1 / 26

網路犯罪案例 Cyber crime Reconnaissance Case

網路犯罪案例 Cyber crime Reconnaissance Case. Decision Group / CEO 張 侃 Casper Kan Chang Chang_kan@decision.com.tw. Analysis Non- Reconstruction Packet 不可還的原網路封包. Network Packet Reconstruction 可還原網路封包. 網際網路犯罪主要可分為二大類 Internet crime is divided into two major categories. 以網路作為犯罪之場所

cole-cross
Télécharger la présentation

網路犯罪案例 Cyber crime Reconnaissance Case

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. 網路犯罪案例Cyber crime Reconnaissance Case Decision Group / CEO 張 侃 Casper Kan Chang Chang_kan@decision.com.tw

  2. Analysis Non-Reconstruction Packet 不可還的原網路封包 Network Packet Reconstruction 可還原網路封包 網際網路犯罪主要可分為二大類Internet crime is divided into two major categories 以網路作為犯罪之場所 Any criminal acts dealing with computers and networks Ex: Release of Viruses & Worms, Invasion of privacy, Cyber-spying, Hacking & Cyber warfare散播病毐影響他人正常使用電腦網路,或取得、刪除或變更他人的電腦資料或紀錄 以網路作為犯罪之客體 Traditional crimes conducted through the Internet. Ex: Credit card fraud, Identity theft, child pornography, indecent chat-room behavior, software & media piracy 利用網路傳遞色情資訊,從事賭博行為,侵害著作權或商標權,販賣違禁物品

  3. 常見網路詐騙犯罪型態及手法 1Common Internet fraud behavior patterns and practices 1

  4. 常見網路詐騙犯罪型態及手法 2Common Internet fraud behavior patterns and practices 2

  5. 常見網路詐騙犯罪型態及手法 3Common Internet fraud behavior patterns and practices 3

  6. 常見網路詐騙犯罪型態及手法 4Common Internet fraud behavior patterns and practices 4

  7. 常見網路詐騙犯罪型態及手法 5Common Internet fraud behavior patterns and practices 5

  8. 網路購物詐欺手法及案例 1-1Online Shopping Fraud

  9. 網路購物詐欺手法及案例 1-2Online Shopping Fraud 假借東森購物免付費顯示電話、雅虎奇摩購物等方式通知 民眾,稱原承辦人誤將退款設為分期扣款或被害人先前交易錯誤,誤將退款設為分期扣款等將使權利受損,即向民眾要求需至提款機操作變更,解除分期付款扣款; 俟民眾受騙上當後,再以「金融監督管理委員會」名義表示帳戶已遭歹徒利用洗錢,需匯「金融安全帳戶」,以免遭凍結帳戶,誘騙被害人將存款解除,改存入前述 詐騙之「金融安全帳戶」。 Swindle, said Eastern Shopping and Yahoo Auctions Payment Error Information to the public, claiming a refund of the original contractors mistakenly set the previous trading installment deductions or victim error, mistake a refund will set phases such as the right to charge damaged, it tells the people to the ATM was required to operate changes, lifting hire charge; as soon as the public deceived again after the "Financial Supervisory Commission," said the account has been criminal to use the name of money laundering, must sink "financial security account" to avoid being the freezing of accounts, lured victims of the deposit removed, changed into the aforementioned fraud of "financial security accounts."

  10. B. 網路詐欺案例 1-1Internet fraud Case 一名馬來西亞籍的華裔賴姓女子,涉嫌與奈及利亞籍男友利用網路詐騙台灣女子。刑事局國際科與馬國警方合作,日前逮捕賴姓女子並追緝共犯 A Malaysian woman of Chinese origin Ms. Lai in connection with a Nigerian boyfriend, used the Internet to defraud Taiwanese woman CIB International Council of Scientific Cooperation with Malaysia arrested by the police and looking for an accomplice Ms. Lai

  11. B. 網路詐欺案例 1-2Internet fraud Case 台北縣警方今年5月間接獲一名女子檢舉,指稱一名在英國倫敦工作的網友,聲稱寄送內有英鎊現金的包裹要給她,因未申報而遭馬國海關查扣,需付稅金後始得放行,請求女子將錢匯至馬國海關處。這名女子不疑有他,連續匯款兩次共計2358美元,但遲未收到包裹,始知受騙。 Taipei County police received an indirect May this year, a woman accused, Alleged that a work of netizens in London, claiming that there are pounds in cash to send parcels to give her, Who were failing to declare the Malaysian Customs and Excise Department seized, pay a tax before it may be released upon the request woman will remit money to the Malaysian Customs and Excise Department. The woman did not suspected him, a total of 2358 U.S. dollars two consecutive remittances, but has not received the latest package, Found out deceived.

