¥ÀÌÅÍ º¹±¸ Åø(Search and Recover, E2Undel,
R-linux, O&O Unerase µî)
• »èÁ¦µÈ ÆÄƼ¼ÇÀÇ º¹±¸ - ÆÄƼ¼Ç »èÁ¦, »èÁ¦µÈ
ÆÄƼ¼ÇÀÇ º¹±¸, ÆÄƼ¼Ç º¹±¸ Åø(GeDataBack, DiskInternals
Partition Recovery µî) |
Module
14 |
Image
Files Forensic |
•À̹ÌÁö
ÆÄÀÏ °³¿ä, ÆÄÀÏÀÇ ÀνÄ, µ¥ÀÌÅÍ ¾ÐÃà, À§Ä¡ ¹× º¹±¸, ÆÄÀÏ
Çì´õ ºÐ¼®, ¼Õ»óµÈ Çì´õÀÇ ¼ö¸®, ÆÄÀÏ Á¶°¢ Àç ±¸¼º
• À̹ÌÁö º¸±â¸¦ À§ÇÑ Åø(Ifran View,
ACDSee, Thumbsplus, AD µî), À̹ÌÁö ÆÄÀÏ¿¡¼
½ºÅ×°¡³ë±×·¡ÇÇ, ½ºÅ×°¡³ë±×·¡ÇÇ
¿ª¼ø(Hex Workshop,
S-tools, Stegdetect µî)
• À̹ÌÁö ÆÄÀÏ Æ÷·»½Ä Åø(GFE Stealth,
llook, p2 eXplorer) |
Module
15 |
Steganography |
•
½ºÅ×°¡³ë±×·¡ÇÇ °³¿ä, ¿ª»ç, ÁøÈ, Á¾·ù ¹× ºÐ·ù
• Steganography¿Í CryptographyÀÇ
Â÷ÀÌ, Stegosystem°ú CryptosystemÀÇ Â÷ÀÌ
• À̹ÌÁö ½ºÅ×°¡³ë±×·¡ÇÇÀÇ ±âº», ½ºÅ×°¡³ë±×·¡ÇÇ
±â¼ú, ¿öÅ͸¶Å·(Wertermaking)
• Æ÷·»½Ä ŽÁö¿Í ºÐ¼®, ½ºÅ×°¡³ë±×·¡ÇÇÀÇ ºñÀ±¸®Àû
»ç¿ë ½ºÅ×°¡³ë±×·¡ÇÇ Åø(Fox Knox, Blindside,
S-Tools, Steghide, Image Hide µî),
ŽÁö Åø(Stego Watch, StegSpy µî) |
Module
16 |
Application
Password Cracker |
•ÆÐ½º¿öµå
¿ë¾î¼³¸í, Å©·¡Ä¿¶õ¼³¸í, ´Ù¾çÇÑ Å©·¡Å· ¹æ¹ý(Brute Force
Attack, Dictionary Attack, Syllable
Attack, Hybrid Attack µî), ÆÐ½º¿öµå Å©·¡Å·
Åø(Cain & Abel, LCP, SID&User,
Ophcrack 2, John the Ripper, Djohn
µî)
• Å©·¡Å· ¼ÒÇÁÆ®¿þ¾î ºÐ·ù, ½Ã½ºÅÛ/CMOS/¾ÖÇø®ÄÉÀ̼Ç
¼ÒÇÁÆ®¿þ¾î ÆÐ½º¿öµå Å©·¡Å·, µðÆúÆ® ÆÐ½º¿öµå µ¥ÀÌÅͺ£À̽º |
Module
17 |
Network
Forensics and Investigating Logs |
•³×Æ®¿öÅ©
Æ÷·»½Ä, ÇØÅ· ÇÁ·Î¼¼½º, ħÀÔ ÇÁ·Î¼¼½º, Áõ°Å°Ë»ö
