Publications

Detailed Information

디지털 포렌식 절차 모델에 대한 새로운 접근

DC Field Value Language
dc.contributor.advisor이상원-
dc.contributor.author김지홍-
dc.date.accessioned2017-07-19T11:00:12Z-
dc.date.available2017-07-19T11:00:12Z-
dc.date.issued2015-08-
dc.identifier.other000000056799-
dc.identifier.urihttps://hdl.handle.net/10371/133269-
dc.description학위논문 (석사)-- 서울대학교 융합과학기술대학원 : 융합과학기술대학원 수리정보과학과(디지털포렌식학전공), 2015. 8. 이상원.-
dc.description.abstract현대 사회는 디지털 기기 사용의 급증으로 인하여, 거의 모든 생활에 디지털 데이
터가 사용된다. 자연스럽게 수사기관도 디지털 데이터에 관심을 가지게 되었고, 이
제 디지털 데이터 없이는 범죄 입증이 어렵게 되는 시대에 이르렀다. 하지만, 디지
털 데이터는 기존의 유체물과 다른 특징이 있어 압수에 여러 가지 주의점이 요구된
다.
그러므로 어떠한 절차로 디지털 데이터를 압수하면 수사의 목적을 달성할 수 있는
지를 규정하는 것이 중요한데, 이를 디지털 포렌식 절차 모델이라 한다. 디지털 포
렌식은 기술적인 부분뿐만 아니라, 법률적인 부분이 함께 고려해야 하기 때문에 각
국의 법률적인 특징에 따라 달라질 수밖에 없다.
2012. 1. 1. 시행된 개정 형사소송법은 디지털 데이터의 압수에 대하여 명문으로 규
정하였다. 디지털 데이터 압수 원칙이 기존 실무인 정보저장매체 자체의 압수에서
사건과 관련된 디지털 데이터 압수로 바뀌는 큰 변화였다. 그러나 아직 개정 형사
소송법에 대하여 규정에 대한 논의는 많이 있지만, 실제 이를 준수하면서 어떻게
디지털 데이터를 압수해야 하는지에 대한 연구는 거의 없다.
본 논문은 디지털 포렌식 절차 모델과 국내외 디지털 포렌식 현황을 살펴보고, 수
사기관 특히, 검찰의 디지털 포렌식 절차를 고찰하면서, 새로운 디지털 포렌식 절차
모델을 제시해보고자 한다.
우리나라의 경우 수사기관인 경찰과 검찰을 중심으로 디지털 포렌식 기관이 있고,
디지털 포렌식 절차는 형사소송법 개정 이전에 형성된 판례의 이론에 기초로 하고
있으나, 이는 개정 형사소송법의 태도에 반하는 부분이 있어 판례 변경이 필요하다.
한편, 검찰은 디지털 수사망(Digital Investigation Network)이라는 시스템을 구축하
여 디지털 데이터의 대용량화와 효율적인 디지털 압수물의 활용을 하고 있다.
검찰의 디지털 포렌식 절차는 원칙적으로 압수·수색 준비, 압수·수색 현장에서 정보
저장매체 수색, 수색한 정보저장매체에서 사건과 관련된 디지털 데이터 조사, 사건과 관련된 디지털 데이터의 획득(예외적인 경우 정보저장매체 전체를 이미징하거나,
정보저장매체 자체를 압수), 문서화, 디지털 압수물 시스템에 업로드, (예외적인 경
우 분석), 색인, 수사팀에서 검색, 분석, 디지털 압수물 폐기의 순이다.
디지털 데이터는 압수의 대상이고, 피압수자의 협력의무는 명문의 규정이 필요하고,
원격지 압수·수색은 필요성은 있으나, 허용 범위나 방법 등 아직 논의가 더 필요하
며, 현장용 디지털 포렌식 도구가 갖추어야 할 기능을 발전시켜야 할 필요가 있겠
다. 형사소송법 제106조 제3항에 따라 정보저장매체 자체를 압수하면 압수·수색 영
장의 집행은 종료되므로 법원의 디지털 데이터 압수에 대한 태도는 형사소송법 개
정으로 변경되어야 한다.
