As the use of Trojan programs by hackers becomes more widespread, the Trojan Defense is likely to be deployed in an increasing number of legal cases. Therefore, Trojans present a challenge to law enforcement agencies (LEAs). This paper examines the digital forensic report of Trojan Defense from a ticket scalping case in Taiwan and proposes the identify/perform/understand (IPU) model for exploring and analyzing evidence-relevant data. The IPU model improving a digital evidence review is proposed in three stages: identify temporal data to build the sequence (when), perform functional testing to gain insights (how), and understand relational reconstructions to clarify the actions (who, what, where). The model can help the judge in a Trojan Defense case weigh the value of digital evidence more systematically. A temporal, functional, and relational analysis was used to reconstruct the events in the ticket scalping case. This research can efficiently assist law enforcement officials in dealing with the ever-increasing Trojan Defense.
當駭客日漸頻繁使用木馬程式入侵電腦網路,木馬抗辯相繼成為資安事件或法律訴訟案件的難解疑題,更讓執法機構面臨嚴峻挑戰。本文個案提出木馬抗辯議題,並主張:不知名駭客植入木馬程式後,移除相關證據;並不斷要求額外的鑑定證人,重新檢驗刑事警察局的鑑識報告品質。本文提出分析數位證據的識別(Identify)/執行(Perform)/理解(Understand)模式,作為法院或鑑定證人,檢驗木馬抗辯案件的數位證據評估依據;並提出識別時序、測試功能及釐清關係等三個階段程序,期重建事件原貌,幫助法官有系統地衡量數位證據的證據能力與證明力。本模式可有效地協助執法人員處理越來越多的木馬抗辯議題。