Incident Response and Computer Forensics, Second Edition

3.67 avg rating
( 39 ratings by GoodReads )
 
9780072226966: Incident Response and Computer Forensics, Second Edition

Written by FBI insiders, this updated best-seller offers a look at the legal, procedural, and technical steps of incident response and computer forensics. Including new chapters on forensic analysis and remediation, and real-world case studies, this revealing book shows how to counteract and conquer today’s hack attacks.

"synopsis" may belong to another edition of this title.

Review:

A strong system of defenses will save your systems from falling victim to published and otherwise uninventive attacks, but even the most heavily defended system can be cracked under the right conditions. Incident Response aims to teach you how to determine when an attack has occurred or is underway--they're often hard to spot--and show you what to do about it. Authors Kevin Mandia and Chris Prosise favor a tools- and procedures-centric approach to the subject, thereby distinguishing this book from others that catalog particular attacks and methods for dealing with each one. The approach is more generic, and therefore better suited to dealing with newly emerging attack techniques.

Anti-attack procedures are presented with the goal of identifying, apprehending, and successfully prosecuting attackers. The advice on carefully preserving volatile information, such as the list of processes active at the time of an attack, is easy to follow. The book is quick to endorse tools, the functionalities of which are described so as to inspire creative applications. Information on bad-guy behavior is top quality as well, giving readers knowledge of how to interpret logs and other observed phenomena. Mandia and Prosise don't--and can't--offer a foolproof guide to catching crackers in the act, but they do offer a great "best practices" guide to active surveillance. --David Wall

Topics covered: Monitoring computer systems for evidence of malicious activity, and reacting to such activity when it's detected. With coverage of Windows and Unix systems as well as non-platform-specific resources like Web services and routers, the book covers the fundamentals of incident response, processes for gathering evidence of an attack, and tools for making forensic work easier.

From the Back Cover:

Completely Updated with the Latest Techniques--Contains All-New Forensics Content and Real-World Scenarios

"An insider's look at the legal, procedural and technical steps of computer forensics and analysis." --Information Security magazine

"This book is an absolute must-read for anyone who plays a role in responding to computer security events." --Marc J. Zwillinger, former trial attorney with the U.S. Dept. of Justice, Computer Crime & Intellectual Property

"An excellent resource for information on how to respond to computer intrusions and conduct forensic investigations." --Network Magazine

"If your job requires you to review the contents of a computer system for evidence of unauthorized or unlawful activities, this is the book for you. The authors, through real-world experiences, demonstrate both technically and procedurally the right way to perform computer forensics and respond to security incidents." --Howard A. Schmidt, Former Special Advisor for Cyber Security, White House, and former Chief Security Officer, Microsoft Corp.

New and Updated Material:

  • New real-world scenarios throughout
  • The latest methods for collecting live data and investigating Windows and UNIX systems
  • Updated information on forensic duplication
  • New chapter on emergency network security monitoring
  • New chapter on corporate evidence handling procedures
  • New chapter on data preparation with details on hard drive interfaces and data storage principles
  • New chapter on data extraction and analysis
  • The latest techniques for analyzing network traffic
  • Up-to-date methods for investigating and assessing hacker tools

Foreword by former FBI Special Agent Scott Larson

"About this title" may belong to another edition of this title.

Top Search Results from the AbeBooks Marketplace

1.

Chris Prosise; Kevin Mandia; Matt Pepe
Published by McGraw-Hill/Osborne (2003)
ISBN 10: 007222696X ISBN 13: 9780072226966
New Paperback Quantity Available: 1
Seller
Irish Booksellers
(Rumford, ME, U.S.A.)
Rating
[?]

Book Description McGraw-Hill/Osborne, 2003. Paperback. Book Condition: New. book. Bookseller Inventory # 007222696X

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 44.83
Convert Currency

Add to Basket

Shipping: FREE
Within U.S.A.
Destination, Rates & Speeds

2.

Prosise, Chris; Mandia, Kevin; Pepe, Matt
Published by McGraw-Hill/Osborne
ISBN 10: 007222696X ISBN 13: 9780072226966
New PAPERBACK Quantity Available: 1
Seller
Cloud 9 Books
(West Palm Beach, FL, U.S.A.)
Rating
[?]

Book Description McGraw-Hill/Osborne. PAPERBACK. Book Condition: New. 007222696X New Condition. Bookseller Inventory # NEW6.0927393

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 49.99
Convert Currency

Add to Basket

Shipping: US$ 4.99
Within U.S.A.
Destination, Rates & Speeds

3.

Chris Prosise, Kevin Mandia, Matt Pepe
Published by McGraw-Hill/Osborne (2003)
ISBN 10: 007222696X ISBN 13: 9780072226966
New Paperback Quantity Available: 2
Seller
Murray Media
(North Miami Beach, FL, U.S.A.)
Rating
[?]

Book Description McGraw-Hill/Osborne, 2003. Paperback. Book Condition: New. Bookseller Inventory # P11007222696X

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 53.03
Convert Currency

Add to Basket

Shipping: US$ 2.99
Within U.S.A.
Destination, Rates & Speeds

4.

Chris Prosise/ Kevin Mandia/ Matt Pepe
Published by McGraw-Hill Osborne Media (2003)
ISBN 10: 007222696X ISBN 13: 9780072226966
New Paperback Quantity Available: 1
Seller
Revaluation Books
(Exeter, United Kingdom)
Rating
[?]

Book Description McGraw-Hill Osborne Media, 2003. Paperback. Book Condition: Brand New. 2nd sub edition. 650 pages. 9.00x7.50x1.25 inches. In Stock. Bookseller Inventory # __007222696X

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 94.83
Convert Currency

Add to Basket

Shipping: US$ 7.71
From United Kingdom to U.S.A.
Destination, Rates & Speeds