  12. 網路性侵案件!Network of sexual assault cases! 07年網路性侵案件: 一天1.5件。12-18歲少年占六成多。 2009年06月10日蘋果日報 台灣 台北 市 Network of sexual assault cases in 2007: Daily average 1.5 case. 12-18 year-olds accounted for more than 60%. June 10, 2009 Apple Daily Taipei Taiwan

  13. 禽獸不如 Is truly pathetic and inferior to animals 台北市兩名一瘦一胖的嫌犯,去年七月起,涉嫌在網路上約女網友開轟趴,等女網友赴約後將對方帶到汽車旅館,誘騙對方進浴室洗澡,再要求發生性關係,女網友不願配合,即遭掌摑強姦得逞 ,警方昨逮捕兩嫌,發現受害多達十多人。 Taipei two suspects a thin one fat, begin July 2008 , Suspected on the Internet to invite Female net friend to participate in party , Female net friend to meet this woman after the other into the Motel, Trick the other into the bathroom taking a bath, and then require a sexual relationship, The victim is unwilling to cooperate, that is, to succeed by slapping rape, the police yesterday arrested two suspected and found that as many as a dozen people injured. 被害人不甘受辱向警方報案,警方根據網路位址清查,並前往汽車旅館調閱車號,昨循線逮捕兩嫌。警方追查發現,兩嫌去年七月開始犯案,每次都由葉嫌以「小豬」、「出來玩」等暱稱,在奇摩即時通及豆豆聊天室等網站向女網友搭訕,葉嫌坦承犯案十多起、周嫌則供稱五、六起,警方正追查其他共犯。 Humiliation of victims unwilling to report to the police, the police inventory of network address and went to the motel access to number, yesterday arrested two suspected through the line. The police traced the two began to commit crimes too 2008 July for each pig by Ye too to come out to play other nickname, the yahoo messange and Peas chat rooms and other websites to Nvwang You strike up, leaves from more than 10 suspected offender admits , Zhou said the suspect are for five or six, the police are tracing the other accomplices.

  14. Hacker Su Po-jung 駭客蘇柏榕 替黑幫盜資料 Hacker Su Po-jung work for the underworld to steal data 中時電子報/蔡旻岳/台北報導 2007/09/22 China Times / Taipei / Choi Min-Yue 刑事局科技犯罪防制中心查出 ,在網路上暱稱「odin」的林姓高二生、以及暱稱「cb」的蘇柏榕兩人,係以學術網路為骨幹,將跳板主機隱藏於台灣學術網路內,並利用木馬程式、網站漏洞侵入各大知名網站非法取得資料後,存放在國外網站主機,用以規避追查。其中xx電信公司用戶帳戶及密碼有兩百四十多萬筆遭竊,部分網站則連程式都被搬走。 CIB Crime Prevention Center for Science and Technology have found that the Internet nickname "odin" Lin, high-school sophomore, and the nickname "cb" two Su Po-jung, an academic department as the backbone network will be a springboard for host hidden in Taiwan Academic Network inside, and the use of Trojan horse programs, Web site vulnerabilities well-known Web site illegally obtained large intrusive information, stored in a foreign website host, to circumvent the tracing. Xx telecom companies in which the user account and password with more than 2.4 million pens stolen, some websites have even the programs are removed.

  15. 網路理財廣告詐貸銀行案 -1 Internet advertising bank loan fraud case 高雄市刑警大隊 2009年5月接獲多家銀行報案,指稱遭人持偽造文件向銀行申辦信用貸款,造成銀行遭詐貸的鉅額損失。案經該大隊15分隊深入調查發現,以洪○○、方○○等人共同基於牟取不法利益之犯意聯絡及行為分擔所籌組之詐欺集團,用國內入口網站之免費網路空間張貼或貼紙廣告刊載『理財達人專辦信用貸款』、『小額信用貸款』訊息等方式,招攬急需資金週轉之人頭客戶,由該集團成員偽變造財稅、薪資等證明文件,美化貸款人之財力,並教唆指導人頭客戶持偽造文件向銀行申辦信用貸款,使金融機構陷於錯誤而核准貸款,該集團則向人頭客戶收取高額手續費牟取暴利

  16. 網路理財廣告詐貸銀行案 -2 Internet advertising bank loan fraud case

  17. 取得報案詳細資料 To obtain detailed information on reported 依案情內容申請技術支援 For technical support in accordance with the contents of the case 組成專案小組 An ad hoc group 網際網路犯罪偵察要領 Cyber Crime Investigation Essentials

