ãã®èšäºã§ã¯ãã³ã³ãã¥ãŒã¿ãŒãã©ã¬ã³ãžãã¯ïŒãã©ã¬ã³ãžãã¯ïŒã§æ å ±ãã£ãªã¢ã®ã³ããŒïŒã€ã¡ãŒãžïŒãäœæããããŸããŸãªæ¹æ³ã®ããã€ãã®æ©èœã«ã€ããŠèª¬æããŸãã ãã®èšäºã¯ãISã€ã³ã·ãã³ãã«å¯Ÿå¿ããå éšèª¿æ»ãå®æœããæ å ±ã»ãã¥ãªãã£éšéã®åŸæ¥å¡ã«åœ¹ç«ã¡ãŸãã ã³ã³ãã¥ãŒã¿ãŒæè¡ã®å°é家ïŒä»¥äžãCTEïŒãå®æœããæ³å»åŠã®å°é家ããæ°ããçºèŠãæåŸ ããŠããŸãã
åŒçšç¬Šã§å§ããã«ã¯ïŒ
èè ã¯ãCHPäžã«å ã®ãã£ãªã¢ã調æ»ããããšã¯äžè¬ã«æãŸãããªããšèããŠããŸãïŒãããŠå€ãã®ç 究è ã¯ããã«åæããŠããŸãïŒã æ å ±ã®äžå€æ§ãä¿èšŒããç¹°ãè¿ããŸãã¯è¿œå ã®æ€æ»ã®å¯èœæ§ãæ®ãããã«ãå ã®æ å ±ããã®ãŸãŸæ®ãå¿ èŠããããŸãã ãããŠããã¹ãŠã®ç 究ã¯ãã®ã³ããŒã§è¡ãããã¹ãã§ãã ããã¯ãä¿¡é Œæ§ãé«ãã ãã§ãªãããã䟿å©ã§ããããŸãããªããªããå°é家ãæã£ãŠããããŒã«ã«ããé©ããã¡ãã£ã¢ã§ã³ããŒãäœæã§ããããã§ãã
N.N. ãã§ãããã ãã©ã¬ã³ãžãã¯-ã³ã³ãã¥ãŒã¿ãŒãã©ã¬ã³ãžãã¯
äœæãããç»åãæ³å»åŠçã«ä¿¡é Œã§ãããã®ã§ããããã«ã¯ããŸããäœæã®éçšã§ãã¹ãåªäœã®å 容ãå€æŽããªãããšãå¿ èŠã§ãã次ã«ãæœåºåŸãã€ã¡ãŒãžã¯ãã¹ãåªäœã«ãããåäœã§å¯Ÿå¿ããå¿ èŠããããŸãã ãã®ãããªã€ã¡ãŒãžã«ã¯ãã©ã€ããã¡ã€ã«ã ãã§ãªãããµãŒãã¹ããŒã¿ããã¡ã€ã«ã·ã¹ãã ã®ç©ºãé åãããã³ãã¡ã€ã«ã·ã¹ãã ã«ãã£ãŠå²ãåœãŠãããŠããªãé åãå«ãŸããŸãã
ãã£ã€ãã·ã§ããã®è±¡ã®ããã«ã調æ»äžã®ã¡ãã£ã¢ãéåžžã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ïŒOSïŒã«æ¥ç¶ãããšãå ã«æ»ããªããªããŸããæšæºæ§æã§ã¯ãOSã¯æ€åºåŸããã«ããã€ã¹ãã¢ã¯ãã£ãã«ãããã¡ã€ã«ã·ã¹ãã ãããŠã³ããããŠãŒã¶ãŒã«ç¢ºèªããã«ãã®å 容ãå€æŽããŸãã ããšãã°ãWindowsã¯ãå¿ èŠã«å¿ããŠãã¡ã€ã«å±æ§ã®ã¿ã€ã ã¹ã¿ã³ããå€æŽãïŒå Žåã«ãã£ãŠïŒãé衚瀺ã®ãã¿ç®±ãã©ã«ããŒãäœæããæ§ææ å ±ãä¿åããŸãã
ã¡ãã£ã¢äžã®æ å ±ã®å€æŽãé²ãã«ã¯ãããŒããŠã§ã¢ãŸãã¯ãœãããŠã§ã¢ã®2ã€ã®æ¹æ³ããããŸãã
ããŒããŠã§ã¢ã¬ã³ãŒãããã¯
ç§ã¯ããŒããŠã§ã¢ãœãªã¥ãŒã·ã§ã³ãæ±ã£ãŠããŸããã§ããããã€ã³ã¿ãŒãããããå°ãçè«ã説æããŸãã 調æ»å¯Ÿè±¡ã®ã¹ãã¬ãŒãžã¡ãã£ã¢ãã³ã³ãã¥ãŒã¿ãŒã«æ¥ç¶ããããã®ã¬ã³ãŒãããã¯ïŒããªããžïŒãããã調æ»å¯Ÿè±¡ã®ãã£ã¹ã¯ã®å®å šãªã³ããŒãšã€ã¡ãŒãžãèªåŸçã«äœæã§ããè€è£œæ©ããããŸãã