우리나라의 현실에 맞는 디지털 포렌식 절차를 제시하면, 준비(Preparation) → 정보
저장매체 수색(Search) → 조사(Examination) → 사건과 관련된 디지털 데이터 획득
(Acquisition) → 1차 분석(1st Analysis) → 시스템 업로드, 색인 (System Upload &
Index) → 2차 분석(2nd Analysis) → 제출(Presentation) → 디지털 압수물 폐기
(Disposal) 순이다.
최근의 해외 동향을 보면, 디지털 포렌식 절차가 피압수자의 권리 보호를 강화하는
방향으로 나아가고 있는 것으로 보인다. 우리나라의 디지털 포렌식 관련 형사소송
법 규정은 우리나라에만 있는 이상한 규정이 아니라, 우리나라에서 최초로 규정
된 선진적인 규정인 것이다. 그러므로 수사기관은 형사소송법 개정으로 과거에 비
하여 디지털 데이터 압수가 어렵고, 효과적이지 못하다고 불만을 늘어놓을 것이 아
니라, 피압수자의 권리를 보호하면서 수사의 목적을 달성하기 위하여 디지털 포렌
식 절차를 확립하는 것이 필요하다.
-
dc.description.tableofcontents국문초록 ··················································································· 1
제1장 서설 ················································································· 1
제1절 연구 배경 ······················································································ 1
제2절 연구 목적 ······················································································ 2
제3절 연구 방법 ······················································································ 2
제2장 디지털 포렌식의 의의 ················································· 5
제1절 디지털 증거의 의의 및 특징 ·················································· 5
1. 디지털 데이터의 의의 ························································································································ 5
2. 디지털 증거의 의의 ···························································································································· 5
가. 디지털 형태의 정보 ·························································································································· 6
나. 저장 전송되는 정보 ·························································································································· 6
다. 증거가치 있는 정보 ·························································································································· 6
3. 디지털 증거라는 용어 사용 문제 - 디지털 압수물 ································································· 7
제2절 디지털 압수물의 특징 ································································ 8
1. 매체독립성 ·········································································································································· 8
2. 비가시성 ················································································································································ 8
3. 취약성 ···················································································································································· 8
4. 대량성 ···················································································································································· 9
제3절 디지털 포렌식의 의의 ································································ 9
1. 포렌식 사이언스(Forensic Science)의 의의 ··············································································· 9
2. 디지털 포렌식(Digital Forensics)의 의의 ················································································· 10
3. 디지털 포렌식의 기본 원칙 ··········································································································· 10
가. 적법절차의 원칙 ······························································································································ 11
나. 동일성, 무결성 유지 ······················································································································ 11
다. 재현의 원칙 ······································································································································ 15
라. 신속성의 원칙 ·································································································································· 15
제3장 기존의 디지털 포렌식 절차 모델 ··························· 16
제1절 디지털 포렌식 절차 모델 ························································ 16
제2절 구체적인 디지털 포렌식 절차 모델 ······································ 16
1. 1995.~2003.의 디지털 포렌식 절차 모델 ················································································· 16
가. Computer Forensic Investigative Process (1995) ···························································· 16
나. DFRWS Investigative Model (2001) ······················································································ 17
다. Abstract Digital Forensics Model (ADFM) (2002) ··························································· 18
라. Integrated Digital Investigation Process (IDIP) (2003) ·················································· 19
2. 2004.~2007.의 디지털 포렌식 절차 모델 ················································································· 21
가. Enhanced Digital Investigation Process Model (EDIP) (2004) ···································· 21
나. Hierarchical Objectives based Framework(2004) ····························································· 21
다. Computer Forensics Field Triage Process Model(2006.) ············································· 22
라. Framework for a Digital Forensic Investigation(2006) ·················································· 23
마. Common Process Model for Incident and Computer Process(2007) ························ 24
3. 2008.~ 현재 디지털 포렌식 절차 모델 ······················································································ 25
가. Digital Forensic Model based on Malaysian Investigation Process(2009) ·············· 25
나. Systematic Digital Forensic Investigation Model(2011) ················································· 26
다. New Approach of Digital Forensic Model for Digital Forensic Investigation(2011) ···································27
라. Harmonized Digital Forensic Investigation Process Model(2012) ······························ 27
마. Integrated Digital Forensic Process Model (2013) ························································· 28
제3절 실무상 디지털 포렌식 절차 ···················································· 28
제4절 소결 ······························································································ 29
제4장 해외 디지털 포렌식 현실 ········································· 30
제1절 외국의 디지털 포렌식 기관 ···················································· 30
1. NIJ(National Institute of Justice) ······························································································ 30
2. NIST (National Institute of Standard and Technology) ··················································· 30
3. RCFL (Regional Computer Forensics Laboratory) ····························································· 31
4. DCFL (Defense Computer Forensics Laboratory) ····························································· 31
5. 네덜란드의 NFI (Netherlands Forensic Institute) ································································ 32
제2절 외국의 디지털 포렌식 관련 현실 ·········································· 32
1. 미국의 디지털 포렌식 관련 현실 ································································································· 32
