Patents by Inventor Ki Bom Kim

Ki Bom Kim has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20230024682
    Abstract: Disclosed herein are a logical imaging apparatus and method for digital forensic triage. The logical imaging method for digital forensic triage includes receiving files selected as a digital evidence target, creating a logical imaging file, inside of which is formatted in a predetermined file system structure, recording the selected files in accordance with the file system structure of the created logical imaging file, and storing selected file list information about a list of the recorded selected files, and creating a separate selected list information file and a separate logical imaging summary file outside the logical imaging file.
    Type: Application
    Filed: July 20, 2022
    Publication date: January 26, 2023
    Inventors: Hyun-Uk HWANG, Seung-Yong LEE, Joong-Soo HAN, Jung-Hoon OH, Jun-Su KIM, Ki-Bom KIM, Won-Ho KIM
  • Patent number: 10219156
    Abstract: Disclosed herein are a data protection apparatus and method for a smart device. The data protection apparatus for a smart device includes a detection unit for detecting unauthorized activity in a bootloader of the smart device, based on whether a program for acquiring an administrator privilege has been installed and whether a compressed-command file is present, during a procedure for loading the bootloader, and a data access blocking unit for, when the unauthorized activity is detected, performing an operation of locking the smart device, thus blocking access to data in the smart device.
    Type: Grant
    Filed: March 14, 2016
    Date of Patent: February 26, 2019
    Assignee: Electronics and Telecommunications Research Institute
    Inventors: Seung-Jei Yang, Jung-Ho Choi, Ki-Bom Kim
  • Publication number: 20170118649
    Abstract: Disclosed herein are a data protection apparatus and method for a smart device. The data protection apparatus for a smart device includes a detection unit for detecting unauthorized activity in a bootloader of the smart device, based on whether a program for acquiring an administrator privilege has been installed and whether a compressed-command file is present, during a procedure for loading the bootloader, and a data access blocking unit for, when the unauthorized activity is detected, performing an operation of locking the smart device, thus blocking access to data in the smart device.
    Type: Application
    Filed: March 14, 2016
    Publication date: April 27, 2017
    Inventors: Seung-Jei YANG, Jung-Ho CHOI, Ki-Bom KIM
  • Patent number: 9613207
    Abstract: Provided is a technology which creates an autorun file that is used in autorun for preventing the autorun of a USB-based portable storage, thereby allowing an arbitrary user or worm virus not to manipulate the autorun file. A method for preventing autorun of portable storage accesses at least one of a master file table entry of a root directory and a master file table entry of an autorun file, and sets non-autorun in the at least one accessed master file table entry.
    Type: Grant
    Filed: August 3, 2010
    Date of Patent: April 4, 2017
    Assignee: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
    Inventors: Hyun Uk Hwang, Ki Bom Kim, Gi Han Kim, Sung Il Lee, Tae Joo Chang, Cheol Won Lee
  • Patent number: 9286165
    Abstract: In a method for recovering a partition using backup boot record information, an unallocated area is separated from a disk or an evidence image. The unallocated area is searched for a location of a backup boot record. Whether is backup boot record of a file system to be detected is present in found sectors is analyzed. If the backup boot record is found to be the backup boot record of the file system desired to be detected as a result of the analysis, it is verified whether the backup boot record is a boot record of a valid partition. If it is verified that the backup boot record is the boot record of the valid partition, a file system of a deleted partition is parsed using the backup boot record and a deleted directory or file is recovered.
    Type: Grant
    Filed: August 3, 2013
    Date of Patent: March 15, 2016
    Assignee: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
    Inventors: Hyun-Uk Hwang, Ki-Bom Kim, Seung-Yong Lee, Young-Chan Shin, Tae-Joo Chang
  • Patent number: 9164845
    Abstract: Provided is a technology which searches an unallocated area to quickly extract information on a deleted partition when checking a disk and an evidence image in digital forensic, and adds a recovered partition to a forensic tool as a new partition. For this, the technology has direct access to the sector of a disk or an evidence image which is obtained, limits information search on an unallocated area only to an area satisfying the minimum size in which a partition may be created, changes an LBA-based sector access scheme into a CHS-based sector access scheme, and reads only the sector of a location having the possibility that a boot record exists to search information of a deleted partition, recovering a partition at high speed.
    Type: Grant
    Filed: November 27, 2009
    Date of Patent: October 20, 2015
    Assignee: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
    Inventors: Hyun Uk Hwang, Ki Bom Kim, Tae Joo Chang, Cheol Won Lee
  • Patent number: 8745100
    Abstract: Method and apparatus for collecting evidence are provided. An exemplary embodiment enhances accuracy and efficiency of collecting evidence by analyzing link information in the target computer and collecting collection target file. And the exemplary embodiment can collect evidence from a target computer as well as from a remote computer through analyzing the link information in the target computer, identifying the path of collection target file and extracting the target file.