ã¬ã³ãŒããããã«ãŒã¯ãOSããã®èšé²ã³ãã³ããã€ã³ã¿ãŒã»ããããã¹ãã¬ãŒãžã¡ãã£ã¢ãžã®éä¿¡ãé²ããŸãã å¯èœãªå Žåã¯åžžã«ãããã€ã¹ãèªã¿åãå°çšã¢ãŒãã§æ¥ç¶ãããŠããããšãOSã«éç¥ããŸããããã§ãªãå Žåã¯ãOSã«æžã蟌ã¿ãšã©ãŒãéç¥ããã ãã§ãã äžéšã®ããã€ã¹ã¯ãå èµã¡ã¢ãªã䜿çšããŠèšé²ãããããŒã¿ããã£ãã·ã¥ãããã£ã¹ã¯äžã®ããŒã¿ãå®éã«å€æŽãããããã«èŠããããã«ããŸãã
ããŒããŠã§ã¢ãœãªã¥ãŒã·ã§ã³ã«ã¯ç¢ºãã«å©ç¹ããããŸãããæ¬ ç¹ããããŸãã
å®ãã¯ãããŸããã ããšãã°ãT35uæžã蟌ã¿ããã¯ã®åžæå°å£²äŸ¡æ Œã¯349.00ãã«ãTableau TD2uãã¥ããªã±ãŒã¿ãŒã¯1,599.00ãã«ã§ãã
- ãããŠã圌ãã¯å®ç§ã§ã¯ãããŸããã ããŒããŠã§ã¢ããã€ã¹ãããã€ã¹ãžã®æžã蟌ã¿ã³ãã³ããã¹ãããããããšããããŸããïŒ äŸ ïŒã
ãã©ã¬ã³ãžãã¯ããŒããã£ã¹ã¯
é åãåæ£ããŠããäŒæ¥ã§ã¯ã ãœãããŠã§ã¢ã®æ€èšŒã¯é¿ããããŸããïŒç¹ã«ITäºç®ã®ååãäžèŠãªéã«åå²ããããªãå ŽåïŒã ãœãããŠã§ã¢ãœãªã¥ãŒã·ã§ã³ã¯ã倧éã®ã€ã³ã·ãã³ããçºçããå Žåã«æéãç¯çŽããŸããã³ã³ãã¥ãŒã¿ãŒã®èª¿æ»ã«å¿ èŠãªæ°ã®ããŒãå¯èœãªãã©ãã·ã¥ãã©ã€ããäœæãããã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒã§åæã«ã€ã¡ãŒãžã®äœæãéå§ã§ããŸãã ãããã®ããŒãå¯èœãªãã©ãã·ã¥ãã©ã€ãã«ã©ã®ãããªãœãããŠã§ã¢ãé 眮ãããã決å®ããã ãã§ãã
Linuxãã£ã¹ããªãã¥ãŒã·ã§ã³
å€ãã®ç¹æ®ãªLinuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã®1ã€ã§ã€ã¡ãŒãžãæ®ãããšãã§ããŸãããããã®ããã€ãã以äžã«ç€ºããŸããRipLinuxãDEFT LinuxãCAINEãPaladinãHelixãKaliã ããã€ãã®å Žåãèµ·åæã«ãã©ã¬ã³ãžãã¯ã¢ãŒãïŒãŸãã¯ãã®ãããªãã®ïŒãéžæããå¿ èŠããããŸãã ãããã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ã®äžéšã«ã¯ããã§ã«ç»ååæãœãããŠã§ã¢ãå«ãŸããŠããŸãã
Linuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã§ã®èªã¿åãå°çšã®åé¡ã«ã€ããŠã¯ã ãã¡ããã芧ãã ãã ã ããããLinuxã®äž»ãªåé¡ã¯ã䜿çšã®çžå¯Ÿçãªè€éãã§ããããã®çµæãååãªå°éç¥èãæã€ã¹ã¿ããã®äžè¶³ã§ãã Linuxã§ã¯ãã³ãã³ãã©ã€ã³ã䜿çšããŠã€ã¡ãŒãžãååŸããå¿ èŠããããŸãïŒããšãã°ãLinuxã®ftk imagerã¯ã³ã³ãœãŒã«ããŒãžã§ã³ã«ã®ã¿ååšããŸãïŒ.1ã€ã®ã¿ã€ããã¹ã§ãã¹ãŠã®èšŒæ ãç Žå£ããããšãã§ããŸãïŒ ãã®ç©èªããã€ã©ã«åºåã§ããããšãå€æããå Žåã§ããå€ãã®äººãä¿¡ããŠããããã§ã¯ãããŸããïŒã
WindowsããŒããã£ã¹ã¯
éåžžã®ITåŸæ¥å¡ã®ã€ã¡ãŒãžã®äœæãä»»ããã«ã¯ããšã©ãŒã®å¯èœæ§ãæå°éã«æããå¿ èŠããããŸãã Windows Forensic EnvironmentïŒWinFEïŒã®ç¹å¥ãªã¢ã»ã³ããªã¯ãéåžžã®Windowsã«äŒŒãå€ãã®æ¹æ³ã§ã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ã€ã¹ãåããŠããŸãããå¿ èŠãªæ©èœã«ãã£ãŠã®ã¿å¶éãããŠããŸãããããã¯ããŸãæ©èœããŠããŸãã WinFEã¯ãMicrosoftã§åããŠããã³ã³ãã¥ãŒã¿ãŒãã©ã¬ã³ãžãã¯ç§åŠè ã«ãã£ãŠäœæãããŸããã ã¢ã»ã³ããªã¯WinPEã«åºã¥ããŠãããããŒãæã«ããŒãã£ã·ã§ã³ãããŠã³ãããªãããã©ã¬ã³ãžãã¯ã«å¥å šãªãLinuxãã£ã¹ããªãã¥ãŒã·ã§ã³ãšåæ§ã«æ©èœããŸãã
WinFEã®ããã€ãã®é·æã次ã«ç€ºããŸãã
- Windowsãã©ã¬ã³ãžãã¯ã¢ããªã±ãŒã·ã§ã³ïŒããŒã¿ãã«ããŒãžã§ã³ïŒã䜿çšã§ããŸãã
- ã»ãšãã©ã®æ³å»åŠã®å°é家ã¯ãã§ã«Windowsã䜿çšããŠããŸã
- ç¡æïŒWindowsã®ã©ã€ã»ã³ã¹ãæã£ãŠããå ŽåïŒ
- çµã¿ç«ãŠãšã«ã¹ã¿ãã€ãºãæ¯èŒçç°¡å
- æ·±å»ãªäœ¿çšãšã©ãŒã®æ©äŒãå°ãªã
WinFEããã«ãããæãç°¡åãªæ¹æ³ã¯ãWinBuilder Mini-WinFEãããžã§ã¯ãã®ãŠãŒãã£ãªãã£ã䜿çšããããšã§ãã ã¢ã»ã³ããªã«å«ããWindowsãã£ã¹ããªãã¥ãŒã·ã§ã³ãšãœãããŠã§ã¢ãå¿ èŠã«ãªããŸãã åºåã§ã¯ãCDãŸãã¯USBïŒ Rufusã䜿çšïŒã«æžã蟌ãããšãã§ããISOãã¡ã€ã«ãååŸããŸãã
WinFEã䜿çšããäž»ãªã·ããªãªïŒ
- WinFEã䜿çšããŠããŒããã£ã¹ã¯ãäœæããŸãã
- ãã¹ãã³ã³ãã¥ãŒã¿ãŒã«WinFEãããŠã³ããŒãããŸãã
- 調æ»å¯Ÿè±¡ã®ã³ã³ãã¥ãŒã¿ãŒã®ãã£ã¹ã¯ã€ã¡ãŒãžãåé€ããŸãã ç»åã¯WinFEã¡ãã£ã¢ãŸãã¯ãã®ä»ã®ã¡ãã£ã¢ã«èšé²ãããŸãã
ãµããŒããããã¢ããªã±ãŒã·ã§ã³ã¯æ¬¡ã®ãšããã§ã-CloneDiskïŒä»å±ïŒ
DMDEïŒä»å±ïŒ
ãã©ã¬ã³ãžãã¯ååŸãŠãŒãã£ãªãã£ïŒä»å±ïŒ