가. 입법례 ················································································································································ 32
(1) 디지털 데이터가 압수의 대상인지 여부 ··················································································· 32
(2) 관련 규정 ········································································································································· 33
나. 디지털 포렌식 절차 관련 ·············································································································· 33
2. 사이버범죄방지조약 ························································································································· 34
가. 사이버범죄방지조약 ························································································································ 34
나. 사이버범죄방지조약의 내용 ·········································································································· 34
3. 영국의 디지털 포렌식 현실 ··········································································································· 35
가. 입법례 ················································································································································ 35
나. 영국의 디지털 포렌식 절차 ·········································································································· 37
4. 독일의 디지털 포렌식 현실 ··········································································································· 37
가. 입법례 ················································································································································ 37
나. 독일의 디지털 포렌식 절차 ·········································································································· 37
5. 소결 ····················································································································································· 38
제5장 우리나라 디지털 포렌식 현실 ································· 39
제1절 디지털 포렌식 관련 기관 ························································ 39
1. 대검찰청 디지털수사과 ··················································································································· 39
2. 경찰청 사이버 안전국 ····················································································································· 40
3. 기타 수사기관 ··································································································································· 40
제2절 디지털 포렌식 절차 ·································································· 40
1. 디지털 포렌식 절차 ························································································································· 40
가. 경찰 ···················································································································································· 40
나. 검찰 ···················································································································································· 41
2. 형사소송법 개정 전의 디지털 포렌식에 대한 법원의 태도 ··················································· 41
가. 전교조 압수·수색 준항고 기각 결정에 대한 재항고 결정(대법원 2011. 5. 26.자 2009모
1190결정) ················································································································································ 41
나. 압수·수색 영장 별지 ······················································································································ 42
3. 형사소송법 개정 ······························································································································· 42
4. 검토 ····················································································································································· 43
제3절 현재 수사기관에서의 디지털 포렌식 절차 ························ 43
제4절 디지털수사망(Digital Investigation Network, D-NET) 44
1. 디지털 포렌식 관련 시스템 구축 필요성 ··················································································· 44
2. 디지털수사망 구축 ··························································································································· 45
3. 디지털수사망 개요 ··························································································································· 45
4. 각 시스템의 구체적 내용 ··············································································································· 47
가. DFIS II ·············································································································································· 47
나. 디지털증거관리시스템 ···················································································································· 48
다. 통합디지털증거분석시스템(IDEAS) ···························································································· 49
(1) 주요인물 등록 ································································································································· 50
(2) 파일 분석 등 동종의 디지털 압수물 분석 ··············································································· 50
(3) 통합상관도 ······································································································································· 51
5. NFI의 XIRAF ···································································································································· 53
가. 개요 ···················································································································································· 53
나. XIRAF의 특징 ································································································································· 54
다. 검토 ···················································································································································· 55
제6장 검찰의 디지털 포렌식 절차 ····································· 56
제1절 압수·수색 준비 ··········································································· 57
1. 압수·수색을 위한 정보 수집 ·········································································································· 57
2. 영장 청구서 작성 ····························································································································· 57
3. 디지털 포렌식 수사지원요청 ········································································································· 57
가. 사전 협의 ·········································································································································· 58
나. 지원 요청 ·········································································································································· 58
4. 디지털 데이터가 압수 대상인지 여부에 대한 문제 ································································· 58