    Type: Grant
    Filed: November 27, 2009
    Date of Patent: June 3, 2014
    Assignee: Electronics and Telecommunications Research Institute
    Inventors: Ki Bom Kim, Hyun Uk Hwang, Young Chan Shin, Tae Joo Chang, Cheol Won Lee, Sung Jai Baik
  • Publication number: 20140059313
    Abstract: In a method for recovering a partition using backup boot record information, an unallocated area is separated from a disk or an evidence image. The unallocated area is searched for a location of a backup boot record. Whether is backup boot record of a file system to be detected is present in found sectors is analyzed. If the backup boot record is found to be the backup boot record of the file system desired to be detected as a result of the analysis, it is verified whether the backup boot record is a boot record of a valid partition. If it is verified that the backup boot record is the boot record of the valid partition, a file system of a deleted partition is parsed using the backup boot record and a deleted directory or file is recovered.
    Type: Application
    Filed: August 3, 2013
    Publication date: February 27, 2014
    Applicant: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
    Inventors: Hyun-Uk HWANG, Ki-Bom KIM, Seung-Yong LEE, Young-Chan SHIN, Tae-Joo CHANG
  • Publication number: 20110099639
    Abstract: Provided is a technology which creates an autorun file that is used in autorun for preventing the autorun of a USB-based portable storage, thereby allowing an arbitrary user or worm virus not to manipulate the autorun file. A method for preventing autorun of portable storage accesses at least one of a master file table entry of a root directory and a master file table entry of an autorun file, and sets non-autorun in the at least one accessed master file table entry.
    Type: Application
    Filed: August 3, 2010
    Publication date: April 28, 2011
    Applicant: Electronics and Telecommunications Research Institute
    Inventors: Hyun Uk HWANG, Ki Bom KIM, Gi Han KIM, Sung Il LEE, Tae Joo CHANG, Cheol Won LEE
  • Publication number: 20110055163
    Abstract: Provided is a technology which searches an unallocated area to quickly extract information on a deleted partition when checking a disk and an evidence image in digital forensic, and adds a recovered partition to a forensic tool as a new partition. For this, the technology has direct access to the sector of a disk or an evidence image which is obtained, limits information search on an unallocated area only to an area satisfying the minimum size in which a partition may be created, changes an LBA-based sector access scheme into a CHS-based sector access scheme, and reads only the sector of a location having the possibility that a boot record exists to search information of a deleted partition, recovering a partition at high speed.
    Type: Application
    Filed: November 27, 2009
    Publication date: March 3, 2011
    Applicant: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
    Inventors: Hyun Uk HWANG, Ki Bom KIM, Tae Joo CHANG, Cheol Won LEE
  • Publication number: 20110047130
    Abstract: Method and apparatus for collecting evidence are provided. An exemplary embodiment enhances accuracy and efficiency of collecting evidence by analyzing link information in the target computer and collecting collection target file. And the exemplary embodiment can collect evidence from a target computer as well as from a remote computer through analyzing the link information in the target computer, identifying the path of collection target file and extracting the target file.
    Type: Application
    Filed: November 27, 2009
    Publication date: February 24, 2011
    Applicant: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
    Inventors: Ki Bom KIM, Hyun Uk HWANG, Young Chan SHIN, Tae Joo CHANG, Cheol Won LEE, Sung Jai BAIK
  • Patent number: 7865493
    Abstract: Provided are an apparatus and method for searching for digital forensic data. In particular, provided are an apparatus and method for searching for digital forensic data capable of automatically determining a character encoding type that is used in searching for data. The apparatus for searching for digital forensic data includes: an imaging module for generating an image file from a data source; a file system analysis module for analyzing a file system of the image file to generate file system analysis information; a search module for determining a search character encoding type based on the file system analysis information and searching for the data using the search character encoding type; and a user interface for receiving a command related to a search from a user, transmitting the received command to the file system analysis module and the search module, and outputting the search results to the user.
    Type: Grant
    Filed: March 28, 2008
    Date of Patent: January 4, 2011
    Assignee: Electronics and Telecommunications Research Institute
    Inventors: Ki Bom Kim, Sang Seo Park
  • Publication number: 20090094203
    Abstract: Provided are an apparatus and method for searching for digital forensic data. In particular, provided are an apparatus and method for searching for digital forensic data capable of automatically determining a character encoding type that is used in searching for data. The apparatus for searching for digital forensic data includes: an imaging module for generating an image file from a data source; a file system analysis module for analyzing a file system of the image file to generate file system analysis information; a search module for determining a search character encoding type based on the file system analysis information and searching for the data using the search character encoding type; and a user interface for receiving a command related to a search from a user, transmitting the received command to the file system analysis module and the search module, and outputting the search results to the user.
    Type: Application
    Filed: March 28, 2008
    Publication date: April 9, 2009
    Inventors: Ki Bom KIM, Sang Seo PARK