• ·Î±×ÆÄÀÏÀÇ ÁøÀ§, Áõ°Å·Î¼ÀÇ ·Î±×ÆÄÀÏ, Á¤È®¼º,
ÇÕ¹ý¼º
• Chain of Custody, °¨»ç·Î±×ÀÇ
Á߿伺, Center LoggingÀ» ¼öÇàÇϱâ À§ÇÑ ´Ü°è, Syslog
Server, °¢Á¾ ·Î±×ºÐ¼® Åø (IISLogger, Socklog,
Firewall Analyzer µî)
• ÄÄÇ»ÅÍÀÇ ½Ã°£À» µ¿±âÈ ÇÏ´Â ÀÌÀ¯, NTF
ÇÁ·ÎÅäÄÝ, NTP Stratum Levels, NIST Time
Server |
Module
18 |
Investigating Network Traffic |
•³×Æ®¿öÅ©
ÁÖ¼Òü°è
• °¢Á¾ Åø
- TCPdump, Softperfect Network Sniffer,
HTTP Sniffer, EtherDetect Packet Sniffer,
OmniPeek, Iris Network Traffic, Analyzer,
SmartSniff µî |
Module
19 |
Investigating
Wireless Attacks |
•
¹«¼± AP¿Í µð¹ÙÀ̽º Á¶ÇÕ, ¹«¼± ³×Æ®¿öÅ©¸¦ À§ÇÑ ¼ö»ö¿µÀå,
¹«¼± °ø°ÝÀÇ Á¶»ç(¼ö»ç)
• ¹«¼± ³×Æ®¿öÅ©¸¦ Å×½ºÆ®¸¦ Çϱâ À§ÇØ ¾Ë¾Æ¾ß
µÉ Æ÷ÀÎÆ®
• ¹«¼± AP¸¦ ¾×¼¼½º Çϱâ À§ÇÑ ¹æ¹ý
- Nmap¸¦ »ç¿ëÇÑ ¹«¼± AP ½ºÄ³´×, Airodump¸¦
»ç¿ëÇÑ ½ºÄ³´×
• MAC ÁÖ¼ÒÀÇ Á¤º¸, MAC ÇÊÅ͸µÀ» À§ÇÑ
üũ, MAC ÁÖ¼ÒÀÇ º¯°æ, ¼öµ¿Àû/´Éµ¿Àû °ø°Ý |
Module
20 |
Investigating Web Attacks |
•À¥
°ø°ÝÀÇ Á¾·ù – ÄÚµåÁÖÀÔ °ø°Ý, ÆÄ¶ó¸ÞÅÍ ÅÛÆÛ¸µ,
ÄíŰ Æ÷ÀÌÁî´×, ¹öÆÛ ¿À¹öÇ÷οì, ÄíŰ ½ºÅõÇÎ, DMZ ÇÁ·ÎÅäÄÝ
°ø°Ý
• Å©·Î½º »çÀÌÆ® ½ºÅ©¸³ÆÃ(XSS) Á¶»ç, ¸®Äù½ºÆ®
Æ÷Àú¸®(CSRF)
• Á¦·Îµ¥ÀÌ °ø°Ý, FTP ħÀÔÀÇ Á¾·ù, ¾îÄí³×ƽ½º
À¥ Ãë¾ßÁ¡ ½ºÄ³³Ê, Ãë¾àŽÁö |
Module
21 |
Router
Forensic |
•¶ó¿ìÆÃ
Á¤º¸ ÇÁ·ÎÅäÄÝ, ÇØÅ· ¶ó¿ìÅÍ, ¶ó¿ìÅÍ °ø°Ý ÅäÆú·ÎÁö, ¼¼¼Ç ±â·Ï,
¶ó¿ìÅÍ ·Î±×
• °¢Á¾ ·Î±×ºÐ¼® Åø – Netgear
Router Logs, Link Logger, Sawnill
Real Time Forensic, Router Audit Tool |
Module
22 |