가. 견해의 대립 ······································································································································ 59
(1) 긍정설 ··············································································································································· 59
(2) 부정설 ··············································································································································· 60
나. 법원의 태도 ······································································································································ 60
다. 검토 ···················································································································································· 60
제2절 압수·수색 현장에서 정보저장매체 수색 ······························· 61
1. 현장 촬영 및 통제 ··························································································································· 61
2. 압수·수색 대상 특정 ························································································································ 62
3. 피압수자 등 관련자의 협조 ··········································································································· 62
4. 원격지에 저장된 디지털 데이터에 대한 압수·수색의 문제 ·················································· 62
5. 피압수자 등의 협력 문제 ··············································································································· 63
가. 협력의무의 내용 ······························································································································ 64
나. 협력의무 명문의 규정 필요성 ······································································································ 64
(1) 보전의무 ··········································································································································· 64
(2) 제출의무 ··········································································································································· 65
(3) 협의의 협력의무 ····························································································································· 65
다. 검토 ···················································································································································· 66
제3절 정보저장매체에서 사건과 관련된 디지털 데이터 조사 ···· 66
1. 현장용 디지털 포렌식 도구의 문제 ····························································································· 68
가. 현장용 디지털 포렌식 도구의 요건 ···························································································· 68
(1) 정보저장매체의 확인 ····················································································································· 68
(2) 데이터 수색 준비 단계(저장매체 분리) ···················································································· 68
(3) 안티포렌식 탐지·분석 단계 ·········································································································· 69
(4) 전체·선별 복사 단계 ······················································································································ 70
2. 디지털 증거 수집도구별 기능 비교 ····························································································· 70
3. 검토 ····················································································································································· 72
제4절 사건관련 파일 복제, 목록 작성 교부, 확인서 ···················· 73
1. 구체적인 절차 ··································································································································· 73
2. 진정성, 무결성을 인정하기 위한 조치 ························································································ 73
제5절 복제한 디지털 압수물 업로드 및 색인 ································ 74
1. 시스템에 디지털 압수물을 업로드 하는 행위에 대한 문제 ··················································· 75
제6절 일선 수사부서에서의 검색, 출력, 복제 ································ 76
제7절 사건 종료 후 디지털 압수물의 처리 ···································· 76
제8절 예외적인 경우 디지털 포렌식 절차 ······································ 77
1. 예외적인 경우의 세부 절차 ··········································································································· 78
가. 압수할 정보저장매체의 분리 및 저장매체·정보시스템 압수 확인서 작성 ························ 78
나. 이미지 파일 생성 및 업로드와 정보저장매체의 환부, 가환부 ············································ 79
다. 이미지 파일 분석, 분석한 디지털 데이터 업로드 ·································································· 79
2. 형사소송법 제106조 제3항 단서의 해석 문제 ·········································································· 79
가. 문제점 ················································································································································ 79
나. 견해의 대립 ······································································································································ 80
다. 법원의 태도 ···································································································································· 80
라. 검토 ···················································································································································· 81
(1) 압수방법의 문제 ····························································································································· 81
(2) 비례의 원칙 적용 ··························································································································· 81
(3) 소결 ··················································································································································· 82
3. 형사소송법 제106조 제3항의 개정필요성 ·················································································· 84
가. 문제점 ················································································································································ 84
나. 입법례 ················································································································································ 84
(1) 미국 연방형사소송규칙 제41조(e)(2)(B) ·················································································· 84
(2) EU 사이버범죄 방지협약 ·············································································································· 84
다. 견해의 대립 ······································································································································ 85
(1) 개정 필요설 ····································································································································· 85
(2) 개정 불요설 ····································································································································· 86
라. 검토 ···················································································································································· 86
