Patents by Inventor Ki Bom Kim
Ki Bom Kim has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20230024682Abstract: Disclosed herein are a logical imaging apparatus and method for digital forensic triage. The logical imaging method for digital forensic triage includes receiving files selected as a digital evidence target, creating a logical imaging file, inside of which is formatted in a predetermined file system structure, recording the selected files in accordance with the file system structure of the created logical imaging file, and storing selected file list information about a list of the recorded selected files, and creating a separate selected list information file and a separate logical imaging summary file outside the logical imaging file.Type: ApplicationFiled: July 20, 2022Publication date: January 26, 2023Inventors: Hyun-Uk HWANG, Seung-Yong LEE, Joong-Soo HAN, Jung-Hoon OH, Jun-Su KIM, Ki-Bom KIM, Won-Ho KIM
-
Patent number: 10219156Abstract: Disclosed herein are a data protection apparatus and method for a smart device. The data protection apparatus for a smart device includes a detection unit for detecting unauthorized activity in a bootloader of the smart device, based on whether a program for acquiring an administrator privilege has been installed and whether a compressed-command file is present, during a procedure for loading the bootloader, and a data access blocking unit for, when the unauthorized activity is detected, performing an operation of locking the smart device, thus blocking access to data in the smart device.Type: GrantFiled: March 14, 2016Date of Patent: February 26, 2019Assignee: Electronics and Telecommunications Research InstituteInventors: Seung-Jei Yang, Jung-Ho Choi, Ki-Bom Kim
-
Publication number: 20170118649Abstract: Disclosed herein are a data protection apparatus and method for a smart device. The data protection apparatus for a smart device includes a detection unit for detecting unauthorized activity in a bootloader of the smart device, based on whether a program for acquiring an administrator privilege has been installed and whether a compressed-command file is present, during a procedure for loading the bootloader, and a data access blocking unit for, when the unauthorized activity is detected, performing an operation of locking the smart device, thus blocking access to data in the smart device.Type: ApplicationFiled: March 14, 2016Publication date: April 27, 2017Inventors: Seung-Jei YANG, Jung-Ho CHOI, Ki-Bom KIM
-
Patent number: 9613207Abstract: Provided is a technology which creates an autorun file that is used in autorun for preventing the autorun of a USB-based portable storage, thereby allowing an arbitrary user or worm virus not to manipulate the autorun file. A method for preventing autorun of portable storage accesses at least one of a master file table entry of a root directory and a master file table entry of an autorun file, and sets non-autorun in the at least one accessed master file table entry.Type: GrantFiled: August 3, 2010Date of Patent: April 4, 2017Assignee: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTEInventors: Hyun Uk Hwang, Ki Bom Kim, Gi Han Kim, Sung Il Lee, Tae Joo Chang, Cheol Won Lee
-
Patent number: 9286165Abstract: In a method for recovering a partition using backup boot record information, an unallocated area is separated from a disk or an evidence image. The unallocated area is searched for a location of a backup boot record. Whether is backup boot record of a file system to be detected is present in found sectors is analyzed. If the backup boot record is found to be the backup boot record of the file system desired to be detected as a result of the analysis, it is verified whether the backup boot record is a boot record of a valid partition. If it is verified that the backup boot record is the boot record of the valid partition, a file system of a deleted partition is parsed using the backup boot record and a deleted directory or file is recovered.Type: GrantFiled: August 3, 2013Date of Patent: March 15, 2016Assignee: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTEInventors: Hyun-Uk Hwang, Ki-Bom Kim, Seung-Yong Lee, Young-Chan Shin, Tae-Joo Chang
-
Patent number: 9164845Abstract: Provided is a technology which searches an unallocated area to quickly extract information on a deleted partition when checking a disk and an evidence image in digital forensic, and adds a recovered partition to a forensic tool as a new partition. For this, the technology has direct access to the sector of a disk or an evidence image which is obtained, limits information search on an unallocated area only to an area satisfying the minimum size in which a partition may be created, changes an LBA-based sector access scheme into a CHS-based sector access scheme, and reads only the sector of a location having the possibility that a boot record exists to search information of a deleted partition, recovering a partition at high speed.Type: GrantFiled: November 27, 2009Date of Patent: October 20, 2015Assignee: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTEInventors: Hyun Uk Hwang, Ki Bom Kim, Tae Joo Chang, Cheol Won Lee
-
Patent number: 8745100Abstract: Method and apparatus for collecting evidence are provided. An exemplary embodiment enhances accuracy and efficiency of collecting evidence by analyzing link information in the target computer and collecting collection target file. And the exemplary embodiment can collect evidence from a target computer as well as from a remote computer through analyzing the link information in the target computer, identifying the path of collection target file and extracting the target file.Type: GrantFiled: November 27, 2009Date of Patent: June 3, 2014Assignee: Electronics and Telecommunications Research InstituteInventors: Ki Bom Kim, Hyun Uk Hwang, Young Chan Shin, Tae Joo Chang, Cheol Won Lee, Sung Jai Baik