  18. 網際網路犯罪情資蒐集Cyber criminal intelligence collection • 收集電腦稽核紀錄 : IP, 帳號, 時間 等 • 客戶登錄資料 : 帳號使用人, 姓名, 地址, 電話 等 • 犯罪事實 • Collection of computer audit records : Log, IP, User account, time • Customer Login information : Account name and address of telephone users • Corpus delicti

  19. 網際網路犯罪證據蒐集Cyber crime, gathering of evidence • 由被害人及嫌犯電腦上取得資料, Log, 檔案, 紀錄 ... 等 • 由業者提供的資料及紀錄 ... 等 • 網路監聽 • 由被害人提供網路封包還原 • By the victims and suspects to obtain information on the computer, Log, files, records, etc. ... • Information provided by the industry, and records and so on ... • Interception • From the victims to restore the network packet

  20. Forensics tools 鑑識軟體 “Stop, look and listen” Forensics software 離線封包鑑識還原軟體 Wired , HTTPS/SSL and VOIP Wireless “Catch-it-as-you-can” forensics systems封包側錄還原鑑識設備 Off-Line packet reconstruction software 網際網路犯罪鑑識工具種類Cyber crime forensics tools

  21. Forensics tools 鑑識軟體 由被害人及嫌犯電腦上取得資料, Log, 檔案, 紀錄 ... 等Collection of computer audit records : Log, IP, User account, time … …etc 鑑識工具使用 Forensics Tool Use 數位證據的鑑識與採集無法透過人類的視覺直接辨識出來,如果沒有適當的工具或軟體也是無法解析,運用適當的工具或軟體採集與辨識數位證據,也是偵辦電腦網路犯罪案件必備的條件 Kam-digital intellectual and collection of evidence can not be humans through direct identified intellectual vision out of future, without the right tools or software are unable to resolve, using the right tools or software acquisition and identified intellectual digital evidence, but also diligent in Internet Highway necessary conditions for criminal cases

  22. 網路監聽 Internet Interception “Stop, look and listen” Forensics software 離線封包鑑識還原軟體 Wired , HTTPS/SSL and VOIP 還原已錄製完成網路封包 Reconstruction, The completion of network packets have been recorded Wireless “Catch-it-as-you-can” forensics systems封包側錄還原鑑識設備 Off-Line packet reconstruction software 網路鑑識工具使用 Cyber Forensics Tool Use

  23. Analysis Non-Reconstruction Packet 不可還的原網路封包 Network Packet Reconstruction 可還原網路封包 網路封包鑑識分析分類Network packet forensics analysis categories 1. Viruses & Worms, Hacking & Trojans ... ... 病毐 駭客 木馬程式… … 2. Email , Web Mail ,IM, FTP , P2P, VoIP, Video Streaming , HTTP, Online Games, Telnet 電子郵件,網頁郵件,FTP,P2P,VoIP,影音串流,網頁瀏覽,線上遊戲,,Telnet

  24. 提供全系列網路鑑識產品Complete Solutions for Cyber Forensics • Wired packet reconstruction. • Wireless (802.11 a/b/g/n) packet reconstruction. • HTTPS/SSL interceptor.. • VOIP packet reconstruction. • Off-line packet reconstruction software • Network packet forensics analysis training For more information www.digi-forensics.com

  25. Frankie Chan Kok Liang Phillip A Russo Ing. Gustavo Presman 網際網路封包鑑識分析教育訓練課程Network Packet Forensics Analysis Training The knowledge of network packet analysis is important for Forensics Investigator and Lawful Enforcement Officer to carry out their daily duty. Network Packet Forensics Analysis Training (NPFAT) provides useful and sufficient knowledge required to analyse network packets. Trainee will be able to identify different packet types according to different Internet Protocols such as packets containing a specific Email (POP3, SMTP and IMAP), Web Mail (Yahoo Mail, Gmail, Hotmail), Instant Messaging (Windows Live Messenger, Yahoo, ICQ etc.), FTP, Telnet, HTTP and VOIP. Forensics investigation is also science and art. 網際網路封包鑑識分析教育訓練課程(NPFAT)提供所需知識來分析網際網路封包。令學員將能夠識別不同類型的網路封包根據不同的Internet協議,如 電子郵件(POP3,SMTP和IMAP),網路郵件(雅虎郵件,Gmail,Hotmail等),即時通(如Windows Live Messenger,雅虎,ICQ等),FTP,遠程登錄,網頁瀏覽和VOIP。鑑識取證調查還技術兼具科學和藝術素養之訓練課程。

  26. The Investigation Bureau of the Ministry of Justice Criminal Investigation Bureau 國家安全局 National Security Bureau 國防部 Ministry of National Defense,R.O.C 憲兵司令部 Military Police, R.O.C 海岸巡防署 Coast Guard Administration 國防大學 National Defense University 中央警察大學 Central Police University 實績 Reference site in Taiwan

More Related