Dergiler / Acta Infologica / 2021 / Cilt: 5 - Sayı: 1

Adli Bilişim İncelemelerinde Şifre Kırma Yöntemve Teknikleri

Password Cracking Methods and Techniques in Computer Forensic Investigation

Sayfa
27–38
DOI
—

Özet

Bilgi sistemleri ve veri kullanımındaki sonsuz artış, bilgi güvenliğinde tehlikenin doğuşunu tetikledi. Sonyayınlanan raporlara göre askeri kuvvetler ve e-ticaret web siteleri dışında sıradan kullanıcılarda sistemlerive belgelerini korumak için şifreleme teknikleri kullanmaya başlanmışlardır. Alınana tedbirlere rağmençeşitli gizleme tekniklerini kullanarak hazırlanan akıllı saldırılar mevcut korunma yöntemlerini atlatarakhedef sistemdeki parola ve kullanıcı adlarını ele geçirebilmektedir. Kurumsal firmalar ve sıradan kullanıcılarverilerini gizlemek için yeni nesil şifreleme yöntemlerini yaygın olarak kullanmaktadır. Bu durum özellikleadli olaylara konu olan bilgi sistemleri ve dosyaların incelenmesinde büyük engeller oluşturmaktadır. Eğerşüpheli kişi kullanmış olduğu bilgi sistemi veya dosyalarını şifrelenmiş ise delil elde etmek için önce buşifrelerin önceden bilinmesi ya da şifrenin kırılması gereklidir. Bu adımda şüpheli kendi rızasıyla parolakolluk kuvvetlerine vermemesi durumunda adli uzmanlar çeşitli yönetmelerle şifreleri kırmaya çalışmaktabu süreç genellikle zor olmakta ve bazı durumlarda şüpheli sistemdeki şifreli verilere ulaşılamamaktadır. Buçalışma iki katkı sunmaktadır. İlk olarak en çok kullanılan şifre kırma yöntemleri detaylı olarak incelenmiştir.İkincisi, “BitLocker” veri şifreleme yöntemiyle şifrelenmiş örnek bir adli vaka incelenerek şifreli verilerikırılma adımları incelenmiştir. Sonuçlardan şifrelenmiş verilerin erişmek için kullanılan yöntemin etkiliolduğunu ve şifrelerin kırıldığı göstermektedir.

Abstract

The unending increase in information systems and data use has triggered the birth of danger to informationsecurity. According to recently published reports, apart from military forces and e-commerce websites,ordinary users have begun to use encryption techniques to protect systems and documents. In spite ofprecautions, smart attacks prepared using a variety of concealing techniques overcome available protectionmethods and can obtain the passwords and user names of on the target system. Corporate firms and ordinaryusers commonly use new-generation encryption methods to hide their data. This situation creates largeobstacles forto the investigation of computer systems and files which are the subject of forensic events,especially. If a suspect uses a computer system with encrypted files, to obtain evidence, firstly, it is necessaryto know these encryptions or to crack them. In this step, if the suspect does not give law enforcement theencryptions willingly, forensic experts attempt to break the encryption with a variety of methods. Thisprocess is generally difficult, and in some situations, the encrypted data on the suspect’s system cannot bereached. This study provides two contributions. The first is that a detailed investigation of the most commonlyused encryption cracking methods are investigated in detail. Secondly, an example forensic case encryptedwith the “BitLocker” data encryption method is investigated and the steps to break the encrypted data areinvestigated. The results show that the methods used to access the encrypted data is effective and that theencryption was cracked.