브라우저 익스텐션 기반 암호화폐 지갑의 디지털 포렌식 아티팩트 수집 및 분석 연구

Translated title of the contribution: A Study on the Digital Forensics Artifacts Collection and Analysis of Browser Extension-Based Crypto Wallet

Research output: Contribution to journalArticlepeer-review

Abstract

Recently, due to the nature of blockchain that guarantees users' anonymity, more and more cases are being exploited for crimes such as illegal transactions. However, cryptocurrency is protected in cryptocurrency wallets, making it difficult to recover criminal funds. Therefore, this study acquires artifacts from the data and memory area of a local PC based on user behavior from four browser extension wallets (Metamask, Binance, Phantom, and Kaikas) to track and retrieve cryptocurrencies used in crime, and analyzes how to use them from a digital forensics perspective. As a result of the analysis, the type of wallet and cryptocurrency used by the suspect was confirmed through the API name obtained from the browser's cache data, and the URL and wallet address used for the remittance transaction were obtained. We also identified Client IDs that could identify devices used in cookie data, and confirmed that mnemonic code could be obtained from memory. Additionally, we propose an algorithm to measure the persistence of obtainable mnemonic code and automate acquisition.
Translated title of the contributionA Study on the Digital Forensics Artifacts Collection and Analysis of Browser Extension-Based Crypto Wallet
Original languageKorean
Pages (from-to)471-485
Number of pages15
Journal정보보호학회논문지
Volume33
Issue number3
DOIs
StatePublished - 2023

Fingerprint

Dive into the research topics of 'A Study on the Digital Forensics Artifacts Collection and Analysis of Browser Extension-Based Crypto Wallet'. Together they form a unique fingerprint.

Cite this