Investigating
Dos Attacks |
•¼ºñ½º°ÅºÎ(DoS)°ø°Ý°ú
Á¾·ù
• ºÐ»ê¼ºñ½º(DDoS) °ø°Ý°ú Á¾·ù
• ¼ºñ½º °ÅºÎ °ø°ÝÀ» ŽÁöÇϱâ À§ÇÑ ±â¼ú°ú µµÀü
°úÁ¦ |
Module
23 |
Investigating
Internet Crime |
•»çÀ̹ö
¹üÁË, ÀÎÅÍ³Ý Æ÷·»½Ä
• IP ÁÖ¼Ò, µµ¸ÞÀÎ ³×ÀÓ ½Ã½ºÅÛ(DNS),
DNS Lookup, À̸ÞÀÏ Çì´õ, URL Rdeirection
• À¥ÆäÀÌÁö·ÎºÎÅÍ Á¤º¸ º¹±¸, ½Ì±Û/À¥»çÀÌÆ® Àüü
´Ù¿î·Îµå, HTTP Çì´õ/Çì´õÁ¤º¸, ÄíŰÁ¶»ç – NetScan
Tools Pro »ç¿ë |
Module
24 |
Tracking
E-mails and Investigation E-mail Crimes |
•À̸ÞÀÏ¿¡¼
Ŭ¶óÀÌ¾ðÆ®¿Í ¼¹ö, ½ÇÁ¦ À̸ÞÀÏ ½Ã½ºÅÛ, À̸ÞÀÏ °ü·Ã ¹ý±Ô
• Çì´õÀÇ Á¾·ù, MailDetective Tool,
FTK, e-Mail Detective, ¾Æ¿ô·è¿¡¼ À̸ÞÀÏ º¹±¸ |
Module
25 |
Investigating
Corporate Espionage |
•
»ê¾÷½ºÆÄÀÌ, »ê¾÷½ºÆÄÀÌ µ¿±â, ã´Â Á¤º¸, ¹æ¾î, ÄÉÀ̽º Á¶»ç(¼ö»ç)
• ³»ºÎ/¿ÜºÎ À§Çù, ½ºÆÄÀ̱â¼ú, Netspionage,
Á÷¿ø ¸ð´ÏÅ͸µ, ½ºÆÄÀÌÅø(SpyBuddy) |
Module
26 |
Investigating
Trademark and Copyright Infringement |
•Æ®·¹À̵å
¸¶Å©, Æ®·¹À̵帶ũÀÇ Æ¯Â¡, ÇýÅÃ, Ä§ÇØ
• ÀúÀÛ±Ç Ä§ÇØ(Ç¥Àý), Ç¥Àý ŽÁö Åø –
Turtin, CopyCatch, COPS, SCAM, CHECK,
Jplag, VAST, PLAGUE µî
• ±¹°¡º° Æ®·¹À̵帶ũ, ÀúÀÛ±Ç ¹ý·ü |
Module
27 |
Investigating
sexually harassment incidents |
•¼ºÈñ·Õ,
Á¾·ù, °á°ú, »ó»çÀÇ Ã¥ÀÓ, Á÷¿øÀÇ Ã¥ÀÓ
• ºÒ¸¸Ã³¸® ÀýÂ÷, Á¶»çó¸® ÀýÂ÷, ¼ºÈñ·Õ Á¤Ã¥,
¿¹¹æ Á¤Ã¥, °ü·Ã ¹ý±Ô |
Module
28 |
Investigating
Child Pornography |
•¾Æµ¿
À½¶õ¹°, µ¿±â, ¿¬·çµÈ »ç¶÷µé, È«º¸Çϱâ À§ÇÑ ÀÎÅͳÝÀÇ ¿ªÇÒ,
¸®Æ÷Æ®, °ü·Ã ¹ý±Ô
• ¾Æµ¿ À½¶õ¹° È®»êÀ» ¿¹¹æÇϱâ À§ÇÑ µµÀü °úÁ¦,
Á¶»çÇϱâ À§ÇÑ °¡ÀÌµå ¶óÀÎ
