shopping cart
Save up to 30% on our Staff Picks
Call us:  800-878-7323 HELP
McAfee SECURE helps keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams.
Original Essays | November 9, 2009

Jesse Bullington: IMG Abash'd the Devil Stood



I don't believe in evil. It's a word I use, certainly, because words are shortcuts and we all take the short way round from time to time, but that's... Continue »
  1. $10.49 Sale Trade Paper add to wish list

Ships free on qualified orders.
Add to Cart
$59.99
New Trade Paper
Ships in 1 to 3 days
Add to Wishlist
Qty Store Section
12 Local Warehouse Internet- General

Real Digital Forensics: Computer Security and Incident Response with DVD

by Keith J. Jones

Real Digital Forensics: Computer Security and Incident Response with DVD Cover

Synopses & Reviews

Publisher Comments:

You can't succeed in the field of computer forensics without hands-on practice—and you can't get hands-on practice without real forensic data. The solution: Real Digital Forensics. In this book, a team of world-class computer forensics experts walks you through six detailed, highly realistic investigations and provides a DVD with all the data you need to follow along and practice.

From binary memory dumps to log files, this DVD's intrusion data was generated by attacking live systems using the same tools and methods real-world attackers use. The evidence was then captured and analyzed using the same tools the authors employ in their own investigations. This book relies heavily on open source tools, so you can perform virtually every task without investing in any commercial software.

You'll investigate environments ranging from financial institutions to software companies and crimes ranging from intellectual property theft to SEC violations. As you move step by step through each investigation, you'll discover practical techniques for overcoming the challenges forensics professionals face most often.

Inside, you will find in-depth information on the following areas:

  • Responding to live incidents in both Windows and Unix environments

  • Determining whether an attack has actually occurred

  • Assembling a toolkit you can take to the scene of a computer-related crime

  • Analyzing volatile data, nonvolatile data, and files of unknown origin

  • Safely performing and documenting forensic duplications

  • Collecting and analyzing network-based evidence in Windows and Unix environments

  • Reconstructing Web browsing, e-mail activity, and Windows Registry changes

  • Tracing domain name ownership and the source of e-mails

  • Duplicating and analyzing the contents of PDAs and flash memory devices

The accompanying DVD contains several gigabytes of compressed data generated from actual intrusions. This data mirrors what analysts might find in real investigations and allows the reader to learn about forensic investigations in a realisticsetting.

© Copyright Pearson Education. All rights reserved.

Synopsis:

You can&#039; t succeed in the field of computer forensics without hands-on practice--and you can&#039; t get hands-on practice without real forensic data. The solution: Real Digital Forensics. In this book, a team of world-class computer forensics experts walks you through six detailed, highly realistic investigations and provides a DVD with all the data you need to follow along and practice. <P>From binary memory dumps to log files, this DVD&#039; s intrusion data was generated by attacking live systems using the same tools and methods real-world attackers use. The evidence was then captured and analyzed using the same tools the authors employ in their own investigations. This book relies heavily on open source tools, so you can perform virtually every task without investing in any commercial software. <P>You&#039; ll investigate environments ranging from financial institutions to software companies and crimes ranging from intellectual property theft to SEC violations. As you move step by step through each investigation, you&#039; ll discover practical techniques for overcoming the challenges forensics professionals face most often.<P>Inside, you will find in-depth information on the following areas: <P>Responding to live incidents in both Windows and Unix environments<P>Determining whether an attack has actually occurred<P>Assembling a toolkit you can take to the scene of a computer-related crime<P>Analyzing volatile data, nonvolatile data, and files of unknown origin<P>Safely performing and documenting forensic duplications<P>Collecting and analyzing network-based evidence in Windows and Unix environments<P>Reconstructing Web browsing, e-mail activity, and Windows Registrychanges<P>Tracing domain name ownership and the source of e-mails<P>Duplicating and analyzing the contents of PDAs and flash memory devices<P>The accompanying DVD contains several gigabytes of compressed data generated from actual intrusions. This data mirrors what analysts might fi

Table of Contents

Preface.

Acknowledgments.

About the Authors.

Case Studies.

I. LIVE INCIDENT RESPONSE.

 1. Windows Live Response.

 2. Unix Live Response.

II. NETWORK-BASED FORENSICS.

 3. Collecting Network-Based Evidence.

 4. Analyzing Network-Based Evidence for a Windows Intrusion.

 5. Analyzing Network-Based Evidence for a Unix Intrusion.

III. ACQUIRING A FORENSIC DUPLICATION.

 6. Before You Jump Right In…

 7. Commercial-Based Forensic Duplications.

 8. Noncommercial-Based Forensic Duplications.

IV. FORENSIC ANALYSIS TECHNIQUES.

 9. Common Forensic Analysis Techniques.

10. Web Browsing Activity Reconstruction.

11. E-Mail Activity Reconstruction.

12. Microsoft Windows Registry Reconstruction.

13. Forensic Tool Analysis: An Introduction to Using Linux for Analyzing Files of Unknown Origin.

14. Forensic Tool Analysis: A Hands-On Analysis of the Linux File aio.

15. Forensic Tool Analysis: Analyzing Files of Unknown Origin (Windows).

V. CREATING A COMPLETE FORENSIC TOOL KIT.

16. Building the Ultimate Response CD.

17. Making Your CD-ROM a Bootable Environment.

VI. MOBILE DEVICE FORENSICS.

18. Forensic Duplication and Analysis of Personal Digital Assistants.

19. Forensic Duplication of USB and Compact Flash Memory Devices.

20. Forensic Analysis of USB and Compact Flash Memory Devices.

VII. ONELINE-BASED FORENSCIS.

21. Tracing E-Mail.

22. Domain Name Ownership.

Appendix: An Introduction to Perl.

Index.

Product Details

ISBN:
9780321240699
Subtitle:
Computer Security and Incident Response [With DVD]
Author:
Jones, Keith J.
Author:
Rose, Curtis W.
Author:
Bejtlich, Richard
Publisher:
Addison-Wesley Professional
Subject:
Computer crimes
Subject:
Computer security
Subject:
Internet - Security
Subject:
Computer crimes -- Investigation.
Publication Date:
September 2005
Binding:
Paperback
Grade Level:
Professional and scholarly
Language:
English
Illustrations:
Y
Pages:
650
Dimensions:
9.14x7.02x1.33 in. 2.19 lbs.

Related Aisles

  • back to top

Powell's City of Books is an independent bookstore in Portland, Oregon, that fills a whole city block with more than a million new, used, and out of print books. Shop those shelves — plus literally millions more books, DVDs, and eBooks — here at Powells.com.