Computer Forensics: Incident Response Essentials

Computer Forensics: Incident Response Essentials

by Jay G. Heiser (Author), Warren G. Kruse II (Author)

Synopsis

Every computer crime leaves tracks-you just have to know where to find them. This book shows you how to collect and analyze the digital evidence left behind in a digital crime scene.

Computers have always been susceptible to unwanted intrusions, but as the sophistication of computer technology increases so does the need to anticipate, and safeguard against, a corresponding rise in computer-related criminal activity.

Computer forensics, the newest branch of computer security, focuses on the aftermath of a computer security incident. The goal of computer forensics is to conduct a structured investigation to determine exactly what happened, who was responsible, and to perform the investigation in such a way that the results are useful in a criminal proceeding.

Written by two experts in digital investigation, Computer Forensics provides extensive information on how to handle the computer as evidence. Kruse and Heiser walk the reader through the complete forensics process-from the initial collection of evidence through the final report. Topics include an overview of the forensic relevance of encryption, the examination of digital evidence for clues, and the most effective way to present your evidence and conclusions in court. Unique forensic issues associated with both the Unix and the Windows NT/2000 operating systems are thoroughly covered.

This book provides a detailed methodology for collecting, preserving, and effectively using evidence by addressing the three A's of computer forensics:

  • Acquire the evidence without altering or damaging the original data.
  • Authenticate that your recorded evidence is the same as the original seized data.
  • Analyze the data without modifying the recovered data.

Computer Forensics is written for everyone who is responsible for investigating digital criminal incidents or who may be interested in the techniques that such investigators use. It is equally helpful to those investigating hacked web servers, and those who are investigating the source of illegal pornography.



0201707195B09052001

$3.47

Save:$55.47 (94%)

Quantity

1 in stock

More Information

Format: Illustrated
Pages: 416
Edition: 01
Publisher: Addison Wesley
Published: 26 Sep 2001

ISBN 10: 0201707195
ISBN 13: 9780201707199
Book Overview:

Computer forensics is any form of thorough and organized computer security investigation that seeks to determine what sequence of events occurred when a misuse or crime is suspected. Now, two leading investigators present the first complete guide to the field: investigative methods, tracking, evidence collecting, reporting, tools, legal issues, and more. With this practical book, any computer or legal professional can master the key skills of the professional computer forensics expert. The authors introduce the basic processes of computer forensics, evidence collection and analysis, demonstrating how to interpret clues inside mail messages and news postings, on hard drives and other computer storage media. The book contains forensics-oriented introductions to cryptography and encryption, digital signatures and time stamping, finding hidden data, handling hostile code, and contending with other hacker tools and robots. The final chapter provides an overview of the criminal justice process as it relates to computer security investigations -- including topics such as affidavits, subpoenas, warrants, and the chain of custody. For computer security professionals, system and network administrators, and law enforcement officials and consultants concerned with computer crime and investigations.


Author Bio



0201707195AB05232001