-
Publication number: 20140059313Abstract: In a method for recovering a partition using backup boot record information, an unallocated area is separated from a disk or an evidence image. The unallocated area is searched for a location of a backup boot record. Whether is backup boot record of a file system to be detected is present in found sectors is analyzed. If the backup boot record is found to be the backup boot record of the file system desired to be detected as a result of the analysis, it is verified whether the backup boot record is a boot record of a valid partition. If it is verified that the backup boot record is the boot record of the valid partition, a file system of a deleted partition is parsed using the backup boot record and a deleted directory or file is recovered.Type: ApplicationFiled: August 3, 2013Publication date: February 27, 2014Applicant: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTEInventors: Hyun-Uk HWANG, Ki-Bom KIM, Seung-Yong LEE, Young-Chan SHIN, Tae-Joo CHANG
-
Publication number: 20110099639Abstract: Provided is a technology which creates an autorun file that is used in autorun for preventing the autorun of a USB-based portable storage, thereby allowing an arbitrary user or worm virus not to manipulate the autorun file. A method for preventing autorun of portable storage accesses at least one of a master file table entry of a root directory and a master file table entry of an autorun file, and sets non-autorun in the at least one accessed master file table entry.Type: ApplicationFiled: August 3, 2010Publication date: April 28, 2011Applicant: Electronics and Telecommunications Research InstituteInventors: Hyun Uk HWANG, Ki Bom KIM, Gi Han KIM, Sung Il LEE, Tae Joo CHANG, Cheol Won LEE
-
Publication number: 20110055163Abstract: Provided is a technology which searches an unallocated area to quickly extract information on a deleted partition when checking a disk and an evidence image in digital forensic, and adds a recovered partition to a forensic tool as a new partition. For this, the technology has direct access to the sector of a disk or an evidence image which is obtained, limits information search on an unallocated area only to an area satisfying the minimum size in which a partition may be created, changes an LBA-based sector access scheme into a CHS-based sector access scheme, and reads only the sector of a location having the possibility that a boot record exists to search information of a deleted partition, recovering a partition at high speed.Type: ApplicationFiled: November 27, 2009Publication date: March 3, 2011Applicant: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTEInventors: Hyun Uk HWANG, Ki Bom KIM, Tae Joo CHANG, Cheol Won LEE
-
Publication number: 20110047130Abstract: Method and apparatus for collecting evidence are provided. An exemplary embodiment enhances accuracy and efficiency of collecting evidence by analyzing link information in the target computer and collecting collection target file. And the exemplary embodiment can collect evidence from a target computer as well as from a remote computer through analyzing the link information in the target computer, identifying the path of collection target file and extracting the target file.Type: ApplicationFiled: November 27, 2009Publication date: February 24, 2011Applicant: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTEInventors: Ki Bom KIM, Hyun Uk HWANG, Young Chan SHIN, Tae Joo CHANG, Cheol Won LEE, Sung Jai BAIK
-
Patent number: 7865493Abstract: Provided are an apparatus and method for searching for digital forensic data. In particular, provided are an apparatus and method for searching for digital forensic data capable of automatically determining a character encoding type that is used in searching for data. The apparatus for searching for digital forensic data includes: an imaging module for generating an image file from a data source; a file system analysis module for analyzing a file system of the image file to generate file system analysis information; a search module for determining a search character encoding type based on the file system analysis information and searching for the data using the search character encoding type; and a user interface for receiving a command related to a search from a user, transmitting the received command to the file system analysis module and the search module, and outputting the search results to the user.Type: GrantFiled: March 28, 2008Date of Patent: January 4, 2011Assignee: Electronics and Telecommunications Research InstituteInventors: Ki Bom Kim, Sang Seo Park
-
Publication number: 20090094203Abstract: Provided are an apparatus and method for searching for digital forensic data. In particular, provided are an apparatus and method for searching for digital forensic data capable of automatically determining a character encoding type that is used in searching for data. The apparatus for searching for digital forensic data includes: an imaging module for generating an image file from a data source; a file system analysis module for analyzing a file system of the image file to generate file system analysis information; a search module for determining a search character encoding type based on the file system analysis information and searching for the data using the search character encoding type; and a user interface for receiving a command related to a search from a user, transmitting the received command to the file system analysis module and the search module, and outputting the search results to the user.Type: ApplicationFiled: March 28, 2008Publication date: April 9, 2009Inventors: Ki Bom KIM, Sang Seo PARK