FTK ImagerïŒããŒã«ã«ã€ã³ã¹ããŒã«ããã³ããŒïŒ
HWiNFOïŒä»å±ïŒ
LinuxReaderïŒèªåçã«ããŠã³ããŒããããŸãïŒ
MWã¹ãããïŒä»å±ïŒ
NTãã¹ã¯ãŒãç·šéïŒä»å±ïŒ
OperaïŒä»å±ïŒ
ã¹ããã©PDFãªãŒããŒïŒä»å±ïŒ
WinHexïŒããŒã«ã«ã€ã³ã¹ããŒã«ããã³ããŒïŒ
X-Ways ForensicsïŒããŒã«ã«ã€ã³ã¹ããŒã«ããã³ããŒïŒ
æžã蟌ã¿ä¿è·ããŒã«ïŒä»å±ïŒ
ãã£ã¹ã¯ãæ¥ç¶ããæé ã§ã®WinFEã®ç¹å¥ãªåäœã«ã€ããŠã¯ã2ã€ã®ã¬ãžã¹ããªãã©ã¡ãŒã¿ãŒãåå ã§ãã
- HKEY_LOCAL_MACHINE \ system \ ControlSet001 \ Services \ MountMgr NoAutoMount DWordãã©ã¡ãŒã¿ãŒã¯1ã« èšå®ãããŸãã ãã®åŸãMount-ManagerãµãŒãã¹ã¯ã¹ãã¬ãŒãžããã€ã¹ãèªåçã«ããŠã³ãããŸããã
- HKEY_LOCAL_MACHINE \ system \ ControlSet001 \ Services \ partmgr \ãã©ã¡ãŒã¿ãŒ SanPolicyãã©ã¡ãŒã¿ãŒã¯ãWindowsã®ããŒãžã§ã³ã«å¿ããŠå€ã3ããŸãã¯ã4ããåããŸãã
WinFEã«ã¯å°ãªããšã7ã€ã®ããŒãžã§ã³ãããããããã32ãããçãš64ãããçããããŸãã
Windows FE 2.0 (6.0.6000 - Vista) Windows FE 2.1 (6.0.6001 - Vista SP1/Server 2008) Windows FE 3.0 (6.1.7600 - 7/Server 2008 R2) Windows FE 3.1 (6.1.7601 - 7 SP1/Server 2008 R2 SP1) Windows FE 4.0 (6.2.9200 - 8/Server 2012) Windows FE 5.0 (6.3.9600 - 8.1) Windows FE 5.1 (6.3.9600 - 8.1 Update 1)
åããŒãžã§ã³ã«ã¯ç¬èªã®æ©èœã»ããã 詳现ãªæ¯èŒããããŸããã32ãããããŒãžã§ã³ã®Windows FE 5.xããå§ãããŸãïŒè©³çŽ°ã¯ä»¥äžïŒã
ãã®ãããããŒãäžã«WinFEã¯ããŒãã£ã·ã§ã³ãããŠã³ãããŸããããç¹å¥ãªãŠãŒãã£ãªãã£ã§ããWrite Protect ToolïŒWProtect.exeãèè Colin RamsdenïŒã䜿çšããŠããŠãŒã¶ãŒã«åå¥ã«ããŠã³ããæäŸããŸãã ååã瀺ãããã«ããã®ãŠãŒãã£ãªãã£ã¯ãã£ã¹ã¯ãžã®æžã蟌ã¿ãé²ããŸãã
ãã ããWinFEã«ã¯æå³ããªãé²é³ã®ã±ãŒã¹ããããŸããã ãããã®ã±ãŒã¹ãããç 究ããWindows <4.0ã®å€ãããŒãžã§ã³ã«é©çšãããŠãŒã¶ãŒããŒã¿ã«åœ±é¿ãäžããªãããšãéèŠã§ãã ãããã¯ãããããã£ã¹ã¯çœ²åã«ã®ã¿åœ±é¿ããŸãããããã¯ãã¹ã¿ãŒããŒãã¬ã³ãŒãïŒMBRïŒã®4ãã€ãã§ããã£ã¹ã¯ãæ¥ç¶ããããšãã«Windowsãè¿œå ããŸãïŒä»¥åNTã·ã¹ãã ã«æ¥ç¶ãããŠããªãã£ãå ŽåïŒã ãã£ã¹ã¯çœ²åã®è©³çŽ°ã«ã€ããŠã¯ãMark Russinovich ã«ãããã®èšäºãã芧ãã ããã ãã®æçš¿ã§ã¯ãWindowsããã£ã¹ã¯çœ²åãå€æŽããã±ãŒã¹ã«ã€ããŠè©³ãã説æããŠããŸãã
