박정흠 교수
Jungheum Park
고려대학교 정보보호대학원 · 컴퓨터과학
연구실 소개
박정흠 교수의 연구실은 디지털 증거의 신뢰성과 확보를 핵심으로 삼아, 차량용 데스크탑 카메라(Dashcam)의 메타데이터 분석, 클라우드 스토리지 및 네트워크 저장장치(NAS)에서의 디지털 포렌식 기법 개발, 전자문서 간의 관계 분석 기술, 그리고 증거 훼손 방지를 위한 사례 추적 기술을 연구하고 있습니다. 특히 실시간 데이터 추적과 분석을 통해 디지털 범죄의 진상 규명에 기여할 수 있는 체계적인 포렌식 프로세스를 개발하고 있습니다. 이는 디지털 증거의 보존과 해석에 있어 기술적·법적 한계를 극복하고자 하는 학문적 도전입니다.
연구 현황
연구 성과 추이
표시된 성과는 수집된 데이터 기준으로 산출되며, 일부 차이가 있을 수 있습니다.
주요 논문
15Dashcam as an on-board camera is useful as a source of potential digital evidence not only to reveal the truth of a traffic accident but also to explain the situation of a crime scene as a moving surveillance camera. It stores multimedia data as well as a variety of additional information needed for accident investigation including time, location, speed, accelerometer, etc. Under these circumstances, various studies have been conducted for dashcam forensics, but most of them focused mainly on ex
With the development of Internet technology, cloud-based services have improved the availability and usability of resources. Among them, cloud storage services enable users to remotely store, access, or share data over a network. Therefore, digital forensic investigators need to collect data stored in remote servers to comprehensively understand a suspect's activities. Although several well-known commercial digital forensic tools provide features for cloud data acquisition in order to support th
Spoliation of evidence is a critical concern in various crimes such as information leakage, digital sexual crimes, accounting fraud, and copyright infringement. Several traditional digital forensic investigation methods such as recovery, carving, and anti-forensic behavior tracking are used to investigate these crimes. However, as technology has advanced, recovery and carving have become increasingly challenging. Shortly, data recovery will reach its technological limit, and it will be essential
Network-attached storage (NAS) is a system that uses a redundant array of disks (RAID) to create virtual disks comprising multiple disks and provide network services such as FTP, SSH, and WebDAV. Using these services, the NAS's virtual disks store data about individuals or groups, making them a critical analysis target for digital forensics. Well-known storage manufacturers like Seagate, Synology, and NETGEAR use Linux-based software RAID, and they usually support Berkeley RAID (e.g., RAID 0, 1,
Electronic documents often contain personal or confidential information, which can be used as valuable evidence in criminal investigations. In the digital investigation, special techniques are required for grouping and screening electronic documents, because it is challenging to analyze relationships between numerous documents in storage devices manually. To this end, although techniques such as keyword search, similarity search, topic modeling, metadata analysis, and document clustering are con
The fields of health care, education, culture, and shopping can all be integrated into the core of a smart city to create an infrastructure that allows people to live more conveniently. We must think ahead about cybersecurity, as cyberattacks can threaten the lives of citizens.
The web browsing activities of a user provide useful evidence for digital forensic investigations. However, existing analysis techniques that aim to analyze local artifacts (e.g., history and cache) cannot find useful data (e.g., visited URLs) if a user accesses the web using private or secret mode. Hence, string-searching and pattern-matching techniques have been proposed and used to examine user activities from a memory dump. These simple techniques are useful for identifying individual URLs v
대표 연구 분야
박정흠 교수의 연구를 Nubint에서 더 깊이 살펴보세요
이 연구실의 논문을 앱에서 열어 AI와 함께 읽고, 핵심을 요약하고, 내 글에 인용하세요.