4. 형사소송법 제106조 제3항 단서의 판단기준 ············································································ 87
가. 문제점 ················································································································································ 87
나. 판단기준 ············································································································································ 87
다. 검토 ···················································································································································· 89
5. 형사소송법 제106조 제3항 단서의 판단시기 ············································································ 89
6. 사건과 관련된 디지털 데이터를 조사하는 행위의 법적 성질 ··············································· 91
가. 문제점 ················································································································································ 91
나. 견해의 대립 ······································································································································ 91
(1) 수색론 ··············································································································································· 91
(2) 2단계 수색론 ··································································································································· 91
(3) 정보 확인절차론 ····························································································································· 92
다. 검토 ···················································································································································· 92
7. 분석에 별도의 영장이 필요한지 여부 ························································································· 92
가. 문제점 ················································································································································ 92
나. 견해의 대립 ······································································································································ 93
다. 법원의 태도 ······································································································································ 94
라. 검토 ···················································································································································· 94
8. 참여의 문제 ······································································································································· 95
가. 문제점 ················································································································································ 95
나. 입법례 ················································································································································ 95
다. 참여의 일반론 ·································································································································· 96
라. 디지털 데이터 압수와 관련된 참여 ···························································································· 97
마. 검토 ···················································································································································· 97
제7장 디지털 포렌식 모델에 대한 새로운 접근 ············· 99
제1절 현재 우리나라 디지털 포렌식 절차 ······································ 99
1. 디지털 포렌식 관련 쟁점 ··············································································································· 99
2. 디지털 포렌식 절차 ······················································································································· 100
제2절 우리나라 디지털 포렌식 절차의 특징 ······························· 100
1. 압수·수색 방법에 따른 특징 ········································································································ 101
2. 각 절차별 확인 ····························································································································· 101
3. 디지털 포렌식 절차에 일선 수사팀의 역할 ············································································· 101
4. 디지털 압수물의 폐기 ··················································································································· 102
제3절 우리나라의 현실에 맞는 디지털 포렌식 절차 모델 제시
102
1. 기존의 디지털 포렌식 절차 모델 ······························································································· 102
2. 디지털 포렌식 절차 모델 제시 ··································································································· 103
가. 새로운 디지털 포렌식 절차 모델 제시 ··················································································· 103
나. 디지털 포렌식 절차 모델의 세부 설명 ··················································································· 104
(1) 준비(Preparation) 단계 ·············································································································· 104
(2) 수색(Search) 단계 ······················································································································· 104
(3) 조사(Examination) 단계 ············································································································· 105
(4) 획득(Acquisition) 단계 ··············································································································· 106
(5) 1차 분석(1st Analysis) 단계 ···································································································· 107
(6) 시스템 업로드 및 색인(System Upload & Index) 단계 ··················································· 107
(7) 2차 분석(2nd Analysis) ············································································································ 107
(8) 제출(Presentation) 단계 ············································································································ 107
(9) 폐기(Disposal) 단계 ···················································································································· 107
제8장 결론 ············································································ 109
참고문헌 ··············································································· 113
Abstract ················································································117
-
dc.formatapplication/pdf-
dc.format.extent14233649 bytes-
dc.format.mediumapplication/pdf-
dc.language.isoko-
dc.publisher서울대학교 융합과학기술대학원-
dc.subject디지털 증거-
dc.subject디지털 압수물-
dc.subject디짙철 포렌식 절차 모델-
dc.subject.ddc510-
dc.title디지털 포렌식 절차 모델에 대한 새로운 접근-
dc.typeThesis-
dc.contributor.AlternativeAuthorJeehong, Kim-
dc.description.degreeMaster-
dc.citation.pages12, 119-
dc.contributor.affiliation융합과학기술대학원 수리정보과학과-
dc.date.awarded2015-08-
Appears in Collections:
Files in This Item:

Altmetrics

Item View & Download Count

  • mendeley

Items in S-Space are protected by copyright, with all rights reserved, unless otherwise indicated.

Share