• µðÁöÅÐ Áõ°ÅÀÇ ¼Ò½º, Antichilporn.org,
°¢Á¾ °ü·Ã Åø |
Module
29 |
PDA
Forensics |
•
PDA(Personal Digital Assistant ) Á¤ÀÇ,
Ư¡
• PDA Æ÷·»½Ä : Á¶»ç → È®ÀÎ →
¼öÁý → ¹®¼È
• Á¶»ç ¹æ¹ý
- Secure the Evidence, Acguire the
Evidence, Examin the Evidence, Present
the Evidence, Maintain the Evidence
• Æ÷·»½Ä Åø – PDASecure,
PDA Seizure(Paraben), Encase ¤§d |
Module
30 |
iPod
Forensics |
•
iPod, iTunes
• iPodÀÇ À߸øµÈ »ç¿ë, Æ÷·»½Ä ¼öÇà ÀýÂ÷,
¾Ð¼öµÈ iPodÀÇ º¸°ü
• iPod ÆÄÀϽýºÅÛ, ¾ÖÇø®ÄÉÀÌ¼Ç Æ÷¸Ë, À©µµ¿ì
¹öÀüÀÇ iPod, iPodÀÇ »ç¿ëÀÚ °èÁ¤ / ´Þ·Â ¹× ¿¬¶ôó
/ »èÁ¦µÈ ÆÄÀÏ |
Module
31 |
Blackberry
Forensics |
•ºí·¢º£¸®ÀÇ
Ư¡, ¿î¿µÃ¼Á¦·Î¼ ºí·¢º£¸®, ÀÛµ¿¿ø¸®
• ºí·¢º£¸®ÀÇ º¸¾È, Áõ°Å¼öÁý, Áõ°ÅÀÇ °ËÅä
• ºí·¢º£¸® °ø°Ý, µ¥ÀÌÅÍÀÇ º¸È£, µ¥ÀÌÅÍÀÇ ÀºÆó |
Module
32 |
Investigative Reports |
•¸®Æ÷Æ®ÀÇ
Á߿伺 ¹× Á¶»ç(¼ö»ç) ¸®Æ÷Æ®ÀÇ Çʿ伺
• ¸®Æ÷Æ® ³»¿ª, ºÐ·ù, ·¹À̾ƿô, ¸®Æ÷Æ® ÀÛ¼ºÀ»
À§ÇÑ °¡ÀÌµå ¶óÀÎ, º¸Á¶ÀÚ·áÀÇ È°¿ë
• Àϰü¼ºÀÇ Á߿伺, ÁÁÀº ¸®Æ÷Æ®ÀÇ Æ¯Â¡, Á¶»ç(¼ö»ç)¿ë
¸®Æ÷Æ® Æ÷¸Ë, ÀÛ¼º Àü Áغñ»çÇ×, FTK »ç¿ëÇÑ ¸®Æ÷Æ® ÀÛ¼º |
Module
33 |
Becoming
an Expert Witness |
•Àü¹®°¡
ÁõÀÎ, Àü¹®°¡ ÁõÀÎÀÇ ¿ªÇÒ, Àü¹®°¡ ÁõÀÎÀÇ Á¾·ù
• Áõ¾ð ÁغñÀÇ Á߿伺, ¹ýÁ¤ Áõ¾ðÀÇ Á߿伺,
Á÷Á¢/¹Ý´ë½É¹® µ¿¾È Áõ¾ðÀÇ Á߿伺
• ÀÚ°ÝÀ» °®Ãá Àü¹®°¡ ÁõÀÎÀ» À§ÇÑ ±ÔÄ¢ ÀÌÇØ,
±â¼úÀû/Àü¹®Àû Áõ¾ðÀÇ ºñ±³ ,Áõ°Å¸¦ ó¸®Çϱâ À§ÇÑ ´Ü°è ÀÌÇØ,
Áõ°Å ¹®¼ÈÀÇ Á߿伺, À±¸®¿¡ ´ëÇÑ ÀÌÇØ, ¹Ìµð¾î ´ëóÀÇ Á߿伺
• Case Studies : 15 °¡ÁöÀÇ ÄÉÀ̽º
»ùÇÃ |
|
|
|
 |
|
 |
| |
|
|
|
|
 |
|
| |
|