ã¡ã€ã³ã®WinFEããã°ã¯ããã«ãããŸã ã
ç»åäœæ
ä¿¡é Œã§ããOSãããŠã³ããŒãããããã€ã¡ãŒãžã®äœæãéå§ã§ããŸãã é»è²ã®ãªãŒããŒã·ã£ãã¯E01圢åŒïŒEncaseïŒã«ãããããã«ã¯ããã€ãã®çç±ããããŸãã
- å°é家ã«ãã£ãŠèªèããã圢åŒ-ããã¯æ³å»·ã«æ¥ãå Žåã«éèŠã§ãã
- ã»ãšãã©ã®ãã©ã¬ã³ãžãã¯ãŠãŒãã£ãªãã£ã¯ãã®åœ¢åŒããµããŒãããŠããŸããåæã®æ®µéã§ã¯ãã€ã¡ãŒãžãå€æããå¿ èŠã¯ãããŸããã
- ä»»æã®å§çž®ç-æçµçãªãµã€ãºãšç»åã®äœæã«å¿ èŠãªæéã¯ããã«å¿ããŠç°ãªããŸãããç¶æ³ã«å¿ããŠåžæã®çšåºŠãéžæã§ããŸãã
- ä»»æã®ãã©ã°ã¡ã³ããµã€ãº-ã€ã¡ãŒãžããããã¯ãŒã¯çµç±ã§ç°¡åã«ã³ããŒããããFAT32ãã¡ã€ã«ã·ã¹ãã ã«ä¿åãããããããã«ãã€ã¡ãŒãžã4000 MBã®ãã©ã°ã¡ã³ãã«åå²ã§ããŸãã
- ããŸããŸãªããŒã¿ãä¿åã§ãããµãŒãã¹ãã£ãŒã«ãïŒããšãã°ãç»åãæ®åœ±ããå°é家ã®ååã調æ»äžã®ã³ã³ãã¥ãŒã¿ãŒã®æå»ãšå®éã®æå»ã®äžäžèŽãç»åãååŸãããã£ã¹ã¯ã®ã·ãªã¢ã«çªå·ãªã©ïŒã
- æŽåæ§å¶åŸ¡-äœæã®æ®µéã§ãã€ã¡ãŒãžã®ãã§ãã¯ãµã ãèšç®ãããŸãã
E01圢åŒã®ã€ã¡ãŒãžãäœæããã«ã¯ãå®çžŸã®ããç¡æã®FTK Imager Liteã䜿çšããã®ãæé©ã§ããããã¯WinFEããŒããã£ã¹ã¯ã«å«ããããšãã§ããŸãã ãšããã§ãUse AD Encryptionæ©èœïŒãã¹ã¯ãŒãä¿è·ïŒã䜿çšããããšã¯ã»ãšãã©æå³ããããŸããã ãã®ä¿è·ã¯ç°¡åã«åãå€ãã§ããŸãã
ãããã«
ãã®èšäºãèªãæéããªã人ã«ã¯å¿ é ã®éšåã§ãã調æ»äžã®ã³ã³ãã¥ãŒã¿ãŒããç»åãååŸããã«ã¯ãFTK Imager Liteã«ãã³ãã«ãããŠããWinFEã䜿çšããE01圢åŒã§ç»åãä¿åããŸãã
PSãã®èšäºã®ç¯å²å€ã§ã¯ããã©ãã·ã¥ãã©ã€ãã®ããŒã«ãããïŒ ãã©ãã·ã¥ã¡ã¢ãªïŒã³ã³ãã¥ãŒã¿ãŒãã©ã¬ã³ãžãã¯ã®åé¡ ã æ¶å»ã埩å ã§ããªã ïŒãããã³å®è¡äžã®ã·ã¹ãã ããã¡ã¢ãªãã³ããåé€ããããã®ããŒã«ããããæ®ã£ãŠããŸããã
Habrã«ãšã£ãŠèå³æ·±ãå Žåã¯ããªãŒãã³ãœãŒã¹ãœãããŠã§ã¢ã䜿çšããŠãåä¿¡ããç»åãåæããæ¹æ³ã«ã€ããŠèª